Introduction
Card Protection Plan Limited (“we/our/us”) respects your privacy and is committed to protecting your personal data.
When you use our website at www.cppdirect.co.uk (the “Site”), you may choose to access the members area for your CPP Card Protection or CPP Identity Protection Alert products. If you log in to your CPP Identity Protection Alert members area, you will stay on this website (the “IPA Members Area”). If you choose to log in to your CPP Card Protection product, you will be redirected to www.cpp.co.uk/servicing. The privacy notice in relation to the Card Site can be found on that site.
This Privacy Notice will inform you as to how we look after your personal data when you visit the Site (regardless of where you visit them from) and tell you about your privacy rights and how the law protects you.
1. Important information and who we are
Purpose of this Privacy Notice
This Privacy Notice aims to give you information on how Card Protection Plan Limited collects and processes your personal data through your use of the Site, including any data you may provide to us.
The Site is not intended for children and we do not knowingly collect data relating to children.
It is important that you read this Privacy Notice together with any other Privacy Notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Privacy Notice supplements the other notices and is not intended to override them.
Controller
Card Protection Plan Limited is the controller and responsible for your personal data (referred to as "we", "us" or "our" in this Privacy Notice). We are a company registered in England and Wales under company number 1490503 and we are registered as a data controller with the Information Commissioner’s Office (“ICO”) with number Z5773216. Our registered office is at 6 East Parade, Leeds, LS1 2AD. We are part of the CPPGroup Plc group of companies (“CPP Group”). If you have any questions about this Privacy Notice, including any requests to exercise your legal rights, please contact us using the details set out below.
Homecare Insurance Limited (“Homecare”) is also a controller with Card Protection Plan Limited in relation to the IPA Members Area and responsible for your personal data in relation to the CPP Identity Protection policy. Homecare is a company registered in England and Wales under company number 2793290 and registered as a data controller with the Information Commissioner’s Office (“ICO”) with number Z5107254. Homecare’s registered office is at 6 East Parade, Leeds, LS1 2AD. Homecare is also part of the CPPGroup. If you are using the IPA Members Area then references to "we", "us" or "our" will also include Homecare.
Contact details
You can contact us:
- by post at: Data Protection, Card Protection Plan Ltd, PO Box 1419 Sunderland, SR5 9RN;
- If you are logged in to the IPA Members Area, by phone on the number displayed on the ‘Need Help’ section;
- by completing the form on the ‘Contact us’ page of the Site or IPA Members Area; or
- by email at: DataPrivacy@cpp.co.uk.
Changes to the Privacy Notice and your duty to inform us of changes
We may change this Privacy Notice from time to time by updating this page. We will not necessarily bring changes or updates to your attention so please revisit this page periodically to re-read this privacy statement and to ensure you are aware of any changes when you visit the Site. If there are substantive changes, we may at our discretion bring those to your attention, for example, by a message posted on the landing page of the Site.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Third-party links
The Site may include links to third-party websites, which may include websites provided by other companies within the CPP Group. Clicking on those links may allow these third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Site, we encourage you to read the privacy notice of every website you visit.
2. The data we collect about you
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
The ways in which we will use your data collected on the Site, and/or the IPA Members Area while you have a CPP Identity Protection product, are outlined in the Privacy Notice - we recommend you read these carefully.
When using the Site, we may collect and process the following data about you:
Information you give us. This may include:
- contact details you may provide to support a query you raise using the ‘Contact us’ form e.g. policy queries or complaints.
- login credentials such as surname, policy number, security answers which may include card payment details, mother’s maiden name, home or mobile telephone number, email address or postcode, and one-time passcode, used for accessing the IPA Members Area.
When using the Site, we may automatically collect and process data about you:
This may include:
- technical information, including the Internet Protocol (IP) address used to connect your computer to the Internet, and the type of device you are using to access the Site, resolution of the screen and operating system; and
- information about your visit such as whether you have visited the Site before and information collected through the use of Google Analytics which is anonymised. We collect statistical information such as the number of visitors to certain areas of the Site during a given period. We collect this information for statistical review only and it cannot be used to identify an individual user.
When using the IPA Members Area, we may also collect and process the following data about you:
Information you give us. This may include:
- your name and contact information (including e-mail address and landline or mobile phone number), home address, and policy number (where relevant).
- login credentials such as username, passwords and pass phrase questions and answers used for accessing the IPA Members Area, as well as any new information you provide if you update these details.
If you fail to provide personal data
Where we need to collect and use personal information by law, to provide you with the features of your CPP Identity Protection product or in order to respond to a query you have raised for example through the ‘Contact Us’ form on the Site, and you fail to provide that information when requested, we may not be able to perform the contract for the CPP Identity Protection product or we may not be able to respond to you and/or action your request.
3. How is your personal data collected?
We use different methods to collect data from and about you including through:
- Direct interactions. You may submit personal data (such as your contact details) by filling in the ‘Contact Us’ form on the Site or by corresponding with us by phone, e-mail or otherwise. When using the IPA Members Area you may also submit new personal information such as updating your home address, email address and mobile phone number.
- Automated technologies or interactions. As you interact with our Site, we may automatically collect technical data about your equipment, browsing actions and patterns as described in section 1 above. Google Analytics will collect information about your online activity on the Site, such as the web pages you visit, the links you click, and where relevant, the searches you conduct on the Site. For more information on our use of Google Analytics, please see our Cookie Policy.
4. Purposes for which we will use your personal data
We have set out below, in a table format, a description of all the ways we plan to use your personal data collected when using the Site and/or the IPA Members Area, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Data Controller |
Website |
Purpose/Activity |
Lawful basis for processing including basis of legitimate interest |
Homecare |
IPA Members Area |
To process, provide you with and manage the CPP Identity Protection policy and provide the benefits described in your terms and conditions |
Performance of the policy for CPP Identity Protection |
Homecare |
IPA Members Area |
To communicate with you by e-mail, telephone or post if you have purchased a policy from us, either regarding the purchase or other matters regarding transactions between you and us or your customer relationship with us |
Performance of the policy CPP Identity Protection |
CPP |
IPA Members Area |
To process, provide you with and manage the agreement between CPP and you for CPP Identity Protection (“CPP Agreement”) and provide the benefits described in your terms and conditions |
Performance of the CPP Agreement (“CPP Agreement”) |
CPP |
IPA Members Area |
To communicate with you by e-mail, telephone or post if you have purchased a policy from us, either regarding the purchase or other matters regarding transactions between you and us or your customer relationship with us |
Performance of the CPP Agreement |
Homecare and CPP |
IPA Members Area |
Internal record keeping |
(a) Necessary for our legitimate interests (for running our business) (b) Necessary to comply with a legal obligation |
Homecare and CPP |
Site IPA Members Area |
To contact you regarding any specific enquiry you make via the ‘Contact Us’ form |
(a) Performance of the Policy for CPP Identity Protection in relation to Homecare (if you hold a CPP Identity Protection product) or performance of the CPP Agreement in relation to CPP (b) Necessary for our legitimate interests (for running our business, to develop our business) |
Homecare and CPP |
Site IPA Members Area |
Statistical analysis |
Necessary for our legitimate interests (to study statistical trends within the business, to develop its business and inform its marketing strategy) |
Cookies
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the Site may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy.
5. Disclosures of your personal data
If you access the Site and/or the IPA Members Area we may have to share your personal data with the parties set out below for the purposes set out in the table in paragraph 3 above:
Service Providers
Your personal information will be made available to our authorised service providers (which will include other companies within the CPP Group which provide services to us) and third party suppliers which perform certain services on our behalf e.g. providing certain features of your CPP Identity Protection (where relevant), providing IT support and maintenance, providing hosting services, providing online payment services and providing marketing services.
These service providers may have access to personal information needed to perform their functions on our behalf but are not permitted to share or to use such information for any other purpose. We require all third parties to respect the security of your personal information and to treat it in accordance with the law.
Other companies within the CPP Group
We may share limited personal information with other companies within the CPP Group e.g. to the extent needed for proper management and parental analysis and decision making.
Other Organisations
We may also disclose your personal information:
- In response to a court order, or a request for cooperation from a law enforcement or other government agency;
- To establish or exercise our legal rights; to defend legal claims; or as otherwise required or permitted by applicable laws and/or regulations;
- When we believe that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding illegal activity, suspected fraud, or other wrongdoing; to protect and defend the rights, property or safety of us, other CPP Group members, customers, staff, suppliers or others; to comply with applicable law or cooperate with law enforcement; or to enforce our terms or other agreements;
- To prospective or actual buyers in the event that we sell any of our business or assets, or to other CPP Group members in the event of a reorganisation
We will not otherwise transfer, disclose, sell, distribute or lease your personal information to third parties unless we have your permission to do so or are otherwise required or permitted to do so by law.
Experian (IPA Members Area only)
To use the Experian Identity Plus service provided as a feature of your Identity Protection Alert product, you will be required to register with Experian and when you register, you will be required to agree to their Privacy Policy (which can be found at https://creditreport.cpp.experian.co.uk/PDF/CPP_PrivacyPolicy_20180525.pdf)
If you request a copy of your credit report, your personal details will be passed to Experian so they can provide you with a copy of this report. Experian will verify your identity by checking the details you provide against details held on databases to which they have access. Experian will keep a record of this check which may be used by other organisations for verification and fraud prevention services. If you have requested a copy of your credit report, we may provide Experian your updated personal and contact information to ensure that their records remain accurate. If you register for Experian’s Identity Plus Web Monitoring services, the ‘Privacy Policy’ on the website at https://creditreport.cpp.experian.co.uk/PDF/CPP PrivacyPolicy_20180525.pdf will explain how your personal information is used. They will only share your personally identifiable information with third parties to carry out your instructions and to provide specific services.
All communications between you and the Experian Identity Plus website, while logged in, are protected through secure socket layer (SSL) encryption. All information you provide to them is stored on their secure servers. Experian asks for your permission before sending you email communications.
6. International transfers
We will ensure that if we transfer your personal information from the United Kingdom or countries inside the European Economic Area (EEA) to countries outside the EEA, adequate safeguards are put in place to protect your personal information.
Please contact us using the contact details set out in section 1 of this Privacy Notice if you want further information on the specific mechanism used by us when transferring your personal data to countries outside the EEA.
7. Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Should your details to log into the IPA Members Area be entered incorrectly on 7 occasions, your on-line account will be locked, although your policy can still be accessed by telephoning customer services. This is to protect your on-line account from misuse. Your account will also 'timeout' after 15 minutes during which no activity is recorded. This will reduce the risk of someone using your account without permission if you have forgotten to logout. If you need to reset your on-line account details for whatever reason you can request help and guidance on-line or by telephoning customer services.
Do not give your on-line account details to anyone not authorised to use your on-line account. We or our employees will never request that you disclose this information at any time other than when you use the IPA Members Area.
8. Data retention
How long will you use my personal data for?
We will retain your personal information for the period necessary to fulfil the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law. Please note that by law we have to keep basic information about our customers (including contact details, financial information and details relating to policies) for at least six years after they cease being a customer for tax and legal purposes.
9. Your legal rights
Under certain circumstances, by law you have the right to:
- Request access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected. If you think any information we have about you is incorrect or incomplete, please contact us as soon as you can using the contact details set out below. We will correct or update any information as soon as possible.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal information to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal information to another party.
If you want to review, verify, correct or request erasure of your personal data, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, you can contact us:
- by post at: Data Protection, Card Protection Plan Limited, PO Box 1419 Sunderland, SR5 9RN
- by email at: DataPrivacy@cpp.co.uk
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
We may need to request specific information from you to help confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
We will try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
You also have the right to make a complaint at any time to the ICO, the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.