PRIVACY POLICY

Last modified:  30 April 2018

TDA (“We” on behalf of Torbay Culture) are committed to protecting and respecting your privacy. We promise to keep your data safe and private, not to sell your data, to give you ways to manage and review your data.

This policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we treat it.

For the purpose of the General Data Protection Regulation (GDPR) (“the Act”) we are registered as a Data Controller with the Information Commissioner’s Office (Registration Reference No ZA175198) and a description of how we use personal information is included in our entry on the data protection register which is maintained by the Information Commissioner’s Office.

Information we may collect from you: 

Under GDPR we have a legal duty to protect any information we collect from you. We have procedures and security features in place that aim to keep your data secure once we receive it.  We may collect and process the following data about you:

  • Information you give us.  You may give us information by paper, corresponding with us via email, social media, phone, by contacting our staff, one of our partners or via CCTV or otherwise.  This includes information you provide when you visit our websites, use our services, and correspond with us.  The information you give us may include your name, address, email contact details, phone number(s), and other information required by us to deliver our services.
     
  • Information we collect about you.  With regard to each of your visits to our websites we may automatically collect the following information:
    • Technical information – cookies (please see our Cookie Policy), the Internet protocol (IP) address used to connect your computer to the Internet, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform
    • Information about your visit to our websites – products you viewed or searched for, page response times, download errors, and length of visit

Legal Basis we rely on

The GDPR protection sets out a number of different reasons for which a company may collect and process your personal data including:

 Consent – in specific situations, we can collect and process your data with your consent e.g when you tick a box to receive email newsletters

Performance of a Contract –we need your personal data to enable us to perform a contract and deliver our services 

Legal compliance – If the law requires us to, we may need to collect and process your data – e.g we can pass on details of people involved in fraud or other criminal activity or details to HMRC

Legitimate interest – in specific situations, we require your data to pursue our legitimate interest in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interests’ e.g to carry out our marketing activities and seeking your consent when we need to contact you

Why do we collect information about you?

 We need to collect and hold information about you, for a variety of reasons including: 

  • the delivery of our TDA services
  • confirming your identify to provide some services
  • contacting you by post, email or telephone
  • understanding your needs to provide the services that you request
  • understanding what we can do for you and inform you of other relevant services and benefits
  • obtaining your opinion about our services
  • updating your customer record
  • helping us to build up a picture of how we are performing at delivering services to you and what services are needed
  • providing information on our TDA services by way of a newsletter
  • processing financial transactions
  • preventing and detecting fraud and corruption in the use of funds
  • making sure we meet our statutory obligations including those related to diversity and equalities

 We may not be able to provide you with a product or service unless we have enough information, or your permission to use that information.

How we use your information

 We will use the information you provide in a manner that conforms to the GDPR Act. We will endeavour to keep your information accurate, up to date and not keep it for longer than is necessary. In some instances the law sets the length of time information has to be kept.

We will process your information for the following purposes:

  • to carry out our obligations arising from any contracts entered into between you and us and to provide you with information, products and services that you request from us
  • to monitor and improve the TDA’s performance in responding to your request
  • to allow us to be able to communicate with you and provide services and benefits appropriate to your needs
  • to ensure that we meet our legal obligations
  • where necessary for the law enforcement functions
  • to prevent and detect fraud or crime
  • to process financial transactions including payments, or where we are acting on behalf of other government bodies, e.g. Department for Work and Pensions
  • to collect tax and monies owed to us
  • where necessary to protect individuals from harm or injury
  • to allow the statistical analysis of data so we can plan the provision of services
  • for other legitimate business purposes

How we protect your information

Our aim is not to be intrusive, and we won't ask irrelevant or unnecessary questions. The information you provide will be subject to rigorous measures and procedures to make sure it can't be seen, accessed or disclosed to anyone who shouldn't see it.

We will not disclose your personal information that you provide to us, to anyone else without your permission, except in the few situations where disclosure is required by law, or where we have good reason to believe that failing to share the information would put someone else at risk. You will be told about this.

We will not keep your information longer than it is needed taking into account the following:

  • Whether we have any legal obligations to continue to process your information (imposed by relevant law or regulations)
  • The purpose(s) and use of your information both now and in the future (such as whether it is necessary to continue to store that information so we can continue to perform our obligations under a contract with you or a contract in the future)
  • Where we have a legal basis to continue to process information (such as your consent)
  • How difficult it is to ensure that the information can be kept up to date and accurate – and -
  • Any relevant surrounding circumstances (such a the nature and status of our relationship with you)

We will always dispose of paper records or delete any electronic personal information in a secure way.

Ways in which we collect and use information 

Information Sharing
Generally, we will use your information within the TDA and will only share it outside the TDA where we need to perform our service, you have requested it or given your consent. We do use trusted third parties – for example IT companies who support our websites, HM Revenue & Customs, fraud management, and to administer our mailing list for e-newsletters with an organisation called Mail Chimp. If you have purchased from us and used a credit or debit card with us, we will share transaction details with companies which help us to provide this service (such as Visa and Mastercard).

If we use products or services which process personal information, we will only use GDPR compliant companies to help deliver our services, we will only provide information they need to perform their specific service and we will work closely with them to ensure your privacy is respected at all times.  These providers are obliged to keep your details securely, and use them only to fulfill your request.   If we do transfer any information outside the European Economic Area (EEA) we will ensure the following safeguards:

  • Transfer to a non-EEA country with privacy laws that give the same protection as the EEA.
  • Put in place a contract with the recipient that means they must protect the data to the same standards as in the EEA
  • Transfer to organisations that are part of Privacy Shield.  This is a framework that sets privacy standards for data sent between the US and EU countries. It makes sure those standards are similar to what is used in the EU.  You can find out more about data protection on the European Commission Justice website.

We may disclose information to other partners where it is necessary, either to comply with a legal obligation, or where permitted under GDPR.  Where we need to disclose sensitive or confidential information such as medical details to other partners, we will do so only with your prior explicit consent or where we are legally required to.

We may disclose information when necessary to prevent risk of harm to an individual. At no time will your information be passed to organisations external to us and our partners, for marketing or sales purposes or for any commercial use without your permission.

Telephone Calls
We will inform you if we record or monitor any telephone calls you make to us and obtain your consent to do so. This will be used, to increase your security, for our record keeping of the transaction and for our staff training purposes.

Emails
Please remember that transmission of information over the internet is not secure and if you submit any information to us over the internet (such as emails, or via our website(s) or by any other means you do so at your own risk.

 If you email us we may keep a record of your contact and your email address and the email for our record keeping of the transaction. For security reasons we will not include any confidential information about you in any email we send to you. We would also suggest that you keep the amount of confidential information you send to us via email to a minimum and use our secure online services or post.

CCTV
CCTV systems are installed in some of our TDA areas and these areas are used by members of the public.  We monitor these, for the purposes of public/ staff safety and crime prevention and detection. 

In our locations, signs are displayed notifying you that CCTV is in operation and should you have any issues please contact the TDA’s Data Protection Manager.

Images captured by CCTV will not be kept for longer than necessary. However, on occasions there may be a need to keep images for longer, for example where a crime is being investigated.   You have the right to see CCTV images of yourself and be provided with a copy of the images. Should you wish to do this please contact the TDA’s Data Protection Manager.

We operate CCTV and disclose in accordance with the codes of practice issued by the Information Commissioner and the Home Office.

When will we contact you?
We may contact you:

  • In relation to any service or activity in order to ensure the TDA can deliver our services
  • In relation to any correspondence we receive from you
  • To invite you to participate in surveys about our service so we can make improvements if necessary
  • For marketing purposes – we will only send you marketing emails or contact you for marketing purposes if you have agreed for us to do so
  • We offer regular emails and newsletters to let you know about our services and you can opt in to receive these  

Your rights
You have the right to request that we stop processing your personal data in relation to any TDA service. However, this may cause delays or prevent us delivering a service to you. Where possible we will seek to comply with your request but we may be required to hold or process information to comply with a legal requirement

You can legally ask to see any information that we hold about you, and get a copy. To do so please contact the TDA’s Data Protection Manager (contact details are at the end of the Policy). 

You have the right to be forgotten and may terminate your arrangement with us at any time, in which case we will permanently delete your record(s) and all data associated with it.  To request this please contact the TDA’s Data Protection Manager. Where possible we will seek to comply with your request but we may be required to hold or process information to comply with a legal requirement.

We try to ensure that any information we hold about you is correct. There may be times where you find the information we hold is no longer accurate and you have the right to have this corrected.

Please contact us if you wish to exercise any of these rights, or if you have a complaint about how your information has been used. We will need to record your personal contact details to be able to respond to, and track the progress of, your request. Where you request access to your information we are required by law to use all reasonable measures to verify your identity before doing so.  These measures are designed to protect your information and to reduce risk of identity fraud, identity theft or unauthorised access to your information.

If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests you have made to use regarding the use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office.  You can contact them by calling 0303 123 1113. Or go online to www.ico.org.uk/concerns (this opens in a new window, please note we can’t be responsible for the content of external websites).

Changes to the TDA’s Privacy Policy
This Privacy Policy may be updated from time to time. The date of the most recent revisions will appear on this page. Your ongoing use of TDA’s website and services confirms your acceptance of this policy. If material changes are made to the Privacy Policy, for instance affecting how we would like to use your personal information, we will provide a more prominent notice.

Contacting the TDA about this Privacy Policy
We hope this Privacy Policy has been helpful in setting out the way we handle your personal data and your rights to control it.

If you have any questions or comments about this Privacy Policy or to make a Subject Access Request please contact:

TDA Data Protection Manager
TDA, Tor Hill House, Torquay TQ2 5QW
(Email: [email protected])

We want to make sure that the personal data we hold about you is accurate and up to date.  If any of the details are incorrect, please let us know and we will amend them.

 

TDA is a trading name of Torbay Economic Development Company Limited, a company registered in England and Wales No. 7604855 Registered Office Tor Hill House, Union Street, Torquay, Devon TQ2 5QW.