SOTRA WEBSITE PRIVACY STATEMENT
Updated October 2018
1.WHAT IS A PRIVACY STATEMENT
1.1 The Sotra website (the “Website“) is operated by Sotra Limited (“Sotra” “we” or “us”) of Chapter House, 33 London Road, Reigate, Surrey RH2 9HZ, United Kingdom. Sotra respects your right to privacy and this Privacy Statement (“Statement“) sets out the basis on which we use, process, store or disclose any personal data detailed below (“Personal Data“) we collect from you or that you provide to us through the Website. The information provided by you will be held by us as a data controller.
- OVERVIEW OF THIS PRIVACY STATEMENT
2.1 We collect Personal Data from you when you use the Website and process this Personal Data for the purposes of providing you with access to the Website. You can also choose to provide your Personal Data to us via email which we will process for the purposes of responding to your queries. Responding to these queries is necessary for the purposes of our legitimate interests. We store your Personal Data on servers located in the EEA and/or the USA. We share your Personal Data within the Sotra Group and with third parties. We will also share your Personal Data with law enforcement agencies or public bodies if we are required by law to do so.
- YOUR PERSONAL DATA
3.1 We will collect and process the following Personal Data from you:
|Device Information||When using the Website or availing of services related to the Website, personal information will be collected from you by Google Analytics and by Sotra. This includes information about:
3.2 You can choose to provide us with the following Personal Data:
|Query Information||You may choose to give us additional information such as your first name, last name, e-mail address, telephone number and other details when contacting us or submitting enquiries through the Website or by e-mailing: email@example.com
If you choose to provide us with this information, we will keep a record of this correspondence for as long as is necessary to deal with this query (for further information please see our section on How Long We Keep Your Data For).
3.3 We may obtain the following Personal Data about you from other third parties:
|Third Party Information||We may receive information about you from social media platforms, such as LinkedIn, when you interact with us via such platforms. This includes information such as first name, last name, e-mail address, job title, location, telephone number.
We may receive information about you from other third parties where we offer co-branded services or engage in joint-marketing activities.
- HOW & WHY WE USE YOUR PERSONAL DATA
4.1 The following table details the legal basis for (the “Legal Basis“) and the reasons why (“Purposes“) we process your Personal Data:
|Legal Basis||Purpose(s)||Personal Data Processed|
It is necessary to process these Personal Data to enter into and perform our contract with you regarding the use of the Website.
|Access to the Website
To provide you with access to the Website and to allow you to use the Website
It is necessary for the purpose of our legitimate interests to collect and process these Personal Data for the purpose of improving and monitoring website efficiency and enhancing your use of the Website.It is also necessary for the purpose of our legitimate interests to process your Personal Data to respond to any queries or requests submitted by you to Sotra.
|Improving Website Functionality & Efficiency
Responding to Queries
Promotional or Marketing materials
|Compliance with a Legal Obligation
We may process your Personal Data where it is necessary to comply with legal obligations to which we are subject.
|To Defend, Establish or be a Party to Legal Claims
We may process your Personal Data as necessary in order for us to establish, investigate, exercise or defend a legal claim to which you are a party.
- WHO WE SHARE YOUR PERSONAL DATA WITH
5.1 We may disclose your Personal Data to other members of our group which means our related companies and their subsidiaries, if applicable (the “Sotra Group“).
5.2 We will only disclose your personal information to third parties outside the Sotra Group in the following circumstances:
|Third Party Service Providers
|Prospective Sellers or Buyers of Business Assets
|Regulatory Authorities, Law Enforcement Agencies, Public Bodies and Other Third Party Companies
- STORING OF AND TRANSFERS OF YOUR PERSONAL DATA
Your personal data may be stored and transferred outside the European Economic Area (“EEA“). We only transfer your personal data outside the EEA where the EU Commission has decided that the third country in question ensures an adequate level of protection in line with EU data protection standards or there are appropriate safeguards in place to protect your Personal Data. If you would like to find out more about the appropriate safeguards that we have in place to govern the transfer of your personal data you can contact us at firstname.lastname@example.org
Unfortunately, the transmission of information via the internet is not completely secure. Although we will always do our best to protect your personal data, we cannot guarantee the security of any information you transmit to us; any transmission is at your own risk. Once we have received your information, we will endeavour to use strict procedures and security features to try to prevent unauthorised access.
7.1 The Website may contain links to other websites (“Linked Websites“). Sotra is not responsible for the privacy statements or practices on the Linked Websites. This Privacy Statement governs only information collected on the Website. When accessing Linked Websites, you should read the privacy statement published on the relevant Linked Website. The terms of our Privacy Statement do not apply to Linked Websites. Please check these statements before you submit any Personal Data to Linked Websites.
7.2 The Website may contain links to other sites and resources provided by third parties for your convenience and information only. We accept no liability in connection with any Linked Website, or any contract entered into or through a Linked Website. We have no control over the contents of those sites or resources, and accept no responsibility for them or for any loss or damage that may arise from your use of Linked Websites.
- HOW LONG WE KEEP YOUR PERSONAL DATA FOR
8.1 In general, we expect to keep your personal data for a period of three (3) years from the date of collection or as long as is necessary for the reason it was obtained.
8.2 Please note that in certain circumstances, we may hold your data for a longer period, for example, if we are processing an ongoing claim or believe in good faith that the law or a relevant regulator may reasonably in our view expect or require us to preserve your data.
- YOUR RIGHTS AND HOW TO EXERCISE THEM
9.1 The table below sets out the rights which you have to address any concerns or queries with us about our processing of your personal data:
|Right to be Informed||You have the right to know whether your Personal Data is being processed by us, how we use your Personal Data and your rights in relation to your Personal Data.|
|Right of Access||You have the right to request a copy of the Personal Data held by us about you and to access the following information in relation to the processing of your Personal Data:
We will only charge you for making such an access request where we feel your request is unjustified or excessive.
|Right to Rectification||You have the right to request that we amend any inaccurate Personal Data that we have about you.|
|Right to Erasure||You have the right to ask us to erase your Personal Data where:
Please note that some of your Personal Data may be required in order for the Website to function properly.
|Right to Restriction of Processing||You have the right to ask us to restrict processing your Personal Data in the following situations:
|Right to Data Portability||You may request us to provide you with your Personal Data which you have given us in a structured, commonly used and machine-readable format and you may request us to transmit your Personal Data directly to another data controller where this is technically feasible.
This right only arises where:
|Right to Object||You have a right to object at any time to the processing of your Personal Data where we process your Personal Data on the legal basis of pursuing our legitimate interests.|
|Right to Object to Automated Decision-Making, including Profiling||You have a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
We may not be able to comply with this request where the processing is necessary to enter or perform our contract with you or where you explicitly consent to this. However, you are entitled to have a person from our team to review the decision so that you can query it and set out your point of view to us.
9.2 You can exercise any of these rights by submitting a request to email@example.com
9.3 We will provide you with information on any action taken upon your request in relation to any of these rights without undue delay and at the latest within one month of receiving your request. We may extend this up to 2 months if necessary however we will inform you if this arises.
9.4 You have the right to lodge a complaint with a data protection supervisory authority with regards to us processing your Personal Data.
- CHANGES TO THIS PRIVACY STATEMENT
10.1 If we amend this Statement, in whole or part, any changes will be posted on this page and, where appropriate, notified to you by email or when you use the Website. The new Statement may be displayed on-screen and you may be required to read and accept it to continue your use of the Website.
10.2 If at any time we decide to use your Personal Data in a manner significantly different from that stated in this Statement, or otherwise disclosed to you at the time it was collected, we will notify you by e-mail, and you will have a choice as to whether or not we use your Personal Data in the new manner.
- WHO TO CONTACT WITH QUERIES
11.1 Questions, comments and requests regarding this Privacy Statement are welcomed and should be addressed to: firstname.lastname@example.org