The South Devon Railway Trust is committed to protecting your privacy in relation to the information we hold about you in line with the requirements of the General Data Protection Regulation (“GDPR”). For the purposes of GDPR we are the Data Controller and can be contacted by post at Buckfastleigh Station, Dartbridge Road, Buckfastleigh, TQ11 0DZ or by email.
References to “our website” are to www.southdevonrailway.co.uk.
Your details will only be made available to other organisations operating under the South Devon Railway name to include: South Devon Railway plc, South Devon Railway Engineering (SDRE) and other South Devon Railway organisations which may be introduced from time to time.
What information we may collect
We collect from you your personal details which we need to process any transaction we enter into with you. This may include your name, address, postcode, email address, telephone number and relevant correspondence. Where you have agreed to receive email updates on products and offers we may record information you have given us on your preferences.
How your data is held and processed
Your personal details are stored on a secure computer system. Any paper documents you have completed and any correspondence are held in a secure environment. We process your data only to contact you on products and matters of interest relating to the South Devon Railway.
Legal basis for processing
We hold and process your data principally on the basis that we have obtained your positive consent. In some circumstances where consent has not been provided we may rely on the South Devon Railway having a legitimate interest in processing your information.
How we use your information
If you have purchased a product or service from us we will provide an after sales service which may include passing your details to another organisation to supply and/or deliver the product or service.
We may use your email address to send you information about our products and services. In each case you will be given the option to re-affirm your consent and also to unsubscribe from email contact.
We may need to pass your information to other organisations for administrative purposes such as processing and sorting data, monitoring how our customers use our website and issuing emails on our behalf. We have verified that the organisations we use for these purposes are compliant with the requirements of GDPR and will not use your data for any purposes other than those authorised by us.
In order to effectively process credit or debit card transactions, it may be necessary for the bank or card processing agency to verify your personal details outside the European Economic Area (“EEA”) for the purpose of authorizing the transaction. Such information will not be transferred ouside the EEA for any other purpose.
This is a string of numbers unique to your computer that is recorded by our web server when you request any page or component of our website. This information is used to monitor use of our website. This provides statistical information about our customers’ browsing patterns and does not identify individual customers.
We will hold your personal data only in line with the legal basis for which it was obtained. If you tell us that you have withdrawn your consent, we will continue to hold and process your data only for such period as is necessary to complete any transaction in which we have a legitimate interest.
You can ask for a copy of the information we hold about you and have it corrected if it is wrong. You have the right to ask us to delete any personal data we hold about you. You have the right to object to your data being used for specific purposes.
If you have any cause for complaint about our use of your data you should contact us to try to resolve the matter. You have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office, if not satisfied.