PRIVACY NOTICE
Like most businesses, Autograph holds and processes a wide range of information about its clients and other persons who may be interested in our services. This privacy notice applies to all operations in the EEA and other global locations, and explains the type of information that we process, why we are processing it and how that processing may affect you. The privacy notice is split into the sections listed below. The Glossary section explains what we mean by “personal data”, “processing”, and other terms used in this notice. We may update this privacy notice from time to time, and will post any revised notice on this webpage. Where appropriate we may notify you by email or by a notice on our website that our privacy notice has changed but we recommend that you check this page regularly. Any changes will be immediately effective on posting.
HOW AND WHEN DO WE COLLECT YOUR PERSONAL DATA?
Collection directly from you in response to our request
Most of the personal data we process about you comes directly from you (whether face to face, over the telephone, on a paper form, by email or online) for example:
when you agree to market or sell your property through Autograph or ask us to perform a valuation;
when you express an interest to one of our staff or representatives in buying or selling real property;
Automatic collection when you visit our premises or our website
Your image may be collected by us if you attend our premises. We use CCTV at our salesrooms and offices for the protection of our staff, our visitors and the property that we sell.
We collect data about your computer when you visit our website, which includes your internet address, your operating system and browser type. We use this information for our internal system administration, to help diagnose problems with our servers, to administer our website and monitor and improve the user experience.
We also collect data about you through cookies. A cookie is a simple text file that is stored on your computer or mobile device by our website’s server which allows our website to remember your preferences or transactions that are in progress. You can see more detail on cookies in our Cookies Policy.
Collection of data from other sources
We may also obtain information about you and/or your property from other sources, for example:
When someone introduces you to us;
When we research real property, artwork or other objects and we find information about you in sources such as newspaper articles, exhibition catalogues, public auction results, or one of our contacts gives us feedback in relation to objects or persons they have been told about.
WHAT PERSONAL DATA DO WE PROCESS AND WHY?
We have set out below the types of personal data that we process, the purposes for which we use it and the legal grounds on which we process it. The Glossary contains more information about the legal grounds for processing.
WHO GETS TO SEE YOUR PERSONAL DATA?
Your personal data will be processed by Autograph that initially receives it, and may also be transferred to and processed by other companies within the Autograph group. We use EU Commission approved standard contractual clauses to regulate the transfer and processing of data between group companies.
Outside the Autograph Group
We do not transfer your personal data to organizations who wish to use it for their own marketing promotions or other purposes. We only transfer your personal data to other organizations where it is necessary to enable us to provide you with the services you have requested (for example: we may transfer your data to our bank, payment card acquirers, shippers, warehouses, insurers, experts who help us authenticate or value property, event venues, caterers, catalogue and direct marketing and distribution). Where we do so it will be on the basis that these organizations are required to keep the information confidential and secure, and they will only use the information to carry out the instructed services. Some of these organizations may be located outside the EEA and you should refer to the section Is your personal data transferred out of the EEA? for more information.
We will also transfer your personal data that you provide to us regarding requested services for properties directly to our affiliate agents and brokers who are able to directly handle your request. Conduct anti-money laundering and trade sanction checks and to assist with fraud and crime prevention and detection.
No government entity has direct access to your data. Where we receive a request from a government or law enforcement authority to provide your data, we will only disclose such information where we are ordered to do so by a court or we are otherwise satisfied after internal review that the body making the request has both the right to seek disclosure and has followed the correct process.
HOW LONG WILL WE KEEP YOUR PERSONAL DATA?
We will retain your personal data for as long as is necessary to provide the relevant services, maintain business records to satisfy tax, legal and other regulatory requirements, and protect and defend against potential legal claims.
WHAT STEPS DO WE TAKE TO KEEP YOUR PERSONAL DATA SECURE?
We will take all reasonable and appropriate steps to protect the security and integrity of all personal information provided via our website, or by any other means electronic or otherwise.
We use a variety of security technologies and procedures to help protect your personal details from unauthorized physical and electronic access.
As effective as modern security practices are, we cannot guarantee the complete security of personal data held in our systems, nor that that information you supply through the internet or any computer network is entirely safe from unauthorized intrusion, access or manipulation during transmission. Any transmission is at your own risk. We will not be liable for any resulting misuse of your personal data.
THIRD PARTY WEBSITES
Our website may contain links to other websites not operated by Autograph. The information you provide to us will not be transmitted to other websites, but these other websites may collect personal information about you in accordance with their own privacy notice. We cannot accept any responsibility for the privacy practices or content of those websites.
ACCESS TO YOUR DATA AND OTHER RIGHTS
We try to be as open as we can about the data that we process and recommend you ask us if you have questions about the data we hold on you.
Subject Access Requests
If you are a resident of the EU, you have the legal right to make a “subject access request”. If you exercise this right and we process personal data about you by automated means or as part of a Filing System, we are required to provide you with a description and copy of that personal data, and tell you why we are processing it.
Other rights for EU residents
As well as your subject access right, you may have a legal right to have your personal data rectified or erased, to object to its processing, or have its processing restricted.
If you have provided us with data about yourself and the grounds for processing is Contract or Consent (see What personal data do we process and why?), you have the right to be given the data in machine readable format for transmitting to another data controller.
If we are relying on Consent as the grounds for processing your data (see What personal data do we process and why?), you may withdraw consent at any time. This will not affect the lawfulness of our processing of your data prior to your withdrawal.
Rights for California residents
If you are a resident of California you may have a right pursuant to Section 1798.83 of the California Civil Code to obtain certain information about the types of personal data that we have shared with third parties for direct marketing purposes during the preceding calendar year, including the names and addresses of those third parties, and examples of the types of services or products marketed by those third parties.
CONTACT INFORMATION
If you have any queries in relation to our processing of your personal data please contact us at [email protected]
GLOSSARY
Compliance with a legal obligation – processing is necessary to ensure we comply with our legal and regulatory obligations.
Consent – you have given specific consent to the processing of your personal data.
Data Controller – the person who determines the purposes and means of processing personal data.
EEA – the European Economic Area which comprises countries that are members of the European Union and Norway, Iceland and Liechtenstein.
Filing System – a structured set of personal data that is accessible according to specific criteria.
Legitimate Interests – processing is necessary for our or a third party’s legitimate interests in carrying on, managing and administering our respective businesses effectively and properly (except where our or the third party’s interests are overridden by your own interests, rights and freedoms).
Performance of a contract – processing is necessary to carry out our contractual duties, exercise our contractual rights or otherwise perform our contract with you, or to take steps at your request to enter a contract.
Personal Data – any data relating to an identified or identifiable natural person. This can include names, user ID, location data, email addresses, photographs, job applications, purchase history, user account information, opinions, and correspondence to and from an individual.
Processing – any operation performed on personal data, such as collection, recording, storage, retrieval, use, combining it with other data, transmission, disclosure or deletion.
Public Interest – processing is necessary for the performance of a task carried out in the public interest.