Our privacy policy

We’re committed to safeguarding your privacy.

This Privacy Policy explains how we treat your personal information when we process it as a data controller in the course of operating our business and website at utu.earth

Please do not submit anyone else’s personal information to us unless you have their express consent to do this.

Contacting us

If you have any questions, comments or requests regarding your personal information, please email privacy@datanauts.co.uk or get in touch via our contact us page.

We are Utu Earth Ltd (“Utu”, “us” or “we”) , a company incorporated in England and Wales under company number 12750191 with registered office at Sussex Innovation Centre, Science Park Square, Falmer, Brighton, England BN1 9SB.

What data do we collect?

We collect the following personal information:

  1. Information you provide directly to us:
    • When we communicate with each other (including your name, email address, telephone number and the content of our communications);
    • When you contract or negotiate with us in relation to our services (including your name, email address, postal address, telephone number, work position, transaction details, card details);
    • When you subscribe to email notifications or newsletters (including your name and email address); and
    • Other information that you choose to send to us.
  2. Data we derive through your use of our website
    • General user information about your computer and your visits (including your IP address, location, browser, operating system, referral source, length of visit and the pages you visit). This information can be facilitated by cookies (see our Cookies policy below);
    • Other information that may be generated when you use our website.

How we use your data and legal grounds

We will only use your personal information for the purposes set out in this Privacy Policy. The legal basis for using your personal information is that either we have a legitimate interest in doing so or we have your express consent. We use your data in these ways:

Legitimate interest:

  • To administer our business and our website
  • To provide requested information to you
  • To promote our services to you, subject to your privacy rights
  • To enable your use of services
  • To respond to technical support requests
  • To send invoices, reports, statements, payment reminders and collect payments from you
  • To send you email notifications or newsletters that you have specifically requested
  • To deal with any enquiries or complaints by or about your use of our website or services;
  • To understand how you (and others) are using our website and services, to help us improve and develop our services;
  • To monitor compliance with our contracts;
  • To keep our systems secure and prevent fraud;
  • To send you other necessary information about our services and our relationship;
  • To otherwise manage our relationship with you or comply with our contractual obligations;
    And:

Consent:

  • If you have expressly agreed, to contact you about new services, offers, events or news if you have subscribed to relevant mailing lists (you can unsubscribe at any time either by managing your account settings or by emailing privacy@datanauts.co.uk).

We do not:

  • Share your data with third parties for their own purposes

Who we share your personal information with

We may disclose your personal information to third parties (provided that they are bound by appropriate obligations to safeguard your information) as follows:

  • To our employees, officers, insurers, professional advisors and agents to the extent that it is reasonably necessary to do so for the above permitted purposes;
  • To our third party suppliers and subcontractors to help us provide our website and services to you and for other legitimate business reasons. These include:
    • Our hosting service providers (we use Hetzner.net and Tagadab)
    • our third party subcontractors and service providers involved in the development, maintenance, backup, storage, financial administration and other integrated services as required in order to provide our website and services to you;
    • anonymous usage data to 3rd party services to assist us in providing continuity. These include, but are not limited to Google Analytics;
  • If we are required to do so by law or in any legal proceedings;
  • If we need to for fraud prevention or to protect the rights, property or safety of us, our customers or others.
  • To third parties wishing to purchase our business or assets.

Where your information is hosted

Our main hosting data centres are located at locations within the EEA.

We have an international customer base. We may need to transfer personal information between any of the countries we operate in and to our suppliers and subcontractors in other countries. We do not transfer any data to third counties or international organisations unless they are deemed by applicable law to have adequate privacy protection or recognised legal mechanisms are in place to ensure adequate protection of your information (e.g. EU Model Contract Clauses or EU-US Privacy Shield or Swiss-US Privacy Shield frameworks).

We will provide current details of our sub-processors and their locations on request.

How your data is kept secure

We work hard to protect our systems and our users from unauthorised access to or unauthorised alteration, disclosure or destruction of information we hold. In particular:

  • We regularly review our information collection, storage and processing practices, including physical security measures, to guard against unauthorized access to systems
  • We restrict access to personal information to our employees, contractors and agents on a need-to-know basis and ensure they are subject to contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations.

How long your information will be held

We will endeavour not keep your personal information for longer than necessary to facilitate your use of our website and services.

We may need to retain certain information for reasonable business purposes (e.g. accounts information, unsubscribe records, information needed to prevent identity theft, legal disputes and misconduct) even if deletion of the data has been requested;

If we are required to retain information by law or in relation to pending or prospective legal proceedings.

Cookies

We use cookies when you browse our site. Cookies are small files which transfer to your hard disk. They can inform us of the pages you visit, and your preferences, which enable us to provide you with a better online experience.

You can set your browser to refuse cookies, or to warn you before accepting them.

Most parts of our site can be accessed even if your cookies are turned off, but you may find there are parts of the site which you cannot access if your cookies are turned off.

Your rights

You have several rights as a data subject as summarised below:

  • Access: You have the right to obtain confirmation as to whether your personal information is being processed by us and, if it is, to access your information and details of how we process it, as long as this does not adversely affect the rights and freedoms of others.
  • Rectification: We will rectify any errors in the personal information we hold on request.
  • Erasure: In addition to functionality that enables you to delete information, you may as us to erase your personal information from our systems in the following situations:
    • The information is no longer necessary in relation to the purpose for which it was collected;
    • You withdraw your consent on which the processing is based and where there is no other legal ground for the processing;
    • You object to the processing and there are no overriding legitimate grounds for the processing;
    • The information has been unlawfully processed;
    • The information has to be erased for compliance with a legal obligation to which we are subject.
  • Right to restrict processing: You have the right to restrict our processing on specified grounds.
  • Notification: Where you have asked us to rectify, erase or restrict processing of your information, we shall communicate the same to each recipient to whom your information has been disclosed, unless this proves impossible or involves disproportionate effort, in which case we shall let you know.
  • Data portability: You have the right in specific circumstances where processing is based on consent to receive your information in a structured, commonly used and machine-readable format and have the right to transmit the information to another controller without hindrance, provided that our processing is carried out by automated means.
  • Right to object: In certain circumstances you have the right to object to our processing of your information, including in relation to profiling, direct marketing or scientific or historical research purposes.
  • Automated individual decision making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you unless this is necessary for our contract, is authorised under applicable law or is based on your explicit consent.

How to exercise your rights

  • To exercise any of your other data subject rights, please email privacy@utu.earth or get in touch via our contact us page.
  • You may request a copy of information undergoing processing, subject to evidence of your identity (normally a certified copy of your passport plus an original copy of a utility bill showing your current address). The first copy shall be provided without charge, but reasonable administration fees shall be charged for additional or subsequent copies.
  • We shall respond to your requests without undue delay and in any event within one month unless we need to extend such period by up to two further months in specific circumstances.
  • Please note that if you delete or restrict your account or required information, this may prevent you from making full use of our services.

What happens if a data breach occurs

Whilst we endeavour to keep your personal information safe, we have an internal investigation procedure in case of data protection security breaches.

In the event of data theft, we may suspend access to our servers, emails and online systems and take other urgent steps to prevent further unauthorised access to information.

If we believe that our data has been compromised, we will report the issue to the Information Commissioner's Office (ICO).

We will notify you without delay if we believe a data breach is likely to result in a significant risk to your rights and freedoms. Any notification will describe in clear and plain language the nature of the personal data breach and contain all required information.

Utu as data processor

This Privacy Policy applies where we are deemed the ‘data controller’ of personal information i.e. where we exercise control over the data processing, decide what personal information to collect, how to process it and for what purposes. In some situations, we may be deemed under applicable law to be your ‘data processor’ e.g. under an Utu contract for services i.e. where we process and host personal information controlled by you, on your behalf. In those situations, our Data Processor Terms shall apply to our processing activities.

Changes

Our Privacy Policy may change from time to time. We will not reduce your rights under this Privacy Policy without your explicit consent. We will post any changes on this page and, if the changes are significant, we will provide a more prominent notice (including, for certain services, email notification of Privacy Policy changes).


Last updated: May 2018