Privacy Policy

1.0 Introduction

1.1. KSR Architects is committed to protecting the personal information of visitors to our office and website, including clients (current and future), suppliers and contractors.
1.2. This privacy statement provides information about the personal information that KSR Architects collects about all external and third parties such as visitors to our studio and website, clients current and future, suppliers and contractors, and the ways in which our practice uses that personal information.
1.3. Any questions regarding this Policy and our privacy practices should be sent by email to KSR Architects:

2.0 How do we collect information from you?

2.1. Our website: you can visit our website without providing any personal information, however certain information such as IP addresses, information about your visit and how you use our website may be collected automatically by Google Analytics or equivalent. You may provide us with information by corresponding with us by phone, email, or otherwise as indicated on the website.
2.2. Visiting our Studio: when you visit our studio, you will be asked to provide your name and the company you work for. This information is recorded manually by Reception for safety reasons so we know who is in the building at any one time. These records are shredded on a monthly basis.
2.3. Events: f you are invited to an event which KSR is hosting you will be asked to confirm your name and the company you are representing. You may be provided with a name badge, if appropriate for the event. There is a high chance that there will be photographers to create a record of the event and possibly which may be used on our social media sites and publications and if that is the case you will be informed beforehand and invited to indicate if you do not wish your photograph to be taken.

3.0 What type of information is collected from you?

3.1. The personal information you provide may include your name, company address, e-mail address, phone number and other information about yourself to enable us to provide you with our services.

4.0 How is your information used?

4.1. When we collect personal information from our clients and other members of the public, it will be used for the following purposes:

  • To maintain responsible commercial relations with you
  • To understand your service and/or project needs
  • To manage and develop our business and operations
  • To meet legal and regulatory requirements
  • To notify you of changes to our services
  • To process a job application if appropriate
  • To recommend your product or service to relevant contacts within the industry.

4.2. We are legally required to hold some types of information to fulfil our statutory obligations. We will hold your personal information on our systems for as long as is necessary for the relevant activity.
4.3. When you voluntarily give us your personal information we will only use it for the above purposes. If we intend to use your personal information for a purpose other than those above, we will seek your express consent.

5.0 Who will it be shared with?

5.1. We will not share your information with third parties for any reason other than those specified above.

6.0 Your rights

6.1. You will have been deemed to agree to having personal information held on you however you have the right to ask us not to process this. You can exercise this right by contacting us at
6.2. Should our website include links to other websites that may offer useful information to our visitors, please note, that this privacy statement does not apply to these links and we do not accept responsibility or liability for their policies.
6.3. You also have the right to see and correct data that we hold about you. If your details change or any other information we hold is inaccurate or out of date, please contact us at

7.0 Security

7.1. KSR Architects will take reasonable technical and organisational precautions to ensure that your personal information is treated securely. We will store all personal information you provide on our secure servers.
7.2. We use a least privilege access to data approach, restricting access to only those who need to so they can discharge their duties.
7.3. In addition, we have deployed a number of systems to ensure your data remains safe, these include:

  • Carry out vulnerability testing on all desktops to ensure that no known issues exist that would allow applications to be hijacked.
  • A program of regular patch management, this ensures desktops and servers stay up to date with latest security patches.
  • Carrying out regular phishing testing, to ensure users are aware of the dangers of phishing emails, part of this testing includes informing users of risks
  • We use firewalls to protect our network borders, to stop our data being breached.
  • All desktops run antivirus and anti-ransomware software.
  • Taking regular backups
8.0 WI-FI

8.1. We provide access to the internet while you are in the studio, it is securely configured to separate our corporate data from internet browsing. As a guest you will be asked to logon to a secure portal that will grant you access to browse the internet only. We do not store any information about your connection or the sites you visit.

9.0 16 or Under

9.1. We do not collect any personally identifiable information from children aged 16 or under without prior verifiable consent from their parent/guardian.

10.0 Data Breaches and reporting

10.1. If it becomes apparent that a potential data breach has occurred, KSR Architects will endeavour to report this to the ICO within 72 hours of becoming aware of the data breach. This will be the case if the data breach is likely to result in damage to a persons reputation, financial loss, loss of confidentiality, or major financial or social disadvantage. If the breach is likely to result in a high risk to the rights and freedoms of the data subject KSR Architects will also contact the data subject without undue delay.
10.2. Data breaches will be reported to the Information Commissioner Office (ICO) by calling the dedicated personal data breach helpline on 0303 123 1113.

1.0 Introduction

1.1. The wording in this document reflects the requirements of the General Data Protection Regulation (GDPR), which will be in effect in the UK from 25 May 2018. See Law relating to this document below for more information.
1.2. Data controller: KSR Architects
1.3. As part of any recruitment process, KSR Architects collects and processes personal data relating to job applicants. KSR Architects is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations.

2.0 What information does KSR Architects collect?

2.1. KSR Architects collects a range of information about you. This includes

  • Your name, address and contact details, including email address and telephone number;
  • Details of your qualifications, skills, experience and employment history;
  • Information about your current level of remuneration, including benefit entitlements;
  • Whether or not you have a disability for which KSR Architects needs to make reasonable adjustments during the recruitment process;
  • Information about your entitlement to work in the UK.

2.2. KSR Architects collects this information in a variety of ways. For example, data might be contained in application forms, CVs or resumes, obtained from your passport or other identity documents, or collected through interviews or other forms of assessment, including online tests.
2.3. KSR Architects will also collect personal data about you from third parties, such as references supplied by former employers. KSR Architects will only seek information from third parties once a job offer to you is being considered, and will inform you that it is doing so.
2.4. Data will be stored on your application record within secure HR management systems and on other IT systems (including email).

3.0 Why does KSR Architects process personal data?

3.1. KSR Architects needs to process data at your request to take steps prior to entering into a contract with you. It also needs to process your data in order to enter into a contract with you.
3.2. In some cases, KSR Architects needs to process data to ensure that it is complying with its legal obligations. For example, it is required to check a successful applicant’s eligibility to work in the UK before employment starts.
3.3. KSR Architects has a legitimate interest in processing personal data during the recruitment process and for keeping records of the process. Processing data from job applicants allows KSR Architects to manage the recruitment process, assess and confirm a candidate’s suitability for employment and decide to whom to offer a job. KSR Architects may also need to process data from job applicants to respond to and defend against legal claims.
3.4. Where KSR Architects relies on legitimate interests as a reason for processing data, it has considered whether or not those interests are overridden by the rights and freedoms of employees or workers and has concluded that they are not.
3.5. KSR Architects processes health information if it needs to make reasonable adjustments to the recruitment process for candidates who have a disability. This is to carry out its obligations and exercise specific rights in relation to employment.
3.6. If your application is unsuccessful, KSR Architects will keep your personal data on file for up to 12 months in case there are future employment opportunities for which you may be suited. If KSR Architects requires to keep your information for longer you will be asked for your consent. You are free to withdraw your consent at any time.

4.0 Who has access to data?

4.1. Your information will be shared internally for the purposes of the recruitment exercise. This includes members of the administration and recruitment team, interviewers involved in the recruitment process, managers in the business area with a vacancy and IT staff if access to the data is necessary for the performance of their roles.
4.2. KSR Architects will not share your data with third parties, unless your application for employment is successful and it makes you an offer of employment. KSR Architects will then share your data with former employers to obtain references for you.
4.3. KSR Architects will not transfer your data outside the European Economic Area.

5.0 How does KSR Architects protect data?

5.1. KSR Architects takes the security of your data seriously. It has internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by the relevant employees of KSR Architects in the proper performance of their duties.
5.2. Job applications are only received via email and are held securely on our email server, only being made available to the appropriate employees to perform their duties, for example Administration in arranging interviews and the Recruitment team of senior staff. We backup the mailbox that received the application securely.
5.3. Applications for successful candidates only are moved from email to a secure location on the network. All data access is strictly controlled using the least access privilege approach.

6.0 how long does KSR Architects keep data?

6.1. If your application for employment is unsuccessful, KSR Architects will hold your data on file for up to twelve months after the end of the relevant recruitment process. At the end of that period [or once you withdraw your consent], your data is deleted or destroyed.
6.2. If your application for employment is successful, personal data gathered during the recruitment process will be transferred to your personnel file and retained during your employment. The periods for which your data will be held will be provided to you in a new privacy notice.

7.0 Your rights

7.1. As a data subject, you have a number of rights. You can:

  • Access and obtain a copy of your data on request;
  • Require KSR Architects to change incorrect or incomplete data;
  • Require KSR Architects to delete or stop processing your data, for example where the data is no longer necessary for the purposes of processing;
  • Object to the processing of your data where KSR Architects is relying on its legitimate interests as the legal ground for processing; and
  • Ask KSR Architects to stop processing data for a period if data is inaccurate or there is a dispute about whether or not your interests override KSR Architects’ legitimate grounds for processing data.

7.2. If you would like to exercise any of these rights, please contact the Office Manager –
7.3. If you believe that we have not complied with your data protection rights, you should first take it up with the Office Manager. If after investigation you feel that your rights are still compromised you can escalate this to the Information Commissioners Office (ICO). The ICOs contact details are available at

8.0 Data Breaches and reporting

8.1. If it becomes apparent that a potential data breach has occurred, KSR Architects will endeavour to report this to the ICO within 72 hours of becoming aware of the data breach. This will be the case if the data breach is likely to result in damage to a persons reputation, financial loss, loss of confidentiality, or major financial or social disadvantage. If the breach is likely to result in a high risk to the rights and freedoms of the data subject KSR Architects will also contact the data subject without undue delay.
8.2. Data breaches will be reported to the Information Commissioner Office (ICO) by calling the dedicated personal data breach helpline on 0303 123 1113.

9.0 What if you do not provide personal data?

9.1. You are under no statutory or contractual obligation to provide data to KSR Architects during the recruitment process. However, if you do not provide the information, KSR Architects may not be able to process your application properly or at all.
9.2. Automated decision-making is not used as part of the recruitment processes.