Liaison Systems Privacy Notice


About us


Liaison Systems Limited is a company registered in England under company registration number 06373241 and having its registered office address at Office C Maple Barn, Beeches Farm Road, Uckfield, East Sussex, TN22 5QD (Liaison Systems).


In this document, the following definitions shall apply:

EU Standard Contractual Clauses for Controllers

means the controller-to-controller clauses set out in decision 2004/915/EC (Set II)

Personal Data

means any information relating to an identified or identifiable natural person


means a person or organisation which determines the purposes and means of the processing of Personal Data


means a person or organisation which processes Personal Data on behalf of a Controller

SAAS Services

the supply and support of business to business web applications

Shared Information

the information provided by Subscribers which is shared with other Subscribers where this sharing is part of the normal functioning of our applications

Special Categories of Personal Data

Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation


corporate users of our SAAS services

About this Privacy Notice

This Privacy Notice sets out how Liaison Systems uses and protects any Personal Data that you give us when you use our SAAS Services or which we otherwise collect from personnel of our Subscribers and prospective Subscribers in connection with the purchase or delivery of our SAAS Services. Liaison Systems acts as Controller in relation to all of this Personal Data unless otherwise specified in our product terms and conditions or licence agreement. This Privacy Notice applies to Personal Data which we process as Controller. It does not apply to Personal Data which we process as Processor.

Liaison Systems may change this Privacy Notice from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This Privacy Notice is effective from June 2018 and was most recently amended in August 2020.

What we collect

The Personal Data we collect comprises:

  • Name, organisation, username and personal corporate email address in relation to users of our SAAS services
  • Name, organisation and national insurance number of workers included in documents or responses uploaded to our SAAS Services
  • Name, organisation and some career information (such as trade qualifications) in relation to individuals with health and safety responsibility where this information is included in documents or responses uploaded to our SAAS Services
  • Name, organisation, signature and personal corporate email address in relation to the personnel of our Subscribers and prospective Subscribers who are involved in subscribing or renewing subscriptions to our SAAS Services
  • Cookie identifiers

The Personal Data we gather using our SAAS Services is kept to the minimum required in order to carry out the specific tasks performed by our applications. In particular, we do not collect any Special Categories of Personal Data or Personal Data relating to criminal convictions.

How is this information gathered?

We collect Personal Data in the following ways:

  • By upload to our SAAS Services or which is otherwise provided to us by Subscribers in connection with the use of our SAAS Services
  • When you complete electronic forms, e.g. when registering as a user of one of our SAAS Services
  • In emails and hard copy correspondence sent to us
  • When taking notes during telephone calls
  • When providing support services to users of our SAAS Services
  • Using cookies where this is necessary for the operation of our SAAS Services

When the provision of Personal Data is mandatory

We are unable to register you as a user of our SAAS Services unless you provide us with an email address and user name. However, if you wish your username may be pseudonym.

What we do with the information we gather

We use the Personal Data we collect for the following purposes:

  • To provide our SAAS Services
  • For record-keeping, accounting, credit control and other management and administrative purposes
  • To comply with legal obligations
  • To defend against legal claims and to enforce our legal rights
  • To protect the security of our systems
  • To complete corporate reorganisations and disposals of assets and undertakings
  • To market and promote our SAAS Services (we will only use the email addresses of personnel of our Subscribers for marketing purposes where the individual was involved in the negotiation to purchase our SAAS Service)

We do not use Personal Data for automated decision-making in relation to data subjects.

Maintaining data accuracy

Every twelve months from the initial date of registration, Liaison Systems asks its Subscribers to review and update the information held in our system, including the Personal Data of users.

Subscribers can change or update user access details at any time. This should be done immediately if the person responsible for entering the information has left the company or responsibility has been handed over to someone else.

Legal Basis for processing Personal Data

We process Personal Data for most purposes on the basis of our legitimate interests in providing our SAAS Services and marketing and developing those services. Where it is necessary for us to process Personal Data for the purpose of complying with a legal obligation, we also process Personal Data on this basis.

Retention of Personal Data

A Subscriber (not an individual user) may request the deletion of their account in any of our SAAS Services at any time but will not be entitled to any refund of charges paid for the unexpired period of the service. Cookies used by our SAAS Services are session specific and expire on termination of the session.

The deletion of an account will not include the deletion of information which is required to be stored by Liaison Systems for legal compliance, billing purposes or record-keeping purposes.

Where we do not receive a request to delete as aforesaid, Personal Data held in our SAAS Services will be deleted within 12 months of the expiry of the Subscriber's subscription or termination of access to the Subscriber's account for any other reason.

Personal Data used for marketing purposes may continue to be processed for that purpose until you ask us not to do so.

Personal Data used for billing and record keeping purposes will usually be retained for 7 years after the end of the financial year in which it is collected.

Personal Data being processed for legal compliance purposes will be retained until such time as retention for these purposes becomes unnecessary.

How we use cookies

When a user visits Samson, the server establishes a unique session for that user that lasts for the duration of the user's visit. For each session, Samson maintains session state information where it can store user-specific information.

Samson must track a session ID for each user so that it can map the user to session state information on the server. Samson uses a non-persistent cookie to store the session state. However, if a user has disabled cookies on the browser, session state information cannot be stored in a cookie.

Because the cookies used by Samson have a short life and are used only for user input and authentication we are not required to obtain consent for their use.

Recipients of Personal Data

We transfer Personal Data to the following categories of recipients:

  • Subscribers to our SAAS Services, limited to the Shared Information
  • Service providers (acting as Processors) based in the United Kingdom who provide hosting of our SAAS Services
  • Service providers, sub-contractors and insurers where there is a business need for them to receive the Personal Data
  • Auditors and professional advisers (acting as Processors or Controllers), including lawyers, bankers and insurance companies who provide auditing or consultancy, banking, legal, insurance and accounting services
  • Successors in title to any assets or undertakings with which the Personal Data is associated (acting as Controllers)
  • Public bodies, taxation authorities, courts, regulators or law enforcement agencies where this is required by law or in connection with the establishment, exercise or defence of legal claims (acting as Controllers)

International Transfers of information

Shared Information may be transferred internationally to a Subscriber who is accessing one of our SAAS Services from outside of the combined area of the UK and the European Economic Area. Such transfers are made on the basis of a finding of adequacy in relation to the laws of the relevant country by the European Commission, the United Kingdom government or the Information Commissioner's Office and where no such finding of adequacy exists, on the basis of the EU's Standard Contractual Clauses for Controllers as incorporated into agreements with our Subscribers.

Your rights

You have the right to:

Request access to your Personal Data (commonly known as a "data subject access request"). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.

Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your Personal Data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of your Personal Data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your Personal Data to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

Complain to complain to the supervisory authority in connection with our processing of your personal data. You can exercise this right by contacting the Office of the Information Commissioner at

Contact us If you have any questions in relation to our processing of your Personal Data you can contact us at or by post addressed to the Chief Technical Officer at the address stated above.