Your privacy is really important to us. We want you to feel confident that your details are secure with us, and we want to help make your experience on the Internet and our websites as enjoyable and easy as possible. We take many steps to ensure your data is safely stored and we will never sell your information on to third parties.
Who are we?
We are the owners of the website NuCanna.org. We are NUCANNA Ltd, a company incorporated in England and Wales under company number 11268627, with our registered address as set out below.
Who’s the Data Controller?
How to contact us
The Data Protection Officer
776-778 Barking Road
Description of Users and Acceptance of Terms
This privacy notice explains how we collect and use your personal data and tells you about your privacy rights. Not only do we want you to feel reassured, we are also under a legal obligation to let you know what personal information we collect about you, what we use it for and on what basis. We always need a good reason and we must also explain to you your rights in relation to that information. You have the right to know what information we hold about you and to have a copy of it, and you can ask us to change or sometimes delete it.
Data Subject’s Rights.
Under GDPR you have a number of Rights which we have outlined below:
- Right of Access.
You are entitled to access your personal data so that you are aware of and can verify the lawfulness of the processing. This is achieved by logging into the www.nucanna.org website. Alternatively, this can be achieved through the mechanism of Subject Access Rights (SAR) and you have the right to obtain:
- Confirmation that your data is being processed;
- Access to your personal data (a copy); and
- Other supplementary information, which corresponds to the information in this privacy notice.
- Right of Rectification. You are entitled to have personal data rectified if it is inaccurate or incomplete. This can be achieved directly through logging into the www.nucanna.org website and amending the details about yourself. Alternatively, NuCanna Ltd will respond within one month of your email request.
- Right of Erasure. You may request the deletion or removal of personal data where there is no compelling reason for its continued processing. The Right to Erasure does not provide an absolute ‘right to be forgotten,’. However, you do have a right to have personal data erased and to prevent processing in specific circumstances:
- Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed;
- When you withdraw consent (and this is the basis of processing);
- When you object to the processing and there is no overriding legitimate interest for continuing the processing;
- The personal data was unlawfully processed;
- The personal data has to be erased in order to comply with a legal obligation; and
- The personal data is processed in relation to the offer of information society services to a child, which NUCANNA Ltd does not provide.
- Right to Restrict Processing. Under GDPR, you have a right to ‘block’ or suppress processing of personal data. When processing is restricted, NUCANNA Ltd is permitted to store the personal data, but not further process it. In this event exactly what is held and why will be explained to you.
- Right to Data Portability. You may request to obtain and reuse your personal data for your own purposes across different services. This allows you to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability. The Right to Data Portability only applies:
- To personal data you have provided to NUCANNA Ltd;
- Where the processing is based on your consent or for the performance of a contract; and
- When processing is carried out by automated means.
In these circumstances NUCANNA Ltd will provide a copy of your data free of charge, without undue delay and within one month. If there is a delay to this, you will be informed.
- Right to Object. You have the right to object to:
- Processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling);
- Direct marketing (including profiling); and
- Processing for purposes of scientific/historical research and statistics.
- Identify Verification. To protect your personal data, NUCANNA Ltd will seek to verify your identity before releasing any information, which will normally be in electronic format.
- Fees and Timings. We will comply with your requests unless we have a lawful reason not to do so. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances. We will try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Storing your data
When storing and using your information, we need a legal basis for doing it.
NUCANNA Ltd processes personal data for a number of different purposes. NUCANNA Ltd will only process your personal data where there is a legal basis for doing so under data protection laws and the table below identifies these (more than one lawful basis may apply in some situations). In summary, the relevant legal bases are:
- (a) Consent: you give consent for us to process your data for a specific purpose.
- (b) Contract: the processing is necessary for a contract or agreement with you.
- (c) Legal Obligation: the processing is necessary to comply with the law.
- (d) Legitimate Interests: the processing is necessary for legitimate interests pursued by NuCanna Ltd or another organisation.
- The purposes for which we process personal data and the legal bases for doing so in each case are:
NuCanna Ltd’s ‘Legitimate Interest’ is to collect your personal data when you visit this website, for the purposes of:
- Email addresses for communications and marketing purposes;
- Financial information for payment and receipt of commissions;
- Address information for delivery;
- Pre-contract actions, such as adding items to a shopping cart.
- Signing up for a newsletters and other communications.
- Nominating third parties for us to contact to use our services and site.
How we collect information
When you browse our site or mobile application;
- When you ‘follow’, ‘like’, post to, or interact with our social media accounts
- When you contact us via our call centres, press office, social media, website, email or Live Chat;
- When you apply for a job or offer services with us by email, via the site.
- When you register an account with us.
Information that we get from third parties, including:
- A person nominating your business or services on your behalf.
- Employers and referees. If you are applying to add your business or services to our site we may contact your given referees to provide information about you and your application;
- Social media plugins. We currently use social media plugins from the following service providers who are based both inside and outside the EU: Facebook, Twitter, LinkedIn Instagram and YouTube. By providing your social media account details you are authorising that third-party provider to share with us certain information about you
- We might also receive information about you from third parties if you have indicated to such third party that you would like to hear from us.
- Third parties and marketing. We might rely on third parties under contract to help us manage our marketing communications but we won’t share your information with any third parties for their marketing purposes.
- Alternatively, we may obtain personal details from third parties. For example, where we acquire third party marketing data or information from, or derived from, public sources such as the electoral roll. This includes your name, address and other contact information, such as your email address and phone numbers.
- If you work for one of our business customers (or nominated project or initiatives) we will record your business’s name, your position in the business and the business’s address, email address and telephone numbers.
The Information We Collect/or Receive; the Purpose of Collection and Use
In the course of operating the Websites and/or interacting with you, we will collect (and/or receive) the following types of information.
When you sign up to receive any of our newsletters, respond to a survey, register for a class, purchase any product or service, or sign up to become our affiliate partner, you may be required to provide us with certain information about yourself, such as your name, address, e-mail address, address, social media information, phone number, PayPal address, credit card details and Tax ID# (only if you sign up to become our affiliate partner) (the “Contact Information”). The Contact Information is used to provide the requested product or service or information and to contact you for purposes of direct marketing of our current and future products and services.
When you place an Order, you must provide us with certain information about the products and services you are seeking to purchase. Such information is collectively called the “Order Information.” The Order Information is used to fulfill your Order.
When you wish to purchase a product or service, you will be required to provide certain information in addition to the Personal Information and Order Information noted above. Such information may include a debit card number, credit card number, expiration date, billing address, activation codes, and similar information. Such information is collectively called the “Billing Information.” Billing Information is collected and processed by our third-party payment processor operating as our agent We do not directly obtain or process any Billing Information.
We may also receive information from third parties, such as banks and credit reference agencies when we obtain authorisation for a payment you make or when undertaking an identity check.
Records of products and services that you have used. You provide much of this information yourself when you use our services. We will also generate information in the course of providing our services.
These are details of any enquiry complaint or claim you have made to NUCANNA Ltd and may include copies of correspondence and call recordings. You will provide us this information when you contact us to make an enquiry or complaint. We will also create records relating to this contact.
Proof of delivery information
Records of delivery including the signature, name and address people who sign for or accept a delivery on your behalf. You provide this information if you accept delivery of a mail item, including when you accept delivery of an item for another person, such as a neighbor.
In addition to the information noted above, we may collect additional information (collectively, the “Other Information”). Such Other Information may include:
- From You.Additional information about yourself that you voluntarily provide to us (e.g., via a survey), such as household income range, gender, product and service preferences, and other information that does not identify you personally.
- From Your Activity.Information that we automatically collect when you use the Websites, including, without limitation:
- IP addresses, which may consist of a static or dynamic IP address and will sometimes point to a specific identifiable computer or device; browser type and language; referring and exit pages and URLs; date and time; amount of time spent on particular pages; what sections of the Websites you visit; and similar data; and
- Information about your device, including the type of device; universally unique ID (“UUID”); advertising identifier (“IDFA”); MAC address; operating system and version (e.g., iOS, Android or Windows); carrier and country location; hardware and processor information (e.g., storage, chip speed, camera resolution, NFC enabled); network type (WiFi, 3G, 4G, LTE); and similar data.
- From Cookies. Information that we collect using “cookie” technology. Cookies are small packets of data that a website stores on your computer’s or mobile device’s hard drive so that your computer will “remember” information about your visit. We may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer until you delete them) to help us collect Other Information and to enhance your experience using the Websites. If you do not want us to place a cookie on your hard drive, you may be able to turn that feature off on your computer or mobile device. Please consult your Internet browser’s documentation for information on how to do this and how to delete persistent cookies. However, if you decide not to accept cookies from us, the Websites may not function properly. For more information visit www.nucanna.org/cookies
What we collect when you interact with our sites and apps
As you may already know, most sites and apps collect certain information automatically in log files about the way in which you interact with them. This includes your IP address, geographical location, device information (such as your hardware model, mobile network information, unique device identifiers), browser type, referral source, length of visit to the site or app, number of page views, the search queries you make, and similar information.
This information will be collected by us or by a third party site analytics service provider and will be collected using cookies.
As we’ve described above, we use this information to help improve our functionality and services, run diagnostics, analyse trends, track visitor movements, gather broad demographic information and personalise our services.
Below is a list of analytics providers that we use; however, such list may be subject to change based on how we wish to understand the user experience and we will endeavor to update it diligently. You may use the accompanying links to learn more about such providers and, if available, how to opt-out from their analytics collection.
For Google Analytics, please visit: https://www.google.com/analytics
For zoho Analytics please visit: https://www.zoho.com/analytics
2. From Other Sources.We also may collect or receive information from third parties, such as Facebook and/or other third-party social media sites.
Information Collected by or Through Third-Party Advertisers/Remarketers
Below is a list of advertising/remarketing providers that we use; however, such list may be subject to change based on the campaigns that we run and we will endeavor to update it diligently. You may use the accompanying links to learn more about such providers and, if available, how to opt-out from their targeted ads or other personalization features. Please note you will not necessarily be opted-out of advertising or content generally; you may still receive generic ads or content.
For Facebook, please visit: http://www.facebook.com/about/privacy
For Twitter, please visit: https://twitter.com/en/privacy
For Google, please visit: https://support.google.com/ads/answer/2662922?hl=en
In an ongoing effort to better understand our visitors, customers, and our products and services, we may analyze the Order Information and Other Information in aggregate form in order to operate, maintain, manage, and improve the Websites and/or our products and services. This aggregate information does not identify you personally. We may share this aggregate data with our affiliates, agents, and business partners. We may also disclose aggregated user statistics in order to describe our products and services to current and prospective business partners and to other third parties for other lawful purposes.
Sharing with Third Parties
Like many businesses, we contract with other companies to perform certain business-related services. We may disclose your information, including personal information in some cases, to certain types of third-party companies, but only to the extent needed to enable them to provide such services, including, without limitation, technical assistance, order fulfillment, customer service, marketing assistance, payment processing, survey collection, promotional and marketing assistance, and business operations. These other companies will have access to your information, including personal information in some cases, only as necessary to perform their functions and to the extent permitted by law. We may also disclose your information, including any personal information, to any of our parent companies, subsidiaries, affiliates, joint ventures, or other companies under common control with us in order to support delivery of our products and services.
Disclosures to Public Authorities
In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may also disclose personal information to other third parties when compelled to do so by government authorities or required by law or regulation including, but not limited to, in response to court orders and subpoenas.
Opt-Out for Direct Marketing
You may opt out at any time from the use of your personal information for direct marketing purposes by e-mailing the instructions to this email address: firstname.lastname@example.org. Please title Opt out, and allow us a reasonable time to process your request.
Accessing and Modifying Personal Information and Communication Preferences
In addition, you may manage your receipt of marketing and non-transactional communications by clicking on the “unsubscribe” link located on the bottom of any NuCanna marketing email. Customers cannot opt out of receiving transactional e-mails related to their account or their Orders. We will use commercially reasonable efforts to process such requests in a timely manner. You should be aware, however, that it is not always possible to completely remove or modify information in our subscription databases.
Information You Share on Public Forums
You should think carefully before disclosing any information in any Public Forum.
How We Protect the Information
We take commercially reasonable steps to protect the Information from loss, misuse, and unauthorized access, disclosure, alteration, or destruction, taking into account the risks involved in processing and the nature of such data, and in compliance with applicable laws and regulations. Please understand, however, that no security system is impenetrable. We cannot guarantee the security of our databases, nor can we guarantee that the Information that you supply will not be intercepted while being transmitted to and from us over the Internet. In particular, e-mail sent to or from the Websites may not be secure, and you should therefore take special care in deciding what information you send to us via e-mail.
Retention of Personal Information
We have no control over the privacy practices or the content of any of our business partners, advertisers, sponsors, or other websites to which we provide links. As such, we are not responsible for the content or the privacy policies of those third-party websites.
How to Contact Us
Or write to us at:
776-778 Barking Road