Updated: 24th May 2018
We want to be transparent as to how we collect, use and protect your personal information. For the purposes of this policy, the data controller is Nineoaks Fisheries (referred to here as "we", "us" or "our").
This Policy explains:
- the personal information we collect;
- how and why we collect and use that personal information;
- why we process your personal information;
- when and why we will disclose your personal information;
- the rights and choices you have when it comes to your personal information;
- how long we will hold your information for; and
- how to contact us.
2. The Personal Information we collect
- When you contact us to make an enquiry, either by telephone, by email or through our web-site or any of our (infrequent) emails you may provide us with your email address, mailing address, contact telephone number(s) and name(s).
- When you book with us you must provide us with personal details, including without limitation your name, postal address, email addresses, phone numbers, title and some limited credit card and/or bank information.
- When you visit our Site, Google (on our behalf) may collect impersonal information about your online browsing behaviour and any devices you have used to access our Site (including your IP address, browser type and mobile device identifiers)
3. How we collect and use your personal informationThis section explains how we collect and use your personal information.
3.1. Holiday AccommodationWe collect your personal information from you when you place a holiday booking or holiday enquiry with us. We use this so that we can identify, manage, deliver and subsequently support your booking. If we need to pass your personal information to a third party to meet your request except for the purpose of delivery (see below), we will make it clear at the time you submit your details. If that happens, then in line with section 1 above, we advise you to read the privacy policies of whichever third parties we tell you about.
3.2. Birthday and Christmas cardsWhere we have an email address and a known Birthday, occasionally we may send a Birthday or Christmas e-card. For those that have visited us within the last two years we usually send a postal Christmas card. We collect your email address when you contact us for holiday and other enquiries. We use this to send you emails as appropriate for example, confirmation of your booking, confirmation of a Credit Card payment and so forth.
3.3. Accommodation ProvisionWe use a third-party International Bank to provide Credit Card processing facilities and we believe their privacy policies to be appropriate for the service they deliver. For them to do this, we need to let them have some of your personal information including but not limited to the title and name as shown on the card to be used, card identification details such as long card number, expiry date, and security code information.
3.4. Internal reporting, deposits and balances analysisWe may use the personal information referred to in this section 3 to generate aggregated, anonymised data for the purposes of internal reporting, insight and analysis, enabling us to improve and personalise our Web Site, the holidays we offer and search results for our Site. We do not use any third parties to perform these analyses.
3.5. Site personalisationWe may use your personal information and/or feedback to personalise aspects of our Site, and for market research. We are always working to make a better Site for you and using your personal information in this way helps us to do this. It also means that if you've given us permission, any email we send to you is appropriate for your needs.
3.6. Contacting youWe collect and may use your personal information to:
3.6.1 contact you in response to communications you have sent to us. We want to help you, so we use your personal data to provide clarification or assistance in response to your communications;
3.6.2 We may invite you to take part in polls and other market research activities carried out by us or by other organisations on our behalf. Any feedback you provide will only be used to improve our Site and will not be published. However, should we contact you about this, you do not have to respond;
4. Why do we process your personal information?We will only collect and use your personal information (as described in sections 2 and 3) in accordance with data protection laws. Our grounds for processing your personal information are as follows:
- Consent – Where necessary we will only collect and process your personal information if you have consented for us to do so. For example, after you have contacted us, we will use your personal information to provide the services detailed in sections 3.1 and 3.2
- Legitimate Interests – We may use and process some of your personal information where we have sensible and legitimate business grounds for doing so. Under European privacy laws, there is a concept of "legitimate interests" as a justification for processing your personal information. Our legitimate interests for processing your personal information are:
- to communicate with you about a booking. For example, sending you a series of confirmation and update emails after you have placed a booking with us. Unless you have agreed to the contrary, this will not include any non-purchase specific emails or other communications
- to enable us to properly and efficiently serve any claims you may have under our Guarantee and/or other terms and conditions of sale; and
- to improve our Site. We may use your personal information to undertake demographic segmentation and generate profiling information to help us understand what you might be interested in and for market research. We are always working to make a better Site for you and using your personal information in this way helps us to do this.
From 25th May 2018, you will have a right to object to our use of your personal information for these legitimate interests, including a right to object to profiling by us (see section 8 below).
5. Use of children's personal informationWe do not knowingly collect or store any personal information about children under the age of 16. If you are aged under 16 please get your parent or guardian's permission before you provide any personal information to us.
6.2 We will periodically review your personal information to ensure that we do not keep it for longer than is permitted by law (see section 12 below).
7. Disclosure of your personal information to other organisationsThe personal information that we collect when you use our Site is confidential, however, we may disclose your personal information to a third party in the following circumstances:
7.1. Our Credit Card provider and our e-card provider – as described in sections 3.2 to 3.5 above, and for the purposes of providing certain services and enabling your interaction with the Site. We won't ask for your permission to do so on our Site.
7.2. If required or allowed to do so by law;
7.3. If ordered to by any court or any other applicable regulatory, compliance, governmental or law enforcement agency;
7.4. If necessary in connection with legal proceedings or potential legal proceedings;
7.6. We use GOOGLE ANALYTICS to anomalously collect data on your journey to our site and around it. We never send personal information to Google. The data is transferred outside of the EU but Google are an active member of the Privacy Shield Framework which you can view here:
8. How you can change permissionsAll emails or other forms of communication directly from us to you will include clear instructions on how to unsubscribe or amend your subscription preferences. In addition, if you don't want to be contacted by us anymore you can simply email firstname.lastname@example.org. Section 9 below also sets out your other information rights.
9. Your information rights and responsibilities9.1. You already have certain rights under existing data protection legislation, including the right to request a copy of the personal information we hold on you if you request it in writing. From 25th May 2018 you will have the following rights:
9.1.1. Right to correct: the right to have your personal information amended if it is inaccurate or incomplete;
9.1.2. Right to erase: the right to request that we delete or remove your personal information from our systems;
9.1.3. Right to restrict our use of your information: the right to 'block' us from using your personal information or limit the ways in which we can use it;
9.1.4. Right to data portability: the right to request that we move, copy or transfer your personal information;
9.1.5. Right to object: the right to object to our use of your personal information including where we use it for our legitimate interests, or where we use your personal information to carry out profiling to inform our market research and user demographics. If you raise an objection we will stop processing your personal information unless exceptional circumstances apply, in which case we will let you know why we're continuing to process your personal information.We will use reasonable efforts consistent with our legal duty to provide you with your rights in accordance with data protection legislation.
9.3. If you're not satisfied with the way any complaint you make in relation to your personal information is handled by us, then you may be able to refer your complaint to the relevant data protection regulator. In the UK, this is the Information Commissioner's Office.
11. Keeping your personal information secure11.1. Keeping information about you secure is very important to us so we store and process your personal information in accordance with the high standards required under data protection legislation. Although we have never done so, it is conceivable that in the future, for operational reasons the personal information we collect from you may be transferred to and stored in countries outside of the European Economic Area ("EEA"). Your information may also be processed by some of our service providers which may in the future be based outside the EEA. Different countries have different data protection and security laws and some of these do not offer the same level of protection as you enjoy under UK data protection legislation. However, when we appoint our service providers to help us provide products and services to you (which may include some based in the USA), we take care to ensure that they have appropriate security measures in place.
11.2. We do our best to keep the information that you disclose to us secure. However, we can't guarantee its 100% security but will always use our best endeavours to ensure its security and safe storage. By using our Site, you accept the inherent risks of providing information online and will not hold us responsible for any breach of security.
13. How to contact usOur Data Protection Officer is the Managing Director of Nineoaks Fishery.
If you have any queries relating to our use of your personal information or any other related data protection questions, please contact us at email@example.com or write to the Data Protection Officer at Nineoaks Fishery, Oakford near Llanarth, Ceredigion, SA47 0RW.
15. Further InformationYou can find further information on how GDPR affects you by visiting the website of the Information Commissioners Office (ICO) ico.org.uk
Effective as of: 25th May 2018