PRIVACY POLICY & NOTICE
ABOUT THIS POLICY
This privacy policy and general privacy notice applies to Rachael Woolley Coaching. We at Rachael Woolley Coaching take your privacy seriously. and this policy and notice has been drafted in accordance with the requirements of the General Data Protection Regulations (“GDPR”), with the support of the legal team at www.legalo.co.uk.
This privacy notice explains how we look after your personal data (in all situations where we collect your data) and sets out your privacy rights and also explains how the law and our approach to privacy and personal data protects you.
This privacy notice supplements any other privacy notices that we may provide to you at the point that we collect data from you and should be read in conjunction with those notices.
OUR STATUS AND DETAILS
For the purpose of the GDPR we are the data controller and any enquiry regarding the collection or processing of your data should be addressed using the contact details below: Email address: contact@rachaelwoolley.com
We encourage you to review this Privacy Policy periodically, when you use our website for any purpose or engage with us on social media. By using the website, you consent to this Privacy Policy.
INFORMATION WE COLLECT
We will collect, process, store personal data, and to our sharing of the data with third party processors as needed for our legitimate business interests, only if it is directly provided to us by you. You may do this in your capacity as the user of this Website, by enquiring in relation to our goods or services, becoming a customer, making a purchase, or interact with use on social media.
Personal information covers any information which relates to you as an identifiable person. Your decision to disclose this data is entirely voluntary. You are under no obligation to provide this information, but your refusal may prevent you from accessing certain benefits from our website or from making purchases.
Below are examples of the type of data that this may include:
- Identity Data: Identity data is information that can identify you specifically, including forenames, last name, date of birth, gender, and username or similar identifier.
- Contact Data: Contact data information that can identify you specifically, may include invoicing; purchase order; home or work address, email address and telephone numbers, personal or job title and position.
- Financial Data: Financial data is data that is related to your payment method, such as credit card or bank transfer details. We collect financial data in order to allow you to purchase, order, return or exchange products or services from our website and any related mobile apps. We store limited financial data. Most financial data is transferred to our payment processor, Stripe and PayPal, and you should review these processors’ Privacy Policy to determine how they use, disclose and protect your financial data.
As a courtesy, Stripe Privacy Policy can be found here: https://stripe.com/no/privacy
As a courtesy, PayPal Privacy Policy can be found here: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full
- Transaction Data may include payments made for products and services you have purchased from us, or in relation to payments that we have made to you. See Financial Data.
- Technical Data: Technical Data is information that our servers automatically collect about you when you access our website, may include internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices used to access this Website. If you are using a mobile application, our servers may collect information about your device name and type, your phone number, your country of origin, and other interactions with our application.
- Profile and Usage Data may include enquiries submitted by you, purchases information, feedback and survey responses, and how you use our website, products and services.
- Marketing Data may include details of any preference that you have advised us of in relation to marketing communications from us.
- Social Networking Data: We may access personal information from social networking sites and apps, including Facebook, Instagram, Linkedin, Twitter, Snapchat, Pinterest or other social networking sites or apps not named specifically here.
- Mobile Data: If you use our website via a mobile device or app, we may collect information about your mobile, including device ID, model and manufacturer, and location information.
- Other data: On occasion, you may give us additional data in order to enter into a contest or giveaway or to participate in a survey. You will be prompted for this information and it will be clear that you are offering this kind of information in exchange for an entry into such a contest or giveaway.
We may also collect non-personal data such as Aggregated Data which is information that may be obtained from your personal data, but which does not directly or indirectly identify you. This may include Usage Data detailing how you use our Website and the features and areas that you have interacted with.
HOW DO WE COLLECT PERSONAL DATA?
A range of different methods may be used to collect data which may include the following methods:
- Direct interactions with us in person, by post, phone, email or otherwise. You may give us your Identity, Contact and Financial Information.
- Automated technologies or interactions with our website, by registering with or make purchases from our website, using the web enquiry form. You may give us Identity, Contact and Financial Information.
- Third parties or publicly available sources (third parties may be used in processing Identity, Contact and Financial categories of personal data).
- Social Media interactions with us from social networking sites and apps, including Facebook, Instagram, Linkedin, Twitter, Snapchat, Pinterest or other social networking sites or apps not named specifically here. You may give us Identity and Contact information which may include your name, your social network username, location, email address, age, gender, profile picture and any other public information. If you do not want us to access this information, please go to the specific social networking site and change your privacy settings.
- Participating in various activities associated with our site, including responding to blogs, contacting us with questions, or participating in group training
DATA ACCURACY
It is important that the data that we hold about you is accurate and up to date. In the event that your data changes please notify us so that we can update our records.
USE OF YOUR INFORMATION
We may hold and process personal data that you provide to us in accordance with the GDPR.
The information that we collect and store relating to you is primarily used:
- To enable us to provide our services to you, to communicate with you and to meet our contractual commitments to you. This may include Identity, Contact, Financial and Transactional data.
- To notify you about any changes to our business, such as improvements to our Website or service/product changes, that may affect our service or relationship with you. This may include Identity and Contact data.
- If you are an existing customer, we may contact you with information about goods and services similar to those that were the subject of a previous sale to you. This may include Identity and Contact data.
- Where you have consented to receive such information, to provide information on other parties’ products or services that we feel may be of interest to you. This may include Identity, Contact and Marketing data.
- Where you have consented to receive our e-newsletters to provide that to you. This may include Identity and Contact data.
- Where we need to comply with a legal obligation. This may include Identity, Contact and Transactional data.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. This may include all types of data.
- To enable us to create and administer your account.
- Interact with you via social media
- Deliver targeted advertising; and
- Request feedback from you; and
- Resolve disputes and troubleshoot any problems; and
- Administer contests or giveaways; and
- Generate a profile that is personalized to you, so that future interactions with our website will be more personal; and
- Compile anonymous statistical data for our own use or for a third party’s use; and
- Prevent fraudulent activity on our website or mobile app; and
- Analyse trends to improve our website and offerings.
Where we collect your data for marketing purposes we will always request your consent, at the point the data is collected, to use your data for that purpose.
We will always obtain your prior consent to sharing your personal data with any third party for their marketing purposes. This may be to enable relevant third parties to advise you of products or services that may be of interest to you.
We will only use your personal data for a reason other than the purpose for which it was originally obtained if we consider that we need to use it for that other purpose and have a legitimate interest in doing so.
DISCLOSURE OF YOUR INFORMATION
We may share your information with third parties in certain situations. In particular, we may share your data with third party processors as needed to serve our legitimate business interests, which include administration of our website, administration of your account, entering into contracts with you, communicating with you, taking orders for goods or services, delivering our goods and services, identifying trends, protecting the security of our company and website, and marketing additional goods and services to you. The legal basis for our disclosure of your data is both your Consent to this Privacy Policy and our own right to protect and promote our legitimate business interests.
There are a range of circumstances where we may disclose your data to third parties. These include:
Regulatory bodies. We may disclose your data to regulatory bodies to enable us to comply with the law and to assist fraud protection and minimise credit risk. This may include Identity, Contact and Transactional data.
Our Suppliers. We may disclose your data to third parties that are involved in the fulfilment of our services to you. This may include Identity, Contact and Transactional data.
Third party marketing. Where you have consented for us to do so, we may provide your data to selected third parties who may contact you about their goods or services that you may be interested in. This may include Identity, Contact and Marketing data. We may disclose your information to third parties who assist us with various tasks, including payment processing, hosting services, email delivery and customer service. For more information, see the “Third Party Processing” Section below.
Business sale. We may disclose your personal data outside of our organisation: (a) in the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets; and (b) if Rachael Woolley Coaching’s business is bought by a third party, in which case personal data held by it about its customers will be one of the assets to transfer to the buyer. However, any such transfer will only be on terms that the confidentiality of your personal data is protected and that the terms of this privacy policy will continue to be complied with by the recipient.
To Protect Our Company: We may use your information to protect our company, including to investigate and remedy any violations of our rights or policies. We may also disclose your information as reasonably necessary to acquire and maintain insurance coverage, manage risks, obtain financial or legal advice, or to exercise or defend against legal claims.
Affiliates: We may share your personal information with our business affiliates who promote our product(s) or service(s) for a commission fee. We require our affiliates to honour this Privacy Policy. They are not allowed to spam you and must disclose they are an affiliate for us. If they do not do so, they are in violation of their affiliate terms and this Privacy Policy, and any violation of this nature should be reported to contact@rachaelwoolley.com
Advertisers: We may use third party advertising companies to run and manage our ads, such as Facebook, Instagram and Pinterest Advertising to produce ads that appears when you visit our Website or mobile app. These companies may use information about your visit to our website and other websites that are contained in web cookies (as described below) to offer you personalized advertisements about goods and services that might interest you. We cannot control the activities of, such other advertisers or web sites. You should consult the respective Privacy Policies of these third-party advertisers for more detailed information on their practices as well as for instructions about how to opt-out of certain practices.
Other Third Parties: We may share information with advertisers, our investors, or other third parties for the purpose of conducting general business analysis. If we do so, we will make reasonable efforts to inform you if required by law.
Interaction with others: If you interact with others on our website or mobile app, such as participating in a group chat or a group online course, other users may have access to some of your data, including your name, profile picture, and your history of interaction with our website, such as prior comments or posts.
Online postings: When you post online, your posts may be viewed by others, and we may distribute your comments outside the website.
External Links: Our website may include hyperlinks to other websites not controlled by us. We suggest you exercise caution when clicking on a hyperlink. Although we use reasonable care in including a hyperlink on our own web page, we do not regularly monitor the websites of these third parties, are not responsible for any damage or consequences you suffer by using these hyperlinks. We are not bound by the Privacy Policies of any third-party website that you access by a hyperlink, nor are they bound by ours. We encourage you to read the Policies of those third-party websites before interacting with them or making purchases. They may collect different information and by different methods than we do.
Other purposes: We may disclose your personal data as necessary to comply with any legal obligation or to protect your interests, or the vital interests of others or our company.
Please be advised that we do not reveal information about identifiable individuals to our advertisers, but we may, on occasion, provide them with Aggregated Data about our Website visitors and customers.
If you do not want us to share your data with third parties you will have the opportunity to withhold your consent to this when you provide your details to us on the form on which we collect your data, or you can do so by writing to us at the address detailed above or sending us an email to contact@rachaelwoolley.com at any time.
CONTROLLING THE USE OF YOUR DATA
Where we rely on consent as the lawful basis for processing your data you can revoke or vary that consent at any time.
If you do not want us to use your data or want to vary the consent that you have provided you can write to us at the address detailed in clause 2 or email us at contact@rachaelwoolley.com at any time.
DATA STORAGE AND THE TRANSFRER OF YOUR DATA
As part of the services offered to you, for example through our Website, the information you provide to us may be transferred to and stored in countries outside of the European Economic Area (EEA) as we use remote website server hosts to provide the website and some aspects of our service, which may be based outside of the EEA, or use servers based outside of the EEA – this is generally the nature of data stored in “the Cloud”. It may also be processed by staff operating outside the EEA who work for one of our suppliers, e.g. our website server host, payment processing provider, or work for us when temporarily outside of the EEA.
A transfer of your personal data may happen if any of our servers are located in a country outside of the EEA or one of our service providers is located in a country outside of the EEA.
If you use our service while you are outside the EEA, your personal data may be transferred outside the EEA in order to provide you with these services.
If we transfer or store your personal data outside the EEA in this way, we will take steps with the aim of ensuring that your privacy rights continue to be protected, as outlined in this privacy policy. Where we use suppliers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US.
SECURITY
The transmission of information via the Internet or email is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of data while you are transmitting it to our site; any such transmission is at your own risk.
We have put in place security measures to prevent your data from accidental, loss or disclosure. Once we have received your personal data, we will use strict procedures and security features to try to prevent unauthorised access.
Where we have given you (or where you have chosen) a password so that you can access certain parts of our site, you are responsible for keeping this password confidential. You should choose a password it is not easy for someone to guess.
We will notify you of promptly any known breach of our security systems or your data which might expose you to serious risk.
DATA RETENTION
The length of time that we retain, and store data depends on the purpose for which it was collected. We will only store data for as long as is required to fulfil that purpose, or for the purpose of satisfying legal requirements.
It is a legal requirement that we keep certain data about our customers and suppliers for at least six years. The type of data includes Contact, Identity, Financial and Transaction Data.
Where you have requested that we provide you with marketing materials we will retain your data until such time as consent is withdrawn by you.
USE OF COOKIES
Our Website uses cookies. We use cookies to gather information about your computer for our services and to provide statistical information regarding the use of our Website. Such information will not identify you personally – it is statistical data about our visitors and their use of our Website. This statistical data does not identify any personal details whatsoever.
We may also gather information about your general Internet use by using a cookie file. Where used, these cookies are downloaded to your computer automatically. This cookie file is stored on the hard drive of your computer, as cookies contain information that is transferred to your computer’s hard drive. They help us to improve our Website and the service that we provide to you.
All computers have the ability to decline cookies. This can be done by activating the setting on your browser which enables you to decline the cookies. Please note that should you choose to decline cookies, you may be unable to access particular parts of our Website. Where we work with advertisers on our Website, our advertisers may also use cookies, over which we have no control. Such cookies (if used) would be downloaded once you click on advertisements on our Website.]
PROCESSING YOUR INFORMATION
For the most part, we do not process your information in-house, but give it to third party processors for processing. For example, when PayPal takes your payment information, they are a third party processor. They process your payment and remit the funds to us. So in many instances, it will be necessary for us to transmit your information to a third party processor, as we do not have the capability to perform these functions. More detail on third party processing is detailed below.
However, we may, from time to time, process your data internally. The legal basis for this processing is both your consent to the processing, and our need to conduct our legitimate business interests. Our purposes in processing this information, if we do, is to administer, maintain, and improve our website and offerings, to enter into contracts with you, to fulfill the terms of those contracts, to keep records of our transactions and interactions, to be able to provide you with goods and services, to comply with our legal obligations, to obtain professional advice, and to protect the rights and interests of our company, our customers (including you), and any third parties. We may process the following data:
- Data associated with your account, such as your name, address, email address and payment information
- Data about your usage of our website, such as your IP address, geographical information, and how long you accessed our website and what you viewed.
- Data related to your personal profile, such as your name, address, profile picture, interests and hobbies, or employment details.
- Data that you provide us in the course of using our services.
- Data that you post on our website, such as comments or responses to blogs.
- Data that you submit to us when you make an inquiry regarding our website or offerings.
- Data related to your transactions with us, including your purchase of our goods or services. This information may include contact details and payment information.
- Data that you provide to us when you subscribe to our emails or newsletters, including your email address and contact information.
- Data that you submit to us via correspondence, such as when you email us with questions.
- Any other data identified in this policy, for the purpose of complying with our legal obligations, or to protect the vital interests of you or any other natural person.
CHILDREN
This website or mobile app is not designed for use by children under age 16, and we do not knowingly solicit personal data from anyone under age 16. If you are under age 16, do not access or use our website or related products or services. If you become aware that we have collected data of anyone under the age of 16, please contact us so that we may delete that data.
YOUR RIGHTS
The GDPR gives you a range of rights in relation to the personal data that we collect from. You have the right to:
- Access your personal data. This right is commonly known as the ‘data subject access request’ and enables you to receive a copy of the personal data we hold about you. You will not need to pay a fee to access your personal data unless we can justifiably demonstrate that the request is repetitive or excessive. We will respond to all legitimate data access requests within one month, but we may need to obtain further information from you in order to confirm your identity and the legitimacy of the request.
- Request update of the personal data. This enables you to have any incomplete or inaccurate data corrected.
- Erasure of your personal data. This enables you to ask us to delete personal data where there is no justifiable reason for us continuing to retain and process it. We may not always be able to delete the data such as if there is an ongoing contractual relationship between us or if we are legally required to retain the data.
- Object to processing of your personal data where we are relying on consent or our legitimate interests (or those of a third party) as the justification for processing the data.
- Restrict the processing of your personal data. This enables you to ask us to change the processing of your personal data. For example, you may wish to vary the basis on which we contact you.
- Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, machine-readable format.
- Withdraw consent. Where we are relying on consent to process your personal data you may withdraw that consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
You can exercise these rights at any time by writing to us at the address detailed above, or by email to contact@rachaelwooley.com.
THIRD PARTY LINKS
You might find links to third party websites on our website. If you click a link to a third-party website and visit that site, you may be allowing that site to collect and share certain data about you. These websites should have their own privacy policies, which you should check. We do not accept any responsibility or liability for their policies whatsoever as we have no control over them.
WEBSITE ANALYTICS
We may partner with third party analytic companies, including Google Analytics. The analytic companies may also use cookies or other tracking technologies to analyse visitors’ use of our website or mobile app to determine the popularity of the content, and better understand online activity. We do not transfer personal information to these third-party vendors. However, in order to access our website, you must consent to the collection and use of your information by these third party analytic companies. You should review their Privacy Policy and contact them directly if you have questions. If you do not want any information to be collected and used by tracking technologies, visit the Network Advertising Initiative Opt-Out Tool or Digital Advertising Alliance Opt-Out Tool
COMPLAINTS
You have the right to complain to a supervising authority if you believe we are misusing your data or have violated any of your rights under this Privacy Policy or applicable law.
If you do wish to raise a complain then we would welcome the opportunity to discuss your concerns to see if we can resolve the issue for you.
CALIFORNIA PRIVACY RIGHTS
The State of California has established its own unique regulations that apply to California residents. If you reside in California, you have the right to obtain from us, once per year and free of charge, information regarding what information we disclose to third party marketers, and the names and addresses of each third party to whom we disclose your data. If you are a California resident and would like to make such a request, please use the contact information listed below.
If you are a California resident and under the age of 18, you have the right to request that we remove any data that you publicly post on our website. To request removal of your data, please use the contact information listed below. Note that while we will remove your data that is publicly posted on our website, we may not be able to completely remove that data from our systems.
NEWSLETTER PRIVACY
We offer the opportunity for you to volunteer certain information to us that is used for email and marketing purposes. This information includes, but is not limited to, your name and email. You will have an opportunity to unsubscribe from any future communications via email, but we reserve the right to maintain a database of past email subscribers. We reserve the right to use this information as reasonably necessary in our business and as provided by law. Your information will be shared with reasonably necessary parties for the ordinary course of conducting our business, such as through Facebook ads or Google Pay Per Click marketing campaigns. We do not ever sell your information to third parties.
SEVERABILITY
If any part of these Terms, Conditions and Privacy Policy is deemed unlawful and/or unenforceable, all other provisions contained herein will remain in full force and effect.
ENTIRE AGREEMENT
The information contained herein constitutes the entire agreement between site users and our company relating to the use of this website.
LAW AND JURISDICTION
These Terms, Conditions and Privacy Policy are governed by and construed in accordance with Norway law. Any dispute arising out of or related to the information contained herein is subject to adjudication in the state of Lillehammer, Innlandet, Norway.
CONTACT INFORMATION
Email: contact@rachaelwoolley.com
CHANGES TO THIS POLICY
We may update these policies to reflect changes to the website and customer feedback. Please regularly review these policies to be informed of how we are protecting your personal data.
We welcome any queries, comments or requests you may have regarding this Privacy Policy. Please do not hesitate to contact us.
Version: June 2020