Privacy Policy
Who We Are
Our website address is: https://plusnext.net/
Plusnext is an IT company based in London, United Kingdom. We provide innovative technology solutions and services to our clients. For privacy-specific concerns, you can contact us at:
Plusnext
London, United Kingdom
Email: support@plusnext.net
Phone: (+44) 07542 726200
In accordance with UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are committed to protecting the privacy and security of your personal data. Our Data Protection Officer can be contacted at support@plusnext.net.
What Personal Data We Collect and Why We Collect It
We collect personal data to provide our services, improve user experience, and comply with legal obligations. Below, we outline the types of personal data we collect, the purposes for collection, and the legal basis under the UK GDPR.
Comments
When visitors leave comments on our website, we collect the data shown in the comments form, along with the visitor’s IP address and browser user agent string to help detect spam. The legal basis for this processing is our legitimate interest in maintaining the security and integrity of our website.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to check if you are using it. The Gravatar service privacy policy is available at: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to our website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors can download and extract any location data from images on the website. The legal basis for processing media uploads is your consent, provided when you upload the content.
Contact Forms
When you submit a contact form on our website, we collect your name, email address, and any additional information you provide in the message. We retain this data for six months for customer service purposes but do not use it for marketing unless you explicitly consent. The legal basis for this processing is your consent or our legitimate interest in responding to your inquiries.
Cookies
Our website uses cookies to enhance user experience and provide functionality. Specifically:
- If you leave a comment, you may opt-in to saving your name, email address, and website in cookies for your convenience. These cookies last for one year.
- Visiting our login page sets a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
- Upon logging in, we set cookies to save your login information and screen display choices. Login cookies last for two days, and screen options cookies last for one year. Selecting “Remember Me” extends your login to two weeks. Logging out removes these cookies.
- Editing or publishing an article saves an additional cookie with the post ID, containing no personal data, which expires after one day.
The legal basis for using cookies is your consent, obtained via our cookie consent mechanism, or our legitimate interest in providing a functional website.
Embedded Content from Other Websites
Articles on our site may include embedded content (e.g., videos, images, articles) from other websites. Embedded content behaves as if you visited the other website, which may collect data, use cookies, or track your interactions if you have an account and are logged in to that website. We do not control the data collection practices of these third-party websites.
Analytics
We use Google Analytics to understand how visitors interact with our website. This collects anonymized data such as page views, session duration, and device information. You can opt out of Google Analytics tracking by using the opt-out tool provided by Google: https://tools.google.com/dlpage/gaoptout. The Google Analytics privacy policy is available at: https://policies.google.com/privacy. The legal basis for this processing is our legitimate interest in improving our website and services.
Who We Share Your Data With
We share your data with the following third-party providers to operate our website and services:
- Google Analytics: For website usage analysis, as described above.
- Cloudflare: For website security and performance optimization. Their privacy policy is available at: https://www.cloudflare.com/privacypolicy/.
- Mailchimp: For email communications, if you subscribe to our newsletter. Their privacy policy is available at: https://mailchimp.com/legal/privacy/.
We ensure that all third-party providers comply with UK GDPR standards through data processing agreements or equivalent safeguards. We do not share your personal data with any other parties unless required by law.
How Long We Retain Your Data
- Comments: Comments and their metadata are retained indefinitely to recognize and approve follow-up comments automatically.
- Contact Form Submissions: Retained for six months for customer service purposes.
- Analytics Data: Retained for one year to analyze website performance trends.
- User Accounts: Personal information provided in user profiles is stored indefinitely until the user requests deletion. Users can edit or delete their information at any time (except their username).
- Customer Purchase Records: Retained for seven years to comply with UK tax and financial regulations.
We ensure that data is not kept longer than necessary, in line with UK GDPR requirements.
What Rights You Have Over Your Data
Under the UK GDPR, you have the following rights over your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal obligations.
- Right to Restrict Processing: Request that we limit the use of your data.
- Right to Data Portability: Receive your data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent where processing is based on consent.
To exercise these rights, contact us at support@plusnext.net. We will respond within one month, as required by UK GDPR.
Where We Send Your Data
Visitor comments may be checked through an automated spam detection service, which may be located outside the UK. We ensure that any data transfers outside the UK (e.g., to the EU or US) comply with UK GDPR through mechanisms such as the UK International Data Transfer Agreement or adequacy decisions. For example, our use of Google Analytics involves data transfers to the US, safeguarded by Google’s adherence to the UK-US Data Bridge.
How We Protect Your Data
We implement robust measures to protect your data, including:
- Encryption: All data transmitted to and from our website is encrypted using HTTPS.
- Access Controls: Only authorized personnel can access personal data, and they receive regular data protection training.
- Two-Factor Authentication: Used for administrative access to our systems.
- Regular Security Audits: Conducted to identify and address vulnerabilities.
We have completed a Privacy Impact Assessment to ensure our data processing activities comply with UK GDPR.
What Data Breach Procedures We Have in Place
In the event of a data breach, we have the following procedures:
- Internal Reporting: All suspected breaches are reported to our Data Protection Officer within 24 hours.
- Investigation and Notification: We investigate breaches promptly and notify the Information Commissioner’s Office (ICO) within 72 hours if required by UK GDPR. Affected individuals will be informed if the breach poses a high risk to their rights and freedoms.
- Mitigation: We take immediate steps to contain and resolve breaches, such as resetting credentials or patching vulnerabilities.
What Third Parties We Receive Data From
We do not receive personal data about users from third parties, such as advertisers, unless explicitly disclosed (e.g., through partnerships with consent).
What Automated Decision Making and/or Profiling We Do with User Data
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on users.
Industry Regulatory Disclosure Requirements
As an IT company, we comply with the UK GDPR and the Data Protection Act 2018. We are registered with the Information Commissioner’s Office (ICO) under registration number ZA123456. For further details, contact our Data Protection Officer at dpo@plusnext.net.
Contact Information
For privacy-specific concerns, please contact:
Data Protection Officer
Plusnext
London, United Kingdom
Email: support@plusnext.net
Phone: (+44) 07542 726200