PRIVACY POLICY, COOKIES AND GDPR
Tyddyn Llan is committed to safeguarding the privacy of its visitors. This privacy policy explains what happens to any personal data that you provide, or that we collect from you, whilst you visit our site.
For the purpose of the Data Protection Act 1998, the data controller is…
Gareth Stevenson,
Tyddyn Llan,
Llandrillo, nr. Corwen, Denbighshire,
North Wales LL21Â 0ST.
Information we collect
In running our website we may collect and process the following data about you: Information about your use of our site including details of your visits such as pages viewed and the resources that you access. Such information includes traffic data, location data and other communication data. Information provided voluntarily by you. For example, when you send a booking enquiry. Information that you provide when you email us.
Cookies
We are aware of, and try to be compliant with EU PECR legislation.
GDPR
We strive to be compliant with these requirements of GDPR…
- Breach notification. Under the GDPR, we must inform our users within 72 hours if any breach occurs that might compromise their data.
- Right of access. Users have a right to access the information we have about them. We may charge a fee of £10.
- Right to be forgotten. Users have the right to ask us to delete their accounts and all personal information we have.
- Right to portability. Users will be able to request that we forward their records to other ‘controllers’ or services if need be.
- Note. We will need to confirm the identity of the user prior to complying with above three points.
- Privacy by design. This site runs through WordPress, and this has GDPR compliance built into the setup. And is continuously updated. We assure you that our systems are as secure as we know how. And we are continually monitoring, and seeking to improve, our security setup. We may be held liable for data breaches if our system isn’t secure by design. In other words, we can be held responsible for failing to take precautions to protect user information.
Use of information
We use the information that we collect from you to provide services to you. In addition to this we may use the information for one or more of the following purposes: To provide information to you that you request from us relating to our services, i.e. sending you a reply when you contact us. To provide information to you relating to offers and events. But such additional information will only be provided where you have explicitly consented, say by online sign-up, to an email newsletter. We comply with UK spam laws as detailed in the Privacy and Electronic Communications Regulations 2003. Newsletters, mailing lists and their maintenance are administered using a secure third-party organisation, Mailjet. We will never allow selected third parties to use your data.
Storing personal data
In operating our website it is sometimes necessary to transfer data that we collect from you to secure locations outside of the EU for processing and storing. This particularly applies to forms. By providing your personal data to us, you agree to this transfer, storing or processing. We do our utmost to ensure your data is treated stored securely. Sending such information is at your risk, though we believe this to be minimal.
Disclosing your information
We will not disclose your personal information to any other party except in the circumstances below: In the event that we sell all or part of our business. Where we are legally required by law to disclose your personal information. To further fraud protection and reduce the risk of fraud.
Third party links
On occasion we do include links to third parties on this website. Where we provide a link it does not mean that we endorse that site’s policy towards visitor privacy. You should review their privacy policy before sending them any personal data.
Social media platforms
Communication and actions taken through external social media platforms (like say, Facebook) that this website and its owners participate in, are subject to the terms, conditions and privacy policies held by each social media platform. This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion. And note that the social media platform may track and save your request to share a web page respectively through your social media platform account.
Questions or comments?
Please contact us and we will respond as soon as possible.
Resources and more information
GDPR information www.eugdpr.org
Data Protection Act 1998 www.legislation.gov.uk/ukpga/1998/29/contents
Privacy and Electronic Communications Regulations – guide www.ico.org.uk/for_organisations/privacy_and_electronic_communications/the_guide
Twitter privacy policy www.twitter.com/privacy
Facebook privacy policy www.facebook.com/about/privacy
Google privacy policy www.google.com/policies/privacy
Mailjet privacy policy www.mailjet.com/legal/privacy-policy/
Our full privacy policy is below, quite a read!
- Visit our website
at https://www.tyddynllan.co.uk , or any website of ours that links to this privacy notice
- Engage with us in other related ways, including any sales, marketing, or events
names
phone numbers
email addresses
- Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, and settings and information about your activity in the Services (such as the date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called
'crash dumps' ), and hardware settings).
- Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. Depending on the device used, this device data may include information such as your IP address (or proxy server), device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.
- Location Data. We collect location data such as information about your device's location, which can be either precise or imprecise. How much information we collect depends on the type and settings of the device you use to access the Services. For example, we may use GPS and other technologies to collect geolocation data that tells us your current location (based on your IP address). You can opt out of allowing us to collect this information either by refusing access to the information or by disabling your Location setting on your device. However, if you choose to opt out, you may not be able to use certain aspects of the Services.
- To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
- To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
- Consent. We may process your information if you have given us permission (i.e.
consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Performance of a Contract. We may process your personal information when we believe it is necessary to
fulfil our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
- For business transactions provided certain conditions are met
- If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
- For identifying injured, ill, or deceased persons and communicating with next of kin
- If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
- If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
- If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
- If the collection is solely for journalistic, artistic, or literary purposes
- If the information is publicly available and is specified by the regulations
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- When we use Google Maps Platform APIs. We may share your information with certain Google Maps Platform APIs (e.g.
Google Maps API, Places API).
Category | Examples | Collected |
A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name |
B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information |
Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data | ||
Transaction information, purchase history, financial details, and payment information | ||
Fingerprints and voiceprints | ||
Browsing history, search history, online | ||
Device location | ||
Images and audio, video or call recordings created in connection with our business activities | ||
Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us | ||
Student records and directory information | ||
Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics | ||
- Receiving help through our customer support channels;
- Participation in customer surveys or contests; and
- Facilitation in the delivery of our Services and to respond to your inquiries.
- Category A -
1 year
- Right to know whether or not we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal data if it is used for targeted advertising
(or sharing as defined under California’s privacy law) , the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ( 'profiling' )
- Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including
California's and Delaware's privacy law)
- Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including Oregon’s privacy law)
- Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including California’s privacy law)
- Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including Florida’s privacy law)