Privacy Information Notice

At Dale Valley Training, we’re committed to protecting and respecting your privacy.

This Policy explains when and why we collect personal information, how we use it, the conditions under which we may disclose it to others and what choices you have.

We may change this Policy from time to time so please check this page occasionally to ensure that you’re happy with any changes. By using our services, you’re agreeing to be bound by this Policy.

Any questions regarding this Policy and our privacy practices should be sent by email to [email protected] or via the other methods on our website contact page.

Date:  25/05/2018
Review Date:  25/11/2018
Author:  Jill Heal, Dale Valley Training Limited

 

1. Who are we?

We are Dale Valley Training Limited, an organisation providing bespoke, end-to-end Health & Safety Training.

Dale Valley Training is a Limited Company.

Registered Address:
Dale Valley Training Limited, 16 Hammonds Lane, Totton, Southampton, SO40 3LG, Registered in England and Wales. Registration Number: 10605929. VAT Registration No: GB 875 8870 55.

Trading Address:
Dale Valley Training Limited, Ground Floor Office, Unit 13 Dale Valley Gardens, Southampton, SO16 6QT.

Full contact details can be found on our website contact page.

 

2. How do we collect information from you?

We obtain information about you when you visit our website and when you contact us to enquire about our training services.

 

3. What information do we collect & how is it used?

The table in section 3.3 below outlines exactly what information we collect from our website and for what purpose.

 

3.0. Sensitive Data

We do not gather sensitive personal data on our website (e.g. health, genetic, biometric data; racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, and criminal convictions). We expressly request that you do not provide any such sensitive data to us.

 

3.1. Children’s information

Our services are not directed to children under 13. If you learn that a child under 13 has provided us with personal information without consent, please contact us.

 

3.2. Third Parties

We will not sell or rent your information to third parties.

We will not share your information with third parties for marketing purposes.

We use a number of 3rd party services to help us fulfil our website contractual obligations. These 3rd party services are listed in full below; we have verified that these 3rd party services are GDPR compliant (or are working towards GDPR compliance) and are certified under the EU-US Privacy Shield Framework (or are working towards certification) where these organisations are based outside of the EU.

 

3.3. Details

The following table outlines the personal data we collect from our website and for what purpose. The table also outlines the 3rd parties the data is processed by or shared with, and how long the data is stored for:

Name What Legal Ground Purpose 3rd Parties Data Retention
Email Prospect, client & supplier contact information Contract To allow initial and ongoing contact with prospects, clients, suppliers, etc. Zen Internet
Servers based in Rochdale
Until request for deletion
Website Forms (contact, course booking & course request forms) Name, contact details, enquiry preferences Contract To allow potential customers to request information about courses WP Engine
Hosted in UK (London) data centre
All contact form entries are automatically deleted from the website server each week
SparkPost Email address, email metadata and content (from above forms) Contract Ensures website form entries are reliably emailed to our Zen email account SparkPost Up to 10 days
Analytics Website visitor behaviour (anonymised – full IP address is NOT stored) Legitimate interests To analyse popular content, website performance, etc – so we can further improve. Google Analytics
We have signed EU model contract clauses & anonymise IP addresses
14 months. NB: not personal data
Website Back-Up Backup of website files and database Contract To ensure business continuity in the event of hardware failure WP Engine Up to 3 months, encrypted
DNS Log Data IP address, system configuration information, etc Legitimate interests Cloudflare provides DNS, web optimisation & security services for our website Cloudflare Stored indefinitely
Server Logs IP address Legal obligation To help prevent DoS (Denial of Service) attacks for website security & diagnostics WP Engine Server logs are stored unencrypted for 7 days & then moved to an encrypted backup which is stored indefinitely & only accessible by WP Engine.

 

4. Controlling your information

You have certain rights concerning the information we hold about you, as defined under the General Data Protection Regulation. If you wish to exercise these rights, please contact us, including your full name and employer name (if appropriate) in the first instance (these are the identifiers we use to identify and collate personal information).

 

4.0. Requesting a copy of your information

You may request a copy of any data we hold about you. Upon request, we will provide a CSV file (which you may open in a program such as Microsoft Excel) detailing the personal data we hold on record about you.

 

4.1. Updating or correcting your information

The accuracy of your information is important to us. If you change email address, or any of the other information we hold is inaccurate or out of date, please contact us so we may correct our records.

 

4.2. Deleting your information

You have the right to request erasure of your personal information. Unless there is a compelling reason for the data not to be erased (for example, if we need to use that data to fulfil our contractual or legal obligations), your personal data will be deleted on request.

 

4.3. Automated decision making

We do not use any personal information for automated decision making or profiling; your data is not subject to automated decision making or profiling.

 

5. Use of ‘cookies’

Like many other websites, our website uses cookies. Cookies are small pieces of information that are stored on your computer or mobile device when you visit a website.

The cookies we use are ‘1st party’ cookies. We don’t use any ’3rd party’ cookies (these are often used to track behaviour across a range of websites, so targeted advertising can then be applied. We don’t do this!!) The following list outlines what we use cookies for:

 

Google Analytics

Google Analytics sets cookies to help us accurately estimate the number of visitors to the website and what content is most popular. This helps to ensure that our website is responding to your needs in the best way possible. Google Analytics may set the following cookies:

  • _ga (Expiry: 2 years)
  • _gid (Expiry: 24 hours)
  • _gat (Expiry: 1 minute)
  • AMP_TOKEN (Expiry: 30 seconds to 1 year)
  • _gac_<property-id> (Expiry: 90 days)

 

Cloudflare

Cloudflare sets a single cookie to allow it to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application, and does not store any personally identifiable information:

  • __cfduid

By using and browsing our website, you consent to cookies being used in accordance with this Policy.

If you do not consent, you must “turn off” cookies or refrain from using the site. Most browsers allow you to turn off cookies. To do this, look at the ‘help’ menu on your browser. Switching off cookies should not noticeably restrict your use of this website.

 

6. Security

Dale Valley Training takes security seriously. To protect your information from loss, misuse or unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect. These steps include the following:

  • Data minimisation
  • Password best practice
  • Security best practice concerning devices (PCs, laptops, mobile devices), online accounts, website hosting, physical access and storage
  • Security best practice concerning documentation
  • Staff training and accountability on data protection

A copy of our internal Data Security Policy and copies of our GDPR training certificates are available on request.

 

7. Data Breaches

Our Data Breach Policy includes a clear process for handling a personal data breach, should one occur. Where appropriate, Dale Valley Training will promptly notify you of any unauthorised access to your personal information.

 

8. Complaints

If you wish to raise a complaint on how we have handled your personal information, you can contact us directly and we will investigate the matter.

If you are not satisfied with our response or believe we are processing your personal information not in accordance with the law, you can complain to the Information Commissioner’s Office (ICO).