We are
committed to safeguarding the privacy of our website visitors; this policy[2]
sets out how we will treat your personal information.[3]
[Our website uses cookies. [We will ask you
to consent to our use of cookies in accordance with the terms of this policy
when you first visit our website. / By using our website and agreeing to this
policy, you consent to our use of cookies in accordance with the terms of this
policy.][4]]
(1) Credit
(2) What information do we
collect?
We may
collect, store and use the following kinds of personal information:
[(a) information about
your computer and about your visits to and use of this website (including [your
IP address, geographical location, browser type and version, operating system,
referral source, length of visit, page views, website navigation and [details]]);]
[(b) information relating to any transactions
carried out between you and us on or in relation to this website, including
information relating to any purchases you make of our goods or services
(including [details]);]
[(c) information
that you provide to us for the purpose of registering with us (including [details]);]
[(d) information that you provide to us for the
purpose of subscribing to our website services, email notifications and/or
newsletters (including [details]);]
[(e) any other information that you choose to
send to us; and]
[(f) other information.][5]
[Before you
disclose to us the personal information of another person, you must obtain that
person's consent to both the disclosure and the processing of that personal
information in accordance with the terms of this privacy policy.]
[(3) Cookies[6]
A cookie is a file containing an identifier (a
string of letters and numbers) that is sent by a web server to a web browser
and is stored by the browser. The identifier is then sent back to the server
each time the browser requests a page from the server. This enables the web
server to identify and track the web browser.
We [may] use
[both] ["session" cookies] [and "persistent" cookies] on
the website. [Session cookies will be deleted from your computer when you close
your browser.] [Persistent cookies will remain stored on your computer until
deleted, or until they reach a specified expiry date.]
[We will use
the session cookies to: keep track of you whilst you navigate the website; keep
track of items in your shopping basket; prevent fraud and increase website
security; and [other uses].] [We will use the persistent cookies to:
enable our website to recognise you when you visit; keep track of your
preferences in relation to your use of our website; and [other uses].]
[We use Google Analytics to analyse the use of this
website. Google Analytics generates statistical and other information about
website use by means of cookies, which are stored on users' computers. The
information generated relating to our website is used to create reports about
the use of the website. Google will store this information. Google's privacy
policy is available at: http://www.google.com/privacypolicy.html.][7]
[Our [advertisers / payment services providers] may
also send you cookies.][8]
[We publish
Google AdSense interest-based advertisements on our website. These are tailored
by Google to reflect your interests. To determine your interests, Google will
track your behaviour on our website and on other websites across the web using
the DART cookie. You can view, delete or add interest categories associated
with your browser using Google's Ads Preference Manager, available at:
http://www.google.com/ads/preferences/. You can opt out
of the AdSense partner network cookie at: http://www.google.com/privacy/ads/ or
by using the NAI's (Network Advertising Initiative's) multi-cookie opt-out
mechanism at: http://www.networkadvertising.org/managing/opt_out.asp. However,
these opt-out mechanisms use cookies, and if you clear the cookies from your browser
your opt-out will not be maintained. To ensure that an opt-out is maintained in
respect of a particular browser, you should use the Google browser plug-in
available at: http://www.google.com/ads/preferences/plugin.][9]
[You can
manage your preferences relating to the use of cookies on our website by
visiting [URL].]
Most browsers allow you to reject all cookies, whilst some browsers
allow you to reject just third party cookies. For example, in Internet Explorer
(version 9) you can refuse all cookies by clicking "Tools",
"Internet options", "Privacy", and selecting "Block
All Cookies" using the sliding selector. Blocking all cookies will,
however, have a negative impact upon the usability of many websites[, including
this one].]
(4) Using your personal information
Personal
information submitted to us via this website will be used for the purposes
specified in this privacy policy or in relevant parts of the website.
We may use your
personal information to:
[(a) administer the
website;]
[(b) improve your browsing
experience by personalising the website;]
[(c) enable your use of the
services available on the website;]
[(d) send you goods purchased
via the website, and supply to you services purchased via the website;]
[(e) send statements and invoices
to you, and collect payments from you;]
[(f) send you general
(non-marketing) commercial communications;]
[(g) send you email
notifications which you have specifically requested;]
[(h) send you [our newsletter
and other] marketing communications relating to our business [or the businesses
of carefully-selected third parties] which we think may be of interest to you,
by post or, where you have specifically agreed to this, by email or similar
technology (and you can inform us at any time if you no longer require
marketing communications);][10]
[(i) provide third parties with
statistical information about our users – but this information will not be used
to identify any individual user;]
[(j) deal with enquiries and
complaints made by or about you relating to the website;]
[(k) keep the website secure and
prevent fraud;]
[(l) verify compliance with the
terms and conditions governing the use of the website [(including monitoring
private messages sent through our website private messaging service)]; and]
[(m) [other uses].][11]
[Where you
submit personal information for publication on our website, we will publish and
otherwise use that information in accordance with the licence you grant to us.][12]
[Your privacy
settings can be used to limit the publication of your information on the
website. You can adjust your privacy settings by [describe how].]
[We will not,
without your express consent, provide your personal information to any third
parties for the purpose of direct marketing.][13]
[All our website
financial transactions are handled through our payment services provider,
[PayPal]. You can review the [PayPal] privacy policy at [www.paypal.com]. We
will share information with [PayPal] only to the extent necessary for the
purposes of processing payments you make via our website, refunding such
payments and dealing with complaints and queries relating to such payments and
refunds.][14]
(5) Disclosures
We may disclose your personal information to [any of our employees,
officers, agents, suppliers or subcontractors] insofar as reasonably necessary
for the purposes set out in this privacy policy.
[We may disclose your personal information to any member of our group of
companies (this means our subsidiaries, our ultimate holding company and all
its subsidiaries) insofar as reasonably necessary for the purposes set out in
this privacy policy.]
In addition, we
may disclose your personal information:
(a) to the extent that we are
required to do so by law;
(b) in connection with any
ongoing or prospective legal proceedings;
(c) in order to establish,
exercise or defend our legal rights (including providing information to others
for the purposes of fraud prevention and reducing credit risk);
[(d) to the purchaser (or
prospective purchaser) of any business or asset that we are (or are
contemplating) selling; and]
[(e) to any person who we
reasonably believe may apply to a court or other competent authority for
disclosure of that personal information where, in our reasonable opinion, such
court or authority would be reasonably likely to order disclosure of that
personal information.]
Except as
provided in this privacy policy, we will not provide your information to third
parties.
(6) International
data transfers[15]
Information that
we collect may be stored and processed in and transferred between any of the
countries in which we operate in order to enable us to use the information in
accordance with this privacy policy.
Information
which you provide may be transferred to countries [(including [the United
States], [Japan], [other countries])]
which do not have data protection laws equivalent to those in force in the
European Economic Area.
[In addition,
[personal information that you submit for publication on the website] will be
published on the internet and may be available, via the internet, around the
world. We cannot prevent the use or misuse of such information by others.]
You expressly
agree to such transfers of personal information.
(7) Security of your personal information
We will take
reasonable technical and organisational precautions to prevent the loss, misuse
or alteration of your personal information.
We will store
all the personal information you provide on our secure (password- and
firewall-protected) servers.[16]
[All
electronic transactions entered into via the website will be protected by
encryption technology.]
You
acknowledge that the transmission of information over the internet is
inherently insecure, and we cannot guarantee the security of data sent over the
internet.
[You are
responsible for keeping your password [and other login details] confidential.
We will not ask you for your password (except when you
log in to the website).]
(8) Policy amendments[17]
We may update
this privacy policy from time to time by posting a new version on our website.
You should check this page occasionally to ensure you are happy with any
changes.
[We may also
notify you of changes to our privacy policy by email.]
(9) Your rights
You may
instruct us to provide you with any personal information we hold about you.
Provision of such information will be subject to:
(a) the payment of a fee
(currently fixed at GBP 10); and
(b) the supply of appropriate
evidence of your identity [(for this purpose, we will usually accept a
photocopy of your passport certified by a solicitor or bank plus an original
copy of a utility bill showing your current address)].
We may
withhold such personal information to the extent permitted by law.
You may
instruct us not to process your personal information for marketing purposes[,
by sending an email to us]. In practice, you will usually either expressly
agree in advance to our use of your personal information for marketing
purposes, or we will provide you with an opportunity to opt out of the use of
your personal information for marketing purposes.
(10) Third party websites
The website
contains links to other websites. We are not responsible for the privacy
policies or practices of third party websites.
(11) Updating information
Please let us
know if the personal information which we hold about you needs to be corrected
or updated.
(12) Contact
If you have any
questions about this privacy policy or our treatment of your personal
information, please write to us by email to [email] or by post to [postal
address].[18]
(13) Data controller
The data
controller responsible in respect of the information collected on this website
is [company/business name].
Our data
protection registration number is [number].[19]
You
must retain the SEQ Legal credit and link set out in Section 1 above. However,
professional legal documents do not ordinarily include such credits and
links. You can purchase the right to use this document without the credit and
link here:
Unless
you have purchased this right, it is an infringement of copyright and breach
of licence to use this document without the credit and link.
|
[1] The purpose of a website
privacy policy is help website operators comply with data protection
legislation. In the UK, that primarily means compliance with the Data
Protection Act 1998 and the Privacy and Electronic Communications (EC
Directive) Regulations 2003. Failure to comply with data protection legislation
can lead to civil liability and criminal law penalties.
Our template privacy policy is designed for
use by businesses based in the UK (although the UK data protection regime
derives from EU law, there are differences in how that EU law has been implemented
in the different member states of the EU). The template is designed for
websites which collect standard kinds of non-sensitive personal data for
standard kinds of use. It may be unsuitable for websites which collect
sensitive personal data (such as information relating to a person’s health,
sexuality, ethnicity or politics) or which collect personal information from
children. It may be suitable, for example, for use with websites which act as
online company brochures or online shops.
The template privacy policy will need to be
edited before it is ready for use. Square brackets in the document indicate the
sections which need or are likely to need to be edited. However, you should of
course carefully review the whole document to ensure that it meets with your
requirements. You should also regularly review your privacy policy to ensure
that it remains up to date, both with respect to the law and to your business's
use of personal data. Please note that the use of a privacy policy does not
exhaust your data protection obligations. If you are in any doubt regarding the
preparation of your privacy policy or your data protection obligations
generally, you should seek professional advice.
[2] The privacy policy should
be clearly and easily accessible to website visitors from the website home page
and any page which collects personal data (eg "The personal information we
collect on this page will be treated in accordance with our privacy
policy"). In addition, key information about the use of personal data
should be provided on the page where the data is collected, rather than in a
separate document.
[3] "Personal
information": for day-to-day purposes, it is best to assume that all
information which relates to a living individual constitutes personal information.
(We use "personal data" and "personal information"
interchangeably in this template.)
[4] The inclusion
of this statement in your privacy policy will not in itself satisfy the
requirements of the Privacy and Electronic Communications (EC Directive) Regulations
2003 as regards consent to the use of cookies. Guidance concerning methods of
obtaining such consent is included on the Information Commissioner's website
(http://www.ico.gov.uk).
[5] You should list in this
provision all of the different kinds of personal information which will be
collected over or in relation to your website. We have suggested a number of
common categories.
[6] If your site does not use
cookies, the paragraphs on cookies can be deleted.
The rules concerning cookies are set out in
Regulation 6 of the Privacy and Electronic Communications (EC Directive)
Regulations 2003 (as amended). Regulation 6 provides that:
"(1) Subject to paragraph (4), a
person shall not store or gain access to information stored, in the terminal
equipment of a subscriber or user unless the requirements of paragraph (2) are
met.
(2) The requirements are that the
subscriber or user of that terminal equipment—(a) is provided with clear and
comprehensive information about the purposes of the storage of, or access to,
that information; and (b) has given his or her consent.
(3) Where an electronic communications
network is used by the same person to store or access information in the
terminal equipment of a subscriber or user on more than one occasion, it is
sufficient for the purposes of this regulation that the requirements of
paragraph (2) are met in respect of the initial use.
(3A) For the purposes of paragraph (2), consent may be
signified by a subscriber who amends or sets controls on the internet browser
which the subscriber uses or by using another application or programme to
signify consent.
(4) Paragraph (1) shall not apply to the
technical storage of, or access to, information—(a) for the sole purpose of
carrying out the transmission of a communication over an electronic
communications network; or (b) where such storage or access is strictly
necessary for the provision of an information society service requested by the
subscriber or user."
[7] If you do not use Google
Analytics, you should check whether your analytics system uses cookies and
include an appropriate explanatory paragraph if it does.
[8] If so, you should provide
details. The following paragraphs give examples.
[9] This text should be used if
you publish Google AdSense interest-based advertisements on your website.
Additional disclosures will be required if you have not opted out of
third-party ad serving. For more information, see:
https://www.google.com/adsense/support/bin/answer.py?hl=en&answer=100557.
[10] As a general rule, where you
plan to use personal information you have collected for the purpose of direct
marketing, this should be made clear on the page where the information is
collected, and you should ensure that this only happens if users opt in to the
marketing (eg "Click here if you would like us to send you information by
email about products which we think will interest you."). There are,
however, exceptions to this general rule. There are also rules about the
content of direct marketing communications. If you are in any doubt about
complying with your legal obligations in relation to direct marketing, you
should seek professional advice.
[11] You must list here all the
uses to which you will (or may in future) put personal data. Again, we have
suggested some common categories.
[12] The relevant licence should
be set out in the appropriate disclaimer/terms of use/terms of subscription etc
document.
[13] It is good practice to also
say what you will not do with personal information (within reason).
[14] You should insert details of
any payment services provider(s) you use here. If you do not collect payments
on your website, you can delete this section.
[15] Give as much detail as
possible about any such international transfers. You also need to be aware that
the inclusion of this provision will not be sufficient to ensure that
all international transfers of personal data are lawful. If in doubt, you
should take professional advice on this point.
[16] There is an obligation upon
data controllers to store personal data securely. You should provide details of
your security measures here.
[17] Changes to the policy – in
particular as to permissible uses of personal data – may not be retrospective.
In other words, if you collect personal information on one basis, you cannot,
simply by changing the terms of your policy, go on to legitimately use that
information on a different basis.
[18] You should include a postal
address as well as an email address.
[19] You should check whether you
need to obtain a data protection registration. You can find out about this on
the Information Commissioner's website at http://www.ico.gov.uk.