Privacy Policy

At THRASS (UK) LIMITED data protection is important to us and, for a good number of years now, we have been committed to ensuring that your privacy is protected. Mindful of the changes in law from 25 May 2018, relating to the application of the General Data Protection Regulation (GDPR), we have updated our Privacy Policy. Essentially, the regulation aims to protect all EU citizens from privacy and data breaches and gives citizens greater transparency and control of their data.

Who we are

THRASS (UK) LIMITED is an international publishing and training company. The Director is Alan Davies. The Company Secretary is Hilary Davies.  The company address is THRASS (UK) LIMITED, The Willows, 18 Long Lane, Upton, Chester,  England, CH2 2PD. Tel. +44 (0)1244 323079 Email. office@thrass.co.uk Company Number: 3532730. VAT Number: 709 8429 04. Our registered office is at Atkinson Accounts, Egerton House, 55 Hoole Road, Chester, England, CH2 3NJ.

Our Data Controller is Alan Davies. Our Data Processor is Hilary Davies. At THRASS (UK) LIMITED, only Alan Davies and Hilary Davies have access to your data.

Our history on data protection

Since May 2005, THRASS (UK) LIMITED has completed registration documents, annually, as a ‘Data Controller’ with the Information Commissioners Office (ICO).

Since May 2009, THRASS (UK) LIMITED has completed registration documents, annually, to be ‘PCI DSS compliant’ (Payment Card Industry Data Security Standard compliant) with SecurityMetrics (Barclaycard’s accredited partner).

Since December 2012, we have had a ‘Secure eCommerce Shopping Cart’, hosted on the www.englishphonicschart.com website. The shopping cart is overseen by EKM (their registered offices are EKM Systems Ltd, Caxton Road, Fulwood, Preston, PR2 9ZB. UK). Currently, in 2018, EKM is the UK’s most popular eCommerce provider. The shopping cart uses 256-bit encryption technology to keep data (including payment data) secure and protected and the website has an ‘SSL Certificate’ - a security certificate which displays a padlock in the address bar. The EKM servers are protected by hardware firewalls to ensure that each customer’s data is kept secure at all times. Our customer data is stored on the EKM servers. The servers are housed within a secure data centre in Manchester which is ISO27001 and PCI-compliant, and has BS5979 security on-site.

Aim and updates

This privacy policy sets out how THRASS (UK) LIMITED uses and protects any information that you give us, through using the website www.englishphonicschart.com (to obtain English Spelling Chart Resources and/or English Spelling Chart Workshop training) and through contacting us by phone, email or post.

THRASS (UK) LIMITED may change this policy from time to time by updating this Privacy Policy page. You should check this page from time to time to ensure that you are happy with any changes.

Lawful basis for processing

Our ‘Lawful basis for processing’ your personal data is related to ‘Contract’, that is, to fulfil our contractual obligations to provide a quote, supply educational resources and/or supply training.


What data we collect

• Contact information including name, address, postcode, email address and telephone number.
• Order details, including product quantities, costs, tax/es and shipping details.

Payment details, including card numbers, are handled by PayPal, not by THRASS (UK) LIMITED.

What we do with the data we gather

• Process your order and obtain payment (to comply with our contractual obligations).
• Help us identify your previous orders.
• Keep records - to administer accounts and keep track of bills and payments.
• Improve our products and services, largely through statistical analysis.
• Periodically send emails about new products and special offers using the email address you provided
(when GDPR-compliant consent was given).
• Review, develop and improve the website and services.
• Notify you about changes to our website and services using the email address you provided.
• Provide customer care, including if you contact us with a query;
• When required, to help detect fraud, money laundering etc and to confirm that the data is correct.

Security

We are committed to ensuring that your data is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable managerial, physical and electronic procedures to secure and safeguard the data we collect.

How we use cookies

A cookie is a small file placed on your computer's hard drive. The cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences. We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system. A cookie does not give us access to your computer or any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can modify your browser setting to decline cookies.

Links to other websites

Our website contains links to other websites (such as You Tube). However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy policy. You should exercise caution and look at the privacy policy applicable to the website in question.

Controlling your personal information

• We will not sell, distribute or lease your personal data to third parties.
• You may request details of the data which we have about you. If you would like a copy of this data, please write to Alan Davies, Data Controller, THRASS (UK) LIMITED (or email him using
alandavies@thrass.co.uk), so that he can arrange a copy to be sent to you (within one month).
• If you believe that any of your data is incorrect or incomplete, please write to Alan Davies, Data Controller, THRASS (UK) LIMITED (or email him using
alandavies@thrass.co.uk), so that he can make the necessary changes.

Retention period

We will keep your personal data for as long as you are a customer of THRASS (UK) LIMITED. After you notify us that you no longer wish to be a customer, we will delete your data from our customer database but we will need to keep your data on our secure internal system for up to seven years. By law, we are not allowed to delete your data before this time in case there are any accountancy, VAT and/or legal queries.

Q: When can the organisation say no?
A: When the organisation is legally obliged to keep hold of your data.

Data Breaches

In the event of a data breach, we shall ensure that our obligations under applicable data protection laws are complied with where necessary. We will inform you within one month of the breach.

Contact us about this privacy policy

If you have any comments or questions about this privacy policy, please email Alan Davies, Data Controller, THRASS (UK) LIMITED using alandavies@thrass.co.uk.

Report a concern

If you have a concern about our handling of your personal data, please contact us. If you think the concern is serious and we are not able to rectify the concern, you can contact the Information Commissioner’s Office by using the link https://ico.org.uk/concerns/


The GDPR features an expansion of individual rights

• Right to be forgotten: An individual can request that all personal data is removed without delay.
• Right to object: An individual can prohibit personal data being processed in certain ways.
• Right to rectification: An individual can request incorrect personal data to be corrected.
• Right of access: An individual has the right to know what the personal data is and how it is processed.
• Right of portability: An individual can request that personal data be transported between organisations.
• Right to fair and transparent processing: An individual has the right to know about the data processing.

Privacy Policy, updated 24 May 2018, THRASS (UK) LIMITED, Chester, England. CH2 2PD. UK

 
 In PayPal, select ‘Check Out as a Guest’ to use a card