Data Privacy Policy
PRIVACY POLICY PURPOSE
The Fantastic Thinking Company Limited (TFTC) has created this privacy policy to demonstrate our commitment to privacy and data security. The following discloses the information use, disclosure and security practices for TFTC’s web site and PERCEPTION PROFILING SYSTEM.
INFORMATION COLLECTED BY US
We hold data for two distinct purposes. Firstly, we hold data for those who use our online web application to administrate and/or complete PERCEPTION PROFILE ASSESSMENTS, to produce PERCEPTION PROFILE REPORTS. Secondly, with consent, we hold data for those who wish to receive marketing (email) communications from us.
We will use and process your personal information, where you have requested us to do so, for the following purposes:
- to register you as a user of our site;
- to provide you with online assessment and profiling services as requested by you;
- to comply with a request from you in connection with the exercise of your rights (for example where you have asked us not to contact you for marketing purposes, we will keep a record of this on our suppression lists in order to be able to comply with your request);
- to manage queries, complaints, or claims.
Personal information about you which is collected by us in the course of your visit to this site is kept confidential. Information required to produce PERCEPTION PROFILE REPORTS is collected via the TFTC PERCEPTION PROFILING SYSTEM and is stored on our secure servers located within the UK.
Marketing information gathered via TFTC for email marketing purposes is held by Mailchimp, on servers located in the USA. For more information on how Mailchimp secure data that is in their possession please refer to https://mailchimp.com/about/security/
PRIVACY POLICY
TFTC acts in two different capacities. First, as a data controller when processing customer data. Second, as a data processor in relation to the processing of individuals’ data for the purposes of compiling PERCEPTION PROFILE REPORTS and PERCEPTION PROFILE GROUP DASHBOARDS on behalf of our customers.
WHO MIGHT WE SHARE YOUR INFORMATION WITH?
Your data may be accessed by appropriate TFTC employees and by your TFTC Perception Profiling Practitioner and your company account holder(s). If you have an allocated Practitioner and/or any company account holder(s) they will be identified in the introductory screens prior to completion of your assessment.
Your data is also accessible to our server providers and contractors who have signed confidentiality agreements with us.
As part of our ongoing research, we may also share collated, anonymised data with trusted third-parties or in publicly.
WHAT DO WE DO WITH YOUR INFORMATION?
We use your responses to the PERCEPTION PROFILE ASSESSMENT to compile your PERCEPTION PROFILE REPORT.
Your gender is used for statistical analysis in group gender based reporting and also as a method of providing us with insights and timings as to how you answer a question within the assessment that requires little thought on your part.
Your data will be held encrypted in our secure database and can be accessed by authorised account holder(s) both as a reference and to produce further reports. TFTC is not responsible for the use or publication of data by account holders. We may use your information anonymously (and in conjunction with other data in our database) to look at general data trends in relation to PERCEPTION PROFILE REPORTS.
DATA SECURITY
Our Web Sites and Databases have security measures in place to protect against the loss, misuse, accidental or unlawful destruction or unauthorised access of the information under our control. All pages and systems that contain customer information are password-protected. Some customer information can be viewed online if a valid account name and password is entered. Customer information and password resets can only be sent to the e‐mail address registered for the user.
OUR LEGAL BASIS FOR PROCESSING AND HOLDING DATA
When you provide us with your details for marketing purposes, you are asked expressly to consent to us processing and storing your personal data in line with this policy. You have the right to withdraw your consent at any time in accordance with this policy. When you provide us with your details as part of the completion of a PERCEPTION PROFILE ASSESSMENT, this information is processed and stored based on our legitimate interest. This means that the data is required by TFTC to fulfil the contract with you or your organisation to produce and issue a PERCEPTION PROFILE REPORT to you or your employer.
You may request that any of your personal data be deleted which we will do. However, we will keep an anonymised equivalent of your data within our database to ensure the ongoing statistical accuracy of the database and reports produced from it.
PRIVACY POLICY ENQUIRIES
If you have any questions about this privacy statement, the practices of our web site, or your dealings with this web site, please e-mail: privacyquestions@perceptionprofiling.com
When completing PERCEPTION PROFILING ASSESSMENTS or administering the TFTC PERCEPTION PROFILING SYSTEM you will be given the opportunity to consent to being contacted for marketing purposes in addition to receiving contact regarding the status of your assessment and report. However, data is held separately, with each purpose clearly defined.
HOW LONG DO WE KEEP HOLD OF YOUR INFORMATION?
There is currently no mandatory limit to how long data may be held. However, we do have an operational aim of anonymising individual responses once they have been within the database for a period of 24 months.
Before we anonymise data (whilst it is live in our database) a PERCEPTION PROFILE REPORT (PDF document) is generated by our systems dynamically when a unique code that is allocated to your assessment is provided to the system.
When we (either TFTC or a PERCEPTION PROFILING PRACTITIONER) email you or your account holder with the produced report then the PDF attachment will stay in the sent mail items folder of the mailbox it was sent from until it is manually deleted, or the email account is deleted.
It is up to you or the account holder, as data controller, to ensure that data is not held longer than necessary for the purposes for which it is intended. You can request for your personally identifiable data to be anonymised or deleted from TFTC’s databases at any time.
GDPR AND DATA DELETION STATEMENT
This statement sets out our policy for responding to requests for deletion of data under the GDPR (General Data Protection Regulation), which came into force in May 2018. This document explains the rights of the data subject in relation to data deletion and the responsibilities of TFTC LIMITED in responding with such a request.
INDIVIDUAL RIGHTS
An individual has the right to erasure, also known as ‘the right to be forgotten’. The principle underpinning this right is to enable an individual to request the deletion or removal of personal data where there is no compelling reason for its continued processing.
WHEN DOES THE RIGHT TO ERASURE APPLY?
As stipulated in the GDPR, individuals have a right to have personal data erased and to prevent
processing in specific circumstances:
- Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed;
- When the individual withdraws consent;
- When the individual objects to the processing and there is no other legal ground for the relevant processing activity;
- When the personal data was unlawfully processed;
- Where the personal data must be erased in order to comply with a legal obligation.
WHAT INFORMATION DOES TFTC RETAIN?
The TFTC PERCEPTION PROFILING SYSTEM stores data about individuals in order to create an individual PERCEPTION PROFILE REPORT and also to contribute to the creation of a PERCEPTION PROFILE GROUP DASHBOARD. We store the name, e-mail address, gender/sexual identification, age-range (at time of assessment), handedness, organisation/department (if provided) and subsequent assessment results for each individual in order to create a PERCEPTION PROFILE REPORT, which is stored on our secure servers in the UK. This data is stored and used in accordance with the statements made in this Privacy Policy.
If consent is provided, personal data (including the above, plus address, telephone number and other notes) may be stored in our CUSTOMER RELATIONSHIP MANAGEMENT system for the purposes of contacting you regarding TFTC news, products and promotions.
HOW CAN DATA BE DELETED?
Individuals and Account Holders (nominated individuals acting on behalf of your organisation) can request in writing by email to profiledatadeletion@perceptionprofiling.com that we delete data from the PERCEPTION PROFILING SYSTEM whenever they wish. This data is deleted from the system by an authorised TFTC DATABASE ADMINISTRATOR within 3 working days.
Before we delete the data, we make an anonymised copy of the data to help keep the integrity of the overall database and any reports that we need to generate from it. Once this anonymised data has been created, we delete the original profile data. WE DO NOT RECORD THE ORIGINAL SOURCE THAT ANONYMISED DATA RECORDS ARE CREATED FROM.
We do keep backups of our database for security and data recovery purposes. We have a rotation of data archives that means that once your data is deleted from our live database servers it may take up to six months before it is deleted from our archives. All archives are encrypted and kept in secure locations within the UK.
Information stored within our CRM can be deleted upon receipt of an email request to: crmdatadeletion@perceptionprofiling.com We undertake to perform the deletion within 15 working days of receipt of the request. We will send you a confirmation once the information has been deleted. Wherever possible, we will aim to complete the request in advance of the deadline.
HOW CAN YOU ACCESS THE INFORMATION HELD ABOUT YOU?
If you purchased your own report, you can request a copy of this to be sent to you by e-mail at any time. If your organisation purchased the report on your behalf, your Account Holder or PERCEPTION PROFILING PRACTITIONER will usually provide the report for a particular purpose, e.g. for use on a training course or event. Please contact your Account Holder in the first instance. If your Account Holder does not respond, please contact us by email to:
profileaccessrequests@perceptionprofiling.com
SUMMARY
We are committed to responsible data management. Data relating to identifiable individuals is only obtained, stored, processed and accessed:
- For defined and justifiable purposes;
- Securely and confidentially;
- Respecting individuals’ rights of review and objection.
Unless required or permitted by law, personal data concerning race, politics, religion, health or sexuality is not processed without express consent. We recognise that you are placing your trust in us and we do not take our obligations lightly.