Legal
Privacy notice
This notice explains what personal data we collect when you browse the site, order a course, write to us or use the chat, why we need it, who else sees it and how long we keep it.
1. Who is responsible for your data
The controller of your personal data is DALBY UK ONLINE LIMITED, trading as Dalby Online (“we”, “us”). Our registered office is 44 Meadowgates, Rotherham, South Yorkshire, S63 8HX, England, United Kingdom. You can reach us about anything in this notice at hello@dalbyonline.co.uk. Our full company details are in section 1 of our terms.
We handle your data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our payment service provider is a separate controller for the payment itself, as section 4 explains.
2. What we collect, and why
Checkout details. To place an order you give us your name, email address, country and billing address (street, postcode and town; county is optional) and, if you want to, a company name. You type these on our own checkout page, not on the payment page. We collect your billing details and hand them to our payment service provider, so that when you reach the payment page all you type is your card details. We use them to take payment, to let the provider work out the right taxes, to create your order, to send your access and to support you with it.
Your order record. When you go to pay, we create a record of your order as a file on our server, named with a long random code. The same code is the permanent address of your order page. The record holds what you bought, the amounts and currency, the payment status, how far your access has got, your name and email address, and your company name if you gave one. It does not hold your card details, and it does not hold your billing address, which the payment provider keeps as part of the payment. Anyone who has the link can open the order page, so please keep it to yourself.
Contact form and email. When you use the contact form we receive your name, your email address, the topic you chose, your message and the address of the page you were on. We store this in a file on our server and send it to our mailbox. If you email us, we keep your email and our replies. We use all of it to answer you. Please do not put card numbers or other sensitive details in a message.
Live chat. When you send a message in the chat we store the message, any file you attach (up to 10 MB), the email address if you give one, and the address of the page you were on. A random identifier in a cookie links your browser to your conversation, so that our replies reach you and your messages stay on screen as you move around the site (see the cookie policy). Nothing is stored until you send your first message. We use it all to answer you. If you choose to send health information or photographs, for example about a skin reaction, you do so with your explicit consent; we use them only to answer you, and you can ask us to delete them at any time.
“Remember my details”. At checkout there is a box, unticked by default, that saves the details you typed in a cookie in your browser, so that the form is filled in next time. If you leave it unticked we set no such cookie, and checking out again with it unticked deletes any saved-details cookie from before. You can erase it at any time on the forget my saved details page or by clearing your browser’s cookies. The details sit in your browser; we do not keep a copy.
Basket. When you add a course to your basket, or open the checkout, we set a session cookie containing a random identifier and keep your basket on our server against it, for as long as the session lasts. If the checkout sends a form back to you for correction, what you typed is held with the basket session so that you do not have to retype it.
Visit log. Each time you load a page on this website, or send a form on it, we record the time, your IP address (and, if your request came through a proxy, the forwarded address), the country that address is in, the page requested with the method and response code, the page you came from (the referrer) and your browser’s identification string. We use this log to keep the website secure, to spot and block fraud and abuse, and to find and fix faults. We do not use it for advertising or to build profiles of visitors.
We do not use analytics or advertising tools, we do not run a mailing list, and we do not sell or rent personal data.
3. Our lawful bases
The law lets us use personal data only where we have a lawful basis. Ours are these.
Scroll the table sideways to see every column.
| What we do | Data involved | Lawful basis |
|---|---|---|
| Take and deliver your order, send your access, support you with it | Checkout details, order record | Contract: Article 6(1)(b) |
| Keep accounting and tax records, and meet other legal duties | Order record | Legal obligation: Article 6(1)(c) |
| Hold the basket you are building | Basket session cookie | Steps you ask for before a contract: Article 6(1)(b) |
| Answer the contact form, emails and the chat | Contact and chat data | Legitimate interests: Article 6(1)(f), our interest in answering people who ask us questions. Where you ask about an order, contract: Article 6(1)(b) |
| Remember your checkout details for next time | Saved-details cookie | Consent: Article 6(1)(a). You can withdraw it at any time |
| Keep the website secure, prevent fraud and abuse, fix faults | Visit log | Legitimate interests: Article 6(1)(f), our interest in protecting the website, our customers and ourselves |
| Deal with complaints, refunds and legal claims | Whatever the matter involves | Legitimate interests: Article 6(1)(f), and legal obligation: Article 6(1)(c) |
Where we rely on legitimate interests we have weighed them against your rights and expectations. The visit log, for example, holds only what any web server sees, is used only for security and reliability, and is deleted after a short time. You can object to processing based on legitimate interests at any time (see section 8).
To buy a course you must give us the checkout details, because we cannot take the order or send your access without them. Writing to us, using the chat and saving your details are optional. The visit log happens automatically when you visit any website. If you send health information, the lawful basis for that part is your explicit consent: Article 9(2)(a).
4. Who receives your data
We do not sell your personal data. We share it only with these categories of recipient.
- Our payment service provider. It acts as merchant of record for your payment and is an independent controller of the payment data it handles: your card or wallet details, the payment itself, its fraud checks and your receipt. We pass it the billing details you typed into our checkout (name, email address, company name if given, and billing address) so that you only enter your card on its page. It uses them to take payment, to work out the right taxes, to issue the receipt and to prevent fraud, and it keeps a customer record linked to your email address. Its own privacy notice explains how it uses data.
- Our web hosting provider. It hosts this website and stores on its servers the data described in this notice, including order records, contact messages, chat conversations and files, and the visit log. It also handles the email that the website sends. It acts on our instructions.
- A font provider. The fonts on this website load from a third-party font service. Your browser asks it for them directly, so it receives your IP address and ordinary browser details.
- A stock-photo CDN. The photographs on this website, and the portrait in the chat panel, load from a third-party content delivery network. It receives your IP address and ordinary browser details when your browser asks for them.
- A payment-icon CDN. The payment-method icons in the page footer and at checkout load from a third-party content delivery network, which receives your IP address and ordinary browser details in the same way.
- An IP-location lookup service. To show us which country a visit in the visit log came from, our server may send the IP address, and nothing else, to a third-party lookup service. This happens only when our hosting network has not already supplied the country, and only when the log is read. The service replies with a country code.
- Professional advisers and authorities. Our accountants and legal advisers, and courts, regulators, tax authorities and law enforcement where the law requires it or where we need to protect our rights.
None of the three content services above (fonts, photographs, icons) is given your name, email address or order. They see only what your browser sends when it asks for a file.
5. Transfers outside the UK
Some of our providers, in particular our payment service provider and the services that deliver fonts, photographs and icons from servers around the world, may handle data in countries outside the UK.
When data leaves the UK it is protected by one of the safeguards UK law provides: UK adequacy regulations, which are the UK government’s decision that a country or scheme gives equivalent protection; the ICO’s International Data Transfer Agreement (IDTA); the UK Addendum to the EU standard contractual clauses; or another safeguard allowed by Article 46 of the UK GDPR. You can email us for details of the safeguard that applies in a particular case.
6. How long we keep it
Scroll the table sideways to see both columns.
| Data | How long we keep it |
|---|---|
| Order records | 6 years from the order, to meet our accounting and tax record-keeping duties. Then we delete them. |
| Contact form messages and emails | 12 months from the day we receive them. |
| Live chat conversations, files and email address | 12 months after the last message in the conversation. The conversation and its files are then deleted automatically. |
| Visit log | 90 days. Older entries are deleted automatically. |
| Saved-details cookie | 180 days from the last time you saved your details, or until you erase it. |
| Basket session cookie | Until you close your browser. |
| Payment records held by our payment service provider | As set out in the provider’s own privacy notice. |
If a complaint, a refund dispute or a legal claim is open, we keep the data it concerns until the matter is closed, even if that is longer than the periods above.
7. How we protect it
Order records, contact messages, chat conversations, files and the visit log are stored in private folders on our hosting that the web server does not serve to the public, and the screens we use to read the chat and the visit log are protected by a password. We never see or store your full card number.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will tell you and the Information Commissioner’s Office as the law requires.
8. Your rights
Under the UK GDPR you have these rights over the personal data we hold about you:
- Access: to ask for a copy of it.
- Rectification: to have anything inaccurate corrected.
- Erasure: to ask us to delete it.
- Restriction: to ask us to pause using it while a concern is looked into.
- Portability: to receive the data you gave us under a contract or with your consent in a common, machine-readable format.
- Objection: to object to processing based on legitimate interests, including the visit log.
- Withdrawing consent: where we rely on your consent, to withdraw it at any time. For the saved-details cookie, use the forget my saved details page. Withdrawing consent does not make earlier use unlawful.
- Automated decisions: not to be subject to a decision based only on automated processing that has a legal or similarly significant effect. We do not make such decisions (see section 10).
To use any of these rights, email hello@dalbyonline.co.uk. We reply within one month and do not charge a fee. We may ask you to confirm who you are before we release or change anything. Chat conversations and the visit log are tied to a random identifier or an IP address, not to your name, so tell us the email address you used, or roughly when you chatted or visited, and we will look for it.
Some rights have limits. For example, we must keep order records for the period in section 6 to meet our accounting and tax duties, so we cannot erase them earlier; if you ask, we will tell you what we are keeping and why, and delete everything else we are allowed to.
9. Complaints to the ICO
If you are unhappy with how we have handled your personal data, please tell us first at hello@dalbyonline.co.uk so that we can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk or on 0303 123 1113.
10. Automated decisions and profiling
We do not make decisions about you based only on automated processing, and we do not profile you. Our payment service provider runs its own fraud checks as part of taking a payment, under its own privacy notice.
11. Adults only
Our website and courses are for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you think a child has given us their details, email hello@dalbyonline.co.uk and we will delete them.
12. Changes to this notice
We may update this notice. The date at the top shows when it last changed. If a change materially affects how we use data you have already given us, we will tell you in a suitable way, for example by email where we hold your address for an order. Our cookie policy and terms are separate pages.