1.0 OUR CORE BELIEFS REGARDING USER PRIVACY AND DATA PROTECTION
- User privacy and data protection are human rights
- We have a duty of care to the people within our data
- Data is a liability, it should only be collected and processed when absolutely necessary
- We loathe spam as much as you do!
- We will never sell, rent or otherwise distribute or make public information that is personally identifiable to you
2.0 RELEVANT LEGISLATION
Along with our business and internal systems, the SmartExpat website is designed to comply with the following national and international legislation with regards to data protection and user privacy:
This site’s compliance with the above legislation, all of which are stringent in nature, means that this site is likely compliant with the data protection and user privacy legislation set out by many other countries and territories as well.
If you are unsure about whether SmartExpat is compliant with your own country of residences’ specific data protection and user privacy legislation you should contact our data protection officer (details of whom can be found in section 12.0) for clarification.
3.0 PERSONAL INFORMATION COLLECTION, STORAGE, USAGE AND ERASURE
3.1 Your email address
Should you register as a member of SmartExpat, we will first ask you for your email address and a password. The email address that you submit will also be stored within this website’s own back end systems and our CRM platform, Salesforce. We consider Salesforce to be a third party data processor (see section 6.0 below).
Your email address could then be used to contact you in three ways based on the preferences you have stated on your profile and your user activity.
- We will pass your email address into our Campaign Monitor account, which provides us with email marketing services for our newsletters and partner mailings. We consider Campaign Monitor to be a third party data processor (see section 6.0 below).
- We use Mandrill and Amazon SES to send automated messages to members based on their behaviour. For example, when you first register on the site you will automatically receive a welcome email from us. We consider Mandrill and Amazon SES to be a third party data processor (see section 6.0 below).
- If you have a business account with SmartExpat, you may receive occasional relevant emails from us based on your unique record in Salesforce, using an integration of Salesforce called Pardot. We consider Pardot to be a third party data processor (see section 6.0 below).
These third parties do not have rights to use your email address for any other purposes other than those described above to allow SmartExpat to perform marketing, member management and sales operations. Your email address will never be shared with any other third parties.
You MUST be over 16 years of age to register as a member of SmartExpat.
3.2 Publicly available profile information
Should you register as a member and fill out your public profile, the information you provide such as nationality, current home town and interests will be available for other people to see on your profile page. We store this information in our website’s systems to allow us to tailor website content, including advertising, and marketing emails to you - according the selections you have made on your profile page – to make SmartExpat more useful to you. You cannot be personally identifiable by third parties from this information and we will never share your personal information with third parties.
3.3 Private profile information
Should you register as a member and fill out your private profile, the information you provide such as birth date, employment status and email preferences will be stored in our website’s systems and Salesforce to allow us to tailor website content, including advertising, and marketing emails to you - according the selections you have made on your profile page – to make SmartExpat more useful to you. We will never share your personal information with third parties.
3.4 Member to member messages, forum comments, blog posts and advertising
Should you choose to contribute to SmartExpat in any of these ways you will first need to register as a member.
Your contribution and its associated personal data will remain on this site and stored in our website’s systems until we see fit to remove it. Should you wish to remove anything yourself you can do so yourself via your profile page, or contact us at firstname.lastname@example.org.
Member to member messaging is a private exchange to another member or within a defined group using our in house chat system and a service called Pusher. Your messages are only available to your recipients and to SmartExpat and they will never be shared unless we are compelled to disclose them to law enforcement or Government officials. We consider Pusher to be a third-party data processor (see section 6.0 below).
You should avoid entering personally identifiable information on any public contributions you submit to this website.
3.5 Contact forms and email links
Should you choose to contact us or a 3rd party using a contact form on the website the data will be collated and stored in our website's systems and sent to the intended recipient over the Simple Mail Transfer Protocol (SMTP). We may us Mandril or SES to send these messages (see section 6.0 below).
If you email a SmartExpat employee directly, your email will be stored securely in SmartExpat’s GSuite account. We consider Google to be a third party data processor (see section 6.0 below).
If you contact our customer service team or our data protection officer your message will be stored and managed in Salesforce. We consider SalesForce to be a third party data processor (see section 6.0 below).
Your details will remain within the systems referenced above for as long as we continue to use their services or until you specifically request removal from our records.
You can unsubscribe from SmartExpat emails using the unsubscribe links contained in any email that we send you or by contacting us at email@example.com. When requesting removal via email, please send your email to us using the email account that is subscribed to the mailing list.
You can delete your profile and its associated data at any time via your profile page or by emailing firstname.lastname@example.org and this will also remove personal information from our storage systems referenced above. Your contributions made to the website may remain visible (see 3.4)
Please note that your right to erasure is superseded by our requirement to retain payment and invoicing information for a minimum of 6 years as described above, and by any requirement to comply with government or law enforcement officials and to protect the property and rights of SmartExpat/Angloinfo Limited or a third party in preventing or stopping any illegal, unethical or legally actionable activity or to comply with the law in any other way.
4.0 USER TRACKING AND RE-TARGETING
4.2 Server logs
We will record in our server logs the device IP address (and potentially the IP address of any proxy or gateway devices) you use when you access our website, send us email or when you interact with our services online. We do this to comply with government or law enforcement and to protect the property and rights of SmartExpat or a third party in preventing or stopping any illegal, unethical or legally actionable activity or to comply with the law in any other way.
5.0 ABOUT SMARTEXPAT’s OWN SYSTEMS
5.1 Amazon Web Services
6.0 OUR THIRD PARTY DATA PROCESSORS
We use a number of third parties to process personal data on our behalf. These third parties have been carefully chosen and all of them comply with the legislation set out in section 2.0. All third parties based in the USA are EU-U.S Privacy Shield compliant.
|Amazon AWS||See here|
|Campaign Monitor||See here|
7.0 INTERNAL DATA POLICY
8.0 LINKS TO OTHER WEBSITES
Our site contains links to other websites. A link is not an endorsement of that third party website and you use any third party sites at your own risk. SmartExpat encourages you to read the privacy statements of the other websites you visit to become informed of their practices and policies.
9.0 DATA BREACHES
We will report any unlawful data breach of this website’s database or the database(s) of any of our third party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.
In the UK, data breaches are to initially be reported to the Information Commissioner’s Office.
10.0 COMPLIANCE WITH LAWS AND LAW ENFORCEMENT
SmartExpat cooperates with government and law enforcement officials. We reserve the right to share any information we have about you with government or law enforcement officials. The decision to share this information will be at the sole discretion of SmartExpat to protect the property and rights of SmartExpat or a third party the personal safety of any person to prevent or stop any illegal unethical or legally actionable activity or to comply with the law in any other way.
11.0 DATA CONTROLLER
The data controller of this website is: Angloinfo Limited, a UK Private Limited Company with company number 05311692, whose registered office and operating office is:
12.0 DATA PROTECTION ENQUIRIES
Tel: +44 (0)1491 836 394
14.0 CHANGE LOG