“[Lotus Spa Centre]” is committed to ensuring that your privacy is always protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement.
“[Lotus Spa Centre]” may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This policy is effective from 25/05/18 and complies with GDPR rules as from May 25th 2018.
What information do we collect?
Depending upon the form data you fill out, we may collect the following information:
· business/company name
· job title
· contact information including email address and telephone
· IP address (automatically collected)
· web browser type
· operating system (automatically collected)
· industry information
· other information relevant to customer preferences
· a list of URL’s starting with and a referring site, your activity on our site, and the site you exit to (automatically collected)
What we do with the information we gather?
· We require this information to understand to address your needs and provide you with the information that you have requested, and in particular for the following reasons:
· Maintain your contact information to provide a marketing, creative or digital service or product
· Providing requested communication (eMarketing, direct mail, etc). With your permission and/or where permitted by law, we may periodically send promotional email about new products, special offers or other information which we think you may find interesting using the email address which you have provided. We will take all reasonable steps to ensure that we fully protect your rights and comply with our obligations under the Data Protections Act 1998 and the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended in 2004, 2011 and 2015. Moreover, this policy will conform to the General Data Protection Regulation (GDPR) which comes into force from 25th May, 2018.
· We may use the information to improve our services.
· Personalising and tailoring your experiences on our site
· Responding to communications from you
· We may also use your information to contact you to follow up on product or service requests. We may contact you by email, phone or mail
· Analysing your use to of our site to enable us to continually improve our site and your user experience
A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website experience, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
Links to other websites
Our website may contain links to enable you to visit other websites of interest easily. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
How and where we store your data?
We only keep your data for as long as we need to in order to use it as described above, and/or for as long as we have your permission to keep it.
If you have signed up to receive marketing information, your data will be stored in a password protected file until you request otherwise or provide updated information.
Any consent forms are also stored as a hard copy in a locked safe as well as, soft copies on our server which, is password protected. Some or all of your data may be stored or transferred outside of the European Economic Area (“the EEA”) (The EEA consists of all EU member states, plus Norway, Iceland and Liechtenstein). You are deemed to accept and agree to this by using our site and submitting information to us. If we do store or transfer data outside the EEA, we will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the EEA and under the Data Protection Act 1998. Such steps may include, but not be limited to, the use of legally binding contractual terms between us and any third parties.
Data security is of great importance to us, and to protect your data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure data collected through our site.
Notwithstanding the security measures that we take, it is important to remember that the transmission of data via the internet may not be completely secure and that you are advised to take suitable precautions when transmitting to us data via the internet.
How do we share your data?
We do not share your data with any other company unless a project that we are undertaking for you requires third party support and you have given us permission to disclose your details (a photographer, for example).
In certain circumstances, we may be legally required to share certain data held by us, which may include your personal information, for example, where we are involved in legal proceedings, where we are complying with the requirements of legislation, a court order, or a governmental authority. We do not require any further consent from you in order to share your data in such circumstances and will comply as required with any legally binding request that is made of us.
Controlling your personal information
You may choose to restrict the collection or use of your personal information in the following ways:
· We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so. We may use your personal information to send you promotional information about third parties which we think you may find interesting if you tell us that you wish this to happen.
· Whenever you are asked to fill in a form on the website, look for the box that you can click to indicate that you are happy for the information gathered to be used by Design Inc for direct marketing purposes. If so, please click the box next to the words “I give my consent for Design Inc to send me news, information & updates that may be of interest to me.” If you do not consent to us using your personal data in this way, do not click the box. By doing this, the form may not process. If you are having second thoughts on receiving marketing information as previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by writing to us at the below address.
· You may request details of personal information which we hold about you under the Data Protection Act 1998 at no expense. If you would like a copy of the information held on you, please write to us at the address below.
How do we edit sensitive data?
Upon request, we will update the necessary databases and store the request as a hard copy in a locked filing cabinet as well as a soft copy on our protected server.
How do we erase a data subject’s personal data?
We will supply a request form for the erasure of personal data that doesn’t need to be maintained for legal obligations or exercise of official authority (i.e HMRC). In order to erase this data, we will delete all soft copies off of our server and hard copies will be shredded and disposed of safely.
In which circumstances do we report a data breach?
A loss of personal data does not result in a data breach unless, the breach results in a risk to the rights and freedoms of an individual. Such as, the breach may have detrimental effects on their reputation, financial loss, loss of confidentiality, discrimination or any significant economic or social disadvantage.
Should a data breach occur, depending on the severity, we will:
- Report internally to the directors; [Emma Edwards]
- Report back directly to the individual exposed if there is a high risk to rights & freedoms,
- Report to the ICO (Information Commissioner’s office with 72 hours).
Lotus Spa Centre Ltd, 14a The Old cider Works, Abbotskerswell, Newton Abbot, Devon, TQ12 5NF
If you believe that any information we are holding on you is incorrect or incomplete, please write to us as soon as possible at the above address. We will promptly correct any information found to be incorrect.