Privacy policy introduction
Resilient ESG Governance Services Limited respects the privacy of its customers, suppliers and partners. We have therefore formulated and implemented a policy on complete transparency regarding the processing of personal data, its purpose(s) and the possibilities to exercise your legal rights in the best possible way. For employees, we have formulated a separate privacy policy, available upon employment and upon request.
Definitions
Party responsible for processing personal data: Resilient ESG Governance Services Limited; with registered address at 20 Humber Road, London SE3 7LT in United Kingdom and company registration number 12512181 (the “Controller”).
Data Protection Authority: The Data Protection Authority of United Kingdom.
Data Protection laws:
For European citizens or residents, the EU GDPR 2018; the EU e-privacy directive 2002 (soon to be replaced by the EU e-privacy regulation);
For UK citizens or residents, the UK GDPR 2020 and the UK Data Protection Act 2018 and/or the national laws of United Kingdom.
Collection of data
Your personal data will be collected by Resilient ESG Governance Services Limited and its data processors.
Personal data means any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
The types of personal data we may process:
Business process Website-Type: Identification; Data subject: Customers; Legal basis: Consent
Business process Email-Type: Financial, Contracts; Data subject: Customers, Employees, Contractors, Suppliers, Partners; Legal basis: Legitimate interest
Business process Storage and exchange of documents-Type: Financial; Data subject: Customers; Legal basis: Legitimate interest
Business process Delivery of goods and services-Type: Identification, Financial, Date of Birth, Educational and employment history, Copy of ID, Location, Social Security Number, Contracts; Data subject: Customers, Employees, Contractors, Suppliers; Legal basis: Performance of a contract
Business process Financial and business administration-Type: Identification, Financial, Date of Birth, Educational and employment history, Copy of ID, Health, Location, Social Security Number, Contracts; Data Subject: Customers, Employees, Contractors, Suppliers; Legal basis: Legitimate interest
Business process Marketing-Type: Identification, Location; Data subject: Customers; Legal basis: Consent
Purposes
Resilient ESG Governance Services Limited processes personal data for one or more of the following purposes:
How we collect, store or otherwise process your data:
The following business processes describe how we may collect, store or otherwise process the types of personal information set out in the table above:
Sharing data with third parties
We may have to share your data with third parties, including third-party service providers. We require third parties to respect the security of your data and to treat it in accordance with the law.
We may transfer your Personal Data outside United Kingdom. If we do, you can expect a similar degree of protection in respect of your Personal Data.
We will only share your Personal Data with third parties in accordance with the GDPR and as outlined in the legal justification table above.
We also share your data with SME third parties, details of which are available upon request. You will be notified when we have engaged with a new third party recipient of your personal data.
For a list of our third party suppliers, please email Andrew.Riley@resilientesg.com.
International data transfers
The third parties we have engaged for the abovementioned business process may transfer your personal information to outside of United Kingdom. Resilient ESG Governance Services Limited’s third party processors take all necessary measures to ensure the confidentiality, availability and integrity of personal data and to comply with the EU GDPR and UK GDPR (“GDPR”) with regards to international data transfers. The international nature of its compliance certifications, as well as far-reaching technical security measures (including but not limited to encryption of the personal data, making the data illegible to an unauthorised recipient) are sufficient to ensure that the data subjects continue to benefit from the fundamental rights they are entitled to under the GDPR.
Resilient ESG Governance Services Limited relies on processing agreements with these sub-processors that include the model clauses (or “Standard Contractual Clauses”) which have been tested on the adequacy of its protection with regards to the specific sub-processing activities carried out in this particular sub-processing relationship.
Storage and protection of data
Your data is protected by Resilient ESG Governance Services Limited and its processors in pursuance to all legal requirements set by the relevant data processing laws. Resilient ESG Governance Services Limited has taken technical and organizational security measures to protect your data and requires its data processors to meet the same requirements. Resilient ESG Governance Services Limited has signed processing agreements with its processors to ensure an adequate level of data protection. The following security measures are taken by Resilient ESG Governance Services Limited to protect your personal data in the course of the listed business processes:
Organisational security measures
Staff
Resilient ESG Governance Services Limited staff members are required to conduct themselves in a manner consistent with Resilient ESG Governance Services Limited’s guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. All staff members and subcontractors undergo appropriate background checks and are made aware of their responsibility in protecting customer data.
We continuously remind staff members on best security practices, including how to identify social hacks, phishing scams, and hackers.
Access controls
Resilient ESG Governance Services Limited maintains your data privacy by allowing only authorized individuals access to information when it is critical to complete tasks for you. Resilient ESG Governance Services Limited staff members will not process customer data without authorization.
Data hosting
As a rule, data is hosted within United Kingdom, but it is possible that we might transfer personal data to countries within the EEA, to the UK or in exceptional circumstances outside of those areas. We ensure that we comply with the GDPR and the DPA when sending data overseas by relying on data processing agreements containing standard contractual clauses with our sub-processors or by taking additional measures to secure this data transfer, such as anonymisation.
Physical security
The data centres on which personal data is hosted are secured and monitored 24/7 and physical access to facilities is strictly limited to select staff.
Technical security measures
All devices which are used to access personal data for which we are responsible are secured with antivirus software, firewalls, encryption and access management. We regularly update operating systems and software to ensure vulnerabilities cannot be exploited.
Your rights regarding information
Each data subject has the right to information on and access to, and rectification, erasure and restriction of processing of their personal data, as well as the right to object to the processing and the right to data portability.
You can exercise these rights by contacting us at the following email address: Andrew.Riley@resilientesg.com.
Each request must be accompanied by a copy of a valid ID, on which you put your signature and state the address where we can contact you. Ensure that you write “Data Request” in the subject line of your email.
Within one month of the submitted request, you will receive an answer from us. We will not charge you for submitting your request unless the request is manifestly unfounded or otherwise unreasonable in its nature. Depending on the complexity and the number of the requests this period may be extended to two months.
Marketing
Data retention
The collected data are used and retained for the duration determined by law. You may, at any time, request your data to be deleted from any Resilient ESG Governance Services Limited account, system or other data processing medium in accordance with the process described above.
Applicable law
These conditions are governed by United Kingdom legislation. The court in the district where the collector has its place of business has the sole jurisdiction if any dispute regarding these conditions may arise, save when a legal exception applies.
Contact
For questions about this privacy policy, product information or information about the website itself, please contact: Andrew.Riley@resilientesg.com.
Safeguards for international data transfers
Resilient ESG Governance Services Limited’s third party processors take all necessary measures to ensure the confidentiality, availability and integrity of personal data and to comply with the GDPR with regards to international data transfers. The international nature of its compliance certifications, as well as far-reaching technical security measures (including but not limited to encryption of the personal data, making the data illegible to an unauthorised recipient) are sufficient to ensure that the data subjects continue to benefit from the fundamental rights they are entitled to under the GDPR.
Resilient ESG Governance Services Ltd
20 Humber Road, Blackheath, London SE3 7LT
Copyright © 2025 Resilient ESG - All Rights Reserved.