Data Protection Act 2018 and the EU General Data Protection
GDPR Data Controller & Data Protection Officer
Officer: Christian Odendaal
We have no requirement for requesting or keeping personal data with clients or general enquiries that come through our quote form. Due to the nature of our business, most details we keep should be contact and address details for work purposes such as a name, work phone number, work email address, address for photography and company name.
In general, we do not intentionally collect sensitive personal data. Sensitive personal data is data of the kind regulated by Article 9 or Article 10 of the GDPR, such as personal identity numbers; financial account information; information concerning racial or ethnic origin; political opinions; religious, philosophical, or other beliefs; membership in trade unions or professional or trade associations; physical or mental health information; biometric data; genetic data; data concerning sexual activity or orientation; or data concerning criminal records or suspected criminal activity.
How do we keep your data protected?
Quote requests are kept on our secure server via Form Ninja (GDPR compliant) policy here and behind a password protected Google Drive account. It is secured with SSL.
Matterport cloud (GDPR compliant) stores virtual tours and some location data and their policy is here. It is secured with SSL.
Our own site https://local-x360virtualtours.com is also secured with encrypted SSL with a password protected admin system protected from brute force attacks with limited attempts. The password would take 1 octillion years to crack with current computing power (as of May 2018)
What do we use your information for? Information we collect from you may be used in one or more of the following ways:
- To send periodic emails about our company, product news or service information, etc.
- To respond via supplied contact details regarding your enquiry (email, telephone or post).
- To personalise your experience (your information helps us to better respond to your individual needs).
- To improve our website (we continually strive to improve our website offerings based on the information and feedback we receive from you.
- If we discover any criminal activity or alleged criminal activity through our use fraud monitoring and suspicious transaction monitoring, we will process this data for the purposes of preventing or detecting unlawful acts.
- To send you communications required by law or which are necessary to inform you about our changes to the services we provide you e.g. updates to this Privacy Notice.
- To create engaging content for our website, social media and newsletters through the medium of photography and videography
Do we share any information with other parties?
We do not sell, trade, or otherwise transfer to outside parties any personally identifiable information.
This does not include trusted third parties who assist us in operating our website, conducting our business, or servicing you. Such trusted parties may have access to personally identifiable information on a need-to-know basis and will be contractually obliged to keep your information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.
For clients we may contact you by email, text, telephone, mail or other agreed means to keep you up to date about our services. The legislation allows us to do this in our own commercial interests for certain communications with previous customers. In other circumstances, we can only do so with your explicit consent. In all cases, you can opt out from receiving such communications at any time.
For online visitors, see our cookie consent policy in the next section. In short, an example of how we may advertise is to show you an advert after to you leave our site on a social media platform.
We will keep client contact data in order to stay in touch with any new offers or sites which their business could make use of in the future. Your data will not be retained for longer than is necessary and will be managed in accordance with our data retention policy.
Your Rights & Consent
Officer: Christian Odendaal
Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent.
This policy was last modified on ….01/06/2018