Driving Holidays Limited trading as Dettaglio (“Dettaglio”) is the data controller. We understand and respect the importance of protecting your personal data. This Privacy Policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us, in respect of your relationship with us as a customer or a potential customer. This information may be collected via our websites (“Sites”), our questionnaires/surveys, our representatives or appointed agents in overseas destinations, or our social media channels (collectively, our “Services”). Please read the following information carefully. You are responsible for ensuring that (i) the other people that you are acting on behalf of are aware of the content of this Privacy Policy; and (ii) you have checked with them that they agree to their personal data being given to us. By giving your personal data to us, we will transfer, store or process it as set out below. We will take all reasonably necessary steps to ensure that your data is treated securely and in accordance with this Privacy Policy and we take appropriate security measures to help protect your personal data from accidental loss and from unauthorised access, use, alteration and disclosure. The security of your data also depends on you. For example, the manner in which you communicate such information to us whether by email, in writing or verbally.
1. REASONS FOR COLLECTING AND USING YOUR PERSONAL DATA
We will only collect and use your personal data if at least one of the following conditions applies:
2. PERSONAL DATA YOU GIVE TO US
When you register your details or connect with us, including by email, post and phone or through social media:
If you complete a survey or questionnaire, or if you give feedback or contributions or report a problem with any of our Services, we will collect your name and relevant contact information and any other personal data you choose to give us. If you contact us online, we may keep a record of your e-mail or other correspondence, and if you call us by telephone, we may monitor and/or record phone conversations for training and customer service reasons. To help us keep your information current, accurate and complete, please ensure you tell us if anything needs to be changed.
3. PERSONAL DATA WE COLLECT ABOUT YOU
Based on how you have used our Services in the past and your activity on our website, social media channels, or with our contact centre, we may collect the following personal data about you:
4. PERSONAL DATA YOU PROVIDE ABOUT OTHER INDIVIDUALS
We use personal data about other individuals provided by you in the course of providing you with the Services. By providing other people’s personal data, you must be sure that they agree to this and you are allowed or authorised to provide it. You should also ensure that, where appropriate, they understand how their personal data may be used by us.
5. WHERE IS YOUR DATA STORED AND WHO IT’S SHARED WITH
Your personal data is held on a combination of our own systems and systems of the suppliers we use to provide our services. When you give your personal data to us, some of the personal data you provide will need to be given to and processed and stored by relevant third parties. These third parties include:
We may need to share personal data to establish, exercise or defend our legal rights, this includes providing personal data to others for the purposes of preventing fraud and reducing credit risk. We may do checks to confirm your identity. That is to help protect you from identity theft and other types of fraud, and to prevent and detect crime or money laundering. Once in a while we might run more checks with CRAs and FPAs to keep your information and your account up to date. If false or inaccurate information is provided and identified as fraud, the details will be passed to FPAs. This information may also be shared with law enforcement agencies.
Due to the decision of the UK leaving the EU, the way your data is transferred from the UK to other countries may change to ensure continuing compliance with applicable data protection laws but it will not change the security of your data. This will depend on the data protection rules in place for the international transfers of data outside of the UK once the UK has left the EU. We only share the minimum personal data that enable our suppliers and retail partners to provide their services to you and us. We may share the minimum personal data necessary with other public authorities if the law says we must, or we are legally allowed to do so.
6. HOW DO WE USE YOUR INFORMATION WHEN PROVIDING OUR SERVICES TO YOU
In order to provide our services to you, we use the information we hold in a number of different ways. We process your information where we have legal basis to do so, including because we have a legitimate business reasons for doing so. We may use and process your personal data as set out below where it is necessary for us to carry out activities for which it is in our legitimate interests as a business to do so:
We may use this information in two ways:
We may use and process your personal data, where we have your consent to do so, to send marketing correspondence about products and Services available from Dettaglio and/or from our business partners/affiliates, where we have asked for your permission to do so. See the section ‘When and how do we use your information for marketing for more information’.
We may use and process your personal data and may pass it to third parties where there is a legal requirement for us to do so, including:
Processing subject to national laws: We may also use and process your personal data (including special category data such as information on your health specifically for insurance purposes) where we have a specific legal basis to do so under applicable data protection law.
7. ADDITIONAL DATA PROVISIONS FOR BANKING TRANSACTIONS FOR CUSTOMERS IN THE EEA
In the event that the Services include a banking transaction, additional data regulations apply. These can be found in Schedule 1 of this Privacy Policy.
8. WHEN AND HOW DO WE USE YOUR INFORMATION FOR MARKETING
If you have made an enquiry through one of our Services, your personal data may be used by us in the ways applicable data protection law allows, to contact you by post, electronic means (e-mail or text message) and/or by phone with information and offers relating to our products or services. We will only do this if you did not opt out of such marketing at the point where we collected your contact details. If you have not made an enquiry, we will only send you information and offers by e-mail or text message if you sign up (opt in) to receive such marketing, either directly through us or by telling a third party that you would like to receive marketing from us. We like to hear your views to help us to improve our products and Services, so we may contact you for market research purposes. You always have the choice about whether to take part or continue in our market research.
9. WHAT YOU NEED TO DO IF YOU DON’T WANT OUR MARKETING COMMUNICATIONS
You have the right at any time to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by selecting the ‘no marketing’ option on the forms we use to collect your data. You can also exercise this right at any later time by using the unsubscribe link on any marketing e-mail you receive, or by contacting us (see How to contact us).
10. YOUR RIGHT TO ACCESS YOUR PERSONAL DATA
You have the right to make a Data Subject Access Request in many circumstances. That is a request for access to the personal data that we hold about you. If we agree that we have to provide personal data to you (or someone else on your behalf), we will provide it to you or them free of charge. We may ask for proof of identity and sufficient information about your interactions with us that we can locate your personal data. If someone is acting on your behalf they will need to provide written and signed confirmation from you that you have given your authority to that person/company for them to make the request. We will ask for this to be provided before we give you (or another person acting on your behalf) a copy of any of your personal data we may be holding. We may not provide you with a copy of your personal data if it includes the personal data of other individuals or we have another lawful reason to withhold that information. Please see the section below titled ‘How to Contact Us’ if you need to make a Data Subject Access Request.
11. CORRECTING AND UPDATING YOUR PERSONAL DATA
The accuracy of your information is important to us and we are working on ways to make it easier for you to review and correct the information that we hold about you. In the meantime, if you change your name or address/e-mail address, or you discover that any of the other information we hold is inaccurate or out of date, please let us know.
12. WITHDRAWING YOUR CONSENT
Where we rely on your consent as the legal basis for processing your personal data, as set out in section above titled ‘How do we use your information when providing our services to you’, you may withdraw your consent at any time. If you would like to withdraw your consent to receiving any direct marketing to which you previously opted-in, please see the section titled ‘What you need to do if you don’t want our marketing communications’ for further details.
13. OBJECTING TO OUR USE OF YOUR PERSONAL DATA
Where we rely on our legitimate business interests as the legal basis for processing your personal data for any purpose(s), you may object to us using your personal data for these purposes by e-mailing or writing to us at the address provided in the ‘How to contact us’ section. Except for the purposes for which we are sure we can continue to process your personal data, we will temporarily stop processing your personal data in line with your objection until we have investigated the matter. If we agree that your objection is justified in accordance with your rights under data protection law, we will permanently stop using your data for those purposes. Otherwise we will provide you with our justification as to why we need to continue using your data.
14. ERASING YOUR PERSONAL DATA OR RESTRICTING ITS PROCESSING
In certain circumstances, you may ask for your personal data to be removed from our systems by e-mailing or writing to us provided in the ‘How to contact us’ section. Provided we do not have any continuing lawful reason to continue processing or holding your personal data, we will make reasonable efforts to comply with your request. You may also ask us to restrict processing your personal data where you believe it is unlawful for us to do so, you have objected to its use and our investigation is pending or you require us to keep it in connection with legal proceedings. We may only process your personal data whilst its processing is restricted if we have your consent or are legally permitted to do so, for example for storage purposes, to protect the rights of another individual or company or in connection with legal proceedings.
Where we rely on your consent as the legal basis for processing your personal data or need to process it in connection with your contract, as set out in the section titled ‘How do we use your data when providing our services to you’, you may ask us to provide you with a copy of that information in a structured data file. You can ask us to send your personal data directly to another service provider, and we will do so if this is technically possible. We may not provide you with a copy of your personal data if it contains the personal data of other individuals or we have another lawful reason to withhold that information.
15. MAKING A COMPLAINT
We encourage you to contact us if you have a complaint and we will seek to resolve any issues or concerns you may have. You have the right to lodge a complaint with the data protection regulator where you believe your legal rights have been infringed, or where you have reason to believe your personal data is being or has been used in a way that does not comply with the law. The contact details for the Information Commissioner’s Office (ICO), the data protection regulator in the UK, are available on the ICO website (ico.org.uk). If you wish to contact us about this Privacy Policy, you can e-mail or write to us using the contact details in the ‘How to contact us’ section.
16. HOW TO CONTACT US
You have a right to ask for a copy of the personal data we hold about you, although you should be able to access online the personal data associated with your account or booking. Please include any details to help us identify and locate your personal data. Where we can provide data access, we will do so free of charge except where further copies are requested in which case we may charge a reasonable fee based on administrative costs. You can also contact us if you have a complaint about how we collect, store or use your personal data. We aim to resolve complaints but if you are dissatisfied with our response, you may complain to the Information Commissioner’s Office. To contact us about this Privacy Policy, to make a Data Subject Access Request, or a data protection related complaint, please submit your complaint or request:
Please note that we may ask you to verify your identity before we can act on your request or complaint. We may also ask you for more information to help ensure that you are authorised to make such a request or complaint when you contact us on behalf of someone else. Once you have made your request and provided us with the information we need to begin a search for the personal data we hold on you (including proof of identity), we will have 30 days to respond.
17. KEEPING HOLD OF YOUR PERSONAL DATA
If you have made an enquiry, or agreed to receive marketing communications, your personal data will be retained to ensure we provide the best possible customer service to you. We retain your personal data for as long as is necessary for us to use your data as set out in this Privacy Policy. This will generally be for up to 2 years, or such other time that may be required for our legal and audit purposes or that is required by law. After this period, we will erase your personal data.
18. WHAT IS OUR APPROACH TO DATA SECURITY
The transmission of information via the internet is not completely secure, and although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our Services, therefore any transmission is at your own risk. Once we have received your information, we will take all reasonable steps to keep your personal data secure and to try to prevent any unauthorised access, use or loss of your data. We have a process to deal with any suspected personal data breach and will notify you and the ICO of a breach where legally required to do so.
19. WHAT HAPPENS WHEN YOU FOLLOW A LINK FROM OUR WEBSITE TO A THIRD PARTY WEBSITE
Our Services may contain links to and frames of websites of our principals, suppliers, advertisers and other third parties. You can tell when a third party is because their name will appear with ours. If you follow a link or otherwise use any of these other websites, please note that these websites have their own privacy policies and cookie policies and you should make sure that you read such policies carefully before providing any personal data on a third party’s website as we do not accept any responsibility or liability for these policies or for these third party websites. Please check these policies before you submit any personal data to these websites.
20. SOCIAL MEDIA FEATURES
Our Services may contain social media features such as Facebook, Twitter, LinkedIn and Instagram that have their own privacy notices. Please make sure you read their terms and conditions and privacy notice carefully before providing any personal data as we do not accept any responsibility or liability for these features.
21. CHANGES TO THIS PRIVACY POLICY
This Privacy Policy replaces all previous versions. We reserve the right to update or alter this Privacy Policy from time to time so please check it regularly on our Sites for any updates. You can request a copy of a previous version of our Privacy Policy. If the changes are significant, we will obtain your consent or provide a prominent notice on our Sites if and where this is required by applicable data protection laws.
Last update: April 2021
SCHEDULE ONE – ADDITIONAL PROVISIONS FOR BANKING TRANSACTIONS IN THE EEA
In order to provide the Services, certain of the information we collect (as set out in this Privacy Policy) may be required to be transferred to other related companies or other entities, including those referred to in this section in their capacity as payment providers, payment processors or account holders (or similar capacities). You acknowledge that according to their local legislation, such entities may be subject to laws, regulations, inquiries, investigations, or orders which may require the disclosure of information to the relevant authorities of the relevant country. Your use of the Services constitutes your consent to our transfer of such information to provide you the Services.
Specifically, you consent to and direct to disclose necessary information to: (i) the police and other law enforcement agencies; (ii) security forces; (iii) competent governmental, intergovernmental or supranational bodies; (iv) competent agencies, departments, regulatory authorities, self-regulatory authorities or organisations, and other third parties, including companies, that: (a) we are legally compelled and permitted to comply with, including but without limitation the Luxembourg laws of 24 July 2015 on the US Foreign Account Tax Compliance Act (“FATCA Law”) and 18 December 2015 on the OECD common reporting standard (“CRS Law”); (b) we have reason to believe it is appropriate for us to cooperate with in investigations of fraud or other illegal activity or potential illegal activity; or (c) to conduct investigations of violations of our terms and conditions (including without limitation, your funding source or credit or debit card provider). If you are covered by the FATCA or CRS Law, we are required to give you notice of the information about you that we may transfer to various authorities. We may also share, access and use (including from other countries) necessary information (including, without limitation the information recorded by fraud prevention agencies) to help us and them assess and to manage risk (including, without limitation, to prevent fraud, money laundering and terrorist financing). Please contact us if you want to receive further details of the relevant fraud prevention agencies.
By using this website, you agree to our use of cookies. We use cookies to provide you with a great experience and to help our website run effectively.