PRIVACY POLICY / EU GDPR COMPLIANCE
General Data Protection Regulation (GDPR) Compliance
The EU General Data Protection Regulation (GDPR) effective from May 2018 gives all EU citizens more rights and protections for their personal data, to minimise the possibility of theft and fraud.
These regulations include provisions for the following areas:
​
• The right to be informed: Companies must publish a privacy notice, in addition to explaining transparently how they use this personal data.
• The right of access: Individuals will have the right to demand details of any of their data that a company may hold. This information must be provided within one month of request at no charge to the individual.
• The right to rectification: If a person’s data is incorrect or incomplete, he or she has the right to have it corrected. If the company that holds the information has passed any of that information to third parties. The company must inform the third party of the correction and inform the person which third parties have their personal data.
• The right to be forgotten: A person may request the removal of his or her personal data in specific circumstances.
• The right to restrict processing: Under certain circumstances, an individual can block the processing of his or her personal data.
• The right to data portability: A person can access their data for their own use anywhere they prefer.
• The right to object: A person can object to the use of their personal data for most purposes.
​​​
​
​
faithsintune.org Privacy & GDPR Policy​
1.0 Our core principles regarding user privacy and data protection
-
User privacy and data protection are inviolable human rights
-
We have a duty of care to people contained within our data
-
Data is a liability: it should only be collected and processed when absolutely necessary
-
We despise spam in all its forms
-
We will never sell, rent or otherwise distribute or make public any personal information
2.0 Relevant Legislation
This faithsintune.org website is designed to comply with the following national and international legislation with regards to data protection and user privacy:
​
3.0 Personal information that this website collects and why we collect it
This website collects and uses personal information only for the following reasons and through the following mechanisms:
3.1 Site visitation tracking
Like most websites, this site uses Google Analytics (GA) to track user interaction. For your information our website uses the Wix implementation of GA.
We use this data to determine the number of people using our site, to better understand how they find and use our web pages and to track their journey through the website. Although GA records data such as your approximate geographical location, device, internet browser and operating system, none of this information personally identifies you to us. GA also records your computer’s IP address which could be used to personally identify you but Google do not grant us access to this. We consider Google to be a third party data processor (see section 5.0 below). GA makes use of cookies, details of which can be found on Google’s developer guides.
​
Disabling cookies on your internet browser will stop GA from tracking any part of your visit to pages within this website.
​​
​3.2 Email links
Should you choose to contact us using an email link, none of the data that you supply will be stored by this website or passed to/be processed only by any of the third party data processors defined in section 5.0 below.
Instead the data will be collated into an email and sent to us over the Simple Mail Transfer Protocol (SMTP). Our SMTP servers are protected by TLS (sometimes known as SSL) meaning that the email content is encrypted using SHA-2, 256-bit cryptography before being sent across the internet. The email content is then decrypted by our local computers and devices.
​
​3.3 Contact forms
Should you choose to contact us using the contact form on our Contact us page the email address that you submit to us will be stored in our Wix website platform in the 'Contacts' database, which we use contacting you. We consider Wix to be a third party data processor (see section 5.0 below). The email address that you submit will be stored within this website’s own database but not in any of our internal computer systems.
Your email address will remain within the Wix 'Contacts' database on our website for as long as we continue to use the Wix platform or until you specifically request removal from the list.
You can do this by unsubscribing using the unsubscribe links contained in any email newsletters that we send you or by requesting removal via email. When requesting removal via email, please send your email to us using the email account that you used on the contact us form, and please note that the removal may take up to 4 weeks. When requesting removal using an unsubscribe link in our email newsletter, removal should take effect within one working day.
3.4 Email newsletter
If you choose to join our regular newsletter mailings (which is sent via email), the email address that you submit to us will be stored in our Wix website platform in the 'Shout Out' database, which we use for our email marketing. We consider Wix to be a third party data processor (see section 6.0 below). The email address that you submit will be stored within this website’s own database but not in any of our internal computer systems.
Your email address will remain within the Wix 'Shout Out' database on our website for as long as we continue to use the Wix platform for email marketing or until you specifically request removal from the list.
​
You can do this by unsubscribing using the unsubscribe links contained in any email newsletters that we send you or by requesting removal via email. When requesting removal via email, please send your email to us using the email account that is subscribed to the mailing list, and please note that the removal may take up to 4 weeks. When requesting removal using an unsubscribe link in our email newsletter, removal should take effect within one working day.
​
Should you somehow have erroneously been added to our Wix 'Shout Out' database in the past, please accept our apologies and feel free to unsubscribe following the aforementioned procedure.
If you are under 16 years of age you MUST obtain parental consent before joining our email newsletter.
While your email address remains within the Wix 'Shout Out' database, you will receive occasional newsletter-style emails from us.
4.0 About this website’s server
This website is hosted in Wix data centers in the United States and Europe. The Wix.com platform complies with the EU-US Privacy Shield Framework and the Swiss-US privacy shield framework as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of personal information transferred from the European Union to the United States, and therefore adheres to the Privacy Shield Principles. Wix.com guarantees that the platform will be compliant with the new regulation from May 2018.
All traffic (transferral of files) between this website and your browser is encrypted and delivered over HTTPS.
5.0 Our third party data processors
We at faithsintune.org don't process or store any personal data.
We use three third parties to process personal data on our behalf. The third parties we use are Wix, Eventbrite and Paypal.
Wix is a content management platform we use to host our website. Wix ensures data protection in the following ways:
-
Wix employ full-time security consultants, dedicated to the security of our customer information.
-
Wix is Payment Card Industry Data Security Standards (PCI DSS) compliant and is accredited as a level 1 service provider and merchant. This standard helps create a secure environment by increasing cardholder data, thus reducing credit card fraud. Wix regularly perform internal security audits to maintain our ISO/PCI security certifications, as illustrated below (please click the links to see the Certificates):
-
Wix's signup and login services are completed through a secure server (HTTPS/SSL).
-
Wix uses cryptography hash functions to protect your information. Your password is stored as a hash digest and, in the event of a security breach, your original password cannot be recovered from ours or Wix servers.
-
Wix is certified under the EU-US Privacy Shield Framework and the Swiss-US privacy Shield Framework as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States, and therefore adheres to the Privacy Shield Principles.
Eventbrite is an event platform we use to manage attendance and allow registrations and ticketing for our events and festivals. In the process of registering for one of our events, you may be asked to enter personal data that will help us identify you for ticketing and event admission purposes or contact you about the event if necessary. This data will be stored on the Eventbrite platform.
​
You may also be asked to enter additional statistical information (such as age, gender, affiliation) or personal feedback through Eventbrite registration forms that will help us better understand our audience and evaluate and improve our offer based on audience needs. This information will only ever be collected on a voluntary basis and never be obligatory in order to register for any of our events. This statistical information will be stored on the Eventbrite platform and evaluated by us only anonymously, meaning that we will only ever retrieve statistical information about our audience separate from and non-relatable to personal data such as their name or contact details.
​
If you have made a purchase or donation using an Eventbrite link or form through this website, any financial information is not stored or used by us as all Eventbrite transactions are made within the PayPal platform which does not retain any financial information once the transaction has been processed.
​
Paypal process payments for any donations made through our website or products purchased from our website. Neither us or PayPal retain any financial information you may submit as part of the purchasing process. PayPal monitor every transaction, 24/7 to prevent fraud, email phishing and identity theft. Every transaction is heavily guarded behind PayPal's advanced encryption. If something appears suspicious, their dedicated team of security specialists will identify suspicious activity and help protect you from fraudulent transactions.
​
Your data as mentioned below is encrypted before transmission to prevent misuse of the transmitted data by third parties. SSL (Secure Socket Layer) is a security technology which guarantees that your personal data, including credit card information, login data and payment method, are securely transferred via the Internet. The data is encrypted so that is only readable by the PayPal payment system.
Your data which is encrypted, is as follows:
-
personal data (address data, telephone number, etc.)
-
login data (username and password)
-
all methods of payment selected, credit card and bank account
​
​
Wix, Eventbrite and PayPal have been carefully chosen and all of them comply with the legislation set out in section 2.0.
Three of the following third parties are based in the USA and one is based in the Republic of Ireland and all are EU-US Privacy Shield compliant.
​
-
Wix (privacy policy)
-
Eventbrite (privacy policy)
-
PayPal (privacy policy)
-
Google (privacy policy)
6.0 Data breaches
We will report any unlawful data breach of this website’s database or the database(s) of any of our third party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.
​
7.0 Social Media Platforms
​
Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are custom to the terms and conditions as well as the privacy policies held with each social media platform respectively.
​
Users are advised to use social media platforms wisely and communicate / engage upon them with due care and caution in regard to their own privacy and personal details. This website nor its owners will ever ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.
This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.
8.0 Shortened Links On Social Media
​
This website and its owners through their social media platform accounts may share web links to relevant web pages. By default some social media platforms shorten lengthy urls (web addresses).
​
Users are advised to take caution and good judgement before clicking any shortened urls published on social media platforms by this website and its owners. Despite the best efforts to ensure only genuine urls are published many social media platforms are prone to spam and hacking and therefore this website and its owners cannot be held liable for any damages or implications caused by visiting any shortened links.
​
9.0 Links To Other Websites
Our website may contain links to other websites run by other organisations. This privacy policy applies only to our website‚ so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website.
In addition, if you linked to our website from a third party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and recommend that you check the policy of that third party site.
10.0 16 And Under
​
We are concerned to protect the privacy of children aged 16 or under. If you are aged 16 or under‚ please get your parent/guardian's permission beforehand whenever you provide us with personal information.
11.0 Transferring Your Information Outside of Europe
As part of the services offered to you through this website, the information which you provide to us may be transferred to countries outside the European Union (“EU”). By way of example, this may happen if any of our servers are from time to time located in a country outside of the EU. These countries may not have similar data protection laws to the UK. By submitting your personal data, you’re agreeing to this transfer, storing or processing. If we transfer your information outside of the EU in this way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this Policy.
If you use our services while you are outside the EU, your information may be transferred outside the EU in order to provide you with those services.
​
12.0 Changes to our privacy policy
​
We keep this Policy under regular review. This Policy was last updated in May 2018.
​
This privacy policy may change from time to time inline with legislation or industry developments. We will not explicitly inform our clients or website users of these changes.
Instead, we recommend that you check this page occasionally for any policy changes. Specific policy changes and updates are mentioned in the change log below.
​
Policies updated
22/05/2018
​