CREST Planning Ltd is committed to protecting the privacy and security of your personal information. We take care to protect the privacy of our customers and users of our products that communicate online with us, through website and social media platforms.
By browsing or using our website and downloading our software you agree to this policy governing the use of our website and products. If you do not accept this policy then you must not use our website or products.
- To keep your data safe and private.
- Not to sell your personal data.
- To only make available for use by third parties, for commercial sale, academic study or use by law enforcement agencies of selected third parties; generic, anonymised statistical information about events and venues.
- To make it easy for you to manage and review your marketing choices at any time.
- To delete your data if it is no longer required.
What data we collect and what we do with it
Personal data means any information capable of identifying any living individual or natural person however anonymised data is excluded.
From the data you share on this website and via our products we may process the following categories of personal data about you:
Customer Data: This includes data relating to any purchase of goods/services including but not limited to your name, title, billing/delivery address, email address, phone number, contact details, purchase details and your card details.
We will only use this data to provide you with the goods and/or services you have purchased and to keep records of such transactions for our records.
Our lawful grounds for this processing is the performance of a contract between you and us and/or taking steps at your request to enter into such a contract.
Communication Data: This includes but is not limited to any communication that you send to us through our website or other products, through email, text, social media messaging, social media posting, online chats or any other communication that you send us.
We process this data for the purposes of communicating with you, for record keeping and for the establishment, pursuance or defence of legal claims.
Our lawful ground for this processing is our legitimate interests which in this case are to reply to communications sent to us, to keep records and to establish, pursue or defend legal claims.
Technical Data: This includes but is not limited to data about your use of our website, online services or other products such as your IP address, any login data, information regarding your choice of browser, length of visits to web pages, your journey through our website, how often you revisit the site, time zone settings and other technology on the devices you use to access our website.
The source of this data is from our analytics tracking system, we process this data to analyse your use of our website and other online services, to administer and protect our business and website, to deliver relevant website content and advertisements to you and to understand the effectiveness of our marketing.
Our lawful ground for this processing is our legitimate interests which in this case are to enable us to properly maintain our website and help our business to grow and define a marketing strategy.
Marketing Data: This includes but is not limited to data about your preferences in receiving marketing from us and our third parties and your communication preferences. We process this data to enable you [where applicable] to partake in competitions, prize draws and free giveaways, to deliver relevant website content and advertisements to you and measure or understand the effectiveness of this marketing.
Our lawful ground for this processing is our legitimate interests which in this case are to study how customers use our products/services, to develop them, to grow our business and to decide our marketing strategy.
User Data: That includes data about how you use our website and any online services together with any data that you post for publication on our website or through other online services.
We process this data to operate our website effectively and ensure relevant content is provided to you. Like all companies, to ensure the security of our website, we maintain backups of our website and/or databases and to enable publication and administration of our website, other online services and business.
Our lawful ground for this processing is our legitimate interests which in this case are to enable us to properly administer our website and our business, to grow our business and inform our marketing strategy.
We may use Customer Data, User Data, Technical Data and Marketing Data to deliver relevant website content and advertisements to you (including Facebook adverts or other display marketing on platforms including but not limited to Youtube, Instagram, Twitter, Google ads display) and to measure or understand the effectiveness of the marketing you see.
How we obtain your data
We will also receive data about you from 3rd party companies such as Google where we access their analytics platform, and Facebook where we use their display networks, such as search information providers such as Google based outside the EU, providers of technical, payment and delivery services, such as data brokers or aggregators.
We may also receive data from publicly available sources such as Companies House and the Electoral Register based inside the EU.
If our client uses Halo we have have access to the information they input to the system and it will be stored on our system in accordance with our data retention policy. This may include sensitive data about you.
We will only use your personal data for a purpose it was collected for a reasonably compatible purpose if necessary. In case we need to use your details for an unrelated new purpose we will let you know and explain the legal grounds for processing.
We may process your personal data without your knowledge or consent where this is required or permitted by law.
How we use your information
As necessary, to perform a contract with you we will use the following information from you.
Your name and contact details
- To deliver your orders.
- Send order updates by text, e-mail or by telephone.
- Sending you information by e-mail or post about new products and services – we will only send you this with your consent.
- For fraud prevention.
- For customer service and product support.
- For training purposes.
- For the prevention and detection of crime.
Your date of birth information
- For Rental and Finance applications and for fraud prevention.
Your payment information
- All payments made to us are done in in accordance with PCA. Where we accept payment for products or services via BACS we do not gather any financial information from our customers and it remains the responsibility of our banking provider, National Westminster Bank.
Your contact history with us
- For customer service and support.
- To monitor complaints.
Purchase history and saved items
- To provide customer service, support and to deal with returns.
- To comply with legal obligations about looking after your data, to prevent and detect fraud against either you or CREST Planning Ltd.
Visitors to our website
When someone visits www.crestplanning.co.uk, we use a third party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way which does not identify anyone. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website. If we do want to collect personally identifiable information through our website, we will be up front about this. We will make it clear when we collect personal information and will explain what we intend to do with it .
Users of our Event Management System – HaloTM and other products
When a client uses HaloTM we obtain data about them, their employees, sub-contractors, event and members of the public including in some cases still digital still images (photographs) and digital moving images (video/FaceTime) and personal data like home address, physical description or aggravating factors like mental or physical ailments.
All of this data is stored via secure third parties servers, Apple iCloud and Amazon Web Servers. It is only obtained and shared via a closed network of pre-authorised and pre-determined users and only obtained and distributed for the purposes of saving life or preventing and detecting crime and is obtained with the consent of the individual and shared within a closed network with the consent of the individual in question.
Sharing your information
We will not sell or rent your personal data to a third party – including your name, address, email address or date of birth.
However, in order to fulfil your order or service we will share it with:
- Payment service providers and delivery companies.
- Companies that provide services selected by you such as Three Mobile.
- Professional service providers, such as marketing agencies, advertising partners and website hosts who help us run our business.
- Credit reference agencies, finance companies, law enforcement and fraud prevention agencies.
- Manufacturers when spare parts are sent to you or for warranty purposes.
- Service engineers or technicians repairing products in your home or work premises. We may provide third parties with anonymised information and analytics about our customers and their events and, before we do so, we will make sure that it does not identify you.
We also anonymise and aggregate personal information (so that it does not identify you) and use it for purposes including testing our IT systems and improving our website and to develop new products and services. We also share this information with third parties.
We will only send you marketing messages if you consent for us to do so. You can stop receiving marketing messages from us at any time.
You can do this:
- By clicking on the ‘unsubscribe’ link in any email.
- By calling into our team on 0800 920 2014
- By e-mailing email@example.com
- or by writing to CREST Planning Ltd, at our registered company address on Companies House.
Once you do this, we will update your profile to ensure that you don’t receive further marketing messages.
Please note that we will update our systems as quickly as we can but you may still get messages from us while we process your request. Stopping marketing messages will not stop communications in regards to orders or customer related issues.
We also engage in online advertising, also to keep you aware of what we’re up to and to help you see and find our products.
Like many companies, we target CREST Planning Ltd banners and ads to you when you are on other websites and apps. We do this using a variety of digital marketing networks and ad exchanges, and we use a range of advertising technologies like, pixels, ad tags, cookies, and mobile identifiers, as well as specific services offered by some sites and social networks, such as Facebook’s Custom Audience service.
The banners and ads you see will be based on information we hold about you, or your previous use of CREST Planning Ltd products or CREST Planning Ltd banners or ads you have previously clicked on.
Third party links
Our website URL sometimes includes links to third-party websites, plug-ins, and applications. By clicking on those links or enabling those connections may allow third parties to collect or share data about you.
We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, therefore we encourage you to read the privacy notice of every website you visit.
We will keep your information for as long as you have an account, or as long as is needed to be able to provide the services to you, or for as long as is necessary to provide product related services. Unless otherwise required by law, your data will be stored for a period of 7 years after the last contact with you, at which point it will be deleted. If required to meet legal or regulatory requirements, resolve disputes, prevent fraud, or enforce our terms and conditions.
- The right to be informed about how your personal information is being used.
- The right to access the personal information we hold about you.
- The right to request the correction of inaccurate personal information we hold about you.
- The right to request that we delete your data, or stop processing it or collecting it, in some circumstances.
- The right to stop direct marketing messages and withdraw consent for other consent-based processing at any time.
- The right to request that we transfer or port elements of your data either to you or another service provider.
- The right to complain to your data protection regulator — the Information Commissioner’s Office.
If you wish to access your personal information that we hold on you (or to exercise any of the other rights), you can contact our DPO/Data Controller Nicola Horsford on firstname.lastname@example.org or by calling 0800 920 2014 or in writing to our registered company address on Companies House.
Before we will release any information to you we will request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights).
This is a robust security measure and is designed to ensure that you have both the right and legal basis for accessing such information. It protects your data from being disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you.
For more information about your privacy rights
The Information Commissioner’s Office (ICO) regulates data protection and privacy matters in the UK. They make a lot of information accessible to consumers on their website and they ensure that the registered details of all data controllers such as ourselves are available publicly. You can access them here https://ico.org.uk/for-the- public
You can make a complaint to the ICO at any time about the way we use your information. However, we hope that you would consider raising any issue or complaint you have with us first. Your satisfaction is extremely important to us, and we will always do our very best to solve any problems you may have.
How long we retain your data
We retain a record of your personal information in order to provide you with a high quality and consistent service. We will always retain your information in accordance with the General Data Protection Regulation (GDPR) and never retain your information for longer than is necessary. Unless otherwise required by law, your data will be stored for a period of 7 years after our last contact with you, at which point it will be deleted.
Transfer of personal data outside the EEA
Although we are based in England, we may transfer your personal information to a location (for example, to a secure server) outside the European Economic Area, if we consider it necessary or desirable for the purposes set out in this notice.
In such cases, to safeguard your privacy rights, transfers will be made to recipients to which a European Commission “adequacy decision” applies (this is a decision from the European Commission confirming that adequate safeguards are in place in that location for the protection of personal data), or will be carried out under standard contractual clauses that have been approved by the European Commission as providing appropriate safeguards for international personal data transfers, or by the adoption of EU-US Privacy Shield.
Throughout our business, we have put in place significant security measures to prevent your personal data from being breached. This includes your data being lost, used, altered, disclosed, or accessed without authorisation.
We also allow access to your personal data only to those employees and partners who have a business need to know such data, They will only process your personal data on our instructions and they must keep it confidential and all employees have signed a Non Disclosure agreement to this effect.
We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach if we are legally required to.
Changes to our privacy statement
If significant changes are made to this statement than we will make that clear on our websites or by e-mailing you so that you are able to review the changes before you continue to receive marketing messages from us.
How to contact us
If you want to exercise your rights, make a complaint, or just have questions regarding the privacy statement then please contact us by e-mailing email@example.com or by writing to us at our registered company address on Companies House.