We will only use your personal information in a way that is fair to you. We will only collect information where it is necessary for us to do so and we will only collect information if it is relevant to our dealings with you. We have implemented appropriate technology and policies to safeguard your data from unauthorised access and improper use.
We undertake to ensure that all personal information in our possession is processed in accordance with the requirements of the European General Data Protection Regulation ('GDPR') and Data Protection Act ('DPA').
We may update this Policy from time to time.
Collection and Use of Information
We collect personal information (such as your name, contact details, credit card information when you request information from us, contact us, make a booking with us, and purchase items from us, including merchandise and e-tickets, or make a donation to us. We will update your information whenever we get the opportunity to keep it current, accurate and complete. We will only keep your information for as long as we are either required to by law or as is relevant for the purposes for which it was collected. We maintain a data retention policy to meet our GDPR obligations in this respect.
Any information you provide when booking with us, buying merchandise, e-tickets and other products will be used for British Motor Museum, British Motor Industry Heritage Centre and BMIHT purposes only. The credit card information you give for any online transaction is used solely for the purpose of processing that transaction.
From time to time we may send you information about other organisations which we think may be of interest to you. We may disclose your information to companies who act as 'data processors' on our behalf, some of whom may be outside the UK/EEA. However we do not sell, rent or otherwise distribute any personal information to third parties.
You may indicate your preference for receiving direct marketing by email, from us or any partner organisations with whom we may work. You will be given the opportunity on every communication we send you to indicate that you no longer wish to receive our direct marketing material. Once properly notified by you, we will stop using your information in this way.
We operate under GDPR and DPA. We ensure lawful processing of personal data by obtaining your consent; or where there is a contractual obligation to do so in providing appropriate products and services; or where processing the data is necessary for the purposes of our legitimate interests in providing appropriate products and services.
To meet our data protection obligations, we have established comprehensive and proportionate governance measures.
The DPA and GDPR apply to 'personal data' we process and the data protection principles set out the main responsibilities we are responsible for.
We must ensure that personal data shall be:
a. processed lawfully, fairly and in a transparent manner;
b. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
c. adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed;
d. accurate and where necessary kept up to date;
e. kept for no longer than is necessary for the purposes for which the personal data are processed.
We only retain personal data for the purposes for which it was collected and for a reasonable period thereafter where there is a legitimate business need or legal obligation to do so. For details of our current retention policy contact our Privacy Officer at; firstname.lastname@example.org
f. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
We use up-to-date industry procedures to protect your personal information. We have appropriate security measures in place to protect against the loss, misuse or alteration of information that we have collected from you via our websites. However please be aware that the internet is not a 100% secure medium of communication. The BMIHT cannot therefore guarantee the security of any information you input on the website or send to us on the internet. The BMIHT is not, and will not be, responsible for any damages you or others may suffer as a result of the loss of confidentiality of any such information.
Under GDPR you have the following specific rights in respect of the personal data we process:
1. The right to be informed about how we use personal data.
3. The right of access to the personal data we hold. In most cases this will be free of charge and will be provided within one month of receipt.
To obtain a copy of the personal information we hold on you, please write to us and provide us with your details or email; email@example.com.
4. The right to rectification where data is inaccurate or incomplete. In such cases we shall make any amendments or additions within one month of your request.
The right to erasure of personal data, but only in very specific circumstances, typically where the personal data is no longer necessary in relation to the purpose for which it was originally collected or processed; or, in certain cases where we have relied on consent to process the data, when that consent is withdrawn and there is no other legitimate reason for continuing to process that data; or when the individual objects to the processing and there is no overriding legitimate interest for continuing the processing.
5. The right to restrict processing, for example while we are reviewing the accuracy or completeness of data, or deciding on whether any request for erasure is valid. In such cases we shall continue to store the data, but will not further process it until such time as we have resolved the issue.
6. The right to data portability which, subject to a number of qualifying conditions, allows individuals to obtain and reuse their personal data for their own purposes across different services.
7. The right to object in cases where processing is based on legitimate interests, where our requirement to process the data is overridden by the rights of the individual concerned; or for the purposes of direct marketing (including profiling); or for processing for purposes of scientific / historical research and statistics, unless this is necessary for the performance of a public interest task.
8. Rights in relation to automated decision making and profiling.
Please contact our Privacy Officer firstname.lastname@example.org for more information about the GDPR and your rights under data protection law or if you have a complaint about data protection at the British Motor Industry Heritage Trust.
Our supervisory authority for data protection compliance is the Information Commissioner ( www.ico.org.uk):
Information Commissioner's Office
1. For statistical purposes to track how many individual unique users we have and how often they visit our websites. We collect data that lists which of our pages are most frequently visited and by which types of users and from which countries.
2. Our marketing emails may contain a single, campaign-unique "web beacon pixel" to tell us whether our emails are opened and verify any clicks through to links within the email. We may use this information for determining which of our emails are more interesting to users in order to improve the content of our emails over time.
3. We use third parties, including Google Analytics, to collect anonymous user information. To learn more about how we use a third party service to collect and use information click here .
4. When you visit the British Motor Museum websites you may notice some cookies that are not related to the British Motor Museum. When you visit one of our pages that contains embedded content, for example if you’d like to watch a video hosted on YouTube, you may be sent cookies from these websites. We have no control over the setting of these cookies. If cookies concern you, we would recommend you check the third-party websites for more information about their cookies and how to manage them.
5. Flash cookies may be used to store user preferences for media player functionality and without them some video content may not render correctly.
6. We use Cloudflare to distribute our website. They set two cookies which are strictly necessary for the website to function. More information can be found here https://www.cloudflare.com/en-gb/cookie-policy/
For more information about cookies and managing them, please visit; www.allaboutcookies.org
Measuring website usage (Google analytics)
We use Google Analytics to collect information about how people use our websites. We do this to make sure they meeting the users’ needs and to understand how we could do it better.
Google Analytics stores information about what pages you visit, how long you are on the site, how you got here and what you click on. They do not collect or store your personal information (e.g. your name or address) so this information cannot be used to identify who you are. We do not allow Google to use or share our analytics data.
Last updated 03 March 2021