Blutick

Privacy Policy

Updated 14th October 2019

1. What Is the Purpose of This Document?

1.1 We are Blutick Limited, registered office at 109 Birdwood Road, Cambridge, United Kingdom, CB1 3TB. Throughout the rest of this document we shall be referred to as “Blutick”.

1.2 This Privacy Policy applies to blutick.com, your Blutick user account, technical support and any other services we provide to you (we’ll just call all this “Blutick Services”).

1.3 The purpose of this document is to inform you of exactly what information about you that we collect, store and process. To generalise we do not store any information about you that does not help us provide the services you have purchased from us. We are committed to being transparent and open and this document will outline exactly what is stored and how it is used.

2. What Do We Mean by “Personal Information”?

2.1 “Personal information” means any information that identifies you, things like your name or email address. Any information that falls outside of this is “non-personal information.”

2.2 If we store your personal information with information that is non-personal, we will consider the combination as personal information. If we remove all personal information from a set of data then the remaining is non-personal information.

3. Your Data

3.1 What we collect

We collect personally identifiable information in order to provide you with a service and identify that you are the owner of the provided service. The following is the set of personally identifiable information we may collect from you and the legal and practical justification for its collection.

Data Process Processing Basis
IP address Security and system maintenance. Your IP address will be checked against a service that determines how likely an IP address is a proxy / VPN / bad IP using statistical analysis. If we determine your current location does not match your billing address we will contact you to confirm the order is genuine. Your IP address will also be recorded on system logs that will be used for general system maintenance.
  • Contract VAT MOSS, to add a single piece of information to determine place of supply
  • Legitimate interest To protect us and our users from fraudulent transactions.
Full Name Your name determines the owner of the Blutick Service.
  • Contract To create invoices and manage payments
  • Legitimate interest To communicate your identity to other parties within the Blutick service, such as teachers, students and parents
  • Legitimate interest Relationship management, we will refer to you by your full name in support communications
Billing Address We need to know your billing address to confirm your order and assess appropriate taxes.
  • Contract To create invoices and manage payments
  • Contract VAT MOSS, to add a single piece of information to determine place of supply
  • Legitimate interest To recover owed money in the event of non payment
  • Legitimate interest To prevent fraudulent orders
Sign up location Your sign up location will be determined from your IP address and referenced against your billing location to determine a place of supply. This is required for both VAT purposes and fraud prevention.
  • Contract VAT MOSS, to add a single piece of information to determine place of supply
  • Legitimate interest To protect us and our users from fraudulent transactions.
Email address Your email address will be stored in our customer database and support system and will be used to contact you for various reasons.
  • Contract We need to be able to contact you to provide support and information regarding your products including notification of technical issues, renewals, and information related to the continued running of the service.
  • Legitimate interest We will contact you regarding new offers and products we develop.
Telephone number Your telephone number will be stored in our customer database.
  • Legitimate interest Fraud prevention, in the event of a suspicious order from your account we may contact you by phone to confirm the order.
  • Legitimate interest We may contact you by phone to remind you of a missed renewal payment.
Date of birth For student accounts, we optionally request your date of birth to tailor the resources to you.
  • Contract Students’ date of birth allows us to provide more relevant educational content to students.

3.2 What We Do Not Collect

Special category data. Special category data is personal data which the GDPR says is more sensitive, and so needs more protection. We do not collect any special categories of personal data. For your reference these special categories are:

  • race
  • ethnic origin
  • sex
  • politics
  • religion
  • trade union membership
  • genetics
  • biometrics (where used for ID purposes)
  • health
  • sex life
  • sexual orientation

3.3 How Your Data Is Collected

Your contact details, including your name, address, email address and phone number are collected via a form that you complete either on sign up or at a later date when ordering products that require it. If you do not order products that require these details they will not be collected unless you complete the contact details form voluntarily.

Your IP address is collected automatically when you sign up to the Blutick Service or navigate pages in the Blutick Service.

To contact you regarding your service – In order to provide your service we will need to contact you to inform you about technical problems, renewal dates and security issues.

3.4 How Your Data Is Used

Third parties
We do not provide any of your details to third parties for the purpose of marketing.
Marketing
We will provide you with choices regarding certain personal data uses, particularly around marketing and advertising. We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you. You may receive marketing communications from us if you have purchased goods or services from us and you have not opted out of receiving that marketing.

3.5  How long is user data stored?

User data is stored for up to 5 years after last use. This is to allow student accounts to remain active throughout their time at secondary school (from age 11 to 15). After that time, user names and email addresses are removed, and the data becomes anonymised. This allows schools to track usage over several years while protecting user privacy. Users can request for their data to be removed at any time by emailing

data@blutick.com

.

4. Third Party Processors

The list of third party processors is maintained at https://blutick.com/agreements/blutick-third-party-processors/

5. Your Rights

The GDPR provides the following rights for individuals

The right to be informed
You will be informed about the collection and use of your personal data.
The right of access
You will have access to your personal data and supplementary information.
The right to rectification
You can have inaccurate personal data rectified, or completed if it is incomplete.
The right to erasure
You can have personal data erased when that erasure does not conflict with our legal obligations or security requirements.
The right to restrict processing
You have the right to request the restriction or suppression of your personal data.
The right to data portability
You can always obtain and reuse your personal data for your own purposes across different services.
The right to object
You have the right to object to data processing based on legitimate interests, direct marketing (including profiling); and processing for purposes of scientific/historical research and statistics. Please note that objections to data processing may make it impossible for us to provide you with a service.

You also have rights in relation to automated decision making and profiling.

For further reference please see the ICO documention

6. Contact and Support

Calls to Blutick are not recorded. Support tickets and emails are stored to provide historical reference information to provide product support.

7. Blutick Data Protection Officer

In the case of any complaint regarding our handling of your data, our privacy policy or our adherence to it, please contact our data protection officer listed below. This individual will carry out a full investigation on your behalf in the event that you feel there is a problem.

  • Name Rob Percival
  • Address 109 Birdwood Road, Cambridge, CB1 3TB, UK
  • Email Address rob@blutick.com