Privacy Policy
Home / Privacy
Privacy & GDPR Policy
At Diablo Initiative, we are committed to protecting your personal data and ensuring your privacy is respected. This policy outlines how we collect, use, and safeguard your information in line with the UK General Data Protection Regulation (UK GDPR).
Who We Are
Diablo Initiative provides payroll and CIS services to UK-based businesses. Our operations involve processing personal data for clients, subcontractors, employees, and other parties as necessary to fulfil our services.
Contact Details:
Phone: 03330 417589
Email: info@diablo-initiative.com
What Data We Collect
We may collect and process the following types of personal data:
Full names and contact details (phone numbers, email addresses)
National Insurance numbers and UTRs (Unique Taxpayer References)
Bank details for payment processing
Employment status and payroll records
Timesheet data and work assignment history
Copies of identification or right-to-work documents
How We Use Your Data
We process your data to:
Administer payroll and CIS services
Verify subcontractors under HMRC rules
Submit reports and returns to HMRC
Issue payslips, remittances, and tax documents
Respond to queries and provide support
Maintain accurate financial and compliance records
Lawful Basis for Processing
Our processing is based on one or more of the following lawful grounds:
Contractual necessity – to deliver services as agreed
Legal obligation – to comply with HMRC and employment law
Legitimate interest – to manage and improve our operations
Consent – where applicable, and only when explicitly given
Data Sharing
We only share data when necessary, and only with:
HMRC and other regulatory authorities
Trusted payroll software providers and IT platforms
Financial institutions for payment processing
Professional advisers (e.g. accountants or legal consultants)
We do not sell or trade your personal data under any circumstances.
Data Retention
We retain payroll and compliance records for a minimum of six years, or as required by HMRC and other legal obligations. Once data is no longer needed, it is securely deleted or anonymised.
Data Security
We implement appropriate technical and organisational measures to safeguard your data, including:
Encrypted communications and secure storage
Access controls and user authentication
Regular data audits and system reviews
Your Rights Under UK GDPR
You have the right to:
Access the personal data we hold about you
Request correction of inaccurate data
Request erasure of your data (subject to legal obligations)
Object to or restrict certain types of processing
Request transfer of your data to another service
Withdraw consent at any time (where applicable)
To exercise these rights, contact us at:
info@diablo-initiative.com
Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the UK’s Information Commissioner’s Office (ICO):