OVERVIEW OF THIS POLICY AND COMMITMENTS TO PRIVACY
Eco World-Ballymore Holding Company Limited (“Eco World-Ballymore“), regularly collects and uses personal data about current, former or prospective purchasers, when you make a reservation, note interest in a property or purchase a property in one of our developments or when you browse our corporate website https://www.ecoworldballymore.com/ or any of the websites for developments of Eco World-Ballymore, in particular Embassy Gardens, Wardian London and London City Island (each a “Website“).
Personal data is any information that can be used to identify you as an individual. The protection of your personal data is very important to us, and we understand our responsibilities to handle your personal data with care and to comply with legal requirements.
- WHO IS RESPONSIBLE FOR LOOKING AFTER YOUR PERSONAL DATA?Eco World-Ballymore is a joint venture between EcoWorld International Berhad (through Eco World ACE Co Ltd) and Ballymore (through ACE Investment Holdings Limited), with a registration number 117383 and having its place of incorporation at 22 Grenville Street, St Helier, Jersey, JE4 8PX (the joint venture and each entity of the joint venture together, “we“, “us“, “our” for the purpose of this Policy). A list of the developments within our current portfolio can be found here https://www.ecoworldballymore.com/.
Eco World-Ballymore is the ultimate Data Controller of any personal data that you provide to us, and we collect from you and can be contacted using the details set in section 9 below.
- WHAT PERSONAL DATA DO WE COLLECT?In relation to potential, historic and current purchasers (“purchaser“, “you“), we collect the following data directly from you in the course of managing your reservation or registration of interest form, monitoring your use of our Website or in the process of managing the sale of any property in our development:
- 2.1 contact details such as your name, address, telephone number and email address*,
- 2.2 demographic information such as postcode, preferences and interests, including any information you complete on a survey to tell us how we might improve our service offering,
- 2.3 property information including details of the property that you are interested in or you have purchased*;
- 2.4 marketing data including your preferences in receiving marketing from us and your communication preferences, and
- 2.5 device data including IP addresses and details about your browsing history, browser type, and session frequency and cookies – please see our separate cookie information page for further details on cookies.The information marked with an * is mandatory, otherwise we would be unable to fulfil our contractual obligations to you pursuant to our contract or to respond to any enquiries you make on an interest form.
- WHAT PURPOSES DO WE USE YOUR PERSONAL DATA FOR AND WHAT IS THE LEGAL BASIS?We will use your personal data to:
- 3.1 comply with internal record keeping requirements.
- 3.2 process information that you provide by filling in forms on our Website or a reservation or registration of interest format one of our sales offices.
- 3.3 deal with any concerns if you contact us with a query or issue.
- 3.4 in order to contact you with details of the progress on your purchase or in the event that we need to contact you urgently about an issue with the property.
- 3.5 carry out our obligations arising from any contracts entered into between you and us, including law enforcement agencies where we consider it necessary to fulfil legal obligations.
- 3.6 ensure that content from our Website is presented in the most effective manner for you and for your computer.
- 3.7 notify you about changes to our service.
We have to establish a legal ground to use your personal data, so we will make sure that we only use your personal data for the purposes set out in this Section 3 and in Appendix 1 where we are satisfied that our use of your personal data is necessary to:
- 3.8 perform a contract or take steps to enter into a contract with you, or
- 3.9 comply with a relevant legal or regulatory obligation that we are subject to (e.g. to comply with ICO requirements), or
- 3.10 support ‘Legitimate Interests’ that we have as a business (for example, to improve our service, or to carry out analytics across
our datasets), provided it is always carried out in a way that is proportionate, and that respects your privacy rights.
- PLEASE NOTE: If we have previously told you that we were relying on consent as the basis of our processing activities, going forward we will not be relying on that legal basis unless we have said that in this Policy.
- WHO DO WE SHARE YOUR PERSONAL DATA WITH?We share the data with the following entities who will also act in the capacity of an independent Data Controller:
- 4.1 Associated companies of: (a) Eco World-Ballymore (Eco World-Ballymore Embassy Gardens Company Limited, Eco World-Ballymore London City Island Company Limited, Eco World-Ballymore Arrowhead Quay Company Limited), for the purposes of: marketing activities relating to their developments (b) Associated companies of Eco World ACE Co Ltd detailed here http://ecoworldinternational.com/corporate-structure/, for the purposes of: marketing activities relating to their developments; and (c) Associated companies of ACE Investment Holdings Limited, in particular joint venture partners of Ballymore branded or co-branded property developments;
- 4.2 our solicitors and third party corporate service providers at an appropriate point in any sales process, where details of prospective purchasers are passed to enable them to prepare relevant paperwork to complete the conveyancing process;
- 4.3 our managing and marketing agents Whistleglade Company and Eco World International Marketing Sdn Bhd who have delegated authority on behalf of Eco World-Ballymore for the purposes of: managing the conduct of negotiations with investors and, where relevant, managing the subsequent sale process through to completion, provision of promotion and marketing services, operating our on-site marketing suite / project branded website;
- 4.4 third parties that manage our properties and collect service charges;
- 4.5 Utility companies who provide services to a property that you have purchased; and
- 4.6 regulators and authorities, which include the ICO and HMRC, as well as other regulators and law enforcement agencies in the E.U. and around the world, in particular National Crime Agency, the National House-Building Council, local authorities and other professional services firms (including our auditors, lawyers, bankers, anti-money laundering agencies and insurers who provide consultancy, banking, legal, insurance and accounting services) for the purpose of ensuring that we comply with our legal obligations.
To ensure we manage our developments in a streamlined manner, we also share the data with the following third parties who act on our behalf in the capacity of processor:
Services Providers, who provide database, IT and system administration services, such as Salesforce which is based in the USA. Also, if we were to sell part of our businesses we would need to transfer your personal data to the purchaser.
- DIRECT MARKETINGWe may use your personal data to send you direct marketing communications about our developments. This will be in the form of email, post, SMS or targeted online advertisements.
Where we require explicit opt-in consent for direct marketing in accordance with the Privacy and Electronic Communications Regulations we will ask for your consent – we may also ask if you wish to receive marketing from any of our Associated Companies listed in Section 4 above. Otherwise, for non-electronic marketing or where we can rely on the soft opt-in exemption under the Privacy and Electronic Communications Regulations, we will be relying on our Legitimate Interests for the purposes of GDPR as further detailed in Section 3 and Appendix 1.
We also use your personal data for customising or personalising advertisements, offers and content made available to you based on your visits to and/or usage of our Website, and analyse the performance of those advertisements, offers and content. This constitutes ‘profiling’ – it does not have any significant legal impact on you but simply means we can ensure marketing materials are tailored to your preferences or what we think you will be interested in.
You have a right to stop receiving direct marketing at any time – you can do this by following the opt-out links in electronic communications (such as emails), or by contacting us using the details in Section 9.
- INTERNATIONAL TRANSFERSWe will always take steps to ensure that any international transfer of information is carefully managed to protect your rights and interests, in particular we will either:
- 6.1 only transfer your personal data to countries which are recognised as providing an adequate level of legal protection in accordance with Article 45 of the GDPR, in particular Jersey & Malaysia; or
- 6.2 ensure that transfers outside your country are subject to additional safeguards required under local law – for example, the EU Model Clauses pursuant to Article 46(2) of the GDPR.
You have the right to ask us for more information about the safeguards we have put in place as mentioned above. Contact us as set out in Section 9 if you would like further information or to request a copy where the safeguard is documented (which may be redacted to ensure confidentiality).
- HOW LONG DO WE KEEP YOUR PERSONAL DATA?We will retain your personal data for as long as is reasonably necessary for the purposes listed in Section 3 of this Policy. Where there has been no interaction from a purchaser, a record will be archived and deleted in line with our data retention policy.
Where we are required to do so to meet legal, regulatory, tax or accounting requirements, we will retain your personal data for longer periods of time, but only where permitted to do so, including so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a possibility of legal action relating to your personal data or dealings.
We maintain a data retention policy which we apply to records in our care. Where your personal data is no longer required and we do not have a legal requirement to retain it, we will ensure it is either securely deleted or stored in a way such that it is anonymised and the personal data is no longer used by the business.
- WHAT ARE YOUR RIGHTS?You have a number of rights in relation to your personal data. In summary, you have the right to request: access to your data; rectification of any mistakes in our files; erasure of records where no longer required; restriction on the processing of your data; objection to the processing of your data; data portability; and various information in relation to the basis of any international transfers. You also have the right to complain to your supervisory authority (further details of which are set out in Section 9 below). These are defined in more detail as follows:
RIGHT WHAT THIS MEANS Access You can ask us to:
• confirm whether we are processing your personal data;
• give you a copy of that data;
• provide you with other information about your personal data such as what data we have, what we use it for, who we disclose it to, whether we transfer it abroad and how we protect it, how long we keep it for, what rights you have, how you can make a complaint, where we got your data from and whether we have carried out automated decision making or profiling, to the extent that information has not already been provided to you in this Policy.
Rectification You can ask us to rectify inaccurate personal data. We may seek to verify the accuracy of the data before rectifying it. Erasure / Right to be Forgotten You can ask us to erase your personal data, but only where:
• it is no longer needed for the purposes for which it was collected; or
you have withdrawn your consent (where the data processing was based on consent); or
• it follows a successful right to object (see ‘Objection’ below); or
• it has been processed unlawfully; or
• it is necessary to comply with a legal obligation which we are subject to.
We are not required to comply with your request to erase your personal data if the processing of your personal data is necessary: for compliance with a legal obligation; or for the establishment, exercise or defence of legal claims, in relation to the freedom of expression or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.
Restriction You can ask us to restrict (i.e. keep but not use) your personal data, but only where:
• its accuracy is contested (see ‘Rectification’ below), to allow us to verify its accuracy; or
the processing is unlawful, but you do not want it erased; or
• it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise or defend legal claims; or
• you have exercised the right to object, and verification of overriding grounds is pending.
We can continue to use your personal data following a request for restriction, where:
• we have your consent; or
• to establish, exercise or defend legal claims; or
• to protect the rights of another natural or legal person.
Portability You can ask us to provide your personal data to you in a structured, commonly used, machine-readable format, or you can ask to have it ‘ported’ directly to another Data Controller, but in each case only where: the processing is based on your consent or the performance of a contract with you; and the processing is carried out by automated means. Objection You can object to any processing of your personal data which has our ‘Legitimate Interests’ as its legal basis (see Appendix 2 for further details), if you believe your fundamental rights and freedoms outweigh our Legitimate Interests. Once you have objected, we have an opportunity to demonstrate that we have compelling Legitimate Interests which override your rights.
You also have various rights in relation to any automated decision making, however we do not carry out these activities in connection with the Website.
To exercise your rights you can contact us as set out in Section 9. Please note the following if you do wish to exercise these rights:
- 8.1 Identity. We take the confidentiality of all records containing personal data seriously, and reserve the right to ask you for proof of your identity if you make a request.
- 8.2 Fees. We will not ask for a fee to exercise any of your rights in relation to your personal data, unless your request for access to information is unfounded, repetitive or excessive, in which case we will charge a reasonable amount in the circumstances.
- 8.3 Timescales. We aim to respond to any valid requests within one month unless it is particularly complicated or you have made several requests, in which case we aim to respond within three months. We will let you know if we are going to take longer than one month. We might ask you if you can help by telling us what exactly you want to receive or are concerned about. This will help us to action your request more quickly.
- 8.4 Exemptions. Local laws, including in the UK, provide for additional exemptions, in particular to the right of access, whereby personal data can be withheld from you in certain circumstances, for example where it is subject to legal privilege.
- CONTACT AND COMPLAINTSThe primary point of contact for all issues arising from this Policy, including requests to exercise data subject rights, is our development manager, who can be contacted in the following ways: firstname.lastname@example.org Whistleglade Company C/O Ballymore, 161 Marsh Wall, London E14 9SJ, United Kingdom If you have a complaint or concern about how we use your personal data, please contact us in the first instance and we will attempt to resolve the issue as soon as possible. You also have a right to lodge a complaint with your national data protection supervisory authority at any time. In the UK, the supervisory authority for data protection is the ICO (https://ico.org.uk/). We do ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time.
Activity Type of information collected The basis on which we use the information Contact you, or register you as a new customer • Contact Details
• Financial Data
• Property Information
• Performance of a contract or potential contract with you;
• Legitimate Interest to operate our business and keep our records updated.
Conduct estate management services, including collection of service charges • Contact Details
• Financial Data
• Property Information
• Performance of a contract or potential contract with you. Provide customer support and to enable you to partake in a viewing, open house, launch or event, prize draw, competition or complete a survey • Contact Details
• Demographic Information
• Marketing Data
• Performance of a contract;
• Legitimate interest for marketing activities relating to our developments and to grow our business.
To ensure that content from our Website is presented in the most effective manner for you and your computer • Contact Details
• Device Data
• Legitimate interest to develop our products or services, to provide administration & IT services and to operate & grow our business. Facilitate reservations and transactions, as well as managing our relationship with you and carrying out various credit checks • Contact Details • Performance of a contract or potential contract with you;
• Legal obligation.
Comply with legal and regulatory obligations • Contact Details and Property Information • Legal obligation. To make suggestions, recommendations and provide information to you about products or services that may be of interest to you • Contact Details
• Demographic Information
• Marketing Data
• Device Data
• Legitimate interest for marketing activities relating to our developments and to grow our business; or
• Where opt-in consent is required for electronic marketing pursuant to PECRs, consent.
Administer and protect our business and our Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) • Contact Details
• Device Data
• Performance of a contract;
• Legitimate interest to operate our business, to provide administration & IT services, for network security and for prevention of fraud.
To use data analytics to improve our Website, products/services, marketing, customer relationships and experiences • Device Data Legitimate interest to define types of customers based on their age, gender & interests for our products or services, to keep our websites updated & relevant, to develop our business and to inform our marketing strategy.
- APPENDIX 2 – GLOSSARYData Controller: means a natural or legal person which determines the means and purposes of processing of personal data.
Data Subject: means an individual whom the personal data is about.
EEA: means the European Economic Area.
GDPR: means the General Data Protection Regulation, which came into force on 25 May 2018 and replaces the previous Data Protection Directive 95/46/EC.
ICO: the Information Commissioner’s Office regulates the processing of personal data by all organisations within the UK.
Legitimate Interests: this is a ground which can be used by organisations as a lawful basis of processing, for example where personal data is used in ways that could reasonably be expected, or there is a compelling reason for the processing.
Member States: means those countries which are part of the European Union.
Privacy Shield: means a framework which has been adopted to protect the rights of those individuals whose data has been transferred to the US.
Service Providers: these are a range of third parties to whom we outsource certain functions of our business. For example, we have service providers who provide / support IT applications or systems, which means that your personal data will be hosted on their servers, but under our control and direction. We require all our service providers to respect the confidentiality and security of personal data.