Privacy Policy

1. About this Privacy Notice:

This Data Privacy Notice contains key information and is a summarised version of our full Data Privacy policy, which is available upon request.

2. Consent

When collecting your personal data, we’ll always make it clear to you which data is necessary in connection with your particular enquiry. You may withdraw your consent at any time by following the contact instructions at the bottom of this privacy policy.

3. How we use your personal data:

We use your data to process requests through sellacar.co.uk. If we don’t collect your personal data during our interactions with you, we won’t be able to process your request for a vehicle valuation and/or wouldn’t be able to comply with our legal obligations should you choose to sell your car to us. We also use your data to respond to your queries or complaints. We’ve communicated with you throughout. We do this on the basis of our contractual obligations to you, our legal obligations and our legitimate interests in providing you with the best service and understanding how we can improve our service based on your experience.

4. Direct Marketing

We will only engage with you via direct marketing channels with your express consent to do so. You have the right to stop us using personal data for direct marketing activity through all channels, or selected channels we will always comply with your request.

5. Sharing Personal Data

We may share your data with other companies in Our group.

Nexus Point has been appointed as a Data Sub-Processor to process Personal Data on behalf of Us. We will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, Our obligations, and the obligations of Nexus Point Ltd under the law.

We may sometimes contract with third parties to supply products and services to you on Our behalf. These may include payment processing, delivery of goods, search engine facilities, advertising and marketing. In some cases, third parties may require access to some or all of your data. Where any of your data is required for such a purpose, We will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, obligations, and the obligations of the third party under the law.

We may compile statistics about the use of Our Site including data on traffic, usage patterns, user numbers, sales and other information. All such data will be anonymised and will not include any personally identifying data, or any anonymised data that can be combined with other data and used to identify you. We may, from time to time, share such data with third parties, such as prospective investors, affiliates, partners and advertisers. Data will only be shared and used within the bounds of the law.

In certain circumstances, We may be legally required to share certain data held by Us, which may include your personal data, for example, where We are involved in legal proceedings, where We are complying with legal requirements, under issue of a court order or at the request of a governmental authority.

6.1. Third Parties

Google Analytics

We use Google Analytics, owned by Google, to collect, monitor, and analyse traffic to Our website.

Google collects data about the device you are using, device type, browser information and device screen size. Google also collects your IP Address which is used to approximate your location. Google does not share your IP Address with Us, which in turn does not allow Us to identify you as an individual.

For further details on how Google Analytics uses and protects your data, please see Google’s privacy policy here. You may also opt-out of Google Analytics tracking by installing this browser plugin, provided by Google.

Cloudflare

We use Cloudflare to protect the identity of Our servers for security reasons. Cloudflare also provides several services such as DDoS (Distributed Denial of Service) attacks protection, SSL/TLS (end-to-end encryption) and caching of web assets.

Due to the nature of Cloudflare, any data you submit to Our servers will also pass through Cloudflare, albeit in a converted format using end-to-end encryption technologies.

Cloudflare complies with the GDPR and other legal frameworks. Further information can be found here.

Mandrill

We use Mandrill to handle outgoing and incoming emails between the Us and the Data Subject. Mandrill keeps a log of all data, including any personal or sensitive data that you include within your email to Us, along with your name and email address. These logs are kept for a maximum of 30 calendar days at which point they are permanently removed.

We do not use Mandrill for marketing purposes unless you give us consent to do so.

7. What Data do we collect

We will only collect the minimal amount of data required to fulfil your request or our legal obligations and our legitimate interests and includes the following:

Data

Reason

How long we keep the data

  • Name
  • Address
  • Phone number
  • Date of birth
  • Email address
  • Vehicle information

Required to respond to your queries submitted via our website

Held for 60 calendar days after the query has been resolved

Digital Footprint (IP Address, Browser Meta Data, Device Meta Data)

Required for maintaining the security of our systems and to prevent abuse

Held for 30 calendar days

8. Your rights

You have the ultimate right to:

  • Information:- To be informed about the processing being carried out by us.
  • Access:- Subject to certain exemptions, to obtain a copy of the personal data being processed.
  • Rectification: - To have inaccurate data rectified.
  • Erasure:- To have personal data erased upon request, subject to certain exemptions.
  • Data Portability:- In certain circumstances have automated data returned to you, or sent direct to another controller, in a structured, commonly used and machine-readable format.
  • Objection:- The absolute right to object to direct marketing and a qualified right to object to processing based on the controller’s legitimate interests, including profiling.
  • Automated decision-making:- Not to be subject to decisions based solely on automated processing.

9. Contact

Data Protection Officer

We have a ‘Data Protection Officer’ who is responsible for matters relating to privacy and data protection. The Data Protection Officer can be reached at the following address:

Stephen Chappell - Compliance Officer - Sell a Car - 01606 861 234 www.sellacar.co.uk

11. Changes to this privacy notice:

It’s likely that we’ll need to update this Privacy Notice from time to time. You’re welcome to come back and check it whenever you wish.

This Privacy Policy was last modified on 14th of November 2023.