Purpose of the processing:
Your personal data may be processed where you have given us your contact and/or financial data by filling in forms or by corresponding with us by post, phone, email or otherwise.
The contact and/or financial data we obtain from you and process may include your name, address, telephone number, email address, user name and passwords to access our websites and services, financial and credit card information.
Your personal data may be processed for purposes related to:
- the provision to you of our products or services or publications;
- setting up and managing an account for you on one of our websites;
- subscribing you to our newsletters or other publications and managing your subscriptions;
- carrying out user surveys or managing feedback that you give us;
- managing and responding to enquiries that you submit to us;
- the performance of an agreement, contract, or licence to which you are a party.
Processing your data must be done in line with one or more lawful bases. The above processing will be carried out in line with one or more of the following lawful bases:
- Consent: where you have given consent to the processing of your personal data for one or more specific purposes; where individuals are under the age of 13 parental consent will be required.
- Contract: where it is necessary for the performance of an agreement, contract or licence to which you are a party or for processes related to entering into an agreement, contract or licence;
- Public Task: where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us;
- Legitimate Interest: where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Our legitimate interests include:
- running and developing our business;
- keeping our records updated;
- studying how customers use our products, services, websites and developing them;
- preventing fraud;
- making payments and recovering debts due to us;
- defining types of customers for our products and services in order to inform our marketing strategy;
- keeping our website updated and relevant;
- developing our products/services.
Newsletters & Publications: When requesting to join mailing lists for newsletters or publications the lawful basis for processing your data will be consent. Where individuals are under the age of 13 parental consent will be required. You will be advised as to how you can withdraw your consent when signing up and when you receive newsletters and publications from CEH.
The recipients or categories of recipients of the personal data include:
Our agents and suppliers where a data controller-data processor contract has been entered into.
The details of transfers of the transfers of the personal data to any third countries or international organisations (if applicable).
Unless otherwise indicated, your information is processed in the UK and European Economic Area (EEA).
In those instances where your information is being processed outside of the EEA, we work with our partners to do all we can to ensure your personal data is processed in line with the data protection requirements of GDPR. The CEH website is hosted by Pantheon in the USA. Some of our newsletters are hosted by Mailchimp, based in the US and certified by the EU-US Privacy Shield.
For specific projects where your information is being processed outside of the EEA, we work with our partners to do all we can to ensure your personal data is processed in line with the data protection requirements of GDPR.