0

Summary: Privacy Policy

Read this Privacy Notice so you know how we collect and process personal data. We comply with the General Data Protection Regulation (GDPR). We are the Data Controller for personal data collected to deliver a service contract. GDPR basis: Art.6(b).

Information we collect 📄

Personal data means any information that identifies you. We may collect, use, store and transfer the following types of data:

  • Identity Data: title, first name, maiden name, last name.
  • Contact Data: billing address, residential address, delivery address, email address, telephone numbers.
  • Transaction Data: payment details and records of products or services purchased.
  • Technical Data: device and browsing technology provided by analytics like Google Analytics.
  • Profile Data: personal information and records of purchases or orders.
  • Usage Data: how you use our website, products and services.
  • Marketing & Communications Data: your preferences for receiving marketing information.
  • Aggregated Data: statistical or demographic data derived from personal data. Aggregated Data does not identify you.

We do not request Special Categories of Personal Data (race, religion, health, sexual orientation, political opinions, trade union membership, genetic or biometric data) to enter into a service contract.


If you fail to provide personal data

Where we need personal data to perform a contract and you do not provide it, we may not be able to perform the contract. We may cancel a product or service or decline your booking. We will notify you if this happens.


How we collect your personal data 🔍

  • Direct interactions: via electronic forms, online booking forms, post, phone or email. This includes applications, enquiries, subscriptions, feedback, competitions, and past product applications.
  • Automated technologies: analytics providers such as Google, search information providers, and payment/technical service providers. These parties may be inside or outside the EU.

How we process your information ⚖️

We only process personal information when we have a lawful basis. Common bases include:

  • Performance of a contract or pre-contractual steps.
  • Compliance with legal or regulatory obligations.
  • Prevention and detection of crime, including fraud.

We generally do not rely on consent as the legal basis. We will only use your personal information for the purposes collected unless a compatible purpose applies. We may process data without your consent where permitted by law.


Disclosures of your personal data 🔐

We may share your data with:

  • Representatives of the Data Controller to enable service delivery.
  • Third Parties for IT hosting and payment services with servers in the EU.
  • Kool Booking Systems (joint data controller) and our email provider.
  • Social media platforms which may collect and process your data.

We may also share data for legal reasons such as insurance claims, tax requirements or criminal investigations. We will expect a similar degree of protection. We will not sell your data for marketing to third parties.


Retention

We retain personal data only as long as necessary to fulfil the purposes collected and to meet legal, regulatory, accounting or reporting requirements. We consider the nature, sensitivity and purpose of the data and legal obligations when setting retention periods.

By law we keep basic customer and supplier information for tax, VAT and insurance purposes. We will retain your data for 2 years from the date your booking and contract are fulfilled. We may anonymise data for research or statistical use indefinitely.


Your rights & complaints ✉️

You can request deletion of your data by emailing the Data Controller. If deletion is requested before a contract is fulfilled, we may not be able to perform the contract and may cancel services or bookings. If you wish to raise a complaint about how your data is handled, you can contact the Information Commissioner's Office (ICO).


Published 23rd May 2018 📅