At AFX Ventures Limited (referred to as “AFX” or by its trading style “Biscuit”, or as “we” or “us”) we are committed to protecting your personal information. This Privacy Notice (‘Privacy Notice’) explains how, when and why AFX uses your information and explains your rights in relation to that information. Your information is described and referred to in this Privacy Notice as your ‘personal data’.
This Privacy Notice also explains how others, including other organisations within our corporate group of companies, may or will use your personal data.
We collect and process personal data about you in order to provide the services offered by AFX in the Biscuit Mobile Application platform which you have agreed to use. AFX also collects and processes your personal data in order to operate our business; meet our contractual and legal obligations; protect the security and integrity of our systems and mobile applications and web service users and customers; or to fulfil our other legitimate interests.
When we update this Privacy Notice (see section (o) below) we will notify you. In addition, when you use our Biscuit Mobile Application or web services, we will also provide you with appropriate ‘just in time’ notices at the moment of data collection.
If you have any queries about this Privacy Notice please contact us at Correlation Risk Partners,1st Floor, 5 St Helen’s Place, City of London, EC3A 6AB. Alternatively send an email to firstname.lastname@example.org.
(b) IDENTITY OF DATA CONTROLLER
AFX is part of the same group of companies as Animal Friends Insurance Services Limited (‘AFI’). AFX is registered with the Information Commissioner’s Office (the ‘ICO’) as a data controller under registration reference ZB279640.
The ICO is the United Kingdom’s independent Regulatory Authority in relation to data protection and information rights. The ICO provides a helpline and complaints service and can be contacted at:
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF or at www.ico.org.uk or by telephone on 0303 1231113.
(c) YOUR RESPONSIBILITIES
Although it is our primary responsibility to ensure compliance with data protection law in relation to your use of the Biscuit Mobile Application and web service; we ask you to act responsibly with your own personal data. Therefore we ask you to:
- Read this Privacy Notice and revisit it when you have a query about our use of your personal data or if you haven’t read it in a while. Our processes will change as our business evolves and we will update this policy in line with those changes;
- The Biscuit Mobile Application is integrated with AFI services for AFI Policy Holders. If you are an AFI Policy Holder please also read your AFI policy documents carefully as they contain important information about your related insurance contract. Most of the personal data we hold about you and process through the Biscuit Mobile Application and web service is done for the purpose of providing services linked to the administration of your insurance contract;
- If you provide us with personal data about other people, or if others give us your personal data, we will only use that personal data for the specific reason for which it was provided;
- You are responsible for your use of our Biscuit Mobile Application and your account, including your username and password; please keep them secret and safe;
- If you believe your privacy has been breached, please contact us immediately;
- You provide personal data at your own risk. The Biscuit Mobile Application and web service uses appropriate security measures, but unfortunately, no data transmission is guaranteed to be 100% secure.
(d) WHEN DO WE COLLECT YOUR PERSONAL DATA?
We collect your personal data when you:
- Access our Biscuit Mobile Application;
- Create an account using our Biscuit Mobile Application and web service;
- Access your Biscuit Mobile Application account;
- Register your interest or participate in marketing, promotions and surveys;
- Ask us for more information about a product or service, or contact us with a question or complaint;
- Send an email to a Biscuit domain-based email account.
We may also collect, match or acquire information about you from other organisations such as Google Analytics or similar technologies.
(e) WHAT PERSONAL DATA DO WE COLLECT?
The personal data we collect about you is required for the purpose of creating and supporting your Biscuit Mobile Application account. Your personal data enables us to securely identify and support you as an account holder and for that purpose we collect the following personal data:
- Your name and date of birth;
- Your address and postcode, telephone number and email address;
- Other data that may identify you including: the mobile telephone number used by your device; the unique device identifier (International Mobile Equipment Identity or International Circuit Card Identifier); IP address, login information, browser type and version, time zone setting, browser plug-in types, geolocation tracking information about where you might be, operating system and version;
- If you are an AFI Policy Holder your AFI policy number;
- Data on how you use our Biscuit Mobile Applications and web service; specifically, your preferences for products and services, activities and clicks as you travel through our Biscuit Mobile Application or web service, the pages viewed, page response times, download errors; how long you stay on our Biscuit Mobile Application and web service and what you do on those pages;
- Data on how you interact with our direct marketing messages and emails – when you open and click-through any of our messages, notifications and/or email content;
- Geolocation data when you record dog walking activity on the App.
(f) HOW DO WE USE YOUR PERSONAL DATA
We will use your personal data to provide you with the services, products or information that you have requested for security and administration purposes; to improve your experience and use of the Biscuit Mobile Application and web service, and for marketing purposes.
We may need to share your information with our service providers, associated organisations and agents for these purposes. We may use your information to:
- Carry out an identity check as part of your secure use of our Biscuit Mobile Application;
- Process and retain your personal data through Azure Cloud, our chosen software provider;
- Keep you informed about our services including operational matters relating to your Biscuit Mobile Application account;
- Tracking our users through the Biscuit Mobile Application to improve performance and design;
- Provide relevant services to you;
- Apply reward points to your account based on the activities you undertake with your pet;
- Contact you with offers or promotions based on our analysis of how you use our Biscuit Mobile Application and web service and what we think will be of interest to you (unless you choose not to receive our marketing messages);
- Respond to any questions or concerns you might have about our services;
- Understand how you use our services, to help us develop relevant and updated services;
- Carry out research and statistical analysis to monitor how customers use our Biscuit Mobile Application services;
- Prevent and detect fraud or other crimes.
We will store your personal data for as long as you continue to use our Biscuit Mobile Application and web service or, following cancellation of your account and to meet our legal requirements including, but without limitation, financial audit, anti-fraud and money laundering regulations, we will store your information for no more than 7 years from the last activity on the account. We may contact you about our services during this 7 years if you haven’t opted out of receiving marketing communications from us.
(g) BASIS OF LAWFUL PROCESSING
Data protection law means that we can only use your personal data for certain reasons and only where we have a legal basis to do so. Here are the legal bases for our processing of your personal data and what each of them mean:
Legal basis: Contract
Processing your personal data is necessary for the purposes of (i) our agreement with you in relation to your use of the Biscuit Mobile Application and our web service as provided for in our terms and conditions and presented to you at ‘sign-up’ to the Biscuit Mobile Application; or, (ii) because we have asked you to take specific steps before entering that agreement. In summary, processing your personal data is necessary for:
- Administering your Biscuit Mobile Application Account;
- Administrative tasks will include, but are not limited to, providing customer service messages and notifications.
- Providing you with Biscuit Mobile Application support services.
Legal basis: Legitimate interests
Processing your personal data is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your individual rights and interests. These legitimate interests are:
- Gaining insights from your behaviour on our Biscuit Mobile Application and web service;
- Delivering, developing, and improving our products and services;
- Determining whether our marketing activities are effective;
- Targeting our products to our customers who we think would be interested to receive them.
In each case, these legitimate interests are only valid if they are not outweighed by your individual rights and interests. In these instances, we will complete an assessment, known as a ‘balancing test’, to determine whether your interests override the legitimate interests gained by AFX in processing your personal data.
Customer services and managing complaints
Notifying you of any changes to our service; solving issues via messages, notifications, telephone, or email; asking you for a review of our products or services.
Management information and business process improvement
We will use your personal data to improve the products we offer, and to streamline and evolve the way that we manage our relationship with you.
Legal basis: Consent
You have given clear consent for AFX to process your personal data for a specific purpose. You can withdraw your consent at any time.
Tracking your geolocation when you are using the App for the purposes of recording dog walking activities. You will be asked for your consent when you undertake a geolocation tracked activity.
Direct marketing purposes (with your consent)
Sending you notifications, text messages and emails about new features, products and services, and content. AFX will only send you information relating to your Biscuit Mobile Application and web service account. We will not share your data with any third parties for marketing purposes, unless you consent.
You can withdraw your consent for this at any time in the User Profile area of the Biscuit Mobile Application, or by clicking on the ‘unsubscribe’ link in our emails.
Legal basis: Legal obligation
Processing your data is necessary to fulfil a legal obligation such as defending your, or our, legal rights, adhering to regulatory requirements, responding to a request from the English courts or the police.
(h) KEEPING YOUR PERSONAL INFORMATION SECURE
We have a dedicated team whose function is to secure our customers’ personal data and we also take appropriate measures to ensure that the personal data we collect and maintain is kept secure, accurate and up to date and kept only for so long as is necessary for the purposes for which it is used.
The personal data we collect is processed and stored in the UK or Europe. In some instances, we will employ other companies who will process your data, and, in every case, we will ensure that any other company that we transfer your personal data to is subject to the same level of data protection as we are.
This means that where we may transfer or store your information outside the UK or EEA (European Economic Area), we will take steps to ensure that your privacy rights continue to be protected as outlined in this Privacy Notice.
We also ensure that the organisations that provide us with linked services related to your use of the Biscuit Mobile Application and web service have appropriate security measures and only process your information in the way we have authorised. These organisations will not be entitled to use your personal data for their own purposes.
Communications over the internet are not secure unless they have been encrypted. Your communications may go through a number of countries before being delivered to us as this is the nature of the internet. We cannot accept liability or responsibility for any unauthorised access to or loss of your personal information that is beyond our control. Please also see section (c) of this Privacy Notice on ‘your responsibilities’.
(i) WILL WE DISCLOSE THE INFORMATION WE COLLECT TO OUTSIDE PARTIES?
We may share information about you with:
- Law enforcement agencies, regulatory organisations, courts or other public authorities where we have a legal obligation to do so;
- We will release information if it is reasonable for the purpose of protecting us against fraud, defending our rights or property, or to protect the interests of our customers;
- If we are reorganised or sold to another organisation, we may transfer any personal information we hold about you to that organisation. We will inform you if we do.
(j) USE OF PERSONAL DATA FOR AUTOMATIC DECISION MAKING
We do not use your personal data for automatic decision-making.
(k) THIRD PARTY TRACKING
We use tools such as Google Analytics and other similar technologies for collecting personal data about your use of our Biscuit Mobile Application and web service for marketing purposes. This is so we can ensure that the Biscuit mobile application and web service gives you the best possible experience.
(l) COLLECTION OF CHILDREN'S DATA
AFX and the Biscuit Mobile Application does not collect or process the personal data of children under the age of 16
(m) YOUR PRIVACY RIGHTS
You have the following rights in relation to your data privacy: the right of access; the right of rectification; the right of erasure (the ‘right to be forgotten’); the right to restriction of processing; the right to be notified; the right to data portability; the right of objection; and the right to not be subject to automated profiling.
Access. You have the right to ask for a copy of the personal data we hold about you and to have any inaccuracies in your personal data corrected. Please contact us through email at email@example.com or use the ‘contact us’ section of the Biscuit Mobile Application or web service or by writing to Correlation Risk Partners, 1st Floor, 5 St Helen’s Place, City of London, EC3A 6AB.
Rectification. If you believe we are holding inaccurate personal data about you, or your personal details change, please update your account information or contact us.
Erasure. You have the right to the erasure of the personal data we hold about you, when it is no longer needed for the purposes of your Biscuit Mobile Application account (and we have no other lawful basis to hold your personal data).
Restriction. You have the right to ask us to place restrictions on processing your data in certain circumstances.
Notification. You have the right to be notified of any rectification or restrictions in relation to your personal data.
Portability. You have a right to receive the personal data we hold about you electronically in a format that allows it to be easily transferred to another data controller.
Object. You have the absolute right to object to data processing of your personal data for direct marketing or profiling purposes.
Profiling. You have the right not to be subject to any decision based on automatic processing of your personal data.
(n) CHANGES TO THIS PRIVACY NOTICE
We will update this Privacy Notice to reflect the way in which we process and protect your Personal Data. When we do so, we will notify you using the Biscuit Mobile Application and by further information on our linked web service and you will have the opportunity to adjust your communications preferences via your Biscuit account.
Date of last revision 6th July 2022