Sapphire Cars Privacy Notice
Last updated: 25 May 2018
Sapphire Cars (“we”,“our”, “us”) is committed to protecting and respecting your privacy.
Sapphire Cars is an Executive and Private hire business established in England with an office at 27 Pudding Lane, Maidstone, Kent, ME14 1PA (“Sapphire Cars”); and for the purpose of the General Data Protection Regulation (the “GDPR”), if you book services as a passenger in England, the data controller is Sapphire Cars.
This policy sets out the basis on which we will process any personal data or usage information we collect from you, or that you provide to us, in connection with your use of our Website at www.sapphire-cars.com, (the “Website”), our mobile App (the “App”) or our services. Please read this notice carefully so that you understand your rights in relation to your personal data, and how we will collect, use and process your personal data. If you do not agree with this Privacy Notice in general or any part of it, you should not access the Website, the App or use our services.
What types of information do we collect and how do we use it?
- The information you give us. You may provide information by contacting us via our Website, App or by email, telephone, social media or otherwise.
- CCTV information. Our booking office is fitted with CCTV cameras. These cameras film the public booking office area, they do not record audio, but your image may be picked up by them when you enter or exit the booking office.
- If you use our services through your company, information provided to us by your employer. In the case of our corporate customers only, your employer may provide us with information about you when it signs up to use our services, for example, your name and business email address.
- Information provided to us by a third party and/or collected from public records in the case of fraud or suspected fraud. In the case of fraud or suspected fraud, we may obtain information from third parties and from public records to prevent and detect fraud.
To perform our contract with you, we will use your information:
- to communicate with you;
- to provide you with ground transportation and/or services;
- to create records of bookings and to send you booking acknowledgements, confirmations, receipts and invoices; and
- to maintain records of lost property.
As it is in our legitimate interests to be responsive to you and to ensure the proper functioning of our services and organisation, we will use your information:
- to detect and prevent fraud and crime;
- for reporting and data analysis purposes;
- to administer our corporate transport accounts(s);
- for insurance purposes;
- to comply with our legal and regulatory obligations imposed by Kent County Council and any other licensing authority where we provide services;
- to meet customer service requirements and for complaint handling and feedback;
- to monitor and assess the quality of our service;
- to host events for our customers;
- to pass on feedback such as ratings or compliments about our drivers;
- to contact you via telephone, email, SMS or via our App;
- to identify our users;
- to personalise our services for you, for example, to provide you with an accessible vehicle where you request such a vehicle.
- to enforce our terms and conditions;
- if you have opted into marketing, to communicate with you about products, services, promotions, events and other news and information we think will be of interest to you; or
- to provide third parties with statistical information about our users (but those third parties will not be able to identify any individual user from that information).
- Technical usage information.
When you visit our Website or use our App, we automatically collect the information sent to us by your computer, mobile phone, or other access devices. This information includes:
- your IP address;
- device information including, but not limited to, identifier, name, and type of operating system (including versions);
- mobile network information;
- standard web information, such as your browser type and the pages you access on our Website;
- mobile device UUID (Unique Download ID) and/or mobile device fingerprint; and
- hardware models, software, file names and versions, preferred languages, unique device identifiers, advertising identifiers, serial numbers and device motion information.
As it is in our legitimate interests to process your data to provide effective services and useful content to you we collect this information in order to:
- personalise our Website and App to ensure content from our Website and App is presented in the most effective manner for you and your device;
- monitor and analyse trends, usage and activity in connection with our Website, App and services and to improve our services;
- administer our Website and App, and for internal operations, in order to conduct troubleshooting, data analysis, testing, research, statistical and survey analysis;
- keep our Website and App safe and secure; or
- measure and understand the effectiveness of the content we serve to you and others.
We receive information from other sources, such as from fraud prevention tools in the case of fraud or suspected fraud, from analytics companies in the case of in-car data usage and in the case of telematics data (including, GPS location data, vehicle usage/driving style data and odometer readings), from third party data validation tools such as Experian and from publicly accessible data such as Companies House, the Land Registry, the Electoral Register and information you post online.
We use Google Analytics, which is a web analytics tool that helps us understand how users engage with our Website. Like many services, Google Analytics uses first-party cookies to track user interactions, as in our case, where they are used to collect information about how users use our site. This information is used to compile reports and to help us improve our Website. The reports disclose website trends without identifying individual visitors. You can opt out of Google Analytics without affecting how you visit our site – for more information on opting out of being tracked by Google Analytics across all Website you use, visit this Google page: https://tools.google.com/dlpage/gaoptout.
How do we share your personal data?
We do not sell, rent or lease your personal information to others except as described in this Privacy Notice. We share your information with selected recipients. These categories of recipients include:
- Analytics and search engine providers located in the UK and the USA that assist us in the improvement and optimisation of the Website and App; merchant acquirers located in the UK and USA and which store your personal data in the UK and the USA for the purpose of processing payments;
- Fraud prevention tools located in the UK and the USA for the purposes of preventing fraud;
- IT support service providers who support and maintain our booking platform and have access at our premises working on a secure server; and
- Our insurance company and claims handling companies, for the purpose of investigating and settling any insurance claims.
We will share your information with law enforcement agencies, public authorities or other organisations if legally required to do so, or if we have a good faith belief that such use is reasonably necessary to:
- comply with a legal obligation, process or request;
- enforce our terms and conditions and other agreements, including investigation of any potential violation thereof;
- detect, prevent or otherwise address security, fraud or technical issues; or
- protect the rights, property or safety of us, our users, a third party or the public as required or permitted by law (exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction).
Where do we store your personal data?
Your personal data is processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff are engaged in, among other things, the fulfilment of your booking, the processing of your payment details and the provision of support services. We will take all steps reasonably necessary to ensure that your personal data is treated securely and in accordance with this policy.
The security of your personal data
Unfortunately, the transmission of information via the internet or email is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your information transmitted through the Website, App, over email or via our booking office; any transmission is at your own risk. Once we have received your information, we will take appropriate technical and organisational measures to safeguard your personal data against loss, theft and unauthorised use, access or modification.
We will, from time to time, host links to and from the Website of our affiliates or third parties. If you follow a link to any of these Websites, these Websites will have their own privacy policies and we do not accept any responsibility or liability for these policies. Please check these policies before you submit any information to those Websites.
How long do we store your personal data?
To determine the retention period of your personal data, we consider several criteria to make sure that we do not keep your personal data for longer than is necessary or appropriate. These criteria include:
- the purpose for which we hold your personal data;
- our legal and regulatory obligations in relation to that personal data, for example, any financial reporting obligations and our regulatory obligations to Kent County Council and other local licensing authorities;
- whether our relationship with you is ongoing, for example, you have an active account with one or more of our services, or you regularly browse or purchase from our Website/App);
- any specific requests from you in relation to the deletion of your personal data; and
- our legitimate business interests in relation to managing our own rights, for example, the defence of any claims.
We will retain your information as follows:
- your customer profile and account information (including your technical usage data), for 7 years after you last use our services;
- if you contact us via email we will keep your data for up to 5 years;
- records of bookings lost property and complaints for a minimum of 12 months (we are required to retain such data to comply with our regulatory requirements).
After you have terminated your use of our services, we will store your information in an aggregated and anonymised format.
You have rights in relation to the personal data we hold about you. Some of these only apply in certain circumstances. We have described these situations below, as well as how you can exercise your rights. To exercise any of your rights, please contact us at email@example.com
- Access: You have the right to ask us to access the personal data we hold about you and be provided with certain information about how we use your personal data and who we share it with.
- Correction: You also have the right to ask us to correct your personal data where it is inaccurate or incomplete.
- Portability: Where you have provided your personal data to us under contract, you have the right to ask us to share (port) this data to another data controller in a structured, commonly used and machine-readable format.
- Erasure: In certain circumstances, you have the right to ask us to delete the personal data we hold about you.
- Restriction: In certain circumstances, you have the right to ask us to restrict (stop any active) processing of your personal data, save for storage.
- Objection: In certain circumstances, the right to restrict or object to our processing of your personal information (e.g. where you request correction or erasure, you also have a right to restrict processing of your relevant data while your request is considered). You can object to our processing of your personal data based on our legitimate interests and we will no longer process your personal data unless we can demonstrate an overriding legitimate ground.
In addition, you have the right to complain to the Information Commissioner’s Office or other applicable data protection supervisory authority.
Please note that these rights are limited, for example, where fulfilling your request would adversely affect other individuals or company trade secrets or intellectual property, where there are overriding public interest reasons or where we are required by law to retain your personal data.
In the event that you wish to make a complaint about how we process your personal data, please contact us in the first instance at firstname.lastname@example.org and we will endeavour to deal with your request as soon as possible. This is without prejudice to your right to launch a claim with the Information Commissioner’s Office where you think we have infringed data protection laws.
Any changes we will make to this policy in the future will be posted on this page. Please check back frequently to see any updates or changes to this policy.
Questions, comments and requests regarding this policy are welcomed and should be addressed to email@example.com. You can also write to our Data Protection Officer at 27 Pudding Lane, Maidstone, Kent, ME14 1PA, firstname.lastname@example.org or by telephoning +44 1622 66 3000.