Please note that this policy applies only to our website and not to the web sites of other organisations to which we may provide links. We are not responsible for the privacy policies or practices of such third party sites and you should make your own enquiries in respect of them.
INFORMATION WE MAY COLLECT FROM YOU
We may collect and process the following data about you:
- Information that you provide by filling in forms on our site http://www.data-edinburgh.co.uk. This includes information provided at the time of registering to use our site, subscribing to our service, posting material or requesting further services. We may also ask you for information when you report a problem with our site.
- If you contact us, we may keep a record of that correspondence.
- We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
- Details of transactions you carry out through our site and of the fulfilment of your orders.
- Details of your visits to our site including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise and the resources that you access.
We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users’ browsing actions and patterns, and does not identify any individual.
We use traffic log cookies (Google Analytics) to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
WHERE WE STORE YOUR PERSONAL DATA
All information you provide to us is stored on our secure servers. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
We are committed to protecting the privacy of your personal data. We use appropriate standards of technology and operational security to protect personal information including a secure server and network firewall connection. Operationally, access to personal information is restricted to authorised personnel who are under a duty to maintain the confidentiality and security of such information.
INTERNET AND DATA STORAGE
The Internet is inherently insecure. Personal information submitted by means of the Internet may be vulnerable to unauthorised access by third parties. Submission of personal information using the Internet is at your own risk. We will take reasonable and appropriate technical measures to ensure that your personal information is stored in a secure manner. However, we shall have no liability for disclosure of data due to errors in transmission or the fraudulent, negligent or other illegal acts of a third party, such as ‘Hacking’. Any transmission of personal information on or through the use of our website is at your own risk
USES MADE OF THE INFORMATION
We use information held about you in the following ways:
- To ensure that content from our site is presented in the most effective manner for you and for your computer.
- To provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes.
- To carry out our obligations arising from any contracts entered into between you and us.
- To allow you to participate in interactive features of our service, when you choose to do so.
- To notify you about changes to our service.
We may also use your data to provide you with information about goods and services which may be of interest to you and we may contact you about these by email, SMS, post or telephone, but only if you provide your consent to this by checking the appropriate box(es) on the website contact form.
We may share your personal information with third parties but only in the strictly limited circumstances set out below.
- In certain circumstances we may share your personal information with affiliated companies and service providers who perform functions on our behalf such as our internet service provider. These third parties must at all times provide the same levels of security for your personal information as us and will be bound by a legal agreement to keep your personal information private and secure.
- We may also supply your personal information to government bodies and law enforcement agencies but only: if we are required to do so by the requirements of any applicable law; if in our good faith judgment, such action is reasonably necessary to comply with legal process; to respond to any claims or actions; or to protect our rights or those of our customers and the public.
TRANSMISSION OF DATA OVERSEAS
In certain circumstances, we may transfer your personal data to countries outside the European Economic Area. This may include circumstances where we use service providers who are based outside the EEA or who use “cloud” infrastructure which means that their servers are based all over the world. Where we transfer your information to companies outside the EEA, we will make sure it’s protected in a manner that is consistent with how your information will be protected by us. This can be done in a number of different ways for instance:
- The country that we send the data to might be approved by the European Commission.
- The recipient company might have signed up a contract obliging them to protect your information.
- The recipient is located in the US and is a certified member of the EU-US Privacy Shield scheme.
In other circumstances the law may permit us to otherwise transfer your information outside the EEA. In all cases however, we will ensure that any transfer of your information is compliant with the Data Protection Legislation.
You have a number of legal rights in relation to the information that we hold about you, including:
Right to access: You have the right to request access to your personal data held by us. Requests are to be made in writing, electronically and information will be provided in a commonly used electronic format. Requests will be handled within one month of receipt of the request, and free of charge with the exception of where requests are manifestly unfounded or excessive we hold the right to charge a reasonable fee taking into account the administrative costs of providing the information. More information can be found at https://ico.org.uk/for-the-public/personal-information/.
Right to rectification: You have the right to have personal data rectified if inaccurate or incomplete. Where the personal data in question has been disclosed to a third party, they will be made aware of the rectification where possible. Requests are to be made in writing, electronically, and will be handled within one month of receipt of the request.
You have the right to request the deletion or removal of personal data in the following circumstances:
- Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed.
- When you withdraw consent.
- When you object to the processing and there is no overriding legitimate interest for continuing the processing.
- The personal data was unlawfully processed (i.e. otherwise in breach of the GDPR).
- The personal data has to be erased in order to comply with a legal obligation.
This does not provide an absolute “Right to be forgotten”. Where the personal data in question has been disclosed to a third party, we will inform them about the erasure of the personal data, unless it is impossible or involves disproportionate effort to do so. Personal data will be erased by removal from our internal and cloud servers.
Right to restrict processing: You have a right to ‘block’ or suppress processing of personal data if you contest its accuracy; have objected to the processing; processing is unlawful and you oppose erasure; we no longer needs the personal data but you require the data to establish, exercise or defend a legal claim. Where the personal data in question has been disclosed to a third party, we will inform them about the restriction on processing of the data, unless it is impossible or involves disproportionate effort to do so.
Right to data portability: You have the right to obtain and reuse your personal data for your own purposes. Requests are to be made in writing, electronically, and will be handled within one month of receipt of the request.
Right to object: You have the right to object to processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling); direct marketing (including profiling); and processing for purposes of scientific/historical research and statistics. Requests will be dealt with by immediate effect with no right for refusal.
You also have the right to make a complaint with the Information Commissioner at www.ico.org.uk if you think that any of your rights have been infringed by us.
All requests will be dealt with in your own merit, and in accordance with the Data Protection Legislation guidance.
Should a data breach occur, we have compliant procedures in place to investigate and report the matter to the Individual. In the event of a breach, it will be reported to you within 72 hours of discovery. A record of any breaches will be kept by the company.
You can exercise your rights by contacting us using the details set out in the “Contact Details” section below.
Data Computer Services
27 Portobello High Street