Privacy Policy Statement
This is our privacy policy from 25th February 2021 in accordance with the Data Protection Act 2018 and the UK GDPR (the “Act” or “GDPR”) . Again, this sets out how we will treat both you and your personal data, but reflects changes to your rights and our obligations introduced as a result of the GDPR. During the course of our activities, Wifinity Limited of 5th Floor, The Grange, 100 High Street, Southgate, London, N14 6BN, United Kingdom (we), will collect, store and process data about users of our website at www.wifinity.co.uk and our Wi-Fi services to you (you).
About this Policy
- The personal data (personal data or information) that we hold about you, which may be held on paper or on a computer or other media, is subject to certain legal safeguards specified in the GDPR and other regulations.
- This policy sets out the basis on which we will process any personal data we collect from you, or that is provided to us by you or from other sources.
Cookies
Where you have consented to our use of cookies, cookies will be used to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our website. For detailed information on the cookies we use and the purposes for which we use them see our Cookie Policy.
What information we may hold about you
- Information you give us. This is information about you that you give us by registering to use our WiFi service including filling in forms, completing a survey on our website at www.wifinity.co.uk (our website) or by corresponding with us by phone, e-mail or otherwise. It is the information you provide when you register with us and when you report a problem with our website or services. The information you give us and we hold about you may include your name, address, age, phone number, email address, billing details, subscription history as well as device identifiers and usage (applications and browsing history).
- Information we collect about you. With regard to each of your visits to our website we will collect the following information:
a. Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform.
b. Information about your visit, including the full Uniform Resource Locators (URL), clickstream to, through and from our website (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number.
c. Information we receive from other sources. This is information we receive about you if you use any of the other services we provide. In this case we will have asked for your consent when we collected that personal data if we intended to share that personal data internally and combine it with data collected on our website. We will also have told you for what purpose we will share and combine your personal data. We work closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies). We will notify you when we receive information about you from them and the purposes for which we intend to use that information.
What we may use this information for
1. Where we need to use your information to perform a contract with you or to fulfil a request originated by you.
2. Where you have given your consent for us using your information
3. When using your information is in our legitimate business interests (provided these interests are balanced against your rights
4. Where we need to process your personal data to comply with legal obligations to which we are subject
We may contact you
- To provide you with information about other goods and services we offer that are similar to those that you have already purchased or enquired about.
- To provide you, or permit selected third parties to provide you, with information about goods or services we feel may interest you. If you are an existing customer, we will only contact you by electronic means (e-mail or SMS) with information about goods and services similar to those which were the subject of a previous sale or negotiations of a sale to you. If you are a new customer, and where we permit selected third parties to use your personal data, we (or they) will contact you by electronic means only if you have consented to this by opting in to receive such information
- To notify you about changes to our services and/or.
- To ensure that content from our website is presented in the most effective manner for you and for your computer.
Information we collect about you. We will use this information:
- To administer our website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes
- To improve our website to ensure that content is presented in the most effective manner for you and for your computer
- To allow you to participate in interactive features of our service, when you choose to do so.
- As part of our efforts to keep our website safe and secure
- To measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you; and/or
- Where you have agreed to this, to make suggestions and recommendations to you and other users of our website about goods or services that may interest you or them.
Information we receive from other sources. We will combine this information with information you give to us and information we collect about you. We will use this information and the combined information for the purposes set out above (depending on the types of information we receive).
Lawfulness of processing
- In the course of our business, we may collect and process personal data and are, for that purpose, a controller of the data. This may include data we receive directly from you (for example, by completing forms or by corresponding with us by mail, phone, email or otherwise) and data we receive from other sources (including, for example, business partners, sub-contractors in technical, payment and delivery services, credit reference agencies and others).
- The GDPR is not intended to prevent the processing of personal data, but to ensure that it is done lawfully and without adversely affecting your rights as the data subject
- We will only process personal data as specifically permitted by the GDPR. We will usually obtain your consent to process your personal data unless one of the exemptions within the GDPR permits processing without your consent.
- For the purposes of processing your personal data we will usually rely on one of the following conditions:
- Where you have given your consent to the processing your personal data for one or more specific purposes and/or
- Processing is necessary for the performance of a contract to which you are a party or in order to take steps you requested prior to entering into a contract with us (for example, a contract for our WiFi services).
Principles relating to the processing of Personal Data
- We will process all personal data fairly and in a transparent manner. In particular personal data will be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. All personal data shall be:
a. Adequate, relevant and limited to what is necessary in relation to the purposes for which the personal data is processed.
b. Accurate and, where necessary, kept up to date; every reasonable step will be taken to ensure that personal data which is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay.
c. Kept in a form which permits the identification of you as a data subject for no longer than is necessary for the purposes for which the personal data is processed and
d. Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
Consent to process personal data
- We shall usually seek your consent to process personal data using clear and plain language. You will have the right to withdraw your consent at any time.
- We will only process and hold your personal data as long as is necessary to provide our services (for example, for the duration of the contract through which we provide our WiFi services to you).
- Where we are providing our Wifi services to you, withdrawing your consent for us to process you personal data may prevent us from providing our services to you. If you still wish to withdraw your consent, you must provide us with any necessary notice to end our provision of services to you as set out in our agreement with you.
Your right of access
The GDPR gives you the right to access copies of the information held about you. Your right of access can be exercised in accordance with the GDPR. The first copy of the personal data held about you will be provided free of charge but any subsequent copy will be subject to a reasonable fee based on the administrative costs of providing this information to you.
The right to correct or erase personal data and restriction of processing
- You have the right to ensure that we correct the records of any personal data held about you which is inaccurate. You also have the right to ensure that we complete any incomplete personal data held about you.
- You have the right to ensure that we erase your personal data (the right to be forgotten).
- In certain circumstances, such as where you have contested the accuracy of personal data, you have the right to restrict our processing of your personal data.
- Where any rectification or erasure of personal data or restriction of processing has taken place we shall communicate any rectification to you or erasure or restriction of processing to each recipient to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort. We shall, if you request, inform you about those recipients.
Your right to request an electronic copy of your personal data
Where you request personal data you have the right to be provided with a structured, commonly used and machine-readable copy and have the right, in certain circumstances, to ensure that we transmit that personal data to another controller without hindrance.
Automated individual decision-making
We do not envisage that any automated decision-making or profiling will be carried out. Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
Right to object to direct marketing
You have the right to object to processing for direct marketing purposes. We will always obtain your prior consent before we carry out any direct marketing.
Data storage and Data security
- We will take appropriate security measures against unlawful or unauthorised processing of personal data, and against the accidental loss of, or damage to, personal data and shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Any payment transactions will be encrypted. Where we have given you (or where you have chosen) a password which enables you to access our services or certain parts of our website, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
- We will put in place procedures and policies to maintain the security of all personal data from the point of collection to the point of destruction. Personal data will only be transferred to a third party to process that personal data on our behalf if that third party agrees to comply with those procedures and policies, or if that third party puts in place adequate security measures. By default only personal data which is necessary for each specific purpose of the processing shall be processed.
- All information you provide to us is stored on our secure servers or with trusted third parties. Some of these third parties are based outside the European Economic Area (the “EEA“). If we do transfer your information outside the EEA we will take appropriate steps to protect that information which include one of the following: (i) transferring to third parties in jurisdictions that the EU Commission has determined offers adequate protection for your information’ (and information relating to Adequacy Decisions made by the European Commission are available; (ii) entering into an agreement with the third party, which includes clauses that the EU Commission has determined offers adequate protection for your information; or (iii) transferring to third parties that have agreed to comply with schemes approved by the European Commission to protect your information.
- Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, as described in this policy, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk.
Retention of records
We shall only hold your personal data in our records for as long as is required to provide our services to you. Unless we have notice from you that you wish us to terminate our services to you, we shall erase all of our records of your personal data within twenty four months from the last ascertainable point that you accessed our services.
Right to complain to the supervisory authority
You have the right to lodge a complaint about the way your personal data has been processed with the Information Commissioner’s Office at any time.
Disclosure and sharing of personal information
- We may share personal data we hold with any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
- We may also disclose personal data we hold to third parties in circumstances such as the following:
a. In the event that we sell or buy any business or assets, in which case we may disclose personal data we hold to the prospective seller or buyer of such business or assets
b. If we sell all of our assets or substantially all of our assets are acquired by a third party, in which case personal data we hold will be one of the transferred assets
c. To provide to business partners, suppliers and sub-contractors for the performance of any contract we enter into with you. Any of these third parties will be required to provide you with a notice that they are processing your personal data if they do so
d. Where you have provided consent for us to do so, to analytics and search engine providers that assist us in the improvement and optimisation of our website
e. Where you have provided consent for us to do so, to credit reference agencies for the purpose of assessing your credit score where this is a condition of us entering into a contract with you and
f. If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply any contract with you or other agreements; or to protect our rights, property, or safety of our employees, customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Notification of a personal data breach
- We shall, without undue delay, and where feasible, not later than 72 hours after having become aware of a personal data breach, notify the personal data breach to the Information Commissioner’s Office, unless the personal data breach is unlikely to result in a risk to your rights and freedoms.
- Where the personal data breach is likely to result in a high risk to your rights and freedoms we shall communicate the personal data breach to you without delay.
Contact
Questions, comments and requests regarding this policy are welcomed and should be addressed to data@wifinity.co.uk.
Other websites
Our website may have links to other websites. This policy only applies to this website and not those of other websites. You should, therefore, read the privacy policies of the other websites when you are using those websites.
Changes to this policy
We reserve the right to change this policy at any time. Where appropriate, we will provide you with notice of those changes by post or email