We take data privacy very seriously and this document describes how we handle and manage your data.
- We are Fort William Car Hire, and you can contact us at firstname.lastname@example.org
- We process your data to provide our service to you, or for our legitimate interests.
- We do not share your data with others unless they are providing a service to us (such as payment service providers), or unless you ask us to share your data.
- We do not sell your data to others.
- We do not market to you.
- You’ve got lots of rights, including the right to complain to the Information Commissioner’s Office. If you need a hand in exercising your rights, feel free to contact us at email@example.com
Who we are
How we process your data
Throughout your interactions with us we will collect only the data that we require in order to provide you with the service that you are requesting. The key information that we process is shown below for your information:
When you access our service we will store a record of your IP address along with details of your request in our logs. This information is stored and used by our web developer to ensure the integrity of our service.
Authorisation and session data
Whenever you use our service we will use several cookies that identify you with our service. This is necessary to provide the service to you.
Session cookies are used to match your browser with your actions on our website.
Browser cookies are used to associate and authenticate you with our website.
In addition to these cookies, there are several third party cookies which are used to track your actions on our site so we can identify areas in which we can improve the functionality of our website.
Your contact information
We ask for contact information, including your name, e-mail address, telephone number so that we can fulfil any service with you. We may obtain this implicitly if you send it to us without us first requesting it, e.g. as a e-mail signature.
We require a physical address and e-mail address in order to provide you with an invoice for our service. This information is collected as a legal obligation and will be stored on our systems along with invoices for a minimum period of 7 years.
Your contact information may be stored in various systems that we use (for example: our fleet management system). This is necessary to provide our service to you.
We store and use your e-mail address for the purposes of fulfilling our service. We will send you transactional e-mails that relate directly to your account or service, for example notification of an upcoming hire. This information is required in order to ensure you are informed about your account and can take appropriate actions in various situations.
We may also use your e-mail address to send you messages about our service which may include notifications about newly launched features, improvements to the service, upcoming maintenance as well as ways to help you make the most of your service.
If you send us e-mails, these may be passed through our mail servers. This is necessary to provide our service to you.
If we send you transactional e-mails, such as hire confirmations, these will be passed through our third party mail provider and stored for a period of time to assist with debugging delivery problems and ensuring messages are appropriately delivered to their destinations. This is necessary to provide our service to you.
The information stored includes the contents of the message sent, the e-mail addresses of the recipients and any other headers.
E-mails directly to/from our employees
If you communicate with our employees directly by e-mail, we may retain your name and e-mail address in the mailboxes of the employee(s) that you communicate with, together with its contents and metadata. This is necessary to provide our service to you.
Call logs and recordings
We do not record or log calls.
We have hierarchical backups of our website and its databases for a period of two years. These are encrypted and stored off-site, in a separate location to our server.
We store backups of accounting data for use in disaster recovery. Backup data is stored on site in a secure area. This is necessary to provide our service to you.
Backups can only be obtained by authorised members of staff.
You will not need to set up an account or supply a password in the provision of our service to you.
We do not store payment card details on our own servers. We work with an external PCI-compliant payment processor (Braintree) who stores these details.
Support by e-mail
If you contact us by e-mail or through our website, you will be sharing your contact details (e-mail address and/or phone number) with us for the purposes of responding to your query. This is necessary to provide our service to you.
We retain all support requests (including name & contact details) that we receive for the purposes of auditing and training of staff.
Our servers and third party services
Our servers and the third party services we use are managed by companies compliant with GDPR regulations or are covered by the EU-US Privacy Shield.
Transfer of data to group companies
We may share and/or transfer your data with other companies within our group for the purposes of administration and company structuring.
Transfer of data on product or service acquisition
If we are acquired by another company or entity, we may share your information with the acquiring company so that they may continue to provide you with the services that you have elected to receive. You will be notified by e-mail in the event that such an acquisition occurs.
Correcting your personal data
It is important to us that the information we store is up to date and accurate. You may update your details at any time by contacting us.
Removal of your personal data
In some cases, you may be able to request that we remove your personal data from our systems. Please feel free to contact us using the information below.
You have a lot of rights, including right to request access to and rectification or erasure of your personal data or restriction of processing of it. You also have the right to object to our processing of your data in some situations, as well as the right to data portability.
Notification of data breaches
Upon discovering any data breaches, we will notify any affected individuals as soon as its practical. In the event of a data breach concerning personal data, the affected parties will be notified by e-mail to the main e-mail address we store with your account.
Use of our services by persons under the age of 16
We do not allow anyone under the age of 16 to signup, use or store any personal data with us on any of our services. If we discover or are notified about the presence of a user under this age, we will remove their data from our systems without notice.
Our lawful basis for data processing
Under the General Data Protection Regulation, unless we have otherwise specified above, we will be processing your data as a legitimate interest. These interests include staff training, ensuring the security of our systems and to allow us to operate our business in an efficient manner.
Where our processing is based on consent, you may withdraw consent at any time.
Where our processing is necessary for us to perform our contract with you, or to take steps to enter into a contract with you, we will not be able to enter into a contract with you or deliver our service to you if you do not give us the data in question.
Disclosure of information to law enforcement agencies
We may disclose your information if we are requested to by any law enforcement agency where we believe we are required to comply with the request under any applicable laws.
Data protection authority
You may have the right to lodge a complaint with your local data protection authority or the Information Commissioner's Office (ICO) in the United Kingdom (our authority).
The ICO can be contacted at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Other information can be found on their website at ico.gov.uk.
2022 Fort William Car Hire. All rights reserved