Dorset Sports Cars, are committed to protecting and respecting your privacy.
This Policy explains when and why we collect personal information, how we use it, the conditions under which we may disclose it to others and what choices you have.
We may change this Policy from time to time so please check this page occasionally to ensure that you’re happy with any changes. By using our services, you’re agreeing to be bound by this Policy.
Any questions regarding this Policy and our privacy practices should be sent by email to firstname.lastname@example.org, or via the other methods on our contact page.
If you wish to write to us, please use the following address:
Data Controller, Dorset Sports Cars Ltd., Three Cross Garage, 99 Ringwood Road, Three Legged Cross, Wimborne, Dorset. BH21 6RD
Date: 18th May 2018
Next Review Date: 18th May 2019
Here is a summary of our Privacy Information Notice; click on any of the linked headings to view further information.
We are Dorset Sports Cars Ltd., we sell vehicles and provide garage services to clients in the UK.
Dorset Sports Cars Ltd. is a company limited by guarantee (Registration Number: 05727654), our registered address is Dorset Sports Cars Ltd., Three Cross Garage, 99 Ringwood Road, Three Legged Cross, Wimborne, Dorset. BH21 6RD. Full contact details can be found here: https://www.dorsetsportscars.co.uk/contact.php.
We obtain information about you when you contact us to enquire about or purchase our products or services.
We may collect information when you voluntarily complete customer surveys, provide feedback or participate in competitions.
We also ask you for permission to keep you updated about our company news, our products, and our services. You can change your preferences at any time by contacting us.
Website usage information is collected using cookies.
We collect information to allow us to fulfil our obligations to our clients, and to respond to business enquiries.
In processing your order or dealing with your request, we may send your details to, and also use information from, credit reference agencies and fraud prevention agencies. We may also send your information to our card processing partner to allow them to process your payment and carry out security and fraud checks.
The table in section 3.3 below outlines exactly what information we collect, and for what purpose.
We do not gather sensitive personal data (e.g. health, genetic, biometric data; racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, and criminal convictions). We expressly request that you do not provide any such sensitive data to us via this website.
Our services are not directed to children under 13. If you learn that a child under 13 has provided us with personal information without consent, please contact us.
We will not sell or rent your information to third parties.
We may pass your information to third party service providers who we have engaged for the purpose of completing tasks and providing services to you on our behalf (for example, we may provide your details to the Search Engine Optimisation company we work alongside or provide information to a car manufacturer or importer that we represent). We disclose only the personal information that is necessary to deliver the service.
We also use a number of 3rd party services to help us fulfil our contractual obligations. These 3rd party services are listed in full below; we have verified that these 3rd party services are GDPR compliant (or are working towards GDPR compliance) and are certified under the EU-US Privacy Shield Framework (or are working towards certification) where these organisations are based outside of the EU.
The following table outlines the personal data we may collect and for what purpose. The table also outlines the 3rd parties the data is processed by or shared with, and how long the data is stored for:
|Name||What||Legal Ground||Purpose||3rd Parties||Data Retention|
|Prospect, client & supplier contact information||Contract||To allow initial and ongoing contact with prospects, clients, suppliers, etc.||G Suite (Google)
We have signed EU model contract clauses.
|Until request for deletion. Data may not be deleted if we are required to keep it to meet our legal obligations.|
|Invoicing||Client & supplier purchase history & contact info.||Legal obligation||For invoicing||Dragon 2000||Indefinitely, for on-going invoicing and accounting records.|
|Invoicing||Client & supplier purchase history & contact info.||Legal obligation||For invoicing||Sage||Indefinitely, for on-going invoicing and accounting records.|
|Customer Relationship Management||Prospect, client and supplier information & communication preferences||Legitimate interests||To allow customer and prospect management||Dragon 2000||24 Months from last point of contact. Data may not be deleted if we are required to keep it to meet our legal obligations.|
|Website forms||Contact information& communication preferences||Contract||To allow initial and ongoing contact with prospective clients||Until request for deletion. Data may not be deleted if we are required to keep it to meet our legal obligations.|
|Reviews||Reviewer name||Legitimate interests||To promote our business to website users.||Secured within our website database provided by our hosting company||Until request for deletion.|
|Analytics||Website visitor behaviour||Legitimate interests||To analyse popular content, website performance, etc – so we can further improve your experience and our performance.||Google Analytics
We have signed EU model contract clauses
|26 Months from last point of contact|
|Tag Manager||Website visitor behaviour||Legitimate interests||Ad measurement & performance purposes||Google Adwords
|26 Months from last point of contact|
|Server Logs||IP address||Legal obligation||To help prevent DoS (Denial of Service) attacks; for website security and diagnostics.||Hosting company||Server logs are stored indefinitely and only accessible by our hosting company.|
You have certain rights concerning the information we hold about you, as defined under the General Data Protection Regulation. If you wish to exercise these rights, please contact us, including your email address in the first instance (this is the unique identifier we use to identify and collate personal information).
You may request a copy of any data we hold about you. Upon request, we will provide the personal data we hold on record about you.
The accuracy of your information is important to us. If you change email address, or any of the other information we hold is inaccurate or out of date, please contact us so we may correct our records.
You have the right to request erasure of your personal information. Unless there is a compelling reason for the data not to be erased (for example, if we need to use that data to fulfil our contractual or legal obligations), your personal data will be deleted on request.
We do not use any personal information for automated decision making or profiling; your data is not subject to automated decision making or profiling.
Dorset Sports cars takes security seriously. To protect your information from loss, misuse or unauthorised access or disclosure, we have put in place suitable physical, electronic, and managerial procedures to safeguard and secure the information we collect. These steps include the following:
A copy of our internal Data Security Policy is available on request.
Our Data Security Policy includes a clear process for handling a personal data breach, should one occur. Where appropriate, Dorset Sports Cars will promptly notify you of any unauthorized access to your personal information.
If you wish to raise a complaint on how we have handled your personal information, you can contact us directly and we will investigate the matter.
If you are not satisfied with our response or believe we are processing your personal information not in accordance with the law, you can complain to the Information Commissioner’s Office (ICO).