PORTAL ONLINE INTERFACE AND LINK PRO APP PRIVACY NOTICE

PURPOSE OF THIS PRIVACY NOTICE

This Privacy Notice aims to give you information on how Ideal Boilers Limited (t/a Ideal Heating) collects and processes your personal data through your use of:

· the Ideal Link Pro mobile application ("App"), once you have downloaded a copy of the App onto your mobile telephone or handheld device ("Device"); and

· the Ideal Portal online interface for installers and certain specified employees of Ideal Boilers Limited available at www.installeridealheating.com ("Portal Site"), together the "Portal Tools".

This Privacy Notice applies to the App, the Portal Site and any of the services accessible through the Portal Tools. The Portal Tools are not intended for children and we do not knowingly collect data relating to children.

This Privacy Notice applies to current employees, workers, contractors or agents (who are part of the customer services team and use the Portal Site) and third party installers who install boilers manufactured by and on behalf of Ideal Boilers and use either of the Portal Tools. This does not form part of any contract of employment or other contract to provide services. Where applicable, this Privacy Notice is supplemental to the Ideal Boilers Limited employee privacy notice (as updated from time to time) and should be read in conjunction with the provisions of such privacy notice.

It is important that you read this Privacy Notice together with any other Privacy Notice or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Privacy Notice supplements other notices and privacy policies and is not intended to override them.

We are subject to both the EU General Data Protection Regulation ("EU GDPR") in relation to our use of personal data about individuals in the European Union when we offer our services directly to you in the Republic of Ireland ("ROI") and the UK General Data Protection Regulation ("UK GDPR") in relation to our use of personal data about individuals in the UK. The UK GDPR is a version of the EU GDPR that has been incorporated into UK law. This Privacy Notice is intended to satisfy our obligations to tell you about how we use your personal data under both the EU and UK General Data Protection Regulation.

IMPORTANT INFORMATION AND WHO WE ARE

Ideal Boilers Limited is part of the Groupe Atlantic UK & ROI Group. When we mention “Ideal Boilers” "we", "us" or "our" in this Privacy Notice, we are referring to Ideal Boilers Limited. Ideal Boilers Limited is the controller responsible for the personal data collected via the Portal Tools as it determines how and why the personal data is used.

We have a data protection officer ("DPO") who is responsible for overseeing questions in relation to this Privacy Notice and our use of personal data. If you have any questions about this Privacy Notice, including any requests to exercise your legal rights, please contact the DPO using the details set out below.

Contact details

Our full details are:

Full name of legal entity: Ideal Boilers Limited ( t/a Ideal Heating)

Email address: DPO@groupe-atlantic.co.uk

Postal address: Box 103 National Avenue, Hull HU5 4JN

Telephone number: 01482 498660

You have the right to make a complaint at any time to the Information Commissioner’s Office ("ICO"), the UK supervisory authority for data protection issues (www.ico.org.uk) or the Data Protection Commission, the Republic of Ireland supervisory authority for data protection issues ( https://www.dataprotection.ie/ ).

Third party links

Please note that these websites and any services that may be accessible through them have their own privacy policies and that we do not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services, such as Contact Data. Please check these policies before you submit any personal data to these websites or use these services.

THE DATA WE COLLECT ABOUT YOU

We may collect, use, store and transfer different kinds of personal data about you as follows:

Identity Data

first name, last name, username or similar identifier

Contact Data

email address, address and telephone numbers

Employment Data (in respect of our employees or workers or contractors that use Portal Site)

job title, location of employment or workplace, gas safe registration number (if applicable)

Technical Data

includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Portal Site.

Device Data (in respect of the App)

includes the type of mobile device you use, a unique device identifier, the MAC address of the Device’s wireless network interface, your mobile operating system, the type of mobile browser you use, time zone setting; your use of the App

Usage Data

includes details of your use of the Portal Tools, products and services.

Marketing and Communications Data

includes your preferences in receiving marketing from us and your communication preferences.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific feature from the Portal Tools or to ascertain other trends in boiler usage in order to develop predictive or preventative maintenance processes or tools. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Notice.

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

IF YOU FAIL TO PROVIDE PERSONAL DATA

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

HOW IS YOUR PERSONAL DATA COLLECTED?

We will collect and process the following data about you:

  • Information you give us. This is information (including Identity, Contact, and Marketing and Communications Data) you give us by filling in forms on any of the Portal Tools by corresponding with us (for example, by email or chat). It includes information you provide when you register to use the App, enter a competition or promotion, join our loyalty scheme or complete a survey, report a problem with the Portal Tools, or give us feedback or contact us.
  • Information we collect about you from your Device. Each time you use the Portal Tools we will automatically collect certain data including Device, Technical and Usage Data (to the extent that each constitutes personal data).

HOW WE USE YOUR PERSONAL DATA

We will only use your personal data when the law allows us to do so. Most commonly we will use your personal data in the following circumstances:

· Where you have consented before the processing.

· Where we need to perform a contract we are about to enter or have entered with you.

· Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

· Where we need to comply with a legal or regulatory obligation.

We will only send you direct marketing communications by email or text if we have your consent. You have the right to withdraw that consent at any time by contacting us using the following details Po Box 103, National Avenue, Hull, HU5 4JN or by email on DPO@groupe-atlantic.co.uk.

Purposes for which we will use your personal data

Purpose/activity

Type of data

Lawful basis for processing

To install the App

Identity

Contact

Device

Your consent

To provide training and access to the Portal Site

Identity

Contact

Employment

Device

Performance of a contract with you

Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security)

To register you as a new user of the Portal Tools

Identity

Contact

Device

Performance of a contract with you

To provide Services via the Portal Tools (for example to allow you to view a homeowner's boiler via the Portal Site)

Identity

Device

Usage

Performance of a contract with you

To manage our relationship with you including notifying you of changes to the Portal Tools (including the Portal Tool's terms of use)

Identity

Contact

Performance of a contract with you

Necessary for our legitimate interests (to supply an Portal Tool which compliments the boilers we supply and gives greater access to information about boilers)

To manage our relationship with you (where you are an installer) which will include asking you to leave a review or take a survey

Identity

Contact

Device

Performance of a contract with you

Necessary for our legitimate interests (to analyse how installers use our products/services and to develop and improve those products/services)

To administer and protect our business and the Portal Tools including troubleshooting, data analysis and system testing

Identity

Contact

Device

Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security)

To monitor trends so we can improve the Portal Tools

Device

Usage

Necessary for our legitimate interests (to make improvements to the Portal Tools to offer a better service to our installers for the benefit of our brand)

Where we rely on legitimate interests as set out above we balance the legitimate interests against your rights and freedoms before we process your personal data for our legitimate interests. We will only use your personal data for our legitimate interests where our interests are not overridden by your rights and freedoms and have we carefully assessed that this is the case.

MARKETING AND OPTING OUT

This section on marketing only applies to installers.

We strive to provide you with choices regarding certain personal data uses, particularly around marketing. You can update your marketing preferences at any time in the Portal Site.

You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or contact us via email to DPO@groupe-atlantic.co.uk.

Where you opt out of receiving these marketing messages, this will not affect our use of the personal data provided to us as a result of services provided by the Portal Tools.

DISCLOSURES OF YOUR PERSONAL DATA

We may share your personal data with the parties set out below for the purposes set out in the table in the Purposes for which we will use your personal data section of this Privacy Notice.

· Internal Third Parties: Other companies within the Groupe Atlantic UK & ROI Group, who are based in UK and ROI and provide IT and system administration services.

· External Third Parties:

o Service providers who provide IT and system administration services (including IT developers).

o Professional advisers including lawyers, bankers, auditors and insurers based in UK who provide consultancy, banking, legal, insurance and accounting services.

o HM Revenue and Customs, regulators and other authorities acting as processors or joint controllers based in the UK who require reporting of processing activities in certain circumstances.

o Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Privacy Notice.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law.

INTERNATIONAL TRANSFERS

Your personal data may be processed both within the UK and within the EEA.

Due to the international nature of our business, we may process your personal data both nationally and internationally for the purposes set out above. This will include transferring your personal data outside either the United Kingdom (UK) or the European Economic Area (EEA) (including to other members of our Group) depending on where we are located.

The Groupe Atlantic Group has a presence globally and the countries outside of the UK and EEA which we may transfer your personal data to include but are not limited to, the United States of America and Canada.

If we transfer your personal data outside of the UK or the EEA, we will ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

· we will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the ICO, for example the adequacy decision in place in relation to transfers of personal data between the EEA and the UK (which achieves compliance with the EU GDPR) and the adequacy regulations in relation to transfers of personal data between the UK and the EEA (which achieves compliance with the UK GDPR), there are also similar adequacy decisions and adequacy regulations in place in relation to transfers of personal data from the EEA to Canada and from the UK to Canada on which we may also rely; or

· we may use specific contracts which give personal data the same protection it has in the UK or the EEA (as applicable). For further details, see here and here for compliance with the UK GDPR and for compliance with the EU GDPR see here . Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK or the EEA (as applicable).

DATA SECURITY

All information you provide to us is stored on our secure servers and encrypted using Secured Sockets Layer Technology (SSL).

Once we have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way.

We have put in place procedures to deal with any suspected personal data breach and will notify you and the ICO when we are legally required to do so.

DATA RETENTION

By law we have to keep basic information about our installers (including financial records) for eight years after they cease being installers for tax purposes all other personal data deleted as set out below.

For employees, workers and contractors, we will retain your personal data in accordance with the terms of our employee privacy notice.

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

In some circumstances you can ask us to delete your personal data. See the Your legal rights section of this Privacy Notice below for further information.

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research, data analytics or statistical purposes (including predictive and preventative maintenance), in which case we may use this information indefinitely without further notice to you.

In the event that you do not use the App for a period of two years then we will treat the account as expired and your personal data may be deleted.

YOUR LEGAL RIGHTS

Under certain circumstances you have the following rights under data protection laws in relation to your personal data.

You have the right to:

  • Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you subject to certain exemptions. We may require further information in order to respond to your request (for instance, evidence of your identity and information to enable us to locate the specific

personal data you require).

  • Request correction of the personal data that we hold about you where it is incorrect or incomplete. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data in certain circumstances. For example:

o this enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it.

o you also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below);

o where we may have processed your information unlawfully;

o where we are required to erase your personal data to comply with the law;

o if you withdraw your consent and there is no other legal ground for which we rely on the continued use of your personal data.

Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

  • Object to processing of your personal data where we are relying on our legitimate interests (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. Where you object to our processing on this ground, you must give specific reasons based on your particular situation concerning why you are objecting to the processing of your personal data and we shall no longer process your personal data unless: (i) we can demonstrate that we have compelling legitimate grounds for processing your information which override your interests, rights and freedoms; or (ii) the data is needed for the establishment, exercise or defence of legal claims.

You also have the right to object where we are processing your personal data for direct marketing purposes.

  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

o if you want us to establish the data’s accuracy;

o where our use of the data is unlawful but you do not want us to erase it;

o where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or

o you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies:

o to personal data which you provided to us;

o where the use of your personal data is based on your consent or where we used the information to perform a contract with you; and

o where the use of your personal data is carried out by automated (i.e. electronic) means.

  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

You also have the right to ask us not to continue to process your personal data for marketing purposes.You can exercise any of these rights at any time by contacting us at Po Box 103, National Avenue, Hull, HU5 4JN or DPO@groupe-atlantic.co.uk.

If you are an employee or worker or contractor of Ideal Boilers, please follow the processes set out in the Employee Privacy Notice if you want to exercise any of your rights.

Changes to the Privacy Notice and your duty to inform us of changes

We keep our Privacy Notice under regular review.

This version was last updated on 15/08/2022. It may change and if it does, these changes will be posted on this page and, where appropriate, notified to you by email in advance, or when you next start the App, the or the Portal Site. The new policy may be displayed on-screen and you may be required to confirm you have read the changes to continue your use of the Portal Tools.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during our relationship with you.