www.Halloween.co.uk part of the Sitefinders Net Limited network of sites, (referred to as the “Site”) is owned and operated by Sitefinders Net Limited of Technology House, Sir William Lyons Road, University of Warwick Science Park, Coventry, CV4 7EZ (“we”, “us”, “our”).
For the purpose of the Data Protection Act 1998 and the General Data Protection Regulations 2016 (GDPR), the data controller is Sitefinders Net Limited with registration number Z3152539.
Personal data or PII means any information relating to a person who can be identified either directly or indirectly by that information; it may include name, address, email address, phone number, credit / debit card number, IP address, location data, purchase history (“Personal Data”).
2.1 We may collect and process the following data from you:
- Information you provide to us – this include:
- Information provided at the time of registering to use our Site, for the use of our services, posting material, submitting testimonials, reviewing products, raising quotes or general enquiries, completing an offer submission, entering a competition or requesting further services. We may also ask you for information when you report a problem with our Site or regarding the products and services provided by us.
- The nature of our business is such that we may on occasion ask you to provide sensitive personal data as defined in the GDPR. Where we do so, you agree to that and give your explicit consent to our use of such sensitive personal data for us to be able to provide our service. Under the GDPR sensitive personal data is defined as data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, biometric data, data concerning health or data concerning a natural person’s sex life or sexual orientation.
- If you contact us, we may keep a record of that correspondence.
- Details of transactions you carry out through our Site and of the fulfilment of your orders.
- Payments details including but not limited to the name on your bank card, the invoice address and partial card number.
- Information we collect about you – When you visit the Site we may automatically collect information about your computer or device, including your IP address, information about your visit, your browsing history, and how you use the Site. This information may be combined with other information you provide to us, as described above.
- Information we receive from other sources – We are also working closely with third parties (including, for example, business partners, advertising sites, analytics providers, and search information providers) and may receive information about you from them. This may be combined with other information you provide to us, as described above.
3.1 We will only process your Personal Data, in accordance with applicable law, for the following purposes:
- creating and maintaining your customer account, if you become a registered customer with us;
- handling and fulfilling your requests, if you request goods and/or services from us;
- offering our services to you in a personalised way, for example, we may provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes;
- to publish testimonials, you submit about the Site and to identify you as the author of such testimonial(s) (identification will be limited to your name, age and location;
- resolving any disputes, if you lawfully exercise your rights or if you wish to dispute any part of our service offering;
- sending you personalised marketing communications, where you have agreed that we may do so, in order to keep you informed of our products and services, as well as those of our selected partners’ and Providers’, which we (or they) consider may be of interest to you;
- providing you, or allow carefully selected third parties to provide you, with information about products or services, that may interest you;
- ensuring the security of your account and our business, preventing or detecting fraud or abuses of our Site, for example, by requesting verification information in order to reset your account password (if applicable);
- developing and improving our products and services, for example, by reviewing visits to the Site and its various subpages, demand for specific products and services and user comments;
- to administer the Site and for internal business administration and operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to notify you about changes to our services and to send you service emails relating to the activities you have asked us to undertake on your behalf;
- as part of our efforts to keep the Site safe and secure; and
- to comply with applicable law, for example, in response to a request from a court or regulatory body, where such request is made in accordance with the law.
3.2 Your consent, as the “Data Subject”, to the processing as specified in this Policy is the primary legal ground for our processing of your Personal Data. However, there may be circumstances where we may also rely on other valid legal grounds for the processing of your Personal Data, such as:
- your request for content, products or services necessitating steps including processing of your Personal Data to be taken prior to entering into contract with you and any processing that is necessary for the performance of such contract;
- legitimate interests we pursue as a business, except where such interests are overridden by your interests and fundamental rights; and
- compliance with any legal obligation to which we are subject, such as, for example, the processing for the purposes of complying with applicable law.
4. Age Restriction
As this Site is of a financial nature, the business, products and services are not designed to appeal to or to be sold to persons under the age of 18. Therefore, we do not knowingly attempt to solicit or receive any information from children. If you are under the age of 18, you must not use any of the financial websites in the Site.
The sites that are primarily directed at children will not use Personal Information for a Secondary Use without obtaining the consent of a parent or guardian. When possible, these Sitefinders Net Limited sites will provide e-mail notice to parents that children have provided Personal Information to the site.
5.1 There are circumstances where we wish to disclose or are compelled to disclose your Personal Data to third parties. This will only take place in accordance with the applicable law and for the purposes listed above. These scenarios include disclosure to:
- our subsidiaries, branches or associated offices;
- our outsourced service providers and suppliers to facilitate the provision of goods and/or services to you, together with such other goods and/or services as we and/or they feel may interest you;
- analytics and search engine providers that assist us in the improvement and optimisation of the Site. Your Personal Data is generally shared in a form that does not directly identify you;
- third party analytics providers that assist us in establishing trends amongst our users based on the information you provide to us and generating associated content (for example, news articles and/or social media posts);
- selected third party service providers in order to share the statistical and analytical information generated above, in an anonymised and aggregated format only;
- third party service providers and consultants in order to protect the security or integrity of our business, including our databases and systems and for business continuity reasons;
- another legal entity, on a temporary or permanent basis, for the purposes of a joint venture, collaboration, financing, sale, merger, reorganisation, change of legal form, dissolution or similar event. In the case of a merger or sale, your Personal Data will be permanently transferred to a successor company;
- public authorities where we are required by law to do so;
- if required, in order to receive legal advice; and
- any other third party where you have provided your consent.
6.1 We may transfer your Personal Data to a third party in countries outside the country in which it was originally collected for further processing in accordance with the purposes set out above. In particular, your Personal Data may be transferred throughout our group and to our outsourced service providers located abroad. In these circumstances we will, as required by applicable law, ensure that your privacy rights are adequately protected by appropriate technical, organisation, contractual or other lawful means. Please contact firstname.lastname@example.org for a copy of the safeguards which we have put in place to protect your Personal Data and privacy rights in these circumstances.
7.1 Your Personal Data will be retained until your last use of our services and normally for a period of three years thereafter, unless longer retention is required by applicable local law or where we have a legitimate and lawful purpose to do so. However, we will not retain beyond this period any of your Personal Data that is no longer required for the purposes set out in this Policy. The retention of your Personal Data will be subject to periodic review.
7.2 We may keep an anonymised form of your Personal Data, which will no longer refer to you, for statistical purposes without time limits, to the extent that we have a legitimate and lawful interest in doing so.
7.3 Please contact us at email@example.com if you would further details about our data retention periods.
8.1 Data protection law provides Data Subjects with numerous rights, including the right to: access, rectify, erase, restrict, transport, and object to the processing of, their Personal Data. Data Subjects also have the right to lodge a complaint with the relevant data protection authority if they believe that their Personal Data is not being processed in accordance with applicable data protection law.
- Right to make subject access request (SAR). Data Subjects may, where permitted by applicable law, request copies of their Personal Data. If you would like to make a SAR, i.e. a request for copies of the Personal Data we hold about you, you may do so by writing to firstname.lastname@example.org whose contact details are above. The request should make clear that a SAR is being made. You may also be required to submit a proof of your identity and a fee.
- Right to rectification. You may request that we rectify any inaccurate and/or complete any incomplete Personal Data.
- Right to withdraw consent. You may, as permitted by applicable law, withdraw your consent to the processing of your Personal Data at any time. Such withdrawal will not affect the lawfulness of processing based on your previous consent. Please note that if you withdraw your consent, you may not be able to benefit certain service features for which the processing of your Personal Data is essential.
- Right to object to processing, including automated processing and profiling. You may, as permitted by applicable law, request that we stop processing your Personal Data. In relation to automated processing and profiling, you may object to the processing and you will have the right to obtain human intervention.
- Right to erasure. You may request that we erase your Personal Data and we will comply, unless there is a lawful reason for not doing so. For example, there may be an overriding legitimate ground for keeping your Personal Data, such as, a legal obligation that we have to comply with, or if retention is necessary for us to comply with our legal obligations.
- Right to data portability. In certain circumstances, you may request that we provide your Personal Data to you in a structured, commonly used and machine-readable format and have it transferred to another provider of the same or similar services. We will comply with such transfer as far as it is technically feasible. Please note that a transfer to another provider does not imply erasure of your Personal Data which may still be required for legitimate and lawful purposes.
- Your right to lodge a complaint with the supervisory authority. We suggest that you contact us about any questions or if you have a complaint in relation to how we process your Personal Data. However, you do have the right to contact the relevant supervisory authority directly. To contact the Information Commissioner’s Office in the United Kingdom, please visit the ICO website for instructions.
9.1. The Site may, from time to time, contain links to and from the websites of our partner sites, advertisers, affiliates and other third parties. If you follow a link to any of these websites, please note that these websites may have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal information to these websites.
1.2 You may delete and block all cookies from our Site by changing your browser settings to refuse the setting of all or some cookies. Making this change may affect the functionality of our Site and you may not be able to access all or parts of the Site.
2.1 Strictly necessary cookies: These are cookies that are required for the operation of our Sites for example, cookies that enable you to log into secure areas of our Site or use the shopping basket.
2.2 Tracking cookies and pixels:
- Tracking cookies are used to provide information on the pages that are viewed. This information is anonymous, not shared with anyone else and used on our Site. Tracking cookies set from our Site will be predominantly from Google Analytics and Hitslink.
- Tracking pixels may also be set in emails and banner display advertising to monitor the number of times that an email or banner has been seen. They are not used for any other purpose.
- Cookies may occasionally be used to display some users’ surveys or different versions of a page. We then use analytics to identify which version of a page provides a better user experience.
- Cookies may also be set to see how well certain banners ads are received. This helps to identify how many times an advertisement has been seen, clicked on or downloaded.
- Common cookies you may encounter on our Sites are __utma, __utmb, __utmc, __utmz, __utmv which are for Google Analytics (see the Google cookie page for more information); reg_fb_gate, reg_fb_ref which are Facebook cookies (see more about these cookies here). Cookies beginning with hellobar_ are used to show you relevant offers on pages that you are visiting, and the cookie expires in 1 year.
For more detailed information about cookies please visit www.allaboutcookies.org