Privacy Policy

Shwmae! Who are we?

Ffenest Siop found at www.ffenestsiop.cymru (“Website”), is governed by the following privacy policy (“Privacy Policy”).

The purpose of this Privacy Policy is to inform you what personally identifiable information we may collect and how it may be used. This statement applies to your use of our Website (including contacting us or posting comments/reviews on our Website), when you purchase services from our Website and when you engage us to provide you with profiles, marketing, translation and PR services (collectively, “Services”).

We respect your privacy and are committed to protecting it. As such, we comply with the EU law retained version of the General Data Protection Regulation (2016/679), together with the UK Data Protection Act 2018. If any of these laws are replaced or superseded, we will also comply with those too.

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (https://ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance by emailing us at ffenestsiop@llaiscymru.wales

This Privacy Policy was last updated in May 2024. We reserve the right to update this Privacy Policy from time to time so please check back regularly. If we make material changes to this Privacy Policy and we need your consent to those changes, we will contact you by email to do so.

What personal data we collect and why we collect it?

Personal data, or personal information, is any information about an individual from which that person can be identified. It doesn’t include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you when you engage with us. Whenever we collect personal data about you, we must have a legal ground (lawful basis) to do so.

Services

Before being able to provide you with our Services, we will need to collect personal information from you. The information we need will depend on the nature of the Services, but may include the following: name, business name, organisational name, email address, phone number, home address, social media profile handles and links. We’ll also need to use this information to contact you about any customer service issue raised. Our lawful basis for collecting this information is that it enables us to provide our Services to you and that you have consented.

Further to this, we may also use your name and email address to send you information about our Services or issue raised (including to provide you with updates on changes to this Privacy Policy or security information). Our lawful basis for using your name and email address in this way is to provide you with relevant information relating to the security of your online account, to ensure you have up-to-date information on how we handle your personal data, and to perform our contract with you (as we have outlined above).

Purchases on our Website

Our website has the ability to take payments for our services to enable you to feature on our platforms, when you make a purchase we need to collect personal information from you, such as your name, email address, phone number and home address. Payments are either taken by third-party payment processor, currently Stripe, PayPal and your chosen credit or debit cards (depending on which you decide and which browser you use). PayPal, for instance, uses the SSL “Secure Socket Layer” protocol, which means all information is encrypted by software and so neither we nor third parties can access this information during the processing of your payment. However you make a payment, we never have sight of your payment details.

These third-party payment processors’ privacy policies will apply to your purchase and so you should read this before making a payment.

If for any reason you are entitled to a refund, we won’t see your full payment details but we may need to confirm the last four digits of your payment card.

Our lawful basis for the collection (and sharing) of this personal information is to fulfil our contract with you so that we can provide you with the services you have chosen to purchase. You have also consented to the collection of this information.

Comments or reviews

When you leave comments or reviews on our website we collect the data shown in the comments form, and also your IP address and browser user agent string to help spam detection.

An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment or review.

We collect information about visitors who comment on our Website that use our Akismet anti-spam service. The information we collect depends on how the user sets up Akismet for the Website, but typically includes the commenter’s IP address, user agent, referrer, and website URL (along with other information directly provided by the commenter such as their name, username, email address, and the comment itself).

Media

If you upload images to our Website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to our Website can download and extract any location data from images on our Website.

Information you voluntarily submit to our Website

To enable us to crate your business, service or job profile on our website, we need to collect personal information from you such as your business or organisational name, website address, contact number, email address, location to be added on to our interactive map on the website, social media handles and external links to any online reviews you may have. For example, you may voluntarily submit information to our Website by leaving a comment or review, subscribing to a newsletter, or submitting a profile or contact form. Our lawful basis is that it’s necessary for our legitimate interest to present relevant content, products and services to you (only where you have provided your consent that we do so) and that you have consented.

Automatically-collected information

We automatically collect certain information about you and the device with which you access our Website. For example, when you use our Website, we will log your IP address, operating system type, browser type, referring website, pages you viewed, and the dates/times when you accessed our Website. We may also collect information about actions you take when using our Website, such as links clicked.

We may use the information collected in the following ways:
To operate and maintain our Website;
To create your account, identify you as a user of our Website, and customise our Website for your account;
To send you promotional information, such as newsletters. Each email promotion will provide information on how to opt-out of future mailings;
To send you administrative communications, such as administrative emails, confirmation emails, technical notices, updates on policies, or security alerts;
To respond to your comments or inquiries;
To provide you with user support;
To track and measure advertising on our Website;
To protect, investigate, and deter against unauthorised or illegal activity.

Cookies

If you leave a comment on our Website you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you have an account and you log in to our Website, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

You are free to withhold consent to cookies, but it means that we might not be able to provide the full website experience to you, including some elements of video advertising.

Our lawful basis for collection of this information is that it’s necessary for us to perform our contract with you, i.e. to give you access to the service our Website provides. We also need this information to study how you use our Website, in order to improve and develop the services we provide, and better inform our marketing strategies.

Embedded content from other websites

Articles on this Website may include embedded content (e.g. videos, images, articles, reviews etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.

What happens when we link to other websites?

This Privacy Policy relates only to our Website. We will link to the website links you provide us when you submit your business, organisation or job profile, so that users can visit these sites for further information about you and your offers and services. These websites will have their own terms and conditions and privacy policies. We have no control over how your data is collected, stored or used by other websites and we advise you to check the privacy policies of any such websites before providing any data to them.

How long we retain your data?

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register or create a profile on our Website, we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data?

If you have a profile or an account on our Website, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where we send your data
Third-party use of personal information?

We may share your information with third parties when you explicitly authorise us to share your information.

Additionally, our Website may use third-party service providers to service various aspects of our Website. Each third-party service provider’s use of your personal information is dictated by their respective privacy policies over which we have no control.

Our Website currently uses the following third-party service providers:

Google Analytics

This service tracks Website usage and provides information such as referring websites and user actions on our Website. Google Analytics may capture your IP address, but no other personal information is captured by Google Analytics. Our lawful basis for collection of this information is that it is necessary for our legitimate interest to present relevant content, products and services to you.

Mailchimp and Flodesk

These services are used for delivery of email updates and newsletters. We store your name and email address for purposes of delivering such communications. Please refer to Mail Chimp and Flodesks’s privacy policy for further information. As we have advised above, our lawful basis is that you have consented to the collection of this information and it’s in our legitimate interest so we can provide you with relevant content, services and products.

At this time, your personal information is not shared with any other third-party applications. This list may be amended from time to time at our sole discretion.

Except when required by law, we will not sell, distribute, or reveal your email addresses or other personal information without your consent; however, we may disclose or transfer personal information collected through our Website to third parties who acquire all or a portion of our business, which may be the result of a merger, consolidation, or purchase of all or a portion of our assets, or in connection with any bankruptcy or re-organisation proceeding brought by or against us.

Advertising

Display Ads

We may use third-party advertising companies to serve content and advertisements when you visit our Website, which may use cookies, as noted above.

Retargeting Ads

From time to time, our Website may engage in remarketing efforts with third-party companies, such as Google, Facebook, TikTok or Instagram, in order to market our Website. These companies use cookies to serve ads based on someone’s past visits to our Website.

Affiliate Program Participation

Our Website may engage in affiliate marketing, which is done by embedding tracking links into our Website. If you click on a link for an affiliate partnership, a cookie may be placed on your browser to track any sales for purposes of commissions.

Newsletters

On our Website, you may subscribe to the newsletter, which may be used for advertising purposes. The newsletters sent may contain tracking pixels. The pixel is embedded in emails and allows an analysis of the success of online marketing campaigns. Because of these tracking pixels, we may see if and when you open an email and which links within the email you click. Also, this allows our Website to adapt the content of future newsletters to the interests of the user. This behaviour will not be passed on to third parties.

Our lawful basis for collection of this information (under the advertising heading) is that it is in our legitimate interest so that we can present relevant content, product and services to you.

How I store your personal data?

Your personal data is stored on our servers within the United Kingdom.

We may transfer your collected data to storage outside the European Economic Area (EEA) or the United Kingdom. It may be processed outside the EEA or the United Kingdom so you can receive our Website and deal with payment. If we do store or transfer data outside the EEA or the United Kingdom, we will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the EEA or the United Kingdom.

This means that sometimes we may need to use legally binding contractual terms between us and any third parties we engage with and the use of the EU-approved Model Contractual Arrangements.

Data security is of great importance to me, and to protect your data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure data collected through our Webite. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We will still be responsible for protection of your personal data, even where it has been transferred outside the EEA or the United Kingdom.

We regularly review our data retention obligations to ensure we are not retaining data for longer than we are legally obliged to.

Notice for California residents of privacy practices and rights

If you are a California resident, California law may provide you with additional rights regarding your personal data. 

Your rights

The California Consumer Privacy Act of 2020 (“CCPA”) gives you the following rights:

Right to know about the personal information we collect and share:

  • The CCPA gives you the right to request that we disclose the specific pieces of personal information we have collected about you;
  • Please see above for information on the data we collect on you, and how we process it; and
  • We do not sell your personal information. However, we do disclose your personal data to limited third parties, as described above

Right of deletion:

  • You have the right to request that we delete your personal information, subject to certain exceptions

If you wish to delete your personal data, please contact us at ffenestsiop@llaiscymru.wales. Please note that we may require certain information from you in order to verify your identity before proceeding with your request.

Disclosures about your personal information

We collect the categories of personal information from you in connection with your use of our Website as described above.

Non-discrimination

We will not discriminate against you for exercising any of your CCPA rights.

Rights relating to your personal information

Opt-out

You may opt-out of future email communications by following the unsubscribe links in our emails. You may also notify us at ffenestsiop@llaiscymru.wales to be removed from our mailing list.

Access

You may access the personal information we have about you by submitting a request us at ffenestsiop@llaiscymru.wales

Amend

You may contact us at ffenestsiop@llaiscymru.wales to amend or update your personal information.

Forget

In certain situations, you may request that we erase or forget your personal data. To do so, please submit a request at ffenestsiop@llaiscymru.wales

Please note that we may need to retain certain information for record keeping purposes or to complete transactions, or when required by law.

Sensitive personal information

At no time should you submit sensitive personal information to our Website. If you elect to submit such information to us, it will be subject to this Privacy Policy.

Contact me

At any time, please contact us at ffenestsiop@llaiscymru.wales with any questions related to this Privacy Policy.