We reserve the right to make changes to this Policy at any time. Your continued use of our products, applications, services and websites that are subject to this Policy will signify your acceptance of any and all changes to this Policy made by us from time to time.
Compass Holidays located in Cheltenham is the data controller in connection with any personal information collected or received by us arising from your use of any of our products, services, applications, websites and customer support communications.
2. How we use your personal data
In this section we have set out:
- the general categories of personal data that we may process
- the purposes for which we may process personal data; and
- the legal basis for the processing
We will process your personal data in accordance with all United Kingdom's Data Protection Legislation. We maintain strict security standards and procedures with a view to preventing unauthorised access to your data by anyone, including our staff. We use leading technologies such as (but not limited to) data encryption, fire walls and server authentication to protect the security of your data. For all Compass Holiday brands, all of our staff and whenever we hire third parties to provide support services, we will require them to observe our privacy standards and to allow us to audit them for compliance.
2.1 Online Purchases/Bookings
When you purchase through our website, which includes but is not limited to booking walking and cycling holiday or tours, you will be asked to provide information specific to that order, including but not limited to your billing address, credit card information and email address. The information that you provide is processed for the purpose of supplying the purchased goods and services and keeping proper records of those transactions. We also use the information to contact you if there is a problem with your order. The legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract and our legitimate interests, namely our interest in the proper administration of our website and business.
All of our transactions automatically take place on a secure server. All of your personal information is encrypted before it is transmitted over the Internet.
2.2 Profiling & Statistics
Where your data is consensually supplied to us, for example when you buy from us online, our system automatically gathers some data for statistical purposes. We use this information in two ways: we review what kinds of products and services appeal most to our consumers as a group. This statistical information helps us improve our offerings in the same way that other companies change their catalogue based on what sells best. We use information such as the number of purchases consumers make and the categories of goods and services they buy to make offers to them we believe will be of interest. We do not give out any information about you, as an individual, to anyone, except to complete your transactions, or to comply with valid legal process such as a search warrant, subpoena or court order. The legal basis for this processing is legitimate interest.
We may process information that you provide to us for the purpose of brochure requests, e-newsletters subscriptions and competition entry. This data may be processed for the purposes of sending you the relevant notifications and media.
- E-newsletters - by completing our e-newsletter signup page you are agreeing to receive email marketing communications. These can be unsubscribed from at any time, simply by clicking the unsubscribe link at the bottom of the email.
- Brochure requests – by requesting a brochure you are agreeing to receive brochures from us.
- Competitions - By entering any of our competitions that we may host and completing our entry forms you are agreeing to receive communications from us in future, via email. You can unsubscribe from future emails at any time by clicking the unsubscribe link at the bottom of the email.
The legal basis for this processing is consent.
2.4 User Generated Content
2.4.1 Social Media
If you use any of our social network pages or applications or you use one of our products or services that allow interaction with social networks, we may receive information relating to your social network accounts. For instance:
- If you click on a ‘like’, ‘+1’ or ‘tweet’ or similar button in one of our websites or services, we may record the fact that you have done so. In addition, the content that you are viewing may be posted to your social network profile or feed. We may receive information about further interactions with this posted content (for example, if your contacts click on a link in the posted content), which we may associate with the details that we store about you
- If you ‘like’, ‘+1’ or similar one of our pages on a social network site, we may receive information about your social network profile, depending on your social network account privacy settings.
2.4.2 Reviews, comments and content
Where you have uploaded product reviews, comments or content to our websites or services and made them publicly visible, we may link to, publish or publicise these materials elsewhere including in our own advertisements.
2.5 Legal Obligation
In addition to the specific purposes for which we may process your personal data set out in this section, we may also process any of your personal data where such processing is necessary for compliance with regulatory and legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
3. Providing your personal data to others
We may use other third party service providers to provide certain data processing services for us (acting as our authorised data processors). Examples of authorised data processors could include billing and fulfilment partners, IT solution providers, data analytics providers who process information on our behalf for the purposes outlined above. For example, we may use the services of third parties to personalise content, fulfil orders, deliver packages, send postal mail and emails, send text messages (SMS), provide marketing assistance, process credit card payments, provide fraud checking services and provide customer services.
When acting as our authorised data processors, our service providers are required to only process data in accordance with our instructions, in line with this Policy, and are subject to appropriate confidentiality and security obligations. They will not be permitted to contact you directly for anything other than the fulfilment of obligations as outlined above.
In addition to the specific disclosures of personal data set out in this section, we may also disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
4. International transfers of your personal data
We store your data on our secure servers in the United Kingdom and retain it for a reasonable period or as long as the law requires. However, your data may be transferred to, stored at, and processed at a destination inside or outside the European Economic Area by our partners or service providers. By submitting your personal data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Notice.
5. Retaining and deleting personal data
This Section sets out our data retention policies and procedure, which are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal data.
- Personal data that we process shall not be kept for longer than is necessary for that purpose or those purposes.
- Your personal data will be retained for 5 years following the date you cease to be a client, or longer as required to meet our regulatory obligations.
- Notwithstanding the other provisions of this Section 6, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests.
6. Links to third party sites
Some of our websites may contain links to other third party websites that are not operated by us. While we try to link only to sites that share our high standards and respect for privacy, we are not responsible for the content, security or privacy practices of those third party websites. We strongly encourage you to view the privacy and cookie policies displayed on those third party websites to find out how your personal information may be used.
7. Mobile App
We want to inform you that whenever you use our Service, in a case of an error in the app we collect data and information (through third party products) on your phone called Log Data. This Log Data may include information such as your device Internet Protocol (“IP”) address, device name, operating system version, the configuration of the app when utilising our Service, the time and date of your use of the Service, and other statistics.We may use and store information about your location if you give us permission to do so (“Location Data”). We use this data to provide features of our Service, to improve and customise our Service.
- We may update this policy from time to time by publishing a new version on our website.
- You should check this page occasionally to ensure you are happy with any changes to this policy.
- We may notify you of changes to this policy by email or through private messaging system or via our website.
9. Your Rights
In this Section we have summarised the rights that you have under data protection law. Some of the rights are complex, and not all of the details have been included in our summaries. Accordingly, you should read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights.
Your principal rights under data protection law are:
(a) the right to access;
(b) the right to rectification;
(c) the right to erasure;
(d) the right to restrict processing;
(e) the right to object to processing;
(f) the right to data portability;
(g) the right to complain to a supervisory authority; and
(h) the right to withdraw consent.
You may instruct us to provide you with any personal information we hold about you; provision of such information will be subject to the supply of appropriate evidence of your identity. For this purpose, we will usually accept a photocopy of your passport certified by a solicitor or bank plus an original copy of a utility bill showing your current address.
In practice, you will usually either expressly agree (opt in) in advance to our use of your personal information for marketing purposes, or we will provide you with an opportunity to opt out of the use of your personal information for marketing purposes.
To the extent that the legal basis for our processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.