- Privacy
Privacy Policy

Contents
- Summary
- Our details
- Information we collect when you visit our website
- Information we collect when you contact us
- Information we collect when you interact with our website
- Information we collect when you place an order on our website
- Our use of automated decision-making and profiling
- How we collect or obtain information about you from third parties
- Disclosure and additional uses of your information
- How long we retain your information
- How we secure your information
- Transfers of your information outside the European Economic Area
- Your rights in relation to your information
- Your right to object to the processing of your information for certain purposes
- Sensitive Personal Information
- Changes to our Privacy Policy
- Children’s Privacy
- California Do Not Track Disclosures
- Copyright, credit and logo
Summary
This section summarises how we obtain, store and use information about you. It is intended to provide a very general overview only. It is not complete in and of itself and it must be read in conjunction with the corresponding full sections of this Privacy Policy.
- Data controller: John Penna
- How we collect or obtain information about you:
- when you provide it to us (e.g. by contacting us )
- from your use of our website, using cookies and similar technologies and occasionally
- from third parties
- Information we collect:
- Name;
- Address;
- Email address;
- Telephone number;
- Business name;
- Job title;
- Profession;
- Payment information;
- IP Address;
- Cookie information;
- Browser information
- How we use your information: for administrative and business purposes (particularly to contact you, to improve our business and website, to fulfil our contractual obligations, to analyse the use of our website and in connection with our legal rights and obligations
- Disclosure of your information to third parties: only to the extent necessary to run our business , to our service providers, to fulfil any contracts with you, where required by law or to enforce our legal rights
- Do we sell your information to third parties (other than in the course of a business sale or purchase or similar event): No
- How long we retain your information: for no longer than necessary, taking into account any legal obligations we have (e.g. to maintain records for tax purposes), any other legal basis we have for using your information (e.g. your consent, performance of a contract with you or our legitimate interests as a business) For specific retention periods in relation to certain information which we collect from you, please see the main section below entitled How long we retain your information.
- How we secure your information: using appropriate technical and organisational measures such as storing your information on secure server, encrypting transfers of data to or from our servers using Secure Sockets Layer (SSL) technology, encrypting payments you make on or via our website using Secure Sockets Layer (SSL) technology, only granting access to your information where necessary and additional security measures you use to protect personal information such as encryption of personal data, encrypted email, pseudonymisation and/or anonymisation of personal information].
- Use of cookies and similar technologies: We do not use cookies on our website
- Transfers of your information outside the European Economic Area: We will only transfer your information outside the European Economic Area if we are required to do so by law OR in certain circumstances we transfer your information outside of the European Economic Area. Where we do so, we will ensure appropriate safeguards are in place, including safeguards used for data transfers outside the European Economic Area e.g. the third parties we use who transfer your information outside the European Economic Area have self-certified themselves as compliant with the EU-U.S. Privacy Shield.
- Use of automated decision making and profiling: We do not use automated decision making / profiling.
- Your rights in relation to your information
- – to access your information and to receive information about its
- use
- – to have your information corrected and/or completed
– to have your information deleted
– to restrict the use of your information
– to receive your information in a portable format
– to object to the use of your information
– to withdraw your consent to the use of your information
– not to have significant decisions made about you based solely on automated processing of your information, including profiling
– to complain to a supervisory authority
- Sensitive personal information: we do not knowingly or intentionally collect what is commonly referred to as ‘sensitive personal information’. Please do not submit sensitive personal information about you to us. For more information, please see the main section below entitled Sensitive Personal Information.
Our details
Please contact the data controller using the following details (for the attention of John Penna):
Email address: support@carnviewassociates.co.uk
Postal Address: 16 Trevingey Close , Redruth,Cornwall TR15 3BX
Information we collect when you visit our website
We collect and use information from website visitors in accordance with this section and the section entitled
Disclosure and additional uses of your information.
Web server log information
We use a third party server to host our website. Our website server automatically logs the IP address you use to access our website as well as other information about your visit such as the pages accessed, information requested, the date and time of the request, the source of your access to our website (e.g. the website or URL (link) which referred you to our website), and your browser version and operating system and insert any additional information your website’s server about an individual’s visit to your website.
Use of website server log information for IT security purposes
We and our third party hosting provider collect(s) and store(s) server logs to ensure network and IT security and so that the server and website remain uncompromised. This includes analysing log files to help identify and prevent unauthorised access to our network, the distribution of malicious code, denial of services attacks and other cyber attacks, by detecting unusual or suspicious activity.
Unless we are investigating suspicious or potential criminal activity, We do not make, nor do we allow our hosting provider to make, any attempt to identify you from the information collected via server logs.
Legal basis for processing: compliance with a legal obligation to which we are subject (Article 6(1)(c) of the General Data Protection Regulation).
Legal obligation: we have a legal obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of our processing of information about individuals. Recording access to our website using server log files is such a measure.
Legal basis for processing: our and a third parties legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).
Legitimate interests: we and our third party hosting provider have a legitimate interest in using your information for the purposes of ensuring network and information security.
Use of website server log information to analyse website use and improve our website
We use the information collected by our website server logs to analyse how our website users interact with our website and its features. For example, we analyse the number of visits and unique visitors we receive, the time and date of the visit, the location of the visit and the operating system and browser used and insert any additional information collected by your website server log files.
We use the information gathered from the analysis of this information to improve our website. For example, we use the information gathered to change the information, content and structure of our website and individual pages based according to what users are engaging most with and the duration of time spent on particular pages on our website.
Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).
Legitimate interest: improving our website for our website users and getting to know our website users’ preferences so our website can better meet their needs and desires.
Cookies and similar technologies
We use cookies or similar technologies on our website.
Heat maps – these are visual representations of how website visitors have interacted with web pages, for example how far down the page they get and what links they interact with. This is aggregated data from thousands of page views, and cannot be used to identify individuals;
Session Recordings – Hotjar records information such as mouse movements and clicks and displays these as session recordings that our web team can watch back. These recordings are anonymous and cannot be linked to any individuals. They’re used to help us better understand what issues our website visitors are facing and what we can do to improve the site experience for them.
Cookies are data files which are sent from a website to a browser to record information about users for various purposes.
You can reject some or all of the cookies we use on or via our website by changing your browser settings but doing so can impair your ability to use our website or some or all of its features. For further information about cookies, including how to change your browser settings, please visit www.allaboutcookies.org or see our cookies policy.
Information we collect when you contact us
We collect and use information from individuals who contact us in accordance with this section and the section entitled Disclosure and additional uses of your information.
When you send an email to the email address displayed on our website we collect your email address and any other information you provide in that email (such as your name, telephone number and the information contained in any signature block in your email).
Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).
Legitimate interest(s): responding to enquiries and messages we receive and keeping records of correspondence.
Legal basis for processing: necessary to perform a contract or to take steps at your request to enter into a contract (Article 6(1)(b) of the General Data Protection Regulation).
Reason why necessary to perform a contract: where your message relates to us providing you with goods or services or taking steps at your request prior to providing you with our goods and services (for example, providing you with information about such goods and services), we will process your information in order to do so).
Transfer and storage of your information
We use a third party email provider to store emails you send us.
Our third party email provider is fastmail located in Australia. Their privacy policy is available here: https://www.fastmail.com/about/privacy/
Emails you send us will be stored outside the European Economic Area on our third party email provider’s servers in Australia. For further information please see the section of this privacy policy entitled Transfers of your information outside the European Economic Area.
Contact form
When you contact us using our contact form, we collect
- Name;
- Address;
- Email address;
- Telephone number;
- Business name;
- IP Address;
- Cookie information;
- Text information
If you do not provide the mandatory information required by our contact form, you will not be able to submit the contact form and we will not receive your enquiry.
Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).
Legitimate interest(s): responding to enquiries and messages we receive and keeping records of correspondence.
Legal basis for processing: necessary to perform a contract or to take steps at your request to enter into a contract (Article 6(1)(b) of the General Data Protection Regulation).
Reason why necessary to perform a contract: where your message relates to us providing you with goods or services or taking steps at your request prior to providing you with our goods and services (for example, providing you with information about such goods and services), we will process your information in order to do so).
Transfer and storage of your information
Messages you send us via our contact form will be stored outside the European Economic Area on our third party email provider’s servers in Australia. Our third party email is Fastmail. Their privacy policy is available here: https://www.fastmail.com/about/privacy/
For further information about the safeguards used when your information is transferred outside the European Economic Area, see the section of this privacy policy below entitled Transfers of your information outside the European Economic Area.
For further information about the safeguards used when your information is transferred outside the European Economic Area, see the section of this privacy policy below entitled Transfers of your information outside the European Economic Area.
Phone
When you contact us by phone, we do not record phone calls.
Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation)
Legitimate interest(s): responding to enquiries and messages we receive and keeping records of correspondence.
Legal basis for processing: necessary to perform a contract or to take steps at your request to enter into a contract (Article 6(1)(b) of the General Data Protection Regulation).
Reason why necessary to perform a contract: where your message relates to us providing you with goods or services or taking steps at your request prior to providing you with our goods and services (for example, providing you with information about such goods and services), we will process your information in order to do so).
Transfer and storage of your information
Information about your call, such as your phone number and the date and time of your call, is processed by our third party telephone service provider Telefónica UK Limited
Post
If you contact us by post, we will collect any information you provide to us in any postal communications you send us.
Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation)
Legitimate interest(s): responding to enquiries and messages we receive and keeping records of correspondence.
Legal basis for processing: necessary to perform a contract or to take steps at your request to enter into a contract (Article 6(1)(b) of the General Data Protection Regulation).
Reason why necessary to perform a contract: where your message relates to us providing you with goods or services or taking steps at your request prior to providing you with our goods and services (for example, providing you with information about such goods and services), we will process your information in order to do so).
Information we collect when you interact with our website
We collect and use information from individuals who interact with particular features of our website in accordance with this section and the section entitled Disclosure and additional uses of your information.
E-Newsletter
When you sign up for our e-newsletter on our website or opt to receive news, offers from us by signing up to receive your e-newsletter on your website e.g. by entering their name and email address and clicking subscribe or ticking a box at checkout indicating that they would like to receive your e-newsletter, we collect name information you collect from a user when they sign up for your e-newsletter e.g. name and email address
Legal basis for processing: your consent (Article 6(1)(a) of the General Data Protection Regulation).
Consent: you give your consent to us sending you our e-newsletter by signing up to receive it using the steps described above.
Transfer and storage of your information
We use a third party service to send out our e-newsletter and administer our mailing list, MailChimp and Dotmailer. Their privacy policy is available here:
https://mailchimp.com/legal/privacy/
https://dotdigital.com/terms/data-processing-agreement/
Registering on our website
When you register and create an account on our website, we collect the following information:
- Name;
- Address;
- Email address;
- Telephone number;
- Business name;
- IP Address;
- Cookie information;
- Text information
If you do not provide the mandatory information required by the registration form, you will not be able to register or create an account on our website.
Legal basis for processing: necessary to perform a contract or to take steps at your request prior to entering into a contract(Article 6(1)(b) of the General Data Protection Regulation).
Reason why necessary to perform a contract: creating an account on our website is necessary to allow you to access the goods and services you have purchased from us
Transfer and storage of your information
Information you submit to us via the registration form on our website will be stored outside the European Economic Area on our third party hosting provider’s servers in Australia. Our third party hosting provider is Fastmail. Their privacy policy is available here: https://www.fastmail.com/about/privacy/
Your information will be transferred and stored outside the European Economic Area (EEA) in the circumstances set out below. We will also transfer your information outside the EEA or to an international organisation in order to comply with legal obligations to which we are subject (compliance