Touchstone Review Limited is committed to safeguarding the privacy and security of your Personal Data.
This Policy sets out how we will treat your Personal Data when you use our Web Platform.
Please read this Policy carefully before using the Web Platform.
By using the Web Platform, you consent to and agree to be bound by the terms of this Policy.
Your continued use of the Web Platform will be deemed acceptance of any amended terms of this Policy.
In this Policy:
Customer: means our customer, or the customer of any reseller who has been appointed by us, who has paid for the use of the Web Platform and authorised you as an individual user to use the Web Platform.
Data Controller: has the meaning defined in the Data Protection Legislation.
Data Processor: has the meaning defined in the Data Protection Legislation.
Data Protection Legislation: means a) unless and until the General Data Protection Regulation (EU) 2016/679 (GDPR) is no longer directly applicable in the UK, the GDPR and any national implementing laws, regulations and secondary legislation, as amended or updated from time to time, in the UK; and then b) any successor legislation to the GDPR or the Data Protection Act 1998.
Personal Data: means information about an individual who can be directly or indirectly identified by reference to the information.
We, our, us: refer to Touchstone Review Limited.
Web Platform: means www.touchstonereview.com and its subdomains including the software, services and documentation made available through these sites.
2. The Data Controller and Data Processor of your personal data
Under the Data Protection Legislation, the Customer is the Data Controller and we are the Data Processor for your Personal Data.
The Data Controller determines the purposes and means of processing of your Personal Data.
We process your Personal Data on behalf of the Data Controller, on the lawful basis of performing the contract with the Customer for the use of the Web Platform.
3. Information we process
The delivery of our Web Platform involves the collection, storage and use of data about individuals and organisations on behalf of the Customer. Individuals’ data includes Personal Data. Such Personal Data may include, but is not limited to:
We do not knowingly collect or process Personal Data from children under the age of 18.
4. Processing Personal Data provided by you about others
In using the Web Platform, you may be asked to provide details of other users. If you provide information about someone else, you must ensure that you are authorised to disclose that information to us.
This means that you must take reasonable steps to ensure the individuals concerned are aware of and consent to this Policy, including the fact that their Personal Data is being processed, the purposes for which that information is being processed, the intended recipients of that information, the individual’s right to obtain access to that information, our identity and how to contact us.
A cookie consists of certain information sent by a web server to your web browser and stored by the browser on your device. This information is then sent back to the server each time the browser requests a page from the server. This enables the web server to identify and track the web browser and by so doing provide a more tailored service.
We only use “session” cookies on the Web Platform. Such cookies do not track a user but are used during the session to control access and permissions. These session cookies will be deleted from your device when you close your browser or connection. The Web Platform and mobile application will not work without these cookies.
Most browsers allow you to reject all cookies, whilst some browsers allow you to reject just third party cookies. If you block all cookies this will negatively impact the functionality and usability of the Web Platform. We do not change our practices in response to a “do not track” signal in the HTTP header from your browser.
6. How we process Personal Data
Your Personal Data submitted on the Web Platform will be used for the purposes specified in this Policy or in relevant parts of the Web Platform.
6.1 Use of information to provide the services
We may use your Personal Data to:
6.2 Create and maintain a trusted and safer environment
We may use your Personal Data to:
By using and continuing to use the Web Platform you consent to us processing your Personal Data in accordance with this section 6.
The Personal Data you provide to us will be shared with the Customer to facilitate the purpose for which your Personal Data was collected and processed, including the provision of the Web Platform.
We may disclose Personal Data about you to any of our employees insofar as reasonably necessary for the purposes set out in this Policy. We will ensure that any such employees to whom your Personal Data is disclosed are obliged to keep such data confidential.
In addition, we may disclose information about you:
Except as provided in this Policy, we will not provide your Personal Data to third parties for marketing or related purposes.
By using and continuing to use the Web Platform you consent to us disclosing your Personal Data in accordance with this section 7.
8. International data transfers and service providers
Information that we collect may be stored and processed in and transferred between any of the countries in which we or the Customer operate to enable us to use the information in accordance with this Policy. We have strict controls over how and why Personal Data can be accessed.
We use third party service providers to help us provide the Web Platform. Service providers may be located inside or outside the United Kingdom or the European Economic Area. Service providers may help to verify or authenticate your identity, check information against public databases, assist with background checks, fraud prevention and risk assessment, and provide you with services. These providers have limited access to your information to perform these tasks and are contractually bound to adhere to strict data protection requirements.
By using and continuing to use the Web Platform you consent to us transferring your Personal Data in accordance with this section 8.
9. Security of your personal data
We take all reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your Personal Data and to protect your personal data from unauthorised access, modification or disclosure. We store all the Personal Data you provide on secure, password and firewall-protected servers. Electronic connections you make to or receive from the Web Platform will be encrypted using industry standard SSL technology.
However, data transmission over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet or on your devices. You should only input Personal Data to our web platform within a secure environment.
You are responsible for keeping your password and user details confidential. We will not ask you for your password and you should not disclose your password to anyone.
10. Data retention
The length of time we retain your personal data depends on the purposes for which we use it. We will retain your data for as long as you are using the Web Platform, or as needed to provide data to the Customer, unless we are required by law to dispose of it earlier or to keep it longer.
11. Third-party web applications
The Web Platform may contain links to other websites and applications. We are not responsible for the privacy policies or practices of third-party websites and applications.
12. Updating information
It is your responsibility to ensure that the Personal Data you provide to us is accurate, complete and up-to-date. We will assume that your Personal Data is correct.
You must contact the Customer if you wish to request access to, changes to or deletion of your personal data, unless you are able to do this yourself on-line.
You can request contact details by emailing email@example.com if you do not know who to contact.
If you have a question or a compliant about this Policy or our treatment of your Personal Data, email us at firstname.lastname@example.org.