Win Nice Cars respects your right to privacy and comply with obligations under the Data Protections Acts 1988 & 2002 and the EU General Data Protection Regulation 2018 (GDPR).
All references to the client will be referred to as “you”, “your”, “customer”, “entrant” or “client”.
2. Who are we
We operate a prize competitions based Website through which entrants can submit their answers to skill and knowledge based questions for an opportunity to win prizes.
D&B Cars Ltd
23 Tir Y Farchnad, Swansea SA4 3GS.
Phone number: 01792732736
3. Types of information collected
We collect the following types of information:
This is data that identifies you or can be used to identify or contact you, which may include your name, address, email address and telephone number. Such information is only collected from you if you voluntarily submit it to us. When you contact us, whether by telephone, through our website, Facebook or by e-mail, we collect the data you have given to us in order to reply with the information you need. We record your request and our reply in order to increase the efficiency of our business.
Like most websites, we gather statistical and other analytical information collected on an aggregate basis of all visitors to our website. This Non-Personal Data comprises information that cannot be used to identify or contact you. Such as user IP addresses where they have been clipped or anonymised, browser and operating system types and other anonymous statistical data involving the use of our website.
This website is not directed towards children and as such we do not seek to collect any personal information from children. If we become aware that personal information from a child under the age of 13 has been collected, we will use reasonable efforts to delete such information from our records.
4. Purposes for which we hold and use your information
We will process any data you provide to us for the following purposes:
to contact the winners of our competitions
to respond to your comments, queries and support requests
to keep you informed of any changes to your order or our services
to send you newsletters, or information via email
to check that use of our services is in accordance with our terms and conditions
for the purposes of security, and prevention and detection of fraud
we use the Non-Personal Data gathered from visitors to our website in an aggregate form to get a better understanding of where our visitors come from and to help us better design and organise our website, products and services
Our legal basis for holding your personal data under GDPR
We are entitled to use your data as described in point (a) as we are responding to your request and, therefore, you have given consent to this processing
We are entitled to use your data as described in points (b), (c), (d) and (e) as we require to do this as part of our contracted obligations to provide our services
We are entitled to use your data as described in points (f) and (g) as the purposes stated are within our legitimate interests
5. Storage and management of your personal data
Data collected through our website and emails is also stored on our secure web server, which is located in a UK Data Centre with 24/7 onsite security.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk.
Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Personal Data Retention Schedule
By law we have to keep basic information about customers and their contact details for a minimum of 7 years for tax purposes.
We only store your information for as long as is necessary for the purpose it was obtained for or for any additional purpose we have explained to you. We also implement policies to regularly audit the personal data we hold to ensure we do not retain any personal data for longer than we are entitled to.
6. Security of your personal data
We place great importance on the security of all personally identifiable information associated with our customers. We use technical security measures to prevent the loss, misuse, alteration, or unauthorised disclosure of information under our control.
Our website utilises industry-standard Secure Sockets Layer (SSL) technology to allow for the encryption of potentially sensitive information such as your name, address and other critically sensitive information. Information passed between your computer and our website cannot be read in the event someone else intercepts it.
This technology includes the following features:
Authentication – this assures your browser that your data is being sent to the correct computer server, and that the server is secure
Data Integrity – this checks the data being transferred to ensure it has not been altered.
Encryption – this encodes the data, so that it cannot be read by anyone other than the secure server
When you access a website secured by an SSL certificate, you will see https:// at the beginning of its URL. Your web browser may also show the connection as secure by displaying a “lock” icon in the address bar.
How we protect your information
We do not use vulnerability scanning and/or scanning to PCI standards.
An external PCI compliant payment gateway handles all Card transactions.
We do not include or offer third-party products or services on our website.
We do not sell, trade or otherwise transfer to outside parties your Personally Identifiable Information
7. Disclosure of information to Third Parties
b) Legal and Compliance Reasons. We may access, preserve and share your information with companies, organisations, governmental entities or individuals outside of our Company if we believe, in good faith, that the law required us to do so. This may include, but is not limited to, responding to court orders or other legal processes (such as law enforcement requests). We may also access, preserve and share your information as necessary to: (i) establish or exercise our legal rights to defend against any legal claim; (ii) investigate, prevent, or take action regarding suspected fraud or other illegal activities; (iii) prevent death or serious physical harm to any person; or (iv) investigate violations of our Terms & Conditions.
Our legal basis for disclosing your personal data under GDPR
We are entitled to disclose your data as described in points (a) and (b), as the purposes stated are all with our legitimate interests or that we are legally required to do so.
9. Links to external websites
This website may contain links to external websites. We are not responsible for the privacy policies or content of these sites. When you leave this website, make sure you read the privacy policies of each and every website that collects your personal data.
11. Your Rights
You have the right to object to how we use your personal information. You also have the right to see what personal information we hold about you. In addition, you can ask for us to correct inaccuracies, delete or restrict personal information or to ask for some of your personal information to be provided to someone else.
Right to object
You can object to our processing of your personal information. Please contact our Data Controller, providing details of your objection.
Access to Your Personal Information
You can request access to a copy of your personal information that we hold, along with information on what personal information we use, why we use it and how long we keep it for.
You can make a request for access by contacting us at D&B Cars Ltd, 23 Tir Y Farchnad, Swansea SA4 3GS.. This must be done in writing and you will be required to provide us with evidence of your identity.
Right to Withdraw Consent
If you have given us your consent to use personal information, you can withdraw your consent at any time and, update your marketing preferences by contacting us.
You can ask us to change or complete any inaccurate or incomplete personal information held about you.
You can ask us to delete your personal information where it is no longer necessary for us to use it, you have withdrawn consent, or where we have no lawful basis for keeping it.
You can ask us to provide you or a third party with some of the personal information that we hold about you in a structured, commonly used, electronic form, so it can be easily transferred.
You can ask us to restrict the personal information we use about you where you have asked for it to be erased or where you have objected to our use of it.
Personal Data Breach Notification
We ensure best to our ability that our systems and servers are protected from hackers, viruses, intruders and other online and offline problems, however, if we experience a data breach of any kind, where a customer’s data has been compromised, a notification will be sent to all those affected within 72 hours of becoming aware of the breach.
Make a Complaint
You can make a complaint about how we have used your personal information to us by contacting our Data Controller. You also have the right to lodge a complaint with a supervisory body. The relevant authority in the UK is the Information Commissioner’s Office at ico.org.uk
We will not make any charge for responding to any request from you to exercise your privacy rights, and we will respond to your requests in accordance with our obligations under data protection law.