Privacy Policy

This privacy policy sets out how Wallsend Guest House uses and protects any personal data that you give to us. 
Wallsend Guest House is committed to ensuring that your privacy is protected and we will take the necessary steps to ensure that personal information is safeguarded and kept in accordance with the law and any applicable regulations.

About us

Wallsend Guest House can be contacted by Email: 
bandb@wallsend.net 
Telephone: 01697351055 
Post at: Wallsend Guest House, Church Lane, Bowness on Solway, Carlisle CA7 5AF
Where we manage personal data, we identify as a Data Controller and recognise and act on our obligations under applicable data protection laws..

The person responsible for Data Protection is Andy Lewis
What data do we collect?

Information that you provide to us is retained and processed in accordance with UK data protection legislation.

Types of personal information collected

name and job title
contact information including email address
demographic information such as postcode, preferences and interests
other information relevant to customer surveys and/or offers

Sources of personal information collected


Reviews: We track users’ activity in relation to the Reviews. If you wish to post a comment on the review, you will be asked to give your name and email address. Email addresses do not appear publicly.

Contact: We use a contact form to collect your name, email and phone number as well as your message, so that we can contact you and provide details of our services to you, provide support and deal with general company enquiries. Data is held on the grounds of being legitimate to our business interests.

Emails: We retain copies of emails sent to us on our servers which are hosted on Office 365 in the Cloud. For details of how your data is handled by this third party you should refer to their Privacy Policy at www.privacy.microsoft.com. Your personal information will be held by us in accordance with this Privacy Policy. 

Phone calls: Phone calls to us may be recorded and any data relating to the call may be retained by us. The data will be held on the basis of being for our legitimate business needs or in order to fulfil our contractual obligations if you are a client of ours. 

Social media: We use social media to engage with users and the Wallsend Guest House website links to our Facebook, Twitter. We do not keep any specific data that identifies you as an individual user, but hold details of our followers on these platforms. You should refer to the Privacy Policies of these channels to understand how they treat your data in relation to linking to our site.
If you send us a direct message via social media, the details may be retained by us only as relevant to any ongoing contract or to further our legitimate business interests or as required for legal purposes. The third party provider may also retain details in accordance with their Privacy Policy. 

Testimonials/Feedback: We may contact you for a testimonial in relation to our services that may be used on our website or social media. Your comments may be added to our testimonial page on www.wallsend.net including your full name and location.
Payment

Wallsend Guest House do not record personal bank details or hold identifying information on an individual’s banking transactions.

Where payments are made by debit or credit card, we are obliged to adhere to the Payment Card Industry Data Security Standard (PCI-DSS) which outlines a number of specific technical and organisational measures that must be followed when data is being processed.
Children
We do not market our services at those under 18 years old. Consistent with the GDPR we will never knowingly request personally identifiable information from anyone under the age of 16 years old.

Information we get from other sources

From time to time, we may need to obtain information from third parties about you. This will only apply where it is necessary to provide our services and as permitted by law.  

How we use your personal information

Your information will be used by us to enable us to provide our services to you. We act as a Data Controller (see below) of your information and undertake to protect your personal and sensitive data in a manner that is consistent with the requirements of the General Data Protection Regulation (GDPR). We will take reasonable measures to ensure the secure storage of your data. 


Personal data will be used for the purposes specified in this Privacy Policy, to include the following:
administer the website;
internal record keeping;
improve your browsing experience by personalising the website;
follow up with email enquires;
send you general (non-marketing) communications;
send you email notifications which you have specifically requested;
send to you marketing communications, where expressly agreed;
provide third parties with statistical information about our users - but this information will not be used to identify any individual user;
ask for feedback and reviews or to conduct market research;
improve the products or services that we offer;
deal with enquiries and complaints made by or about you relating to the website.

Disclosure

We don’t share, sell, or distribute your data to third parties, except as contractually agreed with you or as provided in this Privacy Policy.

We may disclose your personal information if we are required to do so by law, in connection with any legal proceedings, and in order to establish, exercise or defend our legal rights, or if otherwise legally permitted.

Data Processors

We may use Data Processors who act on our instruction in relation to the management of your data and they must adhere to all data protection laws and regulations. We will ensure that any Data Processors used only operate on our written instructions and comply with their obligations under the GDPR.
You will be informed of any other Data Controllers who have access to your data and who may determine processing activities separately to us, or as a Joint Data Controller.  

The following 3rd parties are used by us to provide our services and website functionality. Under data protection legislation, these are categorised as Data Processors:
Our website is hosted by Angelfish
We use ESET for antispam services.

Marketing

We will only send you emails about our services, i.e. direct marketing, with your express consent. You have the option not to give consent or to withdraw consent at any time. You may withdraw your consent for us to contact you by contacting us at bandb@wallsend.net
Non-personally identifiable visitor information may be provided to third parties for marketing, advertising or other uses.

External links

Users of the Wallsend Guest House website are advised to adopt a policy of caution before clicking on any external web links. Clicking an external link will take the user away from our website. Once you leave our website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s terms and conditions.
Wallsend Guest House cannot guarantee or verify the contents of any externally linked website and users click on external links at their own risk. Wallsend Guest House and its owners cannot be held liable for any damages or implications caused by visiting any external links mentioned.

Social media platforms

Communication, engagement and actions taken through external social media platforms that we participate on are subject to our terms and conditions as well as the privacy policies held with each social media platform respectively.

Users are advised to use social media platforms wisely and communicate and/or engage with them with due care and caution in regard to their own privacy and personal details.

Wallsend Guest House uses social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised that before using such social sharing buttons, that they do so at their own discretion, and should consider that the social media platform may track and save requests to share a web page, through the users’ social media platform account.

Retaining your data

We keep your personal information in accordance with our Data Retention Policy which reflects our needs to provide services to you as contracted and also as required to meet legal, statutory and regulatory obligations. The need to hold information is regularly reviewed and information/data will be disposed of when no longer required.

Data Security and Storage

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
Any information that you supply to us may be stored and processed at our office premises and on servers used for 3rd party processing Your data may be transferred in accordance with the relevant data protection laws.

Data Subject Rights

Subject Access Requests
The GDPR gives data subjects the right to access personal data held by a company by making a subject access request (SAR). We will endeavour to respond quickly to any such 
requests, which legally require us to respond within one month of receiving the request and necessary information. 
To make a SAR request email us at bandb@wallsend.net

Right to Rectification
Data subjects have the right to request that we amend or change personal information that we hold about you, that is inaccurate or incorrect.

Right to erasure
Data subjects have the right to ask us to delete personal information from our systems without giving any reason and at any time. We will act on any request without delay.

Right to restrict processing
Data subjects have the right to rectification or erasure of personal data in the following circumstances:
Personal data is not accurate;
The processing of data is unlawful - data subjects may request that processing is restricted;
Data is required to exercise legal rights or defend legal claims;
Data is unlawful but there may be lawful grounds for processing, which override this right. 

Right to data portability
Data subjects have the right to obtain and transfer their data to different service providers.

Right to object
Data subjects have the right to object to the processing of data at any time based on their particular situation. This includes objecting to profiling unless it is in the ‘public interest’ or exercised lawfully by an official authority. We will only process data under lawful grounds.

Right not to be subject to decisions based on automated processing
We do not use any automated processing that results in any automated decision based on a data subject’s personal information.

Using your rights
If you wish to invoke any of these rights, you should contact the person responsible for data protection by emailing us at bandb@wallsend.net

Data Breaches

We will report any unlawful breach of data as required by the GDPR within 72 hours of the breach occurring, if it is considered that there is an actual, or possibility, that data within our control including the control of our data processors, has been compromised. If the breach is classified as ‘high risk’ we will notify all data subjects concerned using an appropriate means of communication. We will report any relevant breaches to the ICO, see below.

Important Information

Questions and queries
If you have any concerns about how we handle your data, you can contact us by email to bandb@wallsend.net

Changes to this policy
We reserve the right to change our Privacy Policy at any time. Please refer to our website for the most up-to-date version.

Complaints
If you wish to raise a concern about the use of your data, you can contact us by email to bandb@wallsend.net

Alternatively, you can formally raise a concern or complaint to the Information Commissioner’s Office (ICO) directly on 0303 123 1113, or see the options for reporting issues on https://ico.org.uk/concerns/