Processing details
Categories of Data
- Identity Data such as names, usernames or similar; marital status; title; date of birth; sex and gender.
- Contact Data such as addresses; email addresses and telephone numbers.
- Financial Data such as bank account and payment card information.
- Technical Data such as IP addresses; login data; browser info; time zone; location; browser plug-ins; operating systems; platforms and other technology on the device used to access this website.
- Transaction Data such as information about payments and details of purchases you have made.
- Usage Data such as analytics relating to how you use the website.
- Profile Data such as usernames; passwords; security answers; purchases/orders; interests; preferences; feedback and responses to surveys, blogs and messages.
- Marketing and Communications Data such as your preferences about receiving communications from us or third parties.
Special Categories of Data
We may collect certain health information. This is upon request by you to ensure any necessary safety precautions can be taken.
Categories of Data Subjects
Clients, customers, suppliers, partners, employees
Locations of Processing Operations
London, UK France
Purposes
To provide Our Services to You.
Duration
For the duration of the Agreement.
2. Obligations and rights of the Data Controller
2.1 As set out above.
3. Approved International Transfers and Sub-Processors
3.1 The Data Controller agrees that the Data Processor may engage the following Sub-Processors:
Name | Processing Activity | Country | Identify the legal basis for transfer of Personal Data (see Note 1) |
---|---|---|---|
OVH | Data backup | Otto | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. OVH may transfer data in accordance with their own Data Protection Agreement found here: https://www.ovh.co.uk/support/contracts/ |
Immoviewer | 3D Imagery- referrals | Germany | c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. |
1&1 IONOS Ltd | Hosting | UK | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. 1&1 IONOS may also use suppliers and transfer data in accordance with their own Data Protection Agreement found here: https://www.ionos.co.uk/terms-gtc/terms-and-conditions/ |
BananaTag | Email Tracking | Canada | a) Located in a country with a current determination of adequacy. |
Docusign | Electronic Document Signatures | US | Ether a) Located in a country with a current determination of adequacy. or b) Binding Corporate Rules. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. Docusign may transfer data in accordance with their own Data Protection Agreement found here: https://www.docusign.com/company/terms-and-conditions/schedule-docusign-signature/attachment-data-protection |
EaziyPay | Payment processor | UK | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. EaziyPay may transfer data in accordance with their own Privacy Terms found here: https://www.eazipay.co.uk/privacy-policy |
Heart Internet | Hosting | UK | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. Heart Internet may transfer data in accordance with their own Privacy Terms found here: https://www.heartinternet.uk/terms/heart-internet-privacy-statement |
iOmart | Hosting | UK | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. iOmart may transfer data in accordance with their own Privacy Terms found here:https://www.iomart.com/privacy-policy/ |
MailChimp | Email Marketing | US | c) Standard Contractual Clauses between Discloser as “data exporter” and Recipient as “data importer”. Mailchimp may transfer data in accordance with their own Data Processing Addendum found here: https://mailchimp.com/legal/data-processing-addendum/#6._International_Transfers |
Giacom | Office 365 Services | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. Giacom may transfer data in accordance with their own Privacy Terms found here: https://cloudmarket.com/about/privacy-policy |
|
Moneypenny | Telephone answering services + webchat | UK | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. Moneypenny may transfer data in accordance with their own terms and conditions found here:https://www.moneypenny.com/uk/terms-and-conditions/ |
My Management Company | Marketing Services- broadcast emails | UK | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. My Management Company may transfer data in accordance with their own terms and conditions found here: https://www.mymanagementcompany.co.uk/terms-and-conditions |
Reality Finance | Business Finance Solutions- referrals | UK | Ether
a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. Reality Finance may transfer data in accordance with their own Privacy Terms found here:https://www.realityfinance.com/company-information/privacy-policy |
UK Reg | Domain Management | UK | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. UK Reg may transfer data in accordance with their own Privacy Terms found here:https://www.fasthosts.co.uk/terms/policies/privacy-notice |
UX Pin | Project Management | US | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. UX Pin may transfer data in accordance with their own Privacy Terms found here: https://www.uxpin.com/privacy |
Vertical Leap | Search Engine Optimisation | US | Ether a) Located in a country with a current determination of adequacy. or c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. Vertical Leap may transfer data in accordance with their own Privacy Terms found here: |
WP Engine | Hosting | US | c) Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”. WP Engine may transfer data in accordance with their own Privacy Terms found here: https://wpengine.com/legal/privacy/ https://wpengine.com/legal/dpa/ |
Note 1: Identify the legal basis for transfer Personal Data outside the Approved Countries in order to comply with international transfer restrictions:
- a. Located in a country with a current determination of adequacy.
- b. Binding Corporate Rules.
- c. Standard Contractual Clauses between Discloser as “data exporter” and Recipient as “data importer”.
- d. Standard Contractual Clauses between Recipient as “data exporter” on behalf of Discloser and Recipients affiliate or subcontractor as “data importer”.
4. Security Measures
4.1 Physical access controls: we use keys, and CCTV for premises where personal data is kept.
4.2 System access controls: we use encryption and password controls including two factor authentications.
4.3 Data access controls: Client data is stored in database systems which are username, password and 2 Factor authentication protected.
4.4 Transmission controls: Email services are protected by 2 Factor Authentication. Form contents from web sites are protected by SSL Encryption.
4.5 Data backups: Backups are retained off-site from the operational repositories in username and password protected environments and stored in data dump format.
4.6 Input controls: Data can only be input and manipulated by use of standardised, secure processes and personnel using username and password, including Yubikey logging.
4.7 Data segregation: Client personal data, our clients’ own client personal data that we process for our clients and The Property Jungle’s personal data that we are Controller of are all stored separately in physically different locations and technically different systems.