GDPR

Introduction

The EU General Data Protection Regulations (GDPR) require all companies to treat personal information collected or handled securely and maintain accurate records as to how this information is stored and used. This policy details the information regarding personal data that the Grand Union Narrowboats Ltd website collects, stores and uses.

Who are we?

Grand Union Narrowboats Ltd is a Limited Company registered in England (No. 10675885). We hire out narrowboats for leisure purposes. Our registered address is: Grand Union Narrowboats Ltd, The Boatyard, Weedon, Northamptonshire NN7 4QD.

How do we collect personal information from you?

Grand Union Narrowboats Ltd collects personal information via the following means:

  • via our website contact form
  • when you send us an email
  • when you call us on the telephone
  • HubSpot (marketing, sales and service software) including when you subscribe to our mailing list to receive marketing communications
  • Holray Booking system (when you book a narrowboat)

What type of information is collected from you?

The personal information we collect might include:

  • Your name and contact information (including email address and phone number)
  • Other information relevant to your interest in hiring a narrowboat
  • Invoicing information which you provide to us when you choose to hire a narrowboat (for example, your address)

Website usage data - we may monitor your use of this website through the use of cookies

For example, we may monitor how many times you visit, which pages you go to, traffic and location data, IP address, operating system and browser type. This information helps us to build a profile of our users. Most of this data is aggregated or statistical, which means that we cannot identify you individually.

Only the IP address could be used to identify you individually (indirectly through your ISP and only by the relevant authorities). Your IP address is only stored in log files that are deleted after 30 days.

Please see further the section on 'Use of cookies' below.

How is your information used?

Collecting this data helps us understand what you are looking for from our business, enabling us to deliver improved products and services, and in particular for the following reasons:

  • to contact you in response to a specific enquiry or request
  • to carry out our obligations arising from any contracts entered into by you and us
  • to collect payments and send invoices and statements
  • to seek your views or comments on the services we provide
  • to contact you via email, telephone or post for market research reasons
  • to send promotional emails or post mailings about products, services and other things we think may be relevant to you (only if you opt-in to these communications)
  • to notify you of changes to our services, legal terms or compliance requirements etc
  • to contact customers relating to past, present and future sales

Who has access to your information?

We will never lease, distribute or sell your personal information to third parties unless we have your permission or the law requires us to.

Third Party Service Providers working on our behalf: We may pass your information to our third party service providers, agents subcontractors and other associated organisations for the purposes of completing tasks and providing services to you on our behalf (for example our website hosting provider). However, when we use third party service providers, we disclose only the personal information that is necessary to deliver the service.

We may transfer your personal information to a third party as part of a sale of some or all of our business and assets to any third party or as part of any business restructuring or reorganisation, or if we're under a duty to disclose or share your personal data in order to comply with any legal obligation or to enforce or apply our terms of use or to protect the rights, property or safety of our supporters and customers. However, we will take steps with the aim of ensuring that your privacy rights continue to be protected.

How you can access and update your information

The accuracy of your information is important to us. If you change email address, or any of the other information we hold is inaccurate or out of date, please contact our Data Controller (see below).

You have the right to ask for a copy of the information Grand Union Narrowboats Ltd holds about you or to ask for it to be removed. We will only remove data we hold on you if we are not legally obliged to retain it (e.g. for tax or contractual purposes).

We will ask you to provide formal proof of identity before releasing, editing or removing any of your information.

Data Controller

Grand Union Narrowboats Ltd is a registered data controller with the Information Commissioner’s Office (ICO). Under our notification with the ICO we are registered to process personal data for the purpose and / or reasons stated in this privacy policy.

Our data controller can be contacted at:

Steve Furniss (Data Controller)
Grand Union Narrowboats Ltd
The Boatyard
High Street
Weedon
Northamptonshire NN7 4QD

Telephone: 01327 342 418

Email: enquiries@grandunionnarrowboats.co.uk

Security precautions in place to protect the loss, misuse or alteration of your information

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.

Grand Union Narrowboats Ltd will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information.

All customer and supplier details will be kept stored on secure servers, and access limited only to authorised personnel with password protected access.

We follow generally accepted industry standards to protect the information submitted to us, both during transmission and once we receive it. We maintain appropriate administrative, technical and physical safeguards to protect Personal Data against accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse, and any other unlawful form of processing of the Personal Data in our possession. This includes, for example, firewalls, password protection and other access and authentication controls. We use SSL and TLS encryption technology to encrypt data during transmission through public internet (your enquiry form submissions and their transmission via email services to us).

However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. We cannot ensure or warrant the security of any information you transmit to us or store, and you do so at your own risk. We also cannot guarantee that such information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. Once we receive your information, we make our best effort to ensure its security on our systems. If you believe your Personal Data has been compromised, please contact us.

Use of 'cookies'

Please see this page.

Links to other websites

Our website may contain links to other websites run by other organisations. This privacy policy applies only to our website‚ so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website.

In addition, if you linked to our website from a third party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and recommend that you check the policy of that third party site.

There may be instances where our website features social sharing buttons, which help share web content directly from web pages to the respective social media platforms. You use social sharing buttons at your own discretion and accept that doing so may publish content to your social media profile feed or page. You can find further information about some social media privacy and usage policies in the third party processors section below.

Email links

If you email us directly, or via a email mailto hyperlink (like this one), the email is transmitted to us via the Simple Mail Transfer Protocol (SMTP). Depending on your email provider, the email contents may or may not be encrypted from the point at which it leaves your computer, until it reaches your email provider or in some cases, until it reaches us. We have no control over this, but most popular email providers like Gmail do provide end-to-end encryption.

Contact Form

Our website contact form operates with a SSL ('Secure Sockets Layer' or 'https'). This means that any information you enter on our contact form will be encrypted by your own web browser from the point you click the 'Submit' button until it reaches our web server. It is briefly decrypted on our web server, but is then re-encrypted and transmitted to us via our email host where it is only ever transmitted in an encrypted form or held in a highly secure manner.

Our website contact form has a reCAPTCHA control, which is an additional safety feature to help prevent businesses from receiving spam or automated data, and thus protecting the website and customer data.

About this website's server

This website is hosted in a virtual server by Amazon (Amazon Web services) within a secure UK data centre. The server may only be accessed by authorised personal and we have taken numerous security precautions including:

  • Anti-Virus and Anti-Malware scans (passive and active)
  • Secure SSH (Secure Shell) access with private/public key and password authentication for access by authorised personnel only
  • Firewall locking down all but essential ports
  • Security settings applied so server meets the technical level of PCI (Payment Card Industry) security requirements.
  • Regular backups to secured backup storage

Our third party processors

We use a number of third parties to process personal data on our behalf.

16 or Under

We are concerned about protecting the privacy of children aged 16 or under. If you are aged 16 or under‚ please get your parent/guardian's permission beforehand whenever you provide us with personal information.

Data Breaches

We will report any unlawful data breach of this website's database or the database(s) of any of our third party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.

Our lawful basis for processing this data

Our lawful basis for processing this data is your explicit consent, without which the enquiry is discarded. We will ensure we have your permission to use the data necessary for the fulfilment of services provided or in order to take steps to procuring further orders.

Data Retention

Grand Union Narrowboats Ltd will retain personal data we process on behalf of our customers as follows: 7 years on invoices for HMRC tax purposes, 3 years on email marketing list.

Review of this Policy

We keep this Policy under regular review. This Policy was last updated in July 2020, but we may change this Policy from time to time so please check this page occasionally to ensure that you're happy with any changes. By using our website, you're agreeing to be bound by this Policy.

Any questions regarding this Policy and our privacy practices should be sent by email to enquiries@grandunionnarrowboats.co.uk or by writing to Grand Union Narrowboats Ltd, The Boatyard, Weedon, Northamptonshire NN7 4QD.

Top