Protecting your personal details
Last updated: 9th May 2017
Here&there is a trading name of Main Image Ltd (registered number: 1776263). We know that you care how information about you is used and shared and we appreciate your trust in us to do that carefully and sensibly. We are committed to protecting and respecting your privacy.
The lawful basis of our information processing under Article 6 of the GDPR has been identified. We have established consent, we support vital interests of our clients in their care of their CFPs, and our business has a legitimate interest in the data processing we do to provide our services. These bases apply to both our monitoring data and commercial data. We have also reviewed our approach to obtaining consent and continue to work with our intermediary agents and families to ensure compliance with the GDPR legislation.
We have verified that we have procedures such that the rights of individuals with respect to their data are assured. In addition, we have verified that our procedures are such that any request to process or amend data is handled in a secure manner with additional processes to detect and investigate any data breaches. Internally, we practice a risk-reduction compliance process of knowledge separation between registration data, commercial information and monitoring data in order to maximise protection of your data. Our systems are structured such as to anonymise as much data as we can, so that any maintenance and servicing of our systems does not involve our developers seeing any link between database data and actual identifiable individuals.
It should be recognised that access to our monitoring service data is not managed by ourselves but by the families and care organisations that use our systems to provide a monitoring service. While we do everything we can to inform those users of the importance of protecting your data, we cannot be held responsible for third party errors and ommisions.
The role of data protection officer has been allocated and formal responsibilities identified.
This website and its data
The Website is brought to you by Here&There. Here&There believes it is important to protect your Personal Data (as defined in the Data Protection Act 1998) and we are committed to giving you a personalised service that meets your needs in a way that also protects your privacy. This policy sets out the basis on which any personal data we collect from you, or that which you provide to us, will be processed by us. For the purpose of the Data Protection Act 1998, the data controller is: The Data Controller, Here & There c/o Main Image Ltd, 37 Southgate St, Winchester, SO23 9EH. It also explains some of the security measures we take to protect your Personal Data, and tells you certain things we will do and not do. You should read this policy in conjunction with the Website Terms.
Some of the Personal Data we hold about you may be ‘sensitive personal data’ within the meaning of the Data Protection Act 1998, for example, information about your health.
Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
Collecting Information for commercial purposes
We may collect data about you from a number of sources, including the following:
1.1. From you when you agree to take a service or product from us, in which case this may include your contact details, date of birth, how you will pay for the product or service and your bank details.
1.2. From you when you contact us with an enquiry or in response to a communication from us, in which case, this may tell us something about how you use our services.
1.3. From documents that are available to the public, such as the electoral register.
Using Your Personal Information
2.1. Personal Data about our customers is an important part of our business and we shall only use your Personal Data for the following purposes and shall not keep such Personal Data longer than is necessary to fulfil these purposes:
• 2.1.1. To help us to identify you when you contact us.
• 2.1.2. To help us to identify accounts, services and/or products which you could have from us or selected partners from time to time. We may do this by automatic means using a scoring system, which uses the Personal Data you have provided and/or any information we hold about you and Personal Data from third party agencies (including credit reference agencies).
• 2.1.3. To help us to administer and to contact you about improved administration of any accounts, services and products we have provided before, do provide now or will or may provide in the future.
• 2.1.4. To allow us to carry out marketing analysis and customer profiling (including with transactional information), conduct research, including creating statistical and testing information.
• 2.1.5. To help to prevent and detect fraud or loss.
• 2.1.6. To allow us to contact you in any way (including mail, email, telephone, visit, text or multimedia messages) about products and services offered by us and selected partners unless you have previously asked us not to do so.
• 2.1.7. We may monitor and record communications with you (including phone conversations and emails) for quality assurance and compliance.
• 2.1.8. We may check your details with fraud prevention agencies. If you provide false or inaccurate information and we suspect fraud, we will record this.
2.3. We may allow other people and organisations to use Personal Data we hold about you in the following circumstances:
• 2.3.1. If we, or substantially all of our assets, are acquired or are in the process of being acquired by a third party, in which case Personal Data held by us, about our customers, will be one of the transferred assets.
• 2.3.2. If we have been legitimately asked to provide information for legal or regulatory purposes or as part of legal proceedings or prospective legal proceedings.
Data Protection Act 1998.
2.5. In connection with any transaction which we enter into with you:
• 2.5.1. We, and other companies in our group, may carry out credit and fraud prevention checks with one or more licensed credit reference and fraud prevention agencies. We and they may keep a record of the search. Information held about you by these agencies may be linked to records relating to other people living at the same address with whom you are financially linked. These records will also be taken into account in credit and fraud prevention checks. Information from your application and payment details of your account will be recorded with one or more of these agencies and may be shared with other organisations to help make credit and insurance decisions about you and members of your household with whom you are financially linked and for debt collection and fraud prevention. This includes those who have moved house and who have missed payments.
• 2.5.2. If you provide false or inaccurate information to us and we suspect fraud, we will record this and may share it with other people and organisations. We, and other credit and insurance organisations, may also use technology to detect and prevent fraud.
• 2.5.3. If you need details of those credit agencies and fraud prevention agencies from which we obtain and with which we record information about you, please write to us at 37 Southgate Street, Winchester, SO23 7DQ.
Protecting Information from our Monitoring Service
We have strict security measures to protect Personal Data.
3.1. We work to protect the security of your information during transmission by using Secure Sockets Layer (SSL) software, which encrypts information any input and protects you against data breaches. We additionally use log in sessions, temporary cookies, authentication tokens, secret passwords and other security processes to provide multi-layered protection for your data.
3.2. We maintain physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of personally identifiable customer information. We maintain a policy of separation between your registration details and monitored data, this separation includes internal separation of knowledge about the security layers implicit in the protection of your data among Here & There staff. Our security procedures mean that we may occasionally request proof of identity before we disclose personal information to you.
3.3. You are responsible for keeping your password confidential. We ask you not to share your password with anyone.
3.4. Unfortunately the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
4.1. If you communicate with us using the internet, we may occasionally email you about our services and products. When you first give us Personal Data through the Website, we will give you the opportunity to say whether you would prefer us not to contact you by email. You can also always send us an email (at the address set out below) at any time if you change your mind.
When we provide services, we want to make them easy, useful and reliable. This sometimes involves placing small amounts of information on your computer. These are called ‘cookies’.
Letting you navigate between pages efficiently
Enabling a service to recognise your computer so you don’t have to give the same information during one task
Recognising that you have already given a username and password so you don’t need to enter it for every web page requested
Measuring how many people are using services, so they can be made easier to use and that there is enough capacity to ensure they are fast
See allaboutcookies.org or www.youronlinechoices.eu to learn more about cookies.
Visit www.google.co.uk/goodtoknow/data-on-the-web/cookies for a video about cookies.
Users typically have the opportunity to set their browser to accept all or some cookies, to notify them when a cookie is issued, or not to receive cookies at any time. The last of these options, of course, means that personalised services cannot be provided and the user may not be able to take full advantage of all of a website’s features. Refer to your browser’s Help section for specific guidance on how it allows you to manage cookies and how you may delete cookies you wish to remove from your computer.
Multiple cookies may be found in a single file depending on which browser you use.
The cookies used on this website have been categorised based on the categories found in the ICC UK Cookie guide, as follows:
Category 1: strictly necessary cookies
These cookies are essential in order to enable you to move around the website and use its features, such as accessing secure areas of the website. Without these cookies services you have asked for, like shopping baskets or e-billing, cannot be provided.
Category 2: performance cookies
These cookies collect information about how visitors use a website, for instance which pages visitors go to most often, and if they get error messages from web pages. These cookies don’t collect information that identifies a visitor. All information these cookies collect is aggregated and therefore anonymous. It is only used to improve how a website works.
Category 3: functionality cookies These cookies allow the website to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. For instance, a website may be able to provide you with local weather reports or traffic news by storing in a cookie the region in which you are currently located. These cookies can also be used to remember changes you have made to text size, fonts and other parts of web pages that you can customise. They may also be used to provide services you have asked for such as a live chat session. The information these cookies collect may be anonymised and they cannot track your browsing activity on other websites.
The list below shows the cookies that we use, other than those that are strictly necessary to this service. If you have any queries about these, or would like more information, please contact us at: 37 Southgate St, Winchester, SO23 9EH.
These cookies are set when you arrive at the site. They are essential to the functioning of the site and are used to ensure that you are recognised when you move from page to page within the website and that any information that you have entered is remembered for the duration of your visit. This minimises the need to authenticate or reprocess each new area of the website that you visit. They are removed when you leave the website and close your browser and contain NO personal information.
This cookie is set when you login to the site to ensure that we can continue to recognise you once you are logged in. It contains NO personal information and lasts for 4 hours from when you login.
Determines the length of the session for a logged in user. There are two options for this cookie: if the user has selected remember me then it is set to 1 year, and if not then it’s set to the datetime that the user logged in. Used only for logged in members.
Non-Essential & Third Party Cookies
These cookies contain NO personal information and last for 6 months to 1 year. They hold the date of your last visit and are used for things like identifying which items on a page have been read previously, your preferences for the number of items viewed per page etc…
The purchase process uses a system called Cartthrob which sets a cookie to remember which items are in the cart. No personal information is stored in these cookies, only a fingerprint ID related to that browser session.
These cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where vistors have come to the site from and the pages they visited. Please note, this cookie may have already been set at an earlier visit.
By using this website, you agree that we can place these types of cookies on your device.
5. Further Information
5.4. If you would like access to the Personal Data that we hold about you, you can do this by writing to us at the address noted above. There may be a nominal charge of £10 to cover our costs in providing this information to you.
5.5. We aim to keep the Personal Data we hold about you accurate and up to date. If you tell us that we are holding any inaccurate Personal Data about you, we will delete it or correct it promptly. Please write to us at the address above to update your Personal Data.