Protecting & respecting your privacy
The Anvil Group Ltd (“We”) are committed to protecting and respecting your privacy.
For the purpose of the Data Protection Act 1998 (the Act), the data controller is The Anvil Group Ltd of Vicarage House, 58-60 Kensington Church Street, London W8 4DB.
Information we collect from you:
We will collect and process the following data about you:
Information you give us.
This is information about you that you give us by filling in forms on our site anvilgroup.com (our site) or by corresponding with us by phone, e-mail or otherwise. It includes information you provide when you register to use our site, subscribe to our service, login to one of our products, participate in discussion boards or other social media functions on our site, enter a competition, promotion or survey, and when you report a problem with our site. The information you voluntarily give us may include your name, address, e-mail address and phone number, financial and credit card information, personal description and photograph, travel details and passport.
Information we collect about you.
With regard to each of your visits to our site we will automatically collect the following information:
- technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform;
- information about your visit, including the full Uniform Resource Locators (URL), clickstream to, through and from our site (including date and time), products you viewed or searched for’ page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number.
Information we receive from other sources.
This is information we receive about you if you use any of the other websites we operate or the other services we provide. [In this case we will have informed you when we collected that data if we intend to share those data internally and combine it with data collected on this site. We will also have told you for what purpose we will share and combine your data]. We are working closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies). We will notify you when we receive information about you from them and the purposes for which we intend to use that information.
- Subscribers of our ETMS system will also automatically supply, full name, email address and travel details.
Uses made of the information
We use information held about you in the following ways:
Information you give to us.
We will use this information:
- to carry out our obligations arising from any contracts entered into between you and us and to provide you with the information, products and services that you request from us;
- to provide you with information about other goods and services we offer that are similar to those that you have already purchased or enquired about;
- to provide you, or permit selected third parties to provide you, with information about goods or services we feel may interest you. If you are an existing customer, we will only contact you by electronic means (e-mail or SMS) with information about goods and services similar to those which were the subject of a previous sale or negotiations of a sale to you. If you are a new customer, and where we permit selected third parties to use your data, we (or they) will contact you by electronic means only if you have consented to this. If you do not want us to use your data in this way, or to pass your details on to third parties for marketing purposes, please tick the relevant box situated on the form on which we collect your data (the [order form OR registration form]);
- to notify you about changes to our service;
- to ensure that content from our site is presented in the most effective manner for you and for your computer.
Information we collect about you.
We will use this information:
- to administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to improve our site to ensure that content is presented in the most effective manner for you and for your computer;
- to allow you to participate in interactive features of our service, when you choose to do so;
- as part of our efforts to keep our site safe and secure;
- to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you;
- to make suggestions and recommendations to you and other users of our site about goods or services that may interest you or them.
Information we receive from other sources.
We will combine this information with information you give to us and information we collect about you. We will use this information and the combined information for the purposes set out above (depending on the types of information we receive).
Disclosure of your information
You agree that we have the right to share your personal information with:
- Any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
- Selected third parties including:
- business partners, suppliers and sub-contractors for the performance of any contract we enter into with them or you;
- analytics and search engine providers that assist us in the improvement and optimisation of our site;
- credit reference agencies for the purpose of assessing your credit score where this is a condition of us entering into a contract with you.
We will disclose your personal information to third parties:
- In the event that we sell or buy any business or assets, in which case we will disclose your personal data to the prospective seller or buyer of such business or assets.
- If The Anvil Group Ltd or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
Where we will store your personal data
All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
You have the right to ask us not to process your personal data for marketing purposes. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at firstname.lastname@example.org.
Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
Access to information
The Act gives you the right to access information held about you. Your right of access can be exercised in accordance with the Act. Any access request will be subject to a fee of £10 to meet our costs in providing you with details of the information we hold about you.
Privacy Shield Policy
The Anvil Group Ltd recognizes that the EU has established strict protections regarding the handling of EU Personal Data, including requirements to provide adequate protection for EU Personal Data transferred outside of the EU. To provide adequate protection for certain EU Personal Data about [consumers/corporate customers/clients/suppliers/business partners/job applicants/employees] received in the US, The Anvil Group Ltd has elected to self-certify to the EU-US Privacy Shield Framework administered by the US Department of Commerce (“Privacy Shield”). The Anvil Group Ltd adheres to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement, and Liability.
For purposes of enforcing compliance with the Privacy Shield, The Anvil Group Ltd is subject to the investigatory and enforcement authority of the [US Federal Trade Commission. For more information about the Privacy Shield, see the US Department of Commerce’s Privacy Shield website located at: https://www.privacyshield.gov. To review The Anvil Group Ltd’s representation on the Privacy Shield list, see the US Department of Commerce’s Privacy Shield self-certification list located at: http://www.anvilgroup.com/privacy-policy/.
Personal data collection and use
When we collect sensitive EU Personal Data, we will obtain your opt-in consent where the Privacy Shield requires, including if we disclose your sensitive EU Personal Data to third parties, or before we use your sensitive EU Personal Data for a different purpose than we collected it for or than you later authorized. Unless such data is received via Passenger Named Recorded (PNR) which is governed by the agreement made between the EU and the USA (to legitimise and regulate the transfer of PNR from EU Airlines to the US Department of Homeland Security) is regarded as providing adequate protection for the rights of the data subjects whose personal data (in the form of PNR) is transferred. Arrangements also exist between the European Commission, Canada and Australia.
Data transfers to third parties
Third-Party Agents or Service Providers
Third-Party Data Controllers
Disclosures for National Security or Law Enforcement
Under certain circumstances, we may be required to disclose your EU Personal Data in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
The Anvil Group Ltd maintains reasonable and appropriate security measures to protect EU Personal Data from loss, misuse, unauthorized access, disclosure, alteration, or destruction in accordance with the Privacy Shield.
You may have the right to access the EU Personal Data that we hold about you and to request that we correct, amend, or delete it if it is inaccurate or processed in violation of the Privacy Shield. These access rights may not apply in some cases, including where providing access is unreasonably burdensome or expensive under the circumstances or where it would violate the rights of someone other than the individual requesting access. If you would like to request access to, correction, amendment, or deletion of your EU Personal Data, you can submit a written request to the contact information provided below. We may request specific information from you to confirm your identity. In some circumstances we may charge a reasonable fee for access to your information.
Questions or Complaints
You can direct any questions or complaints about the use or disclosure of your EU Personal Data to us at The Anvil Group Limited with any questions or concerns. We will investigate and attempt to resolve any complaints or disputes regarding the use or disclosure of your EU Personal Data within 45 days of receiving your complaint. For any unresolved complaints, we have agreed to cooperate with the EU data protection authorities. If you are unsatisfied with the resolution of your complaint, you may contact the EU data protection authorities for further information and assistance.
You may have the option to select binding arbitration for the resolution of your complaint under certain circumstances, provided you have taken the following steps: (1) raised your compliant directly with The Anvil Group Ltd and provided us the opportunity to resolve the issue; (2) made use of the independent dispute resolution mechanism identified above; and (3) raised the issue through the relevant data protection authority and allowed the US Department of Commerce an opportunity to resolve the complaint at no cost to you. For more information on binding arbitration, see US Department of Commerce’s Privacy Shield Framework: Annex I (Binding Arbitration).
If you have any questions about this Policy or would like to request access to your EU Personal Data, please contact us as follows: The Anvil Group Ltd, Vicarage House, 59-60 Kensington Church Street, London W8 4DB.
Changes To This Policy
We reserve the right to amend this Policy from time to time consistent with the Privacy Shield’s requirements.
Effective Date: 5 December 2016
Last modified: 5 December 2016
Scope of policy
Anvil mobile application software, including TripHub and SOS and Locate (App) are available on our sites OR hosted on iTunes, Google Play Store (App Site), once you have downloaded a copy of the App onto your mobile telephone or handheld device.
This policy sets out the basis on which any personal data We collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how We will treat it.
For the purpose of the Data Protection Act 1998, the data controller is the organisation who holds the agreement with The Anvil Group International Ltd.
Information we may collect from you
We may collect and process the following data about you:
Information you give us:
You may give us information about you by filling in forms on the App Site and the Services Sites (together Our Sites), or by corresponding with us (for example, by e-mail or chat). This includes information you provide when you register to use the App Site, download or register an App, subscribe to any of our Services, search for an App or Service, which will provide you with travel related information and when you report a problem with an App, our Services, or any of our Sites. The information you give us may include your name, e-mail address and phone number, the Device’s phone number, username and other registration information.
Information we collect about you and your device:
Each time you visit one of our Sites or use one of our Apps We may automatically collect the following information: technical information, including the type of mobile device you use, a unique device identifier (for example, your Device’s ID number, the MAC address of the Device’s wireless network interface, or the mobile phone number used by the Device), mobile network information, your mobile operating system, the type of mobile browser you use, time zone setting; information stored on your Device, including contact information, check ins, SOS and location information from GPS devices;
details of your use of any of our Apps or your visits to any of Our Sites including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise and the resources that you access Log Information).
We will also use GPS technology and triangulation to determine your current location. Some of our location-enabled Services require your personal data for the feature to work. If you wish to use the particular feature, you will be asked to consent to your data being used for this purpose. You can withdraw your consent at any time by switching off the appropriate services. If you contact us, We may keep a record of that correspondence.
Unique application numbers:
When you install or uninstall a Service containing a unique application number or when such a Service searches for automatic updates, that number and information about your installation, for example, the type of operating system, may be sent to us.
Uses made of the information
We use information held about you in the following ways:
Submitted Information: Data is held in an encrypted format on the device and is transmitted using a secure connection to an encrypted database.
Device information: To provide a method of authentication and tracking of devices.
Location information: Tracking the location of individuals so that they can be assisted in the event of an emergency.
We may associate any category of information with any other category of information and will treat the combined information as personal data in accordance with this policy for as long as it is combined.
We do not disclose information about identifiable individuals, but We may provide anonymous aggregate information about our users.
We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the Companies Act 2006.
We may disclose your personal information to third parties:
- In the event that We sell or buy any business or assets, in which case We may disclose your personal data to the prospective seller or buyer of such business or assets.
- If The Anvil Group International Ltd or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
- If We are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation or request.
In order to:
- protect the rights, property or safety of The Anvil Group International Ltd our customers, or others.
Where we store your personal data
All information you provide to us is stored on our secure servers and will be encrypted using Secured Sockets Layer technology where We have given you (or where you have chosen) a password that enables you to access certain parts of Our Sites, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although We will do our best to protect your personal data, We cannot guarantee the security of your data transmitted to Our Sites; any transmission is at your own risk. Once We have received your information, We will use strict procedures and security features to try to prevent unauthorised access.
We may collect and store personal data on your Device using application data caches and browser web storage (including HTML 5) and other technology.
Access to information
The Data Protection Act 1998 gives you the right to access information held about you. Your right of access can be exercised in accordance with that Act. Any access request may be subject to a fee to meet our costs in providing you with details of the information We hold about you.
Terms of supply specific to USA consumers
Anvil offers various text message programs to their subscribers which are delivered via the short code 50561 for US numbers. This data is for personal safety and information alerting purposes. In the main the subscribers will be corporates who elect that their employees receive Anvil data via SMS.
Recipients of SMS information should raise any queries with their employers if the SMS information is unwarranted.
Charges may apply through your mobile carrier, you approve any such charges from your mobile carrier. Charges for text messages may appear on your mobile phone bill or be deducted from your prepaid balance. Concerns should be raised through your employer for any such charges. If your employer is not a client of Anvil’s or you are not employed, please email email@example.com and we will ensure your number is removed from our systems.
United States Participating Carriers Include
ACS/Alaska, Alltel, AT&T, Bluegrass Cellular, Boost, Cellcom, Cellone Nation, Cellular One of East Central Illinois, Cellular South, Centennial, Chariton Valley Cellular, Cox Communications, Cricket, EKN/Appalachian Wireless, Element Mobile, GCI, Golden State Cellular, Illinois Valley Cellular, Immix/Keystone Wireless, Inland Cellular, iWireless, MetroPCS®, Nex-Tech Wireless, nTelos, Plateau Wireless, South Canaan, Sprint, T-Mobile®, Thumb Cellular, United Wireless, US Cellular®, Verizon Wireless, Viaero Wireless, Virgin, WCC Additional carriers may be added. T-Mobile® is not liable for delayed or undelivered messages.