A very private statement
At Underline we are very good at keeping secrets. Why? Because we take the trust people give us seriously. No one likes a gossip. Equally, we want to safeguard and preserve your privacy when you visit our site or communicate electronically with us.
This privacy policy explains how we capture, store and process your personal information to comply with data protection laws (GDPR).
We do update this Policy from time to time so please do review this Policy when required. But seriously, it’s not a regular thing, so don’t come dashing back tomorrow hoping for a terrific new read, it’s very, very unlikely to happen.
The DPA & GDPR May 2018
We and this website complies to the DPA (Data Protection Act 1998) and already complies to the GDPR (General Data Protection Regulation) which comes into affect from May 2018. We will update this policy accordingly after the completion of the UK’s exit from the European Union.
Cookies
We gather information about your computer for our services & to provide statistical information regarding the use of our website. The information does not identify you personally. It is statistical data about visitors & their use of this site. This statistical data does not identify any personal details whatsoever. Seriously, we don’t know if you are blonde, brunette or fiery red. (Although we’d LOVE to know).
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We collect a number of cookies from our users for various reasons, not least to track our own performance – but also to let us serve you content tailored to your own specifications, hopefully improving your overall experience of the website. By continuing to browse the site, you agree to our use of cookies. Please see our cookie policy for further details.
Underline is a ‘data controller’ which means that we are responsible for deciding how we hold and use your personal information. When we say ‘we,’ ‘us,’ ‘our’ or ‘Underline’ in this policy, we are referring to Altsplash Ltd.
Data we may collect about you
We may collect, use, store and transfer the following information about you:
- Personal Data –
When using the site, you may provide personal data that we collect. Examples of personal data include name, email address, mailing address, and phone number. You may provide us with Personal Data in various ways on our website, for example, when you use our chat option or when you send us a message via our contact form. - Financial Data –
We may store your payment details includes bank account and payment card details including transaction details. We also use GoCardless to process all our Direct Debits, and Stripe to process your debit/credit card transactions so your financial details may be stored with them. - Automatically collected information – When a user visits our website, we automatically collect information from the user’s device, using various technology such as cookies. Examples of automatically collected information include: IP address, web browser, device type, and the web pages/websites visited before using the site. We may also use technology to collect information regarding a user’s interaction with email messages that we send out, such as open & click data.
- Information from other sources –
We may collect information, including personal data, from third parties and sources, such as our partners, advertisers, and integrated services. If we associate or combine information from other sources with Personal Data that we collect through this website, we will treat this information as Personal Data in accordance with this policy.
How your personal data is collected
We may collect your personal data when you make contact with us for any reason. This could be through you contacting us by calling us, using our website contact form, emailing us, using the chat funtion on our website. We may also collect information from third-party sources, i.e.
- Search Engines such as Google and Bing.
- Analytics providers such as Google and Hotjar.
- Networking and social events.
Legal Grounds for using your Personal Data
Under the Data Protection Legislation, we must always have a lawful basis for using your personal data. The following table describes how we will use your personal data, and our lawful bases for doing so:
&npsp;
To fulfil a contract, or take steps linked to a contract, with you or your organisation.
- To register you as a client with us;
- To provide our digital marketing services to you, as agreed by you or your organisation;
- To process payments, billing and collection; and
- To process applications for employment.
As required by us to conduct our business and pursue our legitimate interests.
- To facilitate effective personal contact;
- For handling administration related to our digital marketing services.
- To ensure optimum delivery of our services.
- To gather information required to administer and follow-up with prospective clients.
- To analyse and improve our services and communications and to monitor compliance with our policies and standards;
- To manage access to our premises and for security purposes.
- To provide you with the information of our services that you request;
- To send you our email newsletter, if we have your consent (you can inform us at any time if you no longer require the newsletter);
- To manage our relationship with you which will include notifying you about changes to our terms or privacy policy or requesting feedback or a review;
For purposes required by law.
- Maintaining employee and accounting records, compliance checks.
Consent
- To communicate with you to keep you up-to-date on the latest developments, announcements, and other information about our services (including newsletters and other information), events and initiatives; to send you details promotional activities.
We will only use your personal data for the purpose(s) for which it was originally collected unless we reasonably believe that another purpose is compatible with that or those original purpose(s) and need to use your personal data for that purpose. If we do use your personal data in this way and you wish us to explain how the new purpose is compatible with the original, please contact us.
Who we share your personal data with
In the course of carrying out our work we sometimes need to share your personal data with third parties, including but not limited to:
- Professional service providers, such as IT providers, professional advisers or subcontractors as reasonably necessary for the purposes set out in this policy;
- Website hosting, development and maintenance;
- Processing service orders, support with fulfilment, accounting and record keeping; and
- Email marketing services to collect and stroe personal data to enable us to send marketing communications to you.
- Law enforcement or fraud prevention agencies if we believe the supplied data may violate a law.
- If we sell, transfer, or merge parts of our business or assets, your personal data may be transferred to a third party. Any new owner of our business may continue to use your personal data in the same way(s) that we have used it, as specified in this Privacy Policy.
- In order to establish, exercise, or defend our legal rights and in connection with any ongoing or prospective legal proceedings.
We do not share your personal data with any third party for marketing purposes.
International transfers
Data that we collect may be stored, processed in, and transferred between any of the countries in which we operate and do not have data protection laws equivalent to the European Economic Area.
Keeping and Storing Personal Data
We store the personal data we hold in our password-protected, encrypted & secure CRM, email accounts and cloud document storage.
Opting out
You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you.
Your rights
You have several rights in relation to your personal data and our use of it. The below is a summary of your rights according to our interpretation of the GDPR, which we will always work to uphold:
Right of access Request a copy of your personal data
Right to rectification Request corrections on any mistakes in your personal data
Right to be forgotten Request to delete your personal data – in certain situations
Right to restrict processing Request to require us to restrict processing of your personal data – in certain circumstances
Right to data portability Request a copy of your personal data in a machine-readable format and have the right to transmit the data to another controller.
Right to object Right to block or suppress processing of your personal data or right to withdrawal of your consent
Rights related to automated decision-making You can choose not to be the subject of a decision where the consequence is based on automated processing.
If you would like to exercise any of these rights, please contact us. All subject access requests should be made in writing either via email to hello@underlineagency.com or our postal addresses. Normally there isn’t any charge for a subject access request. If your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding. We will require proof of identity before we provide any personal information, to prevent any unauthorised access.
We will respond to your subject access request within not more than 30 days of receiving it. Normally, we aim to provide a complete response, including a copy of your personal data within that time.
Keeping your personal data secure
In order to prevent unauthorised access or disclosure, we have put technical and operational processes in place to keep your data safe. We also use SSL encryption to transmit information from end-users to their hosted servers.
We have procedures in place to report any data breach of this website, systems and/or database to the ICO and relevant individuals potentially affected within 72 hours of the breach notification.
How to Contact us
Got a query? Loaded with comments? If it is regarding this privacy policy drop us a line at hello@underlineagency.com — we’ll get our top people on the case ASAP.
How to Complain
If you have a complaint regarding any breach of this privacy policy, please contact us. When we receive the complaint, we will review it and ensure that we are in compliance with our privacy policy and all applicable laws. We will contact you within 30 days of receiving your complaint to inform you of the results of this review. The GDPR (May 2018) also gives you the right to lodge a complaint with the Information Commissioner.