This policy sets out how Citibase Limited, and its parent company Newable Limited and its subsidiaries, uses and protects an individual’s personal data, including data from our website. The policy informs you as to how we collect and process your data.
Citibase Limited is committed to protecting the privacy of our customers, clients and users of our website.
Please read the following carefully in order to understand your rights under the new General Data Protection Regulation (GDPR) and our views and practices regarding your personal data and how we will treat it.
2. Who We Are
When you use Citibase, you trust us with your information as a ‘data controller’ and as a data controller, we are committed to preserving that trust and respecting your privacy. We may also be a data processor if we process data supplied by a third party.
• Our website address is www.citibase.com
• Our company name is Citibase Limited under Companies House registration number 12617255
• Our registered address is 140 Aldersgate Street, London, England, EC1A 4HY
• Our Information Commissioner’s Office Registration number is Z4762187
• Our Data Protection Officer (DPO) is Lisa Richardson who can be contacted at firstname.lastname@example.org. Any queries regarding Citibase’s use of data and data policies should be addressed to the DPO.
3. The Data That We May Collect
We may collect and process the following data about you:
Website Users/Prospective Customers
• Information you submit through forms or surveys on our site at any time
• Personal information you have agreed to pass to us through third parties, brokers and agents
• A record of any correspondence between us
• Details of your enquiry
• Details of your visits to our site and the resources you use
• Information about your computer (e.g. your IP address, browser, operating system, etc.) for system administration.
• Email and telephone numbers
• Bank details
• Proof of Identity and Address
• A record of the correspondence between us
• A record of the transactions between us
• Copies of contracts between us
Under GDPR we will ensure that your personal data is processed lawfully, fairly, and transparently, without adversely affecting your rights. We will only process your personal data if at least one of the following basis applies:
a. You have given consent to the processing of your personal data for one or more specific purposes;
b. Processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request, prior to entering into a contract;
c. Processing is necessary for compliance with a legal obligation to which we are subject;
d. Processing is necessary to protect the vital interests of you or of another natural person;
e. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; and/or
f. Processing is necessary for the purposes of a legitimate interest pursued by us or by a third party, such as our credit card payment processing, except where such interests are overridden by the fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
All Cookies used by and on our website are used in accordance with current EU Cookie Law. A cookie is a small file of letters and numbers which websites may send to a computer to make a user’s experience of a website better. The information includes a unique reference code that a website transfers to your device to store and sometimes track information about you.
A few of the cookies we use last only for the duration of your web session and expire when you close your browser. Other cookies are used to remember you when you return to the site and will last for longer.
All cookies used on our site are set by us.
Most computer and some mobile web browsers automatically accept cookies but, if you prefer, you can change your browser to prevent this or to notify you each time a cookie is set. You can prevent the setting of cookies by adjusting the settings on your browser. Please note, however, that by blocking or deleting cookies you may not be able to take full advantage of the site.
Our cookies will be used for:
Essential session management
• Creating a specific log-in session for a user of the site in order that the site remembers that a user is logged in and that their page requests are delivered in an effective, secure and consistent manner;
• Recognising when a user of the site has visited before allowing us to identify the number of unique users we receive to the site and to make sure we have enough capacity for the number of users that we get;
• Recognising if a visitor to the site is registered with us in any way;
• We may also log information from your computer including the existence of cookies, your IP address and information about your browser program in order to allow us to diagnose problems, and to administer and track your usage of our site.
• Customising elements of the promotional layout and/or content of the pages of the site.
Performance and Measurement
• Collecting statistical information about how our users use the site so that we can improve the site and to identify which parts are the most popular to users.
5. How We Use the Data That We Collect
We use information about you to:
• Present website content effectively to you.
• Provide information, products and services that you request, or (with your consent) which we think may be of interest to you.
• Carry out our contracts with you.
• Comply with specific legal obligations
• Allow you to use our interactive services if you want to.
• Tell you our charges.
• Tell you about other Citibase goods and services that might interest you.
If you are already our customer, we will only contact you electronically about services similar to those that we already provide to you.
If you are an existing customer and you don’t want to be contacted in future concerning marketing, then please let us know at email@example.com and we will delete you from all future marketing campaigns.
If you are a new customer, then we will only contact you if you have agreed to be contacted.
In addition, if you don’t want us to use your personal data for any other reasons, then please let us know at any time, by contacting us at firstname.lastname@example.org and we will delete your data from our systems (unless we have a legal obligation to retain the record). However, you acknowledge that this may limit our ability to provide you with the best possible products and services.
In some cases, the collection of personal data may be a statutory or contractual requirement, and we will be limited in the products and services we can provide to you, if you don’t provide us with sufficient personal data.
6. Storing Your Data
We will store your data securely and our contractors will only ever process your data on our behalf, in accordance with our principles and instructions, and not for any other purposes.
At present we do not transfer your collected data to be stored outside the European Economic Area (EEA). If this was to change in the future, then we will take appropriate steps to ensure adequate data security.
By giving us your personal data, you agree to this arrangement. We will do what we reasonably can to keep your data secure.
We only keep your personal data for as long as we need to in order to use it as described above in section 5, and/or for as long as we have your permission to keep it. In any event, we will conduct an annual review to ascertain whether we need to keep your personal data. Your personal data will be deleted if we no longer need it.
7. Disclosing Your Information
We are allowed to disclose your information in the following cases:
• If we want to sell our business, or our company, then we can disclose it to the potential buyer.
• We can disclose it to other businesses in our group.
• We can disclose it if we have a legal obligation to do so, or in order to protect other people’s property, safety or rights.
• We can exchange information with others to protect against fraud or credit risks.
We may contract with third parties to supply services to you on our behalf. These may include payment processing, search engine facilities, advertising and marketing. In some cases, the third parties may require access to some or all of your data.
These are the third parties that may have access to your information if a service they provide is specifically requested by you:
• Telephony and broadband suppliers
• Dry cleaners
• Waste disposal
Where any of your data is required for such a purpose, we will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, our obligations, and the obligations of a third party under GDPR and the law.
8. Your rights
You can ask us not to use your data for marketing purposes. You can do this by ticking the relevant boxes on our forms, or by contacting us at any time at email@example.com.
Under the GDPR, you have the right to:
• Request access to, deletion of or correction of, your personal data held by us at no cost to you;
• Request that your personal data be transferred to another person (data portability);
• Be informed of what data processing is taking place;
• Restrict processing;
• Object to processing of your personal data; and
• Complain to a supervisory authority
You also have rights with respect to automated decision-making and profiling as set out in section 11 below.
9. Links to Other Sites
Please note that our terms and conditions and our policies will not apply to other websites that you are able to access, via a link from our site. We have no control over how any other website collects, stores or uses your data. We advise you to check the privacy policies of any such websites before providing any data to them.
11. Automated Decision-Making and Profiling
11.1 In the event that we use personal data for the purposes of automated decision-making and those decisions have a legal (or similarly significant effect) on you, then you have the right to challenge such decisions under GDPR. You may request human intervention, and obtain an explanation regarding any decision which we have made.
11.2 The right described in section 11.1 does not apply in the following circumstances:
a) the decision is necessary for the entry into, or performance of, a contract between you and us;
b) the decision is authorised by law; or
c) you have given your explicit consent.
11.3 Where we use your personal data for profiling purposes, the following shall apply:
a) Clear information explaining the profiling will be provided, including its significance and the likely consequences;
b) Appropriate mathematical or statistical procedures will be used;
c) Technical and organisational measures necessary to minimise the risk of errors and to enable such errors to be easily corrected shall be implemented; and
d) All personal data processed for profiling purposes shall be held securely in order to prevent discriminatory effects arising out of profiling.
12. Dispute Resolution
12.2 If any such dispute cannot be settled amicably through ordinary negotiations, or either or both is or are unwilling to engage in this process, then either party may propose to the other in writing that structured negotiations be entered into with the assistance of a fully accredited mediator before resorting to litigation.
12.3 All negotiations connected with the relevant dispute(s) will be conducted in confidence and without prejudice to the rights of the parties in any further proceedings.
12.4 If the parties agree on a resolution of the dispute at mediation, the agreement shall be reduced to writing and, once signed by the duly authorised representatives of both parties, shall be final and binding on them.
12.5 If the parties fail to resolve the dispute(s) within 60 days (or such longer term as may be agreed between the parties) of the mediator being appointed, or if either party withdraws from the mediation procedure, then either party may exercise any right to seek a remedy through arbitration by an arbitrator.
13. Your Right to Complain
You have the right to complain to the Information Commissioner’s Office at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, if you believe that there is a problem with the way that Citibase has handled your data.