Privacy Notice

This notice applies to all websites, applications, services and products developed, provided or delivered by The Manufacturers’ Information Hub (UK) (The MIH).

The Manufacturers’ Information Hub Limited (“The MIH”) is a company limited by guarantee registered in England and Wales under company number 16887975, with its registered office at Pipits, Chapel Lane, Curdridge, Southampton, Hampshire, United Kingdom, SO32 2BB. The sole member of The MIH is The Manufacturers’ Information Hub (EUROPE) AISBL, a Belgian international non-profit association (AISBL), registered under company number 1037.366.894.

The MIH processes personal data in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable UK data protection laws. The EU General Data Protection Regulation may also apply where The MIH’s activities fall within its territorial scope. This notice is set out to help you understand the types of data that we collect from you, and/or your business, and how that data is used and managed.

Commitment

MIH is committed to protecting the privacy and security of personal data. We monitor compliance by implementing policies and procedures designed to safeguard personal data and by reviewing those measures regularly.

Data Controller

The MIH is registered with the Information Commissioner’s Office under registration number ZC190868. The MIH is the data controller where it determines why and how personal data is processed in connection with its websites, applications, products, services, membership activities, stakeholder engagement and organisational administration. In some circumstances, another organisation may act as a separate controller, joint controller or processor. Where relevant, we will explain those arrangements to you.

About Us

The MIH is an organisation that supports manufacturers by providing access to information, resources, and services relevant to the manufacturing sector.

Who we collect data from

We collect personal data from a range of sources, including:

  • Directly from you – when you register for services, create an account, contact us, or sign up for communications
  • Your employer or organisation – where your organisation engages with The MIH services or provides your details as a contact
  • Partner organisations – where referrals or joint working arrangements are in place
  • Publicly available sources – such as company websites or professional directories
  • Third-party service providers – where they support the delivery of our services (for example, event platforms or registration systems)
  • Employers, engaging organisations and sending organisations – where they provide limited information needed to establish or administer an employment, contractor or secondment arrangement.
  • The MIH systems and service providers – where information is generated through use of The MIH accounts, platforms, communications, support services, security logs or collaboration tools.

Where you interact directly with another organisation, that organisation may process your information under its own privacy notice, which you should review.

What data do we collect

We may collect and process the following personal data:

  • Name, job title and professional role
  • Contact information, such as email address, telephone number and postal address where required
  • Organisation or company details, including company number and your authority to represent an organisation
  • Account, registration and login information
  • Membership, subscription and service-access information
  • Records of enquiries, communications, meetings, support requests and relationship history
  • Event and webinar registration, attendance, feedback and participation information
  • Professional profile, qualifications, experience and organisation-verification information
  • Marketing and communication preferences
  • Payment, invoice, expense and transaction information
  • Information relating to products, services, resources or platforms you access or request
  • Technical and usage data, such as IP address, browser, device, login, audit and website usage information
  • Security, access-control and IT support information
  • Audio, video recordings and transcripts where meetings, calls or webinars are recorded
  • Information relating to employees, workers, contractors and secondees, such as role, working arrangements, training, performance, equipment, expenses and system access
  • Limited health, reasonable-adjustment or other special-category information where necessary and lawful
  • Information processed through approved AI-assisted or automated tools where relevant to the service or activity

We will only collect the information that is necessary and proportionate for the relevant purpose, and not every category above will apply to every individual.

How and why we use your data

We use personal information for the following purposes:

Category Purpose How we use it Lawful basis
Contact, organisation and professional information To communicate with you and manage The MIH’s relationships To respond to enquiries, identify your role and organisation, confirm your authority to act, maintain contact details and tailor relevant services and communications Contract where applicable; legitimate interests
Account, membership and service-access information To provide and administer The MIH products, services, memberships and digital platforms To register users, manage memberships and subscriptions, authenticate access, administer benefits and provide access to websites, applications, portals, resources and services Contract; legitimate interests
Organisation and eligibility verification information To confirm eligibility, identity and authority To verify company details, professional roles, email domains, membership eligibility and authority to represent an organisation Legitimate interests; legal obligation where applicable
Communications, enquiries and relationship records To manage relationships and maintain appropriate records To record correspondence, meetings, support requests, decisions, actions, complaints and relationship history Legitimate interests; legal obligation where applicable
Marketing and communication preferences To send relevant news and promotional information To send newsletters, event invitations, updates and industry information, and to manage preferences, objections and suppression records Consent or legitimate interests, as appropriate; PECR where applicable
Event, webinar and participation information To organise, deliver and improve events To manage registration, attendance, joining instructions, questions, feedback, follow-up, attendee interaction and information shared with event partners where explained Contract; legitimate interests
Recordings, transcripts and professional profiles To maintain records and support networking or visibility To record selected meetings or events, prepare minutes and summaries, and display or share professional profiles, photographs or biographies where appropriate Legitimate interests; consent where appropriate
Employee, worker, contractor and secondee information To establish and manage working relationships To recruit, onboard, allocate and supervise work, manage attendance, performance, training, expenses, equipment, workplace safety, access and the ending of an engagement Contract; legal obligation; legitimate interests
Employer and sending-organisation information To administer employment, contractor and secondment arrangements To receive and share necessary information about status, role, dates, attendance, training, performance, welfare, expenses, conduct, safety and changes to an arrangement Legitimate interests; legal obligation where applicable
Payment, invoice and transaction information To manage payments and financial administration To issue invoices, receive payments, manage subscriptions, process expenses and refunds, collect sums due and maintain accounting, tax and audit records Contract; legal obligation; legitimate interests
Website, technical, cookie and usage information To operate, secure and improve The MIH’s websites, applications and services To understand use and performance, manage cookies and preferences, diagnose faults, maintain functionality and improve user experience Legitimate interests; consent where required under PECR
Security, access and IT-support information To protect The MIH’s systems, people and information To authenticate users, manage access, monitor activity, investigate incidents, prevent misuse or fraud and provide technical support Legitimate interests; legal obligation; contract where applicable
Health, disability and other sensitive information To meet legal duties and provide appropriate support To make reasonable adjustments, manage accessibility, health and safety, emergencies and other necessary support arrangements Legal obligation; legitimate interests; applicable Article 9 condition
Criminal-offence, vetting and conduct information To meet legal, security or role requirements and investigate concerns To carry out permitted checks and manage complaints, conduct, capability, grievances, security incidents, disputes and legal claims Legal obligation or legitimate interests, with an applicable DPA 2018 condition where required
Legal, regulatory, governance and publicly available information To comply with law and manage The MIH responsibly To maintain records for legal, regulatory, audit, insurance, funding and governance purposes, and to use appropriate public sources such as Companies House and professional directories Legal obligation; legitimate interests
Partner, referral and social-media information To work with other organisations and engage stakeholders To manage referrals, jointly delivered services, partnerships, campaigns, messages and professional engagement through social media and other channels Legitimate interests; contract or consent where applicable
AI-assisted and automated processing To support approved activities if The MIH and improve efficiency To assist with drafting, summarising, transcription, analysis, administration, security and approved workflows, subject to appropriate safeguards and human oversight The lawful basis applying to the underlying processing purpose
Organisational change and legal claims information To protect The MIH and manage corporate changes To establish, exercise or defend legal claims and manage restructuring, mergers, funding, investment or transfers of The MIH activities Legitimate interests; legal obligation

The lawful basis used will depend on the particular circumstances. Not every category or purpose applies to every individual. Where The MIH relies on legitimate interests, we consider whether the processing is necessary and whether individuals’ rights and interests override those interests. Where consent is used, it may be withdrawn at any time. Electronic marketing and non-essential cookies are also subject to the Privacy and Electronic Communications Regulations.

Who are our stakeholders

The MIH works with a range of stakeholders to deliver our services and support the manufacturing sector.

Our stakeholders include:

  • Manufacturers and engineering businesses
  • Industry bodies and trade associations
  • Supply chain partners and suppliers
  • Public sector organisations and enterprise agencies
  • Partner organisations delivering support services
  • Funders and supporters
  • Staff and governance
  • Professional contacts and service providers
  • Members and registered users of the The MIH platform

How we protect your personal data

The MIH recognises the importance of data security and takes appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, misuse, alteration, destruction, unauthorised access or disclosure.

Depending on the nature of the information and the systems used, these measures may include:

  • secure website connections;
  • password protection and multi-factor authentication;
  • access controls based on role and business need;
  • encryption and secure transfer methods;
  • system monitoring, audit logging and security testing;
  • staff training and confidentiality requirements;
  • supplier security and data protection requirements; and
  • processes for managing security incidents and personal data breaches.

Access to personal data is limited to authorised individuals who need it for their role. The MIH regularly reviews its security measures and updates them where appropriate, taking account of the nature of the personal data, the risks involved and changes in technology.

No method of electronic transmission or storage is completely secure. However, The MIH takes reasonable and proportionate steps to protect personal data and to respond promptly if a security incident occurs.

Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including applicable legal, accounting and reporting requirements. Retention periods vary according to the type of information, the reason it is used and our legal obligations. When information is no longer required, we will securely delete or anonymise it. You may contact us for further information about applicable retention periods.

Who we share personal data with

We may share personal data with other organisations where this is necessary to provide our products, services and activities, manage our organisation, comply with legal obligations or protect our legitimate interests.

Depending on the circumstances, these organisations may include:

  • Staff, workers, contractors, consultants and secondees involved in delivering The MIH activities
  • Partner organisations involved in jointly delivered services, projects, events or funded programmes
  • Organisations that refer individuals to The MIH or receive referrals from The MIH
  • Website, application, platform and hosting providers
  • IT support, cybersecurity and data-storage providers
  • Email, online meeting, webinar and communication-platform providers
  • Customer relationship management and membership-platform providers
  • Portal developers and service providers
  • Event, training and workshop providers
  • Payment, banking, accounting and expense providers
  • Professional advisers, including lawyers, accountants, auditors, insurers and consultants
  • Funders, public bodies and organisations involved in programme monitoring or evaluation
  • Employers or sending organisations in connection with an employee, contractor or secondment arrangement
  • Regulators, government bodies, courts and law-enforcement agencies where required or permitted by law
  • Organisations involved in a merger, restructuring, investment, sale or transfer of The MIH activities

Some recipients process personal data only on The MIH’s instructions and act as data processors. Other organisations determine how they use personal data for their own purposes and act as independent data controllers. In limited circumstances, The MIH and another organisation may jointly determine a processing activity.

We only share personal data where there is an appropriate lawful basis and the information shared is necessary, relevant and proportionate for the purpose.

Where an event, webinar or programme is delivered with another organisation, we may share registration, attendance, participation or feedback information with that organisation where this is necessary and has been explained to you. Other attendees may see your name, profile, questions, comments or contributions where these are visible within the event platform.

Where an individual is seconded to The MIH, The MIH may receive limited personal information from the individual’s employer or sending organisation and may provide limited information back where necessary to support and manage the secondment or enable the employer to meet its continuing employment responsibilities. The categories and purposes of routine sharing should be set out in the applicable secondment information-sharing schedule.

Website

The MIH collects personal data through website forms used for enquiries, account registration, event registration and access to services. The particular information requested will be shown on the relevant form. Mandatory and optional fields will be identified at the point of collection.

Social Media

The MIH uses social media platforms such as LinkedIn and YouTube to communicate about our services, products, events and activities, respond to enquiries and engage with stakeholders. When you interact with The MIH on social media, we may process your name, username, public profile information, comments, messages, reactions and any other information you choose to share with us. We use this information to manage our social media presence, respond to enquiries, promote The MIH activities and understand how people engage with our content. We normally rely on our legitimate interests, although we will obtain consent where this is required.

The MIH may tag or mention individuals or organisations in a professional context, for example when promoting events or collaborative work. We will consider reasonable requests to remove or amend a tag or mention. Social media platforms process personal information under their own privacy notices. The MIH is responsible for the information it collects and uses through its own pages, messages and campaigns, while the platform will normally act as a separate data controller for its own processing. Where The MIH uses targeted advertising, retargeting, analytics or similar tools, we will provide appropriate information and obtain consent where required. You should avoid posting sensitive or confidential information in public comments and use a private contact method where necessary.

Payment Data

The MIH may collect and process personal and financial information to issue invoices, receive payments, manage subscriptions, process refunds and maintain accounting records.

Where The MIH invoices an organisation or individual, we may process information such as:

  • name and job title;
  • organisation name;
  • billing and postal address;
  • email address and telephone number;
  • purchase order or invoice reference;
  • payment status and transaction history; and
  • other information needed to manage the account or payment.

Some payments may be made through Stripe. Where Stripe is used, payment-card details are entered directly into Stripe’s secure payment system. The MIH does not normally receive or store full payment-card details. The MIH may receive limited transaction information, such as the payer’s name, payment amount, payment reference, payment status and limited card information.

Stripe processes personal data under its own privacy notice and may act as an independent controller for some of its activities and as a processor for others.

The MIH uses payment and invoice information to provide paid services, administer accounts, collect sums due, process refunds and meet legal, tax, accounting and audit obligations. We rely on contract, legal obligation and legitimate interests, as appropriate.

Website Analytics and Cookies

The MIH uses cookies and similar technologies to operate its websites, understand how visitors use them and improve performance and user experience.

Cookies are small files or technologies placed on your device. Some cookies are necessary for the website to function, while others support analytics, preferences or other optional features.

Where analytics tools such as Google Analytics are used, they may collect information including:

  • IP address and approximate location;
  • device, browser and operating-system information;
  • pages visited and time spent on the website;
  • date and time of visits;
  • referral source; and
  • interactions with website content.

This information helps The MIH understand website use, identify technical issues, measure performance and improve its websites and services.

Essential cookies may be used where necessary to provide the website and maintain security. Non-essential cookies, including analytics or advertising cookies, will only be used where the required consent has been obtained.

You can accept, reject or manage non-essential cookies through The MIH’s cookie settings. You may also change your browser settings, although disabling some cookies may affect website functionality.

Third-party analytics and technology providers may process information under their own privacy notices. Where information is transferred outside the UK, The MIH will ensure that an appropriate transfer mechanism or safeguard is in place.

The Principles

The MIH follows the data protection principles. This means we process personal data lawfully, fairly and transparently; collect it for specified purposes; limit it to what is necessary; keep it accurate; retain it only as long as required; and protect it using appropriate security measures.

How we manage organisations that process personal data for The MIH

The MIH uses approved service providers to support the delivery of its websites, applications, products, services and wider business activities.

Where a service provider processes personal data on The MIH’s instructions, it acts as a data processor. The MIH requires those organisations to:

  • process personal data only for the agreed purposes and in accordance with The MIH’s documented instructions;
  • keep personal data confidential and restrict access to authorised personnel;
  • use appropriate technical and organisational security measures;
  • notify The MIH promptly of any actual or suspected personal data breach;
  • assist The MIH with data protection rights, complaints, audits and regulatory obligations where required;
  • use sub-processors only where appropriate authorisation and contractual safeguards are in place;
  • retain personal data only for as long as necessary to provide the agreed service or meet a legal requirement; and
  • return, delete or securely anonymise personal data when the service ends, unless the law requires it to be retained.

The MIH only provides service providers with the personal data they reasonably need to perform the agreed service.

Not every organisation that receives personal data from The MIH acts as a processor. Some organisations, such as payment providers, professional advisers, regulators, employers, funders or partner organisations, may act as independent data controllers for their own processing. Further information about these organisations is provided under Who we share personal data with.

The MIH does not sell personal data. Our service providers may store, access or process personal data in the United Kingdom, the European Economic Area or other countries. Further information about international transfers and the safeguards The MIH uses is provided in the International Transfers section.

Protecting your personal information

The MIH is committed to protecting personal data and continually reviews its technical and organisational measures to improve data security. We maintain processes for detecting, managing, investigating and recording actual or suspected personal data breaches. Our response process includes four stages.

Containment and recovery: We take prompt steps to contain the incident, limit further loss or unauthorised access, preserve relevant evidence and restore affected systems or information where possible.

Risk and impact assessment: We investigate what happened, the personal data involved, the individuals who may be affected and the potential consequences. We assess the likelihood and severity of any risk to individuals’ rights and freedoms.

Notification: Where the legal reporting threshold is met, The MIH will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If all relevant information is not available at that time, it may be provided in stages.

Where a breach is likely to result in a high risk to affected individuals, The MIH will also notify those individuals without undue delay, unless an applicable legal exception applies.

Evaluation and response: We record the incident, review its cause and assess the effectiveness of our response. We take appropriate corrective action, which may include improvements to security controls, policies, procedures, training or supplier arrangements.

International Transfers

The MIH makes decisions about the processing of personal data in accordance with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018.

The MIH primarily stores and processes personal data within the United Kingdom and the European Economic Area (EEA). However, some of our service providers, systems, partners or users may access, store or process personal data in other countries.

Where personal data is transferred internationally, The MIH will ensure that the transfer is permitted under applicable data protection law. Depending on the location and circumstances, this may include relying on:

  • UK adequacy regulations or, where EU GDPR applies, an applicable EU adequacy decision;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • the EU Standard Contractual Clauses where applicable; or
  • another approved transfer mechanism or lawful exception.

Where required, The MIH will assess the risks associated with the transfer and put additional contractual, technical or organisational safeguards in place.

If you access The MIH services from outside the UK or EEA, personal data may be transferred to or accessed from the country in which you are located where this is necessary to provide the requested service.

The MIH takes appropriate steps to ensure that personal data transferred internationally remains protected in accordance with this privacy notice and applicable data protection law. Further information about relevant safeguards is available by contacting The MIH.

Your data protection rights

Under data protection law, you may have the following rights. The rights available to you will depend on the circumstances and the reason why The MIH processes your personal data.

Your right of access: You have the right to ask for confirmation that The MIH processes your personal data and to request a copy of that information.

Your right to rectification: You have the right to ask us to correct personal data that you believe is inaccurate or to complete information that you believe is incomplete.

Your right to erasure: You have the right to ask us to delete your personal data in certain circumstances.

Your right to restriction of processing: You have the right to ask us to restrict how we use your personal data in certain circumstances.

Your right to object to processing: You have the right to object to certain processing, including processing based on legitimate interests. You have an absolute right to object to the use of your personal data for direct marketing.

Your right to data portability: In certain circumstances, you have the right to receive personal data that you provided to us in a structured, commonly used and machine-readable format, or to ask us to transfer it to another organisation.

Your rights relating to automated decision-making: You may have rights where a decision producing legal or similarly significant effects is made using solely automated processing. The MIH does not currently use solely automated processing to make such decisions about individuals.

Your right to withdraw consent: Where we rely on consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn. It may affect our ability to provide a particular optional product, service or feature.

Your right to complain to The MIH: You have the right to complain if you believe that The MIH has not handled your personal data in accordance with data protection law. We will acknowledge your complaint without undue delay, investigate it appropriately, keep you informed where necessary and communicate the outcome within the period required by law.

We may ask you to provide information to confirm your identity, explain your relationship with The MIH, for example, whether you are a member, customer, supplier, employee, contractor, secondee or event attendee, and help us locate the personal data relevant to your request.

We will respond to a valid request without undue delay and normally within one month. In certain circumstances, the response period may be extended where permitted by law.

Communications

The Privacy and Electronic Communications Regulations (PECR) apply alongside the UK GDPR and the Data Protection Act 2018. They regulate matters including electronic direct marketing and the use of cookies and similar technologies. Where The MIH sends marketing communications or uses technologies that store information on, or access information from, a user’s device, we will comply with PECR and applicable data protection law.

Direct Marketing

The MIH may use your contact details to send relevant information about our products, services, events and activities where we have an appropriate lawful basis and comply with PECR where it applies.

You have the right to object to the use of your personal data for direct marketing at any time. You can:

  • use the unsubscribe link in a marketing email; or
  • contact The MIH and ask us to stop sending marketing communications through all or selected channels.

When you unsubscribe or object, we will stop using your personal data for direct marketing through the relevant channel. We may retain limited information on a suppression list to ensure that we continue to respect your preference.

Service and operational communications

Opting out of marketing will not prevent The MIH from sending necessary service, account, security, payment, legal or contractual communications. These communications are not sent for direct marketing purposes and may be required to manage your relationship with The MIH.

Artificial Intelligence (AI)

The MIH may use artificial intelligence to support its work, improve efficiency and assist with the delivery of its products and services. AI may be used to help organise and analyse information, prepare drafts or summaries, support searches and complete approved administrative workflows.

The types of AI used by The MIH may include:

  • Analytical or non-generative AI, which helps identify patterns, organise information or support analysis;
  • Generative AI, which can produce draft content such as summaries, reports or communications; and
  • AI agents, which can complete defined multi-step tasks within approved instructions, permissions and system controls.

Where AI processes personal data, The MIH will ensure that there is an appropriate lawful basis and that the use is necessary, proportionate and subject to suitable safeguards. Depending on the nature and risk of the activity, these safeguards may include:

  • completing a data protection or AI risk assessment;
  • limiting the personal data provided to the AI system;
  • using approved tools and suppliers;
  • applying access, security and confidentiality controls;
  • checking outputs for accuracy, fairness and bias; and
  • ensuring appropriate human oversight.

The MIH does not currently use solely automated AI processing to make decisions about individuals that produce legal or similarly significant effects. AI-generated outputs are used to support, rather than replace, appropriate human judgement.

Where a particular product or service uses AI in a way that materially affects how personal data is processed, The MIH may provide additional information at the point of collection or use.

Contact Us

Privacy email: privacy@themih.org

Pipits, Chapel Lane,
Curdridge,
Southampton,
Hampshire,
SO32 2BB

Regulatory Information

Further information about your rights can be found at https://ico.org.uk/your-data-matters

Your right to complain to the ICO: You may complain to the Information Commissioner’s Office if you believe your personal data has not been handled properly. The ICO will normally expect you to raise the matter with MIH first so that we have an opportunity to investigate and respond.

The ICO’s address:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF