In this policy, “processes” means collects, stores, shares and otherwise uses for lawful purposes. “We” and “our” means XSolution and it covers all the instances where we might process personal information of customers, clients, supporters, event attendees, beneficiaries and other relevant parties.
This policy has been updated in April 2018 to reflect the new data protection legislation called the General Data Protection Regulation (GDPR) and the Privacy and Electronic Communications Regulation (PECR).
If you have any questions about this policy or how we use your personal information, please contact us using the contact details given below.
Organisations are permitted to process data if they have a legal basis for doing so XSolution processes data on the basis that in furtherance of our business objectives:
Express and informed consent has been given by the person whose data is being processed; and/or XSolution has a legitimate interest in processing the data; and/or It is necessary in relation to a contract or agreement which the person has entered into or because the person has asked for something to be done so they can enter into a contract or agreement; and/or There is a legal obligation on XSolution to process data.
Where XSolution is relying solely on consent as the basis for processing data, we are required to obtain your expressed consent and you can modify or withdraw this consent at any time by notifying us in writing, although this may affect the extent to which XSolution is able to provide services to or interact with you in future.
XSolution may change this policy from time to time and any such changes will be published on our website. Notwithstanding any change to this policy, we will continue to process your personal data in accordance with your rights and our obligations in law.
Your personal information: what we collect
The personal information we collect about you will depend on your relationship with our business. It includes (but isn’t limited to):
Your name, address, telephone number, date of birth, gender and email address; debit or credit card information, your bank account number, sort code and other banking information, information required to validate your identity and prevent fraud; your preferences and interests, we may utilise your preferences to ensure we send you the most relevant communication in the future; other information you provide to us from time to time which is relevant and necessary for us to collect and process your activity online concerning your visit/s to our website and when we send you an email information on your family’s background, or your own, specifically so that we can find your record in our archive collection;
You, as the data subject, may change your preferences or request deletion of your data at any time in writing, subject to any overriding legal obligation that we may have for its retention.
We may keep such data on a ‘suppression list’ so we know not to contact you or process your data in future until further notice.
You also have the right to raise any issues of concern about us regarding data protection and our processing of your information to the data protection regulator, The Information Commissioner’s Office (ICO). Here is a helpful link to their website. https://ico.org.uk/concerns/
We do not, and never would, profile your information. Profiling is an automated process which uses publically available information to reach conclusions about supporters and then marketing to them accordingly.
We would also never sell your information to a third party.
How we use your personal information
We use your personal information for the following purposes:
To confirm that any purchases have been processed correctly or to validate your;
To send you administrative notices, relating to our organisation and its activities, where relevant;
For our internal purposes such as management, research, analytics, organisational reporting, and ways that will improve efficiencies;
to check with you that you are content with regards the type of communications that you receive;
To market our company and its relevant services, products and information including occasionally third-party events or activities that may be of interest to you by the appropriate means and in accordance with the GDPR and the PECR.
To create anonymous and aggregated reports about our supporters, customers or members to ensure our organisation is communicating with and delivering the best possible services.
To help the emergency services if required;
To prevent and detect criminal activity and fraud;
To comply with applicable
Best regards! – XSolution Team