Please note that our Site is not intended for children (those aged 16 and under) and we do not knowingly collect data relating to children.
We may change this policy from time to time and at our absolute discretion. We will do so by updating this page. You should check this page from time to time to ensure that you are happy with any changes and are aware of the most up to date version of this policy.
This policy was last updated on 24.05.2018.
All staff have been made aware in our organisation that the law is changing with regard to an individual’s rights to have their personal data protected. These changes are set out in the General Data Protection Regulations which come into effect on the 25th May 2018. The GDPR will be similar to the existing UK Data Protection Act 1998 (DPA) but brought up to date and with many more legal requirements. The UK agency that will be responsible for enforcing the GDPR is the Information Commission’s Office (ICO). Once the GDPR comes into effect there are significant financial penalties that can be enforced for a data breach or a failure to follow the stipulations under GDPR or a failure to obtain formal consent.
We may collect, store and use the following kinds of personal information:
As a business we collect, use, store and transfer different types of personal data depending on who you are.
If you are purchasing, renting, selling or letting a property through Knightsbridge Estate Agents, or purchasing, renting, selling or letting a property from one of our clients, we collect and use your personal data in order for us to provide you with our services. The personal data we collect and use may include:
- information about your computer and about your visits to and use of this website (including your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views, and website navigation details.)
- Information relating to any transactions carried out between you and us on or in relation to this website. We do not however sell anything directly through our website and direct purchases cannot be made via the website.
- information that you provide to us for the purpose of registering with us (including your email address, telephone number, address, and name)
- Information that you provide to us for the purpose of subscribing to our website services, email notifications and/or newsletters.
- Any other information that you choose to send to us.
- Identity Data (name, marital status, title, date of birth, gender, username and password, purchases made by you, your interests and preferences, feedback and survey responses)
- Contact Data (billing address, delivery address, email address and telephone numbers)
- Financial Data (bank account and payment details)
- Transaction Data (details about payments to and from you and other services you have purchased through us)
- Technical Data (internet protocol address, login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, identification number, online identified, location data and other similar identifying information required for the customer's device(s) to communicate with websites and applications on the internet)
- Usage Data (how you use our website products and services, the full uniform resource locators clickstream to, through and from our site (including date and time), download errors, lengths of visit to certain pages, page interaction information, methods to browse away from the page and any phone numbers you use to call us)
- Marketing and Communications Data (your marketing preferences from us and our third parties and your communication preferences)
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us. You can ask us to rectify or update your personal information at any time by email to firstname.lastname@example.org
Google’s advertising requirements can be summed up by Google’s Advertising Principles. They are put in place to provide a positive experience for users. https://support.google.com/adwordspolicy/answer/1316548?hl=en
How is your personal data collected?
You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
- apply for our services;
- create an account on our website;
- subscribe to our service or publications;
- request marketing to be sent to you;
- contact us through social media;
- walk-in to our branch offices or telephone
- enter a competition, promotion or survey; or
- Give us some feedback.
Through Third party:
- TwentyCi based inside the EU
- Rightmove based inside the EU
- Zoopla Property Group based inside the EU
- Facebook based outside the EU
Identity and Contact Data from publicly availably sources such as Companies House and the Electoral Register based inside the EU.
Using your personal information
- To carry out our obligations arising from any contracts entered into between you and us and to provide with you the information, products and services you request from us Identity
- To facilitate and to enable you to partake in a property viewing, open house event or visits to property marketing suites
- administer the website;
- improve your browsing experience by personalising the website;
- enable your use of the services available on the website;
- send you general (non-marketing) commercial communications;
- Send you by post or marketing email notifications which you have specifically agreed to and have been also unambiguously and properly opted in. For example loan calculator used on our website
- Send to you our newsletter and other marketing communications relating to our business, where you have specifically agreed to this and they have also been unambiguously and properly opted in, by post, by email or similar technology. You can inform us at any time if you no longer require marketing communications.
- provide third parties with statistical information about our users – but this information will not be used to identify any individual user; for example as used by google analytics
- Deal with enquiries and complaints made by or about you relating to the website;
We will not provide your personal information to any third parties for the purpose of direct marketing.\
- Merchant cardholder receipt data is stored for the required minimum accounting period of 7 years and also to respond to providing copy receipts and chargebacks.
- We may disclose your data to our agents or third party service providers to undertake processing operations on our behalf (see ‘Service Providers’ below).
- We may analyse and disclose aggregate statistics about users of our services in order to provide services to our agents and service third parties and for other lawful purposes, but these statistics will include no personally identifying information.
- We may disclose personal data if required to do so by law or if we believe that such action is necessary to protect and defend the rights, property or personal safety of our Site or its visitors.
Our Lawful basis for processing personal data:
Asking for consent
- We consider that consent is the most appropriate lawful basis for processing personal data.
- The request for consent is prominent and separate from our terms and conditions.
- We ask people to positively opt in.
- We don’t use pre-ticked boxes or any other type of default consent.
- We use clear, plain language that is easy to understand.
- We specify why we want the data and what we’re going to do with it.
- We give individual detailed options to consent separately to different purposes and types of processing.
- We name our organisation and any third party controllers who will be relying on the consent.
- We tell individuals they can withdraw their consent.
- We ensure that individuals can refuse to consent without detriment.
- We avoid making consent a precondition of a service.
A record is kept of when and how we gained consent from an individual.
We regularly review consents to check that the relationship, the processing and the purposes have not changed.
There are processes in place to refresh consent at appropriate intervals, including any parental consents.
Individuals may withdraw their consent at any time, and we publicise how to do so.
Withdrawals of consent are acted on as soon as possible.
We will not penalise individuals who wish to withdraw consent.
Legitimate Business Interests
- We consider that legitimate interests are also another appropriate basis for processing and storing of for instance photographic images.
- We understand our responsibility to protect the individual’s interests.
- We have conducted a legitimate interest’s assessment (LIA) and kept a record of it, to ensure that we can justify our decision.
- We have identified the relevant legitimate interests.
- We have checked that the processing is necessary and there is no less intrusive way to achieve the same result.
- We have done a balancing test, and are confident that the individual’s interests do not override those legitimate interests.
- We only use individuals’ data in ways they would reasonably expect, unless we have a very good reason.
- We are not using people’s data in ways they would find intrusive or which could cause them harm, unless we have a very good reason.
- We have considered safeguards to reduce the impact where possible.
- We have considered whether we can offer an opt-out.
If our LIA identifies a significant privacy impact, we have considered whether we also need to conduct a DPIA.
- We keep our LIA under review and repeat it if circumstances change.
- We include information about our legitimate interests in our privacy notice.
- To the extent that we are required to do so by law;
- In connection with any legal proceedings or prospective legal proceedings;
- In order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk);
- To any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information.
Security of your personal information
- We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. We will store all the personal information you provide on our secure (password- and firewall- protected) servers. All electronic transactions you make to or receive from us will be encrypted using SSL technology. All information is handled in accordance with the data protection act 1998. Of course, data transmission over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.
Any breach which leads to accidental, unlawful destruction or the loss or alteration of personal data will be notified to the ICO within 72 hours and to all affected individuals without undue delay.
You have the absolute right to object to your data being processed and profiled for direct marketing purposes. You have the right to have your information withdrawn at any time. Your information will be provided to you within one month and no fee will be levied. You may instruct us to provide you with any personal information we hold about you. Provision of such information will be subject to:
the supply of appropriate evidence of your identity. For this purpose, we will usually accept a photocopy of your passport certified by a solicitor or bank plus an original copy of a utility bill showing your current address.
We may withhold such personal information to the extent permitted by law. You may instruct us not to process your personal information for marketing purposes by email at any time. In practice, you will usually either expressly agree in advance to our use of your personal information for marketing purposes, or we will provide you with an opportunity to opt-out of the use of your personal information for marketing purposes.
Third party websites
The website contains links to other websites. We are not responsible for the privacy policies or practices of third party websites.
Please let us know if the personal information which we hold about you needs to be corrected or updated.
The data controller responsible in respect of the information collected at Knightsbridge Estate Agents