We ask that you read this privacy notice carefully as it contains important information on who we are, how and why we collect, store, use and share personal information, your rights in relation to your personal information and on how to contact us and supervisory authorities in the event you have a complaint.
Importantly, (i) where we use the term “client” we are referring to the entity in contract with us to use the dotdigital services; (ii) where we use the term “you” we are referring to visitors to our website www.dotdigital.com or www.dotdigitalgroup.com or clients using the dotdigital services; (iii) where we use the term “end-user” we are referring to individual users of a client, and; where we use the term “contact” we are referring to a person contacted through your use of the dotdigital services, or any individual whose information you provide to us in your use of the dotdigital service.
This notice applies in addition to the Shareholder privacy notice.
dotdigital (including dotdigital EMEA Limited (based in the UK), dotdigital B.V. (based in the Netherlands), dotdigital, Inc. (based in the US), dotdigital SG Pte Ltd (based in Singapore) and dotdigital APAC Pty Ltd (based in Australia)) collects, uses and is responsible for certain personal information about you.
In the United Kingdom and across Europe, when we do so we are regulated under the Data Protection Act 2018 and General Data Protection Regulation and we are responsible as ‘controller’ of that personal information for the purposes of those laws.
In connection with personal data provided through your use of the Engagement Cloud platform and other services that we provide, we are a ‘processor’ for the purposes of the General Data Protection Regulation.
We also obtain personal information from your use of the Engagement Cloud platform. When you upload contact data in the Engagement Cloud platform, we may have access to the data and content of your messages. We receive information about how you use the Engagement Cloud platform and store it in log files or other types of files associated to your account and link it to other information we hold about you. This information might include the date and date of any activity, the browser and IP address as well as actions your end-users have taken within the Engagement Cloud platform. This information helps us to improve the Engagement Cloud platform for you for all users of the platform.
dotdigital may obtain information about you or end-users from third parties, such as public databases, social media platforms, third party data providers and our marketing partners. Examples of the information we may receive from other sources include device information (e.g. IP address and browser), location, behavioural data and demographic information. We may use this information, alone or in combination with other information described above, to develop or provide more relevant platform features or services (e.g. social media data of end-users allowing you to send more relevant content) or provide more relevant marketing and content to you.
dotdigital websites include social media features (either hosted by a third party or hosted directly on our website), which may collect information about your IP address and which page you are visiting. The feature may set a cookie to make sure the feature functions properly. We also maintain presences on social media platforms including Facebook, Twitter, and Instagram. Your interactions with these platforms are governed by the privacy policies of the companies that provide them. Anything you submit to dotdigital via a social media platform is done so at your own risk without any expectation of privacy.
Further, any comments or information you supply on any blog that dotdigital operates can be read, used or collected by anyone. If your information appears in our blog pages and you want it removed, contact our Marketing team: firstname.lastname@example.org.
We use and disclose personal information to:
- Supply, improve and support the services we provide (this includes using the data you provide to use the Engagement Cloud platform to contact end-users, aggregating information from your use of the platform or our website and sharing this with third parties to improve the services that we provide);
- Confirm your identity in using the Engagement Cloud platform;
- Send you information and promotional content (you can amend your marketing preferences in our preference centre or stop receiving messages by unsubscribing);
- Promote our services to you (e.g. when we collect your personal information on our website, we may contact you further to invite you to use our platform);
- Perform the obligations of our contract with you or applicable law (e.g. to enforce our terms, communicate with you and provide support);
- Protect, investigate and deter against fraudulent, harmful, unauthorized or illegal activity;
- Fulfil requests that you may make;
- Bill you (e.g. to send you invoices, process payment, notices). Note that we use third parties for secure credit card transaction processing, and we send billing information to those third parties to process your orders and credit card payments;
- Send notifications about the platform;
- Bring or defend legal proceedings, meet legal requirements (e.g. complying with court orders, enforcement actions, or other legally valid mechanisms) or respond to lawful requests by public authorities or law enforcement requests; and
- Provide information to our professional advisors.
When using the Engagement Cloud platform, you may import contact or other personal information you have collected into our system. We have no direct relationship with your contacts or any person other than you, and for that reason, you are responsible for making sure you have the appropriate permission for dotdigital to collect and process information about those individuals.
Further to the uses described above, we may aggregate and/or de-identify any information that we collect, such that the information no longer identifies any specific individual. We may use, disclose and otherwise process such information for our own legitimate business purposes without restriction. We may transfer personal information of you or your end-users to companies that help us promote, provide, or support our platform or other services that we provide. We may partner with and use various third party software and services, including analytics services, to help understand your usage of our products and services. In particular, we provide a limited amount of your information (such as your email address and sign-up date) to select third party services to collect data for analytics purposes when you visit our website or use our products and services. This allows dotdigital to monitor your use of our website, products and services and tracks our relationship so that we can improve our service to you. We may also use these third party services for communications, either through email, or through messages within our products and services. These third party services may collect publicly available contact and social information related to you, such as your name, email address, gender, company, job title, photos, website URLs, social network handles and physical addresses, to enhance your user experience.
For details about how we engage third parties when we process your contact or end-user data when you use our platform and services, please see our terms & conditions, the standard form of which can be found at https://www.dotdigital.com/terms-of-service/.
In providing services to you, we will hold personal information for as long as are providing you the services for or in order to comply with our legal obligations, enforce the terms of our contracts, resolve disputes or prevent abuse. Otherwise, we only hold personal information for as long as is necessary.
In relation to clients, the lawful basis for which we rely on to collect and process your data is typically performance of our contractual obligations.
If you are not a dotdigital client, we rely on legitimate interest as the lawful basis on which we collect and use your personal data in relation to contacting you further in certain situations. Our legitimate interests are usually to provide individuals representing a business with details of our products or services through B2B direct marketing . If you are an individual, the basis on which we collect and use your personal data to contact you is often consent.
If you have any questions about the lawful basis on which we are processing your personal data, please contact email@example.com.
For UK & European residents, under the General Data Protection Regulation, you have a number of important rights free of charge. In summary, those include rights to:
- fair processing of information and transparency over how we use your use personal information
- access to your personal information and to certain other supplementary information that this Privacy Notice is already designed to address
- require us to correct any mistakes in your information which we hold
- require the erasure of personal information concerning you in certain situations
- receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- object at any time to processing of personal information concerning you for direct marketing
- object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
- object in certain other situations to our continued processing of your personal information
- otherwise restrict our processing of your personal information in certain circumstances
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals rights under the General Data Protection Regulation.
If you would like to exercise any of those rights, please:
- email, call or write to our Data Protection Officer
- let us have enough information to identify you,
- let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill), and
- let us know the information to which your request relates, including any account or reference numbers, if you have them
If you would like to unsubscribe from any email newsletter you can also click on the ‘unsubscribe’ button at the bottom of the email. It may take up to 24 hours for this to take place.
- request information, including a list of the categories of Personal Information (e.g. name, email, and mailing address, and the type of services provided to the customer that a business has disclosed to third parties (including affiliates that are separate legal entities) during the immediately preceding calendar year for the third-parties’ direct marketing purposes, from businesses with whom you have an established business relationship, & the names and addresses of all such third parties.;
- portability of such information and receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- require the erasure of personal information concerning you in certain situations; and
We have appropriate security measures in place to prevent personal information from being accidentally lost, used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so
We hope that we can resolve any query or concern you raise about our use of your information.
For individuals in the UK & Europe, the General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred.
For UK individuals, the supervisory authority in the UK is the Information Commissioner who may be contacted at http://ico.org.uk/concerns or telephone at 0303 123 1113 or other channels as updated at https://ico.org.uk/global/contact-us.
For individuals in the Netherlands, the supervisory authority is the Dutch Data Protection Authority who may be contacted at https://autoriteitpersoonsgegevens.nl/en/contact-dutch-dpa/contact-us.
This privacy notice was published on 22 December 2020. We may change this privacy notice from time to time, when we do we will inform you via email.
If you have any questions or concerns about the way in which dotdigital handles any privacy matter or the information we hold about you, please contact us on the details below.
For the purposes of UK data protection legislation, please use the following contact details if you wish to contact our Data Protection Officer. Please direct emails to firstname.lastname@example.org, or write to Data Protection Officer, dotdigital EMEA Limited, No.1 London Bridge, London, SE1 9BG.
For the purposes of European data protection legislation, please use the following contact details if you wish to contact our Data Protection Officer. Please direct emails to email@example.com, or write to Data Protection Officer, dotdigital B.V., Evert van de Beekstraat 354, 1118 CZ Schiphol, Netherlands.