Here at Express Publishing, we take all personal information you provide us with very seriously. For that reason, we have designed and implemented clear and integrated procedures that will allow us to protect and safeguard all the information we hold about you. All information submitted by you is treated in a confidential and secure way, using technical and organisational measures, and with the most efficient protection of your personal data in mind at all times.
We strongly advise you to spend some time to read and understand how we treat and protect your personal data, and we encourage you to contact us with any questions or queries you may have regarding the protection of your personal data.
16 YEARS OLD OR YOUNGER
We are deeply concerned regarding the protection of personal data of children. Therefore, if you are under the age of 16 years or equivalent minimum age depending on jurisdiction, you are advised to read this Privacy Notice with your parents or guardian. Please note that if you are under 16 years old or equivalent minimum age depending on jurisdiction, you are NOT permitted to provide us with any of your personal data, except with your parents’, guardian’s or teacher’ s explicit permission. To that end, we may use any technical means available in order for us to ensure that personal data of children under the age of 16 years or equivalent minimum age depending on jurisdiction are shared with us in a legitimate and transparent way.
WHO THE CONTROLLER OF YOUR DATA IS
Express Publishing Ltd. is a company registered in the United Kingdom under registration number 3493880 and has a wide number of branch offices and representatives around the world. It is engaged in the provision of a variety of services, including innovative teaching materials, interactive digital platform services and Certification for Vocational English.
All issues in relation to the personal data you provide to us and the way we use them are handled by our branch office in Athens, Greece, which is responsible for the processing of your personal data under the applicable data protection law.
3-5 Mac Millan Street, 111 44
Or email us at: firstname.lastname@example.org
WHAT KIND OF INFORMATION WE MAY COLLECT ABOUT YOU
Depending on the use of our services and the level of your interaction with us, we may collect any or even all of the following information:
- contact information such as full name, address and telephone number
- account settings, such as e-mail address and password, when you open an account with our website
- personal information, such as date of birth or gender
- Information so as to verify your identity, such as ID or passport number
- language school information, contact details, order history & delivery information when you use our products
- educational & professional status information, for example, if you are a teacher or a student
- navigation and browsing history when using our website and services, in order to improve our services or the way our website is displayed
Special Categories of Personal Data
Special categories of personal data include personal information pertaining to medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union memberships and any information defining sexual orientation of an individual.
Express Publishing will never request, seek or receive information pertaining to special categories of personal data from you.
HOW WE COLLECT INFORMATION FROM YOU
In most cases this information will be submitted directly by you, after we explain to you what kind of information we require on your behalf and for what purpose we need such information. Any such information may be collected when you are registering and/or using our website, when you order our products and services or when you contact us with a query etc. Please, note that all this information is collected from us in order to be able to provide you with our services. In a different case and if you choose not to submit the requested personal information when registering to our services, we may not be able to offer you our products and services.
Alternatively, we may collect such information about you from third parties, for example, if you choose to register for our services through a private language school or an affiliated examination centre, in which case you are authorising them to provide us with your personal information or if you choose to register to our website by linking this account to your social media account (such as Twitter or Facebook), in which case you are authorising that third-party provider to share with us certain information about you.
If you are a tutor, student, or learner, we may also receive information about you from your centre, training provider, or employer when they register to receive products and/or services from us. In case you share with us information about others, such as your relatives, friends or students, you are required to ensure that they understand how their personal data will be used, as well guarantee that they have granted you with their explicit consent to share their data with us.
HOW WE USE THIS INFORMATION
We will use your information for the purposes listed below either on the basis of:
- performance of your contract with us and the provision of our services to you;
- your consent (where we request it); or
- our legitimate interests (see details below).
Indicatively, we may use your information for the following purposes:
- to provide you with access to our website and/or our services in a manner convenient and optimal and with personalised content relevant to you based on your orders history or your preferences for our products (on the basis of your consent when registering on our website and our legitimate interest to ensure our website is presented in an effective and optimal manner);
- to administer and provide you with the services you requested either individually or through your language school, for example for delivering tests, examination results, customer service support and other related information, as well as sharing your information with our external service providers (on the basis of performing our contract with you);
- to keep in contact with you about our news, events, new website features or services or new books and products that we believe may interest you (either on the basis of your consent where we have requested it, or our legitimate interests to provide you with marketing communications where we may lawfully do so);
- to share your information with our publishing partners and associated companies, to enable them to contact you with information about things that may interest you (where we have your consent to do so);
- to provide customer service and support (on the basis of our contract with you) and deal with enquiries or complaints about the website and the provided services (on the basis of our legitimate interest in providing the correct products and services to our website users);
- to carry out aggregated and anonymised research about general engagement with our website, to develop and improve our services and products, to adopt a more user-friendly approach and to upgrade our IT systems (on the basis of our legitimate interest in providing the right kinds of products and services to our website users);
- to protect, investigate, and deter against fraudulent, unauthorised, or illegal activity, to comply with our policies and procedures and enforce our legal rights (on the basis of our legitimate interests to operate a safe and lawful business or where we have a legal obligation to do so);
- to analyse your personal information and create a profile of your interests and preferences so that we can contact you with information relevant to you. We may make use of additional information about you when it is available from external sources to help us do this effectively (on the basis of our legitimate interest in providing the right kinds of products and services to our website users).
What does the term “legitimate interests” mean?
Where we refer to using your information on the basis of our “legitimate interests”, we mean our legitimate business interests in conducting and managing our business and our relationship with you, including the legitimate interest we have in:
- personalising, enhancing, modifying or otherwise improving the services and/or communications that we provide to you;
- detecting and preventing fraud and operating a safe and lawful business;
- improving security and optimisation of our network, sites and services.
Where we use your information for our legitimate interests, we make sure that we take into account any potential impact that such use may have on you. Our legitimate interests don’t automatically override yours and we won’t use your information if we believe your interests should override ours, unless we have other grounds to do so (such as your consent or a legal obligation). If you have any concerns about our processing of data, please refer to details of “Your Rights to the Information We Hold about You” below.
WHO WE MIGHT SHARE YOUR INFORMATION WITH
In connection with the purposes and on the lawful grounds described above and in addition to the recipients of your information as described above, we may share your personal information with third parties that we work with such as:
- third parties connected with the provision of our services & products, for example when registering for a course or an examination we will share your personal information with your teachers, language school or affiliated center that administers the examinations in your area and solely to the extent this is required for the successful provision of our services to you;
- third parties we work with to deliver our business (including, for example, hosting or operating the website and our databases, website analytics providers in order to analyse our customer online behaviour, providers of technical assistance and support for the conduct of the deliverable examinations, financial institutions for the receipt of payment of your orders, media agencies and technical suppliers for distribution of direct marketing material etc.);
- our group of companies and any selected third party that you consent to our sharing your information with for marketing purposes.
Please note that we require third parties to maintain appropriate security to protect your information from unauthorised access or processing.
NOTE: Express Publishing will never sell or transfer without proper authorisation your personal information to any third party.
HOW WE LOOK AFTER YOUR INFORMATION AND HOW LONG WE KEEP IT FOR
We operate a policy of “privacy by design” by looking for opportunities to minimise the amount of personal information we hold about you. We use appropriate technological and operational security measures to protect your information against any unauthorised access or unlawful use, such as:
- ensuring the physical security of our offices, warehouses or other sites;
- ensuring the physical and digital security of our equipment and devices by using appropriate password protection and encryption;
- maintaining a data protection policy for, and delivering data protection training to, our employees;
- limiting access to your personal information to those in our company who need to use it in the course of their work.
We will retain your information for as long as is necessary to provide you with the services that you have requested from us or until you withdraw your consent (when we hold your personal data on the legal basis of your consent) or for as long as we reasonably require to retain the information for our lawful business purposes, such as for the purposes of exercising our legal rights or due to a legal obligation or where we are permitted to do so for purposes of academic or research purposes. We operate a data retention policy and look to find ways to reduce the amount of information we hold about you and the length of time that we need to keep it.
INTERNATIONAL TRANSFERS OF YOUR INFORMATION
YOUR RIGHTS TO THE INFORMATION WE HOLD ABOUT YOU
Informing you about your rights under the Data Protection legislation and facilitating you in understanding and exercising your rights is of great importance to us here at Express Publishing. In this section you can find information about the rights you have and the way you can exercise any of them with Express Publishing:
- the right to know what kind of personal data we hold about you, how we use them and to receive a copy of such information directly from Express Publishing (right to access);
- the right, when we hold information about you by automated means (for example, not on paper) on the legal basis of the performance of a contract with you or on the basis of your consent, to request that we transfer such information to another service provider in an accessible format (right to portability);
- the right to request the rectification, correction and/or update of your personal information (right to rectification);
- the right to ask us to limit and restrict the processing of personal information about you (right to restriction), as well as the right to object to our processing of your personal data (right to objection), in certain circumstances;
- The right to request at any time the deletion of the personal data we hold for you, unless we have a legal obligation to maintain it or a legal dispute is pending (right to deletion or to be forgotten);
- the right to ask us not to process your personal data for marketing purposes either by following the instruction in each marketing email or by contacting us directly (right to objection to direct marketing);
- the right to lodge a complaint about us with the Hellenic Data Protection Authority or the relevant authority in your country of work or residence (right to complain to an Authority).
Please note that we may need to retain certain information for our own record-keeping and research purposes or when we are obliged to do so by law. We may also need to send you service-related communications relating to your website user account, even when you have requested not to receive marketing communications.
DATA BREACH MANAGEMENT
In the event of a suspected breach relating to personal data and depending on the extent and seriousness of the breach, we will undertake immediately certain actions, including:
- restricting the extent of the breach
- undertaking the right measures for the recovery of all data
- notifying the Authorities about the breach
- evaluating the risk caused by the breach
- evaluating the way we responded to the breach so as to improve
We will accordingly request guidance and advice from the Hellenic Data Protection Authority on how to manage data breaches, as well as if and when it is important to inform the personal data subject.
ACCESSIBILITY & ACCURACY OF YOUR INFORMATION
We understand and respect your need to keep your personal information accurate and accessible. To that end, we have implemented technological and management processes and policies to maintain and secure the accuracy of all personal data we keep.
Within the scope of the exercise of your rights above, we will provide you with access to the information we hold about you, as well as with the right to rectify or supplement such information. To ensure your personal data’s safety and security, we will take all reasonable measures to verify your identity, such as require the obligatory use of a combination of a username and a password, any Two Factor Authentication tools, if applicable, as well as any other technical means that may be available and appropriate.
In order to be informed in detail regarding our Cookies Policy, please refer to the relevant section of our website, which can be accessed here.
CHANGES TO THIS PRIVACY NOTICE