With the introduction of the General Data Protection Regulation (GDPR) on 25th May 2018, all organisations within the EU must review how they manage personal data, such as customer details, to ensure they meet GDPR requirements. At Privatus Club, the security of your data is a priority and we respect your privacy. This privacy notice will inform you as to how we look after your personal data and tell you about your privacy rights and how the law protects to you.
WHO WE ARE
The website we use to collect and store information about you is https://www.privatusclub.com
We have appointed a data controller officer (DCO) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, please contact the DCO at firstname.lastname@example.org
Privatus Club Registered office is 1 Great Austins House, Farnham, Surrey, GU9 8DS, United Kingdom
We do not control third-party websites and are not responsible for their privacy statements. When you leave our website you should read the privacy notice of the website you visit.
HOW CAN YOU ACCESS YOUR PERSONAL INFORMATION?
You can request details of the personal information we hold on you by writing to us at:
Privatus Club, 1 Great austins House, Farnham, Surrey, GU9 8DS, United Kingdom
Or contact us on our email: email@example.com
We endeavour to respond to all enquiries within five working days of receiving them, and will offer a full response to all information access requests within one month.
HOW IS YOUR PERSONAL DATA COLLECTED?
We use different methods to collect data from and about you including through:
– Direct interactions. You may give us identity, contact and financial data by filling in forms or by corresponding with us by post, phone, email or otherwise. This data includes personal data you provide when you join Privatus Club or place a request for services with us.
– Third parties or publicly available sources. We may receive personal data about you from various third parties and public sources including from analytics providers such as Google based outside the EU or from publicly available sources such as Companies House and the Electoral Register based inside the EU.
THE DATA WE COLLECT ABOUT YOU
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:
– Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.
– Contact Data includes billing address, delivery address, email address and telephone numbers.
– Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences
– Financial Data includes bank account and payment card details.
– Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.
– Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to interact with or access this website.
– Profile Data includes your membership identification number, purchases or orders made by you, your interests, preferences, feedback and survey responses.
– Usage Data includes information about how you use our website, products and services.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. If we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
If you have an account with Privatus Club and you log into this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select ‘Remember Me’, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
Other cookies are used to anonymously track data – for example our Popup Maker (which shows popups when you click on links on profiles) anonymously tracks the amount of popup views so we can record this data on our systems.
HOW WE USE YOUR PERSONAL DATA
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances (i) where we need to perform the contract we are about to enter into or have entered into with you (ii) where it is necessary for our legitimate interests (or those of a third party) and your interests do not override those interests, or (iii) where we need to comply with a legal or regulatory obligation.
In general we do not rely on consent as a legal basis for processing your personal data other than in relation to sending third party direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.
Purposes for which we will use your personal data
We have set out below a description of the ways we plan to use your personal data.
– To register you as a new member or customer
– To process and deliver your requests and orders including fulfilment of requests placed by you or on your behalf, management of payments, fees and charges, collection and recovery of money owed to us
– To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
– To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you
– To use data analytics to improve our website, products/services, marketing, customer relationships and experiences
– To make suggestions and recommendations to you about goods or services that may be of interest
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising:
– Promotional offers from us. We may use your identity, contact, technical, usage and profile data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you. You will receive marketing communications from us if you have requested information from us or placed a request with us or purchased goods or services from us or if you provided us with your details when you entered a competition or registered for a promotion and, in each case, you have not opted out of receiving that marketing.
– Third-party marketing. We will get your express opt-in consent before we share your personal data with any company outside Privatus Club for marketing purposes.
– Opting out. You can ask us or third parties to stop sending you marketing messages at any time by contacting us at any time. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase, product/service experience or other transactions.
– Change of purpose. We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
DISCLOSURES OF YOUR PERSONAL DATA
We may have to share your personal data with third parties. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
We share your personal data within the Privatus Club. This may involve transferring your data outside the European Economic Area (EEA). Some of our external third parties are based outside the EEA so their processing of your personal data will involve a transfer of data outside the EEA
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Website hosting provider: GoDaddy
Website location: England, United Kingdom
Data location: England, United Kingdom
Security measures: We ensure that our website has the latest security patches whenever possible, all transactions are performed over https, use WordFence Security and perform regular audits.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. By law we have to keep basic information about our customers (including contact, identity, financial and transaction data) for seven years after they cease being customers for tax purposes.
In some circumstances you can ask us to delete your data and in other circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protection laws in relation to your personal data. You may, for example request to access, correct, erase or restrict processing of your personal data, or withdraw consent to us holding the data. If you wish to exercise any of the rights set out above, please contact us at firstname.lastname@example.org . We reserve the right to charge a fee if your request is clearly unfounded, repetitive or excessive.
We try to respond to all communication within one week. Occasionally it may take us longer if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.