Privacy Statement
The MGH Conglomerate is a data controller for the purposes of the Data Protection Act 1998. The group is notified on the public register maintained by the ICO under registration number Z6841127. Responsibility for the group notification rests with the Company Secretary, Alan Fitchett, at the registered office, Sceptre House, 12-14 Farringdon Row, London EC1M 3JQ.
This statement explains what personal information is collected through this website, what is done with it, and the standards applied by MGH generally under the 1998 Act.
Information collected
When you contact us through this site we may collect your name, organisation, postal address, telephone number, fax number, e-mail address and the text of your enquiry. We also record the date, the page requested, your Internet Protocol address, browser type and the size of the response in the ordinary web server log. The site additionally places one temporary session cookie containing a random reference number so that a form can be submitted properly. We do not ask for card details on this site and we do not invite sensitive personal data to be sent through it.
Enquiry correspondence is used to answer the point raised, to route it to the correct division and, where appropriate, to prepare a quotation or brochure request. Server logs are used for traffic measurement, fault diagnosis and basic security review. They are not used to build marketing profiles, nor are they sold, rented or traded to third parties.
Cookies
A cookie is a small text file stored by your browser on your own machine and returned to the same site on a later request. The cookie used here does not read your hard disc, carry a programme or disclose your identity; it merely holds the temporary session reference mentioned above. If you prefer, you may refuse cookies. In Internet Explorer, use Tools, then Internet Options, and adjust the privacy or security settings accordingly. In Netscape Navigator, use Edit, then Preferences, and select the cookie controls under the advanced options. Most pages will continue to display perfectly well, although form submission may become less convenient.
The eight data protection principles
- Personal data shall be processed fairly and lawfully, with the individual told who is collecting it and for what purpose.
- Personal data shall be obtained only for specified and lawful purposes and shall not be used in a manner incompatible with those purposes.
- Personal data shall be adequate, relevant and not excessive in relation to the purpose for which it is held.
- Personal data shall be accurate and, where necessary, kept up to date.
- Personal data held for any purpose shall not be kept for longer than is necessary for that purpose.
- Personal data shall be processed in accordance with the rights of data subjects under the Act.
- Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing and against accidental loss, destruction or damage.
- Personal data shall not be transferred outside the European Economic Area unless the destination affords an adequate level of protection for the rights and freedoms of data subjects.
Within MGH these principles are applied by retention schedules, controlled access, locked archives, password discipline and annual review of forms and working practices.
Subject access and correction
You are entitled under section 7 of the Act to ask whether we hold personal data about you and, if so, to receive a copy in intelligible form. Requests must be made in writing and accompanied by the statutory fee of £10. We may ask for enough information to satisfy ourselves as to identity and to locate the relevant record. A response will be provided within the statutory period of 40 days, and sooner where the search can sensibly be completed sooner.
Questions about this statement may be sent to that address. Formal subject access applications should still be posted to the Data Protection Officer at the registered office, with the fee enclosed by cheque and enough detail to avoid delay.
Recruitment, vetting and customer information
Information supplied in connection with recruitment, references, medical declarations, security screening and government vetting is handled separately from routine enquiries and retained only for the periods stated to the applicant at the time. Unsuccessful applications are held for a limited period for audit and equal opportunities review; successful applications become part of the employment record. Further detail on vacancies and appointment procedures appears on the Careers page.
Operational customer data supplied to or processed within Defence operations requires a different distinction. Products such as MERIDIAN are supplied to customers for use within their own accredited environments, and the handling of export-controlled material, security classification and onward disclosure is governed by the arrangements described under Export & Compliance. MGH does not publish customer files through this website, and the site is not intended as a route for transmitting programme material, warrants, case papers or other controlled information.
Changes to this statement
This statement may be revised where the law, our notification entry or our working practice changes. The version number and issue date below will be amended when that occurs, and earlier versions may be supplied on request for reference.
Version 3.1, issued 11 February 2003. This text supersedes version 3.0 of 4 June 2002.
Page last updated 11 February 2003.
![]()
