Privacy Policy
Hello, thanks for reading our Data Policy.
We want you to know that we take your privacy and the security of the data we hold about you and your customers very seriously and we are committed to doing everything we can in order to protect it. Also, to let you know what we are doing with it, how we manage it and why.
Our Data Policy aims to ensure we have complete transparency across DestinationCore and the companies and brands which fall within it. Our policy covers:
- The collection of data
- Usage of data including processing and what we believe to be both Operational purposes and Legitimate Interest
- Management of our Data Policy, who is accountable and how often we review and update our processes, and how we will keep you informed about updates
- How we will store your data, for how long and how we will protect it
- How you can access your data, update it and request to be removed or restricted from any data processing
- How we transfer data within the UK, EU and Overseas, including working with our US based office
- And finally, what the procedure is if there has been a potential data security breach
Our Data Policy has been written to ensure compliance with all applicable laws including the Data Protection Act 1998, ePrivacy 2002, superseded by the General Data Protection Act 2018 (these are collectively referred to as "data protection laws").
Our Policy covers all and any information we collect, data provided by you or provided by one of our clients about their customers which may also include you. We do not accept any responsibility for data which you have provided to us that has been processed by a third party outside of our agreed contracted supplier list. Nor do we accept any responsibility for data you provide to another company (outside of DestinationCore) which we may link to through our website, white papers, reports or other collateral and documentation.
DestinationCore Inc specifically complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union to the United States. DestinationCore Inc has certified to the U.S. Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.
Who Are DestinationCore?
DestinationCore is a specialist creative business services agency and consultancy delivering Data, Technology and Creative projects for companies and brands. We carry out marketing communications, including data processing and management services for a range of clients across all sectors globally.
When we refer to "we" or "our" or "DestinationCore" we are referring to Decipher Innovation Ltd (Trading as DestinationCore) and its parent companies.
1. What data will DestinationCore collect?
When you or a company you have signed up to chooses to work with DestinationCore, we will typically collect data on you both directly, through forms, and indirectly through platforms such as, but not limited to, Facebook, Twitter, LinkedIn as well as through third parties such as, but not limited to, CACI, Experian and approved data warehouses.
The data we are likely to collect will include, but is not limited to:
- First and Surname
- Date of birth
- Email address
- Address, including postcode
- Phone and mobile number
- Job title and seniority
- Company information including firmographics
- Sector information
- Social identifiers
- Preference data – provided by you at the point of sign up
- Cookie and behavioural data – based on web and email activity
- Sales data – including order details and value, transaction date and method
- Marketing Opt-in data
- Email communications responses
- History – full audit trail of data usage for compliance requirements
If we hold data, or are asked to process data for a child under 13, we will hold additional data including but not limited to:
- Parent or Guardian name and contact information
- Parental or Guardian consent for marketing communications
DestinationCore also collects information about how you use our website, as well as how you use any website or mobile app we have built for a client, or when a client is using our SEO, PPC, Online Advertising, Email Marketing, Web Analytics or other Data Services.
We are committed to the principles of the data regulations and therefore we will only collect and process data which is collected in a lawful and transparent way, and where the company who collected the data can provide sufficient evidence of the method of collection.
2. How will DestinationCore use the data it collects or is provided by clients?
In line with the data regulations we will only use the data we collect or are provided by our clients in a lawful way for legitimate and specific purposes. We will use your personal information for a number of purposes including the following:
Provision of consultancy and marketing services
- To provide our services to our clients in line with our contract or Master Services Agreement we have in place
- To provide you with the most user-friendly online navigation experience for our website or those we are building for our clients
- Where we, or our client, are providing personalised services, we may analyse the information you supply, as well as your activity on our (and other) services, so that we can offer a more relevant, tailored service
- We will use your data to target relevant advertising on third party sites and platforms
- We will use IP addresses and device identifiers to identify the location of users, to block disruptive use, to establish the number of visits from different countries, and to determine whether you are accessing the services from the UK or not
- For analysis and research purposes so that we may improve the services offered by DestinationCore or our client, which can include using geo-demographic information from external sources
- We may also use and disclose information in anonymised format (so that no individuals are identified) for marketing and strategic development purposes as well as data analysis and reporting purposes
- For direct marketing purposes including (but not limited to), email, mobile, web, post and telemarketing. We may also share your data with email service providers, internet service providers, call centres, printers and mailing houses in order to provide this service to you and our client
We will only use third parties who we have audited to ensure they are fully compliant with the data protection regulations and have sufficient processes and policies in place to protect your data and personal information.
We will also only use data for marketing purposes where there is evidence of a valid opt-in consent to say that you have freely given and indicated you wish to receive such communications.
Operational purposes
In order for our business to operate we will use data we collect for DestinationCore clients and supplier companies in the following ways:
- For Financial and Accounting purposes, including but not limited to, quoting, raising purchase orders, sending statements, discussing payments and invoicing
- For credit checking purposes
- For contractual purposes
- For Human Resource purposes
- For potential Mergers and Acquisition purchases
As a past, current or prospective client
We consider the following use of your data to be considered "Legitimate Interest" and illustrates ways in which we will use data to provide and enhance our services to you as a client of DestinationCore.
- Contacting you by telephone, mobile, email or post in order to discuss past, current or future projects and opportunities for you to utilise our services
- Sending to you via email or post, invitations to events, company and services updates, seasonal communications and access to reports and white papers we have produced
- Connecting with you via LinkedIn and Inmail
- Connecting with you via social and sharing platforms, with your acceptance
- Sending files to you via email and file sharing platforms
- Access to your web analytics
- Tracking your IP address for web and email analytics
- Logging your online behaviour via cookies and web analytics
- Lead scoring information based on data provided by you and behavioural data
3. How DestinationCore manages its Data Policy
Reviewing our policies
We want to keep your data as secure as we can so we will regularly review our processes and policies. We will review and update our policy at least every 12 months and when data regulations are updated.
Keeping you informed and up to date
We want you to know your data is in safe hands, so we will email you to let you know that we are currently storing data and personal information about you if we collect it indirectly.
We will also email you when we update our policy, providing you with a link to view the updated policy on our website.
4. How DestinationCore stores and accesses data
Data we store on behalf of our clients
We will hold data provided to us by clients for processing for as long as required to complete the service, or as long as is set out in our contract or Master Service Agreement. Unless specifically requested by our client we will hold data for a maximum of 12 months after the service we provided is complete.
Data will be stored in a number of secure environments. All environments are tested and audited to ensure compliance and high levels of security and protection.
Data is only accessible by authorised employees and all access rights are managed and monitored centrally via secure log in and password.
5. How can you access or update your data?
We want to make it easy for you to be in control of your data. You have the right to:
- Access the data we hold on you
- Ensure the data we have is accurate and up to date
- Object to us using your data within automated processing or profiling
- Restrict how we process/use your data
- Request the erasure or deletion of the data we hold on you
To exercise any of these rights, please contact us at info@destinationcore.com.
6. Reporting a potential data breach
If we suspect a data breach of any kind we will report it to the Information Commissioner's Office immediately.
If you suspect a data breach, which you believe may have involved DestinationCore and the data we hold on you, please email info@destinationcore.com with the subject "Data Breach" and we will respond within 72 hours.
7. How to contact us
Any questions around our privacy or Data Subject Access Requests:
Email: info@destinationcore.com
The Supervisory Authority for the UK is the Information Commissioner's Office. They can be contacted at: ico.org.uk