Privacy Notice
Bath Spa University ("We") are committed to protecting and respecting your privacy.
This notice (together with our Terms and Conditions and any other documents referred to in them) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us or on our behalf. Certain definitions set out in the Terms and Conditions also apply in this notice. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. By visiting bathspa.hubbub.net you are accepting and consenting to the practices described in this notice.
Bath Spa University (the Data Controller) and BathSpa.Hubbub.net (the Data Processor; “the Site”) will hold and process your data securely in line with the Data Protection Act 2018 and the General Data Protection Regulations, as amended Your data will be treated confidentially and handled with the utmost care and respect and is never passed on to third parties for their uses.
Third Party Sites
If you agree to create a login for the site using your social media account (Facebook or Twitter), you will be doing so in agreement with the privacy notice associated with Shareaholic, which can be read here (https://www.shareaholic.com/privacy/). Creating an account using your social media account is optional, and should you prefer to use another method of creating an account, you may also create an account using a valid email address, providing other personal identification details when it may be required to do so on the site (for example: creating projects or making a donation projects that you wish to support).
Your financial information.
We process all donations through the Bath Spa University Stripe account. Stripe is PCI-DSS compliant. If you would like to read Stripe's privacy notice you may do so here: https://stripe.com/en-gb/privacy
How we collect information
We get data directly from you when you:
- Register to use the Site
- Fill in forms on our Site
- Correspond with us by phone, email or otherwise
- Participate in discussions on the Site
- Use the Site's social media functions
- Pledge sponsorship monies to a Project
- Register a Project
- Report a problem with a user, a Project or the Site.
What Information we collect
The personal information you provide us with may include:
- Name
- Address
- Phone or mobile number
- Email address
- Social media information
- Pledge\donation amount
- Bank account name, number and sort code
- Project relationship
- University affiliation
- Gift Aid choices
- Photograph or avatar
- Reward choices
Other information we may automatically collect for each visit to the Site include:
- Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform.
- Information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from the Site (including date and time); products you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page and any phone number used to call our user service number.
When making a single donation if you are an alumni, student or part of the university community and already on our Bath Spa University’s alumni\external affairs database a record of your donation amount will be recorded, along with gift aid status and your contact details checked and updated as appropriate on our internal database. If you are not already on our internal database but agree to gift aid your donation, your name, full address and donation amount will be added to our internal database as required by HMRC.
When setting up a direct debit payment a record of your bank account details and donation amount will be recorded, along with gift aid status and your contact details checked and updated as appropriate on our internal database.
Any personal data stored in our internal database is held on a secure pci-/dss compliant (see www.pcisecuritystandards.org/pci_security for details) database, with access restricted to authorised personnel only.
If choosing a reward your contact details, as appropriate, will be accessible by the project creator to deliver the reward.
Information we receive from other sources.
We may receive information about you if you use any of the other websites we operate or the other services we provide, including publicly available social media information about you. In this case we will have informed you when we collected that data that it may be shared internally and combined with data collected on the Site. We are also working closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them.
Cookies.
The Site uses cookies to distinguish you from other users of the Site. This helps us to provide you with a good experience when you browse the Site and also allows us to improve the Site. For detailed information on the cookies we use and the purposes for which we use them see our Cookie Policy.
Uses made of information.
We will use information held about you in various ways:
Information you give to us. We will use this information:
- if choosing a reward your contact details, as appropriate, will be accessible by the project creator to deliver the reward.
- to carry out our obligations arising from any contracts entered into between you and us and to provide you with the information and services that you request from us, such as making donations;
- to notify you about changes to our services;
- to ensure that content from the Site is presented in the most effective manner for you and for your computer.
Information we collect about you. We will use this information:
- to administer the Site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to improve the Site to ensure that content is presented in the most effective manner for you and for your computer;
- to allow you to participate in interactive features of our service, including (but not limited to) registering to use the Site, posting a Project on the Site, sending messages to other users of the Site, sponsoring a Project, and using social media tools, when you choose to do so;
- as part of our efforts to keep the Site safe and secure.
Information we receive from other sources. We may combine this information with information you give to us and information we collect about you. We may use this information and the combined information for the purposes set out above (depending on the types of information we receive).
Your use of information
Users of the Site agree not to abuse Creators' personal information. For these purposes, abuse is defined as the use of personal information for any purpose other than those specifically stated in the Creator's Project.
Users of the Site agree not to abuse Sponsors' personal information. For these purposes, abuse is defined as using personal information for any purpose other than to contact Sponsors directly with regard to the Creator's project.
Disclosure of your information. We may share your information with selected third parties including:
- Business partners, suppliers and sub-contractors for the performance of any contract we enter into with you, including, Sponsorcraft Limited, which operates the Site and processes your information on our behalf.
- Analytics and search engine providers that assist us in the improvement and optimisation of our site.
We may disclose your personal information to third parties:
- In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the seller or buyer of such business or assets.
- If Bath Spa University or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
- If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our Terms and Conditions and other agreements; or to protect the rights, property, or safety of Bath Spa University, our customers, or others.
Where we store your personal data
The data collected from you for processing is stored in Dublin, Ireland, hosted by Amazon Web Services (AWS), in line with the EU-approved AWS Data Protection Agreement and Model Clauses.
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy notice. All information you provide to us is stored on secure servers.
Where we have given you (or where you have chosen) a password which enables you to access certain parts of the Site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to the Site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Your rights
The Site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy notices and that we do not accept any responsibility or liability for these notices. Please check these policies before you submit any personal data to these websites.
Access to information
The Act gives you the right to access information held about you. Your right of access can be exercised in accordance with the Act.
Changes to our privacy notice
Any changes we may make to our privacy notice in the future will be posted on this page and, where appropriate, notified to you by email. Please check back frequently to see any updates or changes to our privacy notice.
Contact
Questions, comments and requests regarding this privacy notice are welcomed and should be addressed either by post to Newton Park, Newton St Loe, Bath, BA2 9BN or by email at crowdfund@bathspa.ac.uk.
Date of Last Review: February 2021