Privacy Policy
At NIS, we are 100% committed to protecting the privacy and security of our clients, customers and site visitors. We understand the trust you place in our business when you provide us with personal information. Our Privacy Policy sets out our privacy promise to you. We do not share your data with third parties for them to market their products/services to you. If you have any questions about how we Protect Your Privacy, please contact us at hello@norwichis.com
When you interact with us through our website (or otherwise) you may provide, or we may collect, certain information from which you are personally identifiable (which is referred to as personal data). For the purposes of the General Data Protection Regulation or “GDPR” (and all other laws relating to the use your personal data), we are the “data controller”, meaning that we are responsible for deciding how your personal data is used and more importantly, for keeping your data safe and only using it for legitimate reasons.
We are committed to protecting your privacy and will take all steps necessary to comply with our legal obligations when using your personal data. This Privacy Policy explains how we fulfil this commitment, so please read this carefully.
WHAT THIS POLICY TELLS YOU
1. What types of personal data you provide to us (or which we collect from you) when using our website or when you directly interact with us on other occasions;
2. How and why we use this data and the reasons we are legally allowed to do so;
3. Who we share your data with;
4. Your rights over your data and how you can exercise those rights; and
5. How to contact us if you have any issues or want to find out more.
WHAT INFORMATION DO WE COLLECT AND WHAT DO WE USE IT FOR?
You may provide us with the following types of personal information when you register with Swiss500 or otherwise when you directly interact with us (when using our website or otherwise):
- Identity - first name, surname, NIS log-in information (password), country of residence
- Contact - email address, telephone numbers and address
- Financial - payment card details, billing address, purchase information, payment history
- Profile - your preferences for marketing, other website preferences and feedback on your NIS experiences through reviews and surveys
- Social - if you choose to open a Swiss500 account using your Facebook, Twitter or Google account, we will use your contact information used for the relevant account to help populate your Swiss 500 registration page
We may collect the following types of information from you when you use our website (using cookies or other tracking technologies):
- Usage - information about how you use our website, including time spent on page, click-through s', download errors
- Technical - IP address, browser type, hardware type, network and software identifiers, device information, operating system and system configuration
The table below sets out how we use your personal data and our lawful basis for doing so. We may process your personal data for more than one lawful basis depending on the specific purpose for which we are using it. Importantly, we will only use your personal data when the law allows us to.
Reason why we use the data |
What data |
Legal ground for using the data |
Register you as a NIS customer |
Identity, Contact, Profile, Social |
Performance of a contract with you |
Enable you to log-in to your NIS account |
Identity, Contact, Social |
Performance of a contract with you |
|
||
To process payments which you make through our website |
Identity, Contact, Financial |
Performance of a contract with you |
For internal administration and record keeping purposes |
All |
Performance of a contract with you Necessary to comply with a legal obligation Necessary for our legitimate interests (for effective business administration and service provision)
|
Notify you of changes to our Privacy Policy, our Terms and Conditions or other changes to our services or products |
Identity, Contact |
Performance of a contract with you Necessary to comply with a legal obligation
|
Answer your enquiries which may involve contacting you by post, e-mail or phone |
Identity, Contact |
Performance of a contract with you Necessary for our legitimate interests (to ensure our customers are informed and satisfied with our services)
|
Get in touch with you about relevant Swiss500 competitions, products and services |
Identity, Contact, Profile |
Necessary for our legitimate interests (to develop our business, including our competitions, products and services) Consent
|
Contact you about third party products and services which we believe may be relevant to you or pass your details on to third parties to contact you directly about the same (in each case, only where you have indicated you would like to hear about these) |
Identity, Contact, Profile |
Consent |
Improve and personalise your experience of the NIS website by delivering more relevant content and advertising whilst you browse |
Identity, Contact, Profile, Usage, Technical |
Necessary for our legitimate interests (to develop our business, improve our website and overall user experience and inform our marketing strategy)
|
Administer the Swiss 500 website, including website trouble shooting, testing and analysis and to enable you to participate in interactive features of our website |
All |
Performance of a contract with you Necessary for our legitimate interests (to ensure that our website is fully functional and operating in the most effective way for you)
|
Verify your identity and detect fraud and security issues |
All |
Necessary for our legitimate interests (to prevent and detect fraudulent activity, security incidents and criminal activity)
|
Give you the opportunity to provide us with feedback through reviews and surveys |
Identity, Contact, Profile, Usage, Technical |
Necessary for our legitimate interests (to develop our business, promote new products and services, obtain feedback from customers to improve our services)
|
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
In addition to the above, we may also anonymise and aggregate your personal data in a way which means you cannot be identified. This may be helpful to us for testing our internal systems, carrying out research and general customer data analysis. Because this is not personally identifiable, we can use this for any purposes.
WHO DO WE SHARE YOUR DATA WITH?
Importantly, we do not pass your personal data onto any third parties for them to market their products/services to you. If in the future we decide that we want to, we will only do so if we have your consent.
We do however share your personal data with third parties to help us deliver our products and services to you in the most effective way possible. These include third parties who assist us with:
- Delivering relevant NIS email and text marketing (to the extent you have not unsubscribed)
- Our customer reviews and surveys
- Personalising the content on our website to ensure a tailored user experience
- Delivering relevant targeted and re-targeted advertising to keep you up to date with our services
- Detecting fraud or criminal activity
- Creating your Swiss500 account (being your social media companies who you have used to provide log-in information as part of the sign-up process)
- Running our competitions, such as our auditors, judges, professional advisers
- Other aspects of our service delivery, such as hosting our website and processing customer payments
If we share personal data with third parties, we will ensure that access is limited on a strictly need to know basis and is subject to suitable obligations relating to confidentiality and security. Please note that certain of these third party service providers use cookies or other tracking technologies, which are explained more fully in our cookies policy.
In addition to the above, we may also be required to share your personal data with third parties if required by law or regulation. In such circumstances, we will make sure that the disclosure is only to the extent required by law or regulation.
DO WE SEND ANY OF YOUR DATA OUTSIDE OF THE EEA?
The European Economic Area or “EEA” is deemed to have good standards when it comes to data privacy. As such, we consciously limit the occasions when we may need to transfer or handle your data outside of the EEA. Where we do, for example where our service providers are based outside of the EEA, we make sure that your data is still treated fairly and lawfully in all respects (including making sure we have a legal ground for sending your data outside the EEA and putting in place all necessary safeguards for such arrangement).
Where relevant, you will have the right to see a copy of any safeguards we put in place for international transfers of your data. Just get in touch with us if you would like to find out more.