We ask that you read this privacy notice carefully as it contains important information on who we are, how and why we collect, store, use and share personal information, your rights in relation to your personal information and on how to contact us and supervisory authorities in the event you have a complaint.
Importantly, (i) where we use the term “client” we are referring to the entity in contract with us to use the dotdigital services; (ii) where we use the term “you” we are referring to visitors to our website www.dotdigital.com or www.dotdigitalgroup.com or clients using the dotdigital services; (iii) where we use the term “end-user” we are referring to a person contacted through your use of the dotdigital services, someone that you may contact in the future using the dotdigital services, or any individual whose information you provide to us in your use of the dotdigital service.
This notice applies in addition to the Shareholder privacy notice.
- Who we are
- The personal information we collect and use
- How we use your personal information
- Transfer of your information out of the EEA
- EU – US & Swiss-US Privacy Shield Framework
- Your GDPR rights
- Your CCPA rights
- Keeping your personal information secure
- How to complain
- Changes to this privacy notice
- How to contact us
dotdigital (including dotdigital EMEA Limited (based in the UK), dotdigital, Inc. (based in the US) and dotdigital APAC Pty Ltd (based in Australia)) collects, uses and is responsible for certain personal information about you.
In the United Kingdom and across Europe, when we do so we are regulated under the Data Protection Act 2018 and General Data Protection Regulation and we are responsible as ‘controller’ of that personal information for the purposes of those laws.
In connection with personal data provided through your use of the Engagement Cloud platform and other services that we provide, we are a ‘processor’ for the purposes of the General Data Protection Regulation.
As some dotdigital affiliates are based outside of the European Economic Area, and these affiliates have appointed dotdigital EMEA Limited to be our representative within the EEA as necessary. Contact details are available
We also obtain personal information from your use of the Engagement Cloud platform. When you upload end-user data in the Engagement Cloud platform, we may have access to the data and content of your messages. We receive information about how you use the Engagement Cloud platform and store it in log files or other types of files associated to your account and link it to other information we hold about you. This information might include the date and date of any activity, your browser and IP address as well as actions you have taken within the Engagement Cloud platform. This information helps us to improve the Engagement Cloud platform for you for all users of the platform.
dotdigital may obtain information about you or end-users from third parties, such as public databases, social media platforms, third party data providers and our marketing partners. Examples of the information we may receive from other sources include device information (e.g. IP address and browser), location, behavioural data and demographic information. We may use this information, alone or in combination with other information described above, to develop or provide more relevant platform features or services (e.g. social media data of end-users allowing you to send more relevant content) or provide more relevant marketing and content to you.
dotdigital websites include social media features (either hosted by a third party or hosted directly on our website), which may collect information about your IP address and which page you are visiting. The feature may set a cookie to make sure the feature functions properly. We also maintain presences on social media platforms including Facebook, Twitter, and Instagram. Your interactions with these platforms are governed by the privacy policies of the companies that provide them. Anything you submit to dotdigital via a social media platform is done so at your own risk without any expectation of privacy.
Further, any comments or information you supply on any blog that dotdigital operates can be read, used or collected by anyone. If your information appears in our blog pages and you want it removed, contact our Marketing team: email@example.com.
We use and disclose personal information to:
- Supply, improve and support the services we provide (this includes using the data you provide to use the Engagement Cloud platform to contact end-users, aggregating information from your use of the platform or our website and sharing this with third parties to improve the services that we provide);
- Confirm your identity in using the Engagement Cloud platform;
- Send you information and promotional content (you can amend your marketing preferences in our preference centre or stop receiving messages by unsubscribing);
- Promote our services to you (e.g. when we collect your personal information on our website, we may contact you further to invite you to use our platform);
- Perform the obligations of our contract with you or applicable law (e.g. to enforce our terms, communicate with you and provide support);
- Protect, investigate and deter against fraudulent, harmful, unauthorized or illegal activity;
- Fulfil requests that you may make;
- Bill you (e.g. to send you invoices, process payment, notices). Note that we use third parties for secure credit card transaction processing, and we send billing information to those third parties to process your orders and credit card payments;
- Send notifications about the platform;
- Bring or defend legal proceedings, meet legal requirements (e.g. complying with court orders, enforcement actions, or other legally valid mechanisms) or respond to lawful requests by public authorities or law enforcement requests; and
- Provide information to our professional advisors.
When using the Engagement Cloud platform, you may import end-user or other personal information you have collected into our system. We have no direct relationship with your end-users or any person other than you, and for that reason, you are responsible for making sure you have the appropriate permission for dotdigital to collect and process information about those individuals.
Further to the uses described above, we may transfer personal information of you or your end-users to companies that help us promote, provide, or support our platform or other services that we provide. We may partner with and use various third party software and services, including analytics services, to help understand your usage of our products and services. In particular, we provide a limited amount of your information (such as your email address and sign-up date) to select third party services to collect data for analytics purposes when you visit our website or use our products and services. This allows dotdigital to monitor your use of our website, products and services and tracks our relationship so that we can improve our service to you. We may also use these third party services for communications, either through email, or through messages within our products and services. As part of our service agreements, these third party services may collect publicly available contact and social information related to you, such as your name, email address, gender, company, job title, photos, website URLs, social network handles and physical addresses, to enhance your user experience.
For details about how we engage third parties when we process your or end-user data when you use our platform and services, please see our terms & conditions, the standard form of which can be found at https://www.dotdigital.com/terms-of-service/.
In providing services to you, we will hold personal information for as long as are providing you the services for or in order to comply with our legal obligations, enforce the terms of our contracts, resolve disputes or prevent abuse. Otherwise, we only hold personal information for as long as is necessary.
In relation to clients, the lawful basis for which we rely on to collect and process your data is typically performance of our contractual obligations.
If you are not a dotdigital client, we rely on legitimate interest as the lawful basis on which we collect and use your personal data in relation to contacting you further in certain situations. Our legitimate interests are usually to provide individuals representing a business with details of our products or services through B2B direct marketing . If you are an individual, the basis on which we collect and use your personal data to contact you is often consent.
If you have any questions about the lawful basis on which we are processing your personal data, please contact firstname.lastname@example.org.
NOTE: The following is provided in accordance with the U.S. Department of Commerce statement available here. Despite being certified under the Privacy Shield Program, dotdigital does not rely on the Privacy Shield as a mechanism to comply with EU / Swiss data protection requirements when transferring personal data to the United States.
Data Protection Officer
No. 1 London Bridge
SE1 9BG London
Via email: email@example.com
dotdigital has further committed to refer unresolved Privacy Shield complaints to JAMS, an alternative dispute resolution provider located in the United States with offices in London (70 Fleet Street, London, EC4Y 1EU). If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please use the JAMS complaint form found here. The services of JAMS are provided at no cost to you. As the exclusive means of resolving through adversarial dispute resolution any disputes arising out of this Privacy Statement, a party may demand that any such dispute be resolved by arbitration administered by JAMS. Judgment on the award rendered in any such arbitration may be entered in any court having jurisdiction.
In certain situations, more fully set on the Privacy Shield website here, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
Please be aware that dotdigital is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). In addition, dotdigital is required to disclose personal information in response to lawful requests by public authorities, including to meet national security and/or law enforcement requirements.
For European residents, under the General Data Protection Regulation, you have a number of important rights free of charge. In summary, those include rights to:
- fair processing of information and transparency over how we use your use personal information
- access to your personal information and to certain other supplementary information that this Privacy Notice is already designed to address
- require us to correct any mistakes in your information which we hold
- require the erasure of personal information concerning you in certain situations
- receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- object at any time to processing of personal information concerning you for direct marketing
- object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
- object in certain other situations to our continued processing of your personal information
- otherwise restrict our processing of your personal information in certain circumstances
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals rights under the General Data Protection Regulation.
If you would like to exercise any of those rights, please:
- email, call or write to our Data Protection Officer
- let us have enough information to identify you,
- let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill), and
- let us know the information to which your request relates, including any account or reference numbers, if you have them
If you would like to unsubscribe from any email newsletter you can also click on the ‘unsubscribe’ button at the bottom of the email. It may take up to 24 hours for this to take place.
- request information, including a list of the categories of Personal Information (e.g. name, email, and mailing address, and the type of services provided to the customer that a business has disclosed to third parties (including affiliates that are separate legal entities) during the immediately preceding calendar year for the third-parties’ direct marketing purposes, from businesses with whom you have an established business relationship, & the names and addresses of all such third parties.;
- portability of such information and receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- require the erasure of personal information concerning you in certain situations; and
We have appropriate security measures in place to prevent personal information from being accidentally lost, used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so
We hope that we can resolve any query or concern you raise about our use of your information.
For individuals in Europe, the General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at http://ico.org.uk/concerns or telephone at 0303 123 1113 or other channels as updated at https://ico.org.uk/global/contact-us.
This privacy notice was published on 18 August 2020.
We may change this privacy notice from time to time, when we do we will inform you via email.
Please contact our Data Protection Officer, Joseph Stoker, if you have any questions about this privacy notice or the information we hold about you.
If you wish to contact our Data Protection Officer please send an email to firstname.lastname@example.org, write to Data Protection Officer, dotdigital EMEA Limited, No.1 London Bridge, London, SE1 9BG, United Kingdom or call +44(0)20 3953 4518.