5.1 How we use your personal data
In this section, we have set out:
- the general categories of personal data that we may process;
- In the case of personal data that we did not obtain directly from you, the source and specific categories of that data;
- the purposes for which we may process personal data; and
- the legal bases of the processing.
Usage Data
We may process data about your use of our website and services. The usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is Google Analytics, Google Search Console, Shopify ecommerce platform and WordPress plug-ins. This usage data may be processed for the purposes of analysing the use of the website and services. The legal basis for this processing is our legitimate interests, namely monitoring and improving our website and services.
Account Data
We may process your account data. The account data may include your name and email address. The source of the account data is you, your employer or authorised third party representative. The account data may be processed for the purposes of providing our services, ensuring the security of our services, maintaining back-ups of our databases and communicating with you. The legal basis for this processing is consent OR our legitimate interests, namely the proper administration of our business OR the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
Service Data
We may process your personal data that are provided in the course of the use of our services. The service data may include:
- Names of individuals
- Dates of birth
- Telephone numbers
- Email addresses
- Postal Addresses
- Passport numbers
- Driver numbers
- National Insurance numbers
- Other forms of identification and associated numbers
- *Current medication
- *Health data
- *Genetic data
- *Ethnic background
- Payment details
Special category data as defined by the Information Commissioner’s Office:
https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/special-category-data/
The source of the service data is you, your employer or authorised third party representative. The service data may be processed for the purposes of operating our website, providing our services, ensuring the security of our website and services, maintaining back-ups of our databases and communicating with you. The legal basis for this processing is consent OR our legitimate interests, namely the proper administration of our website and business OR the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
Service data is collected via means of version controlled documentation by employees of Crystal Health Group Limited or approved and authorised contractors. At this point, written consent is obtained by you to fulfil the service requested. Please refer to section 7 for your rights on withdrawing consent.