Scuba Diving Lav
Last Updated: March 2020
As a responsible organisation, we have implemented numerous technical and organisational measures to ensure the most complete protection of any personal data (e.g. name, address, email, phone number) processed through this website, in order to meet the General Data Protection Regulation (“GDPR”), and in accordance with any country-specific data protection regulations. However, Internet-based data transmissions may in principle have security gaps, so absolute protection may not be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, e.g. by telephone.
- Name and Address of the Data Controller
The data controller for the purposes of the GDPR, other data protection laws applicable in Mexico and other provisions related to data protection is:
Scuba Diving Lav
Playa Del Carmen
Phone: 984 138 8777
As a data controller we are responsible for deciding how we hold, use and keep personal data secure. It also means we are responsible for responding to requests you make in relation to how your personal data is used. If you have any questions about the way your personal data is processed, you can contact us on these details:
2.1 Name and Address of the Data Protection Officer
Data Protection Officer based in its Head Office in Playa Del Carmen (Mexico) and Data Protection Leads in each entity. For any queries relating to data protection please contact our local Data Protection Lead below:
Section B) Why and How We Use Your Data
- Collection of personal data and general information
We will collect personal data when you set up an account with us, purchase products or services from us, complete forms we provide to you, make a report or notification about our products or services, contact us by phone, email or communicate with us directly in some other way.
We collect the following types of personal data from you:
Contact details: information that allows us to contact you such as your name, email address, telephone number and addresses associated with your account, order or query.
Purchase and account history: records relating to the products and services which you have purchased.
Personal data in reports and notifications you submit to us: if you submit information to us about our products and services through our website we will collect any personal data you include.
Records of your discussions with us: when you contact us, whether by email or phone, we will keep a record of this. We also record calls with our customer support team so that we can keep up with training and ensure a good quality of service for you.
How you use our website: Our website collects a series of general data and information when a user or automated system calls up the website. This general data is stored in the server log files. We may collect (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites, (5) the date and time of access to the Internet site, (6) an Internet protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems.
We do not draw any conclusions about the user from the website data. Rather, this information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as its advertisements, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. Therefore, the controller analyses anonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.
- Legal basis for the processing
We limit the collection of personal data to only that which is absolutely necessary to carry out our legal or business obligations. In some cases however the provision of personal data may be partly required by law (e.g. tax regulations), is needed as part of contractual negotiations, or as part of providing a service. The non-provision of the personal data would have the consequence that the contract or service with the data subject could not be provided or concluded, therefore is considered Legitimate Interest for processing.
Below, we describe:
- the purposes we collect your personal data for;
- the categories of personal data we process for that purpose;
- the legal basis that allows us to process your personal data; and
- how long we will keep your personal data for.
|Purpose of processing||Categories of data processed||Legal basis of processing||Data storage period|
|Provide our services to
you and maintain your
|All the personal information we collect||Fulfilment of a
contract between us
|Duration of the contract|
|Deliver products to you||Contact details||Fulfilment of a
contract between us
|Duration of the contract|
|Answer your queries or complaints||All the personal information we collect||Fulfilment of a
contract between us
|Duration of the contract|
|Investigating misuse of your account, fraud and debt collection||All the personal information we collect||Legitimate Interest Legal obligation||Duration of the contract|
|Maintain and improve our products and services||All the personal information we collect||Legitimate interest|
Duration of the contract
Products and services that we have determined may be of interest to you
Duration of the contract
Before you provide personal data, you can contact our Data Protection team who can clarify whether the provision of the personal data is required by law or contract, whether there is any obligation to provide the personal data, and the consequences of non-provision.
- Your consent
Where the legal basis for us processing your personal data is that you have provided your consent, you may withdraw your consent at any time. You will not suffer any detriment for withdrawing your consent. If you withdraw your consent, this will not make processing which we undertook before you withdrew your consent unlawful.
You can withdraw your consent by contacting the Data Protection team, whose details are provided in section 2.
- Who has access to your personal data
We share your personal information with the following:
Our staff: Your personal data will be accessed by our staff but only where this is necessary for their job role.
Companies in the same group of companies as us: For the purpose of providing a service to you.
Delivery companies: To deliver products that you have ordered from us.
Credit reference agencies: So that we can verify your identity, and to provide information on missed or late payments or other activity which may affect your credit score.
Other service providers and advisors: Such as companies that support our IT, help us analyse the data we hold, process payments, send communications to our customers, provide us with legal or financial advice and help us deliver our services to you.
The government or our regulators: Where we are required to do so by law or to assist with their investigations or initiatives, including the Information Commissioner’s Office.
Police and law enforcement: To assist with investigation and prevention of crime.
We do not disclose personal information except as set out above. We may provide other third parties with statistical information and analytics but we will make sure that the information is aggregated and no one can be identified from this information before we disclose it.
- Transfer of personal data
To ensure that your personal data is secure, we will only transfer your information to any Countries outside of the EU or EEA with your permission, where we do so in accordance with the GDPR. This requires that one of the following conditions applies:
- the European Commission has decided that the country provides an adequate level of protection for your personal data;
- the transfer is subject to a legally binding and enforceable commitment on the recipient to protect the personal data;
- the transfer is made subject to binding corporate rules; or
- the transfer is based on a derogation from the GDPR restrictions on transferring personal data outside of the EU.
We do not currently transfer data outside of the EU and European Economic Area (“EEA”).
Our webpages use “cookies”. Cookies are text files that are stored in a computer system via an Internet browser.
Profiling involves the analysis of personal data (e.g. digital behaviour such as pages visited, links clicked, downloads) in an automated way, to identify or predict behaviour in website users.
We do not currently use profiling on our website. If we start any profiling activity, we will notify you specifically that we are using profiling.
- Registration and Website Enquiry Forms
Certain users can register on our website with personal data via a registration form, for example for our partner portal service or for our online training service (Academy). This personal data (e.g. name, email address, date and time of registration) is captured to provide them with this service, verify their identity, and provide them with a secure log in to a protected web environment. It also enables Scuba Diving Lav to provide access or deny access due to misuse of service.
Users can also submit personal information by submitting a general enquiry (e.g. a sales or service enquiry) via a form. In doing so, the personal data transmitted is automatically stored via email to the recipient contact at Scuba Diving Lav Such personal data is transmitted on a voluntary basis and is stored for the purpose of contacting the data subject to fulfil their enquiry. Additionally, consent can sometimes also be given on the forms for other forms of communication e.g. marketing. This consent is freely given via an opt-in mechanism (see Section 10 below).
This data may also be passed on to Scuba Diving Lav group companies and partners to fulfil the enquiry if it relates to a different area of the business than the one the user selected when submitting the enquiry. It may also be passed to third parties for example Sales CRM systems, Service CRM systems or Marketing Automation platforms, however in this case Scuba Diving Lav remains the data controller.
- Sales and Marketing Communications
As a Scuba Diving Lav website user you also have the opportunity to provide personal data to register for specific sales and marketing programmes, for example to express interest in a product or service, subscribe to email newsletters, or register for events. We inform our users, customers and business partners regularly about our products, services and promotions through sales and marketing communications. Users are given the option to consent to receiving these communications via various channels, and are given the option to opt-out of these communications at every practical opportunity. Service communications for existing customers (such as billing/ contract information) is considered Legitimate Interest and as such these communications form part of providing the service. In the case of marketing communications they may only be received by the data subject if (1) they have a valid e-mail address, phone number or postal address and (2) they register for the marketing communication.
During registration for marketing communications, we also store the IP address of the computer system assigned by the Internet service provider (ISP) and used by the data subject at the time of the registration, as well as the date and time of the registration. The collection of this data is necessary in order to understand the (possible) misuse of the e-mail address of a data subject at a later date, and it therefore serves the aim of the legal protection of the controller.
The personal data collected as part of a registration for a marketing communications programme will only be used to send our specific communication, unless otherwise stated in the consent form. We use third party platforms such as marketing automation providers and Sales CRM systems to process this data in some cases. All third party providers have GDPR compliant Data Protection Agreements with Scuba Diving Lav and the data is fully controlled and owned by Scuba Diving Lav. The consent to the marketing communications programme or storage may be terminated by the data subject at any time. Each communication we send contains a link to remove consent (in the case of electronic communications), alternatively you can remove consent by contacting the Data Protection team, whose details are set out in section 2.
- Tracking & Analytics
Our marketing communications can sometimes contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in e-mails, landing pages etc., which are sent in HTML format to enable log file recording and analysis. This allows a statistical analysis of the success or failure of online marketing campaigns. Based on the embedded tracking pixel, the controller may see if and when a marketing communication and specific content was viewed or downloaded by a data subject, and may use this information to re-target users with more specific/ relevant content the next time they visit their digital properties. You can remove your consent to this either through the consent management link in each electronic communication, or by contacting the Data Protection Officer.
We use Google Analytics to track, report and optimise our website performance (e.g. number of visitors, where they came from, what pages they visited). This is tracked by us at an aggregate level and not on an individual level.
The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States.
We use Google Analytics with the anonymizer function (the application “_gat. _anonymizeIp”). This means the IP address of the user is abridged by Google and anonymised when accessing our websites from a Member State of the European Union or another Contracting State to the Agreement on the European Economic Area.
When a user accesses our site from a Google search (whether through an organic search listing or a paid-for digital advertisement), Google Analytics places a cookie on the user’s computer/ device. This enables Google to track what happens after they click on the link and hit our website. In the case of paid-for digital advertising, we pay Google based upon the number of clicks or impressions, so this also ensures accurate reporting and billing, and helps with the prevention of click-fraud. Google gathers personal information from the user, such as the IP address, access time and location. With each visit to our site, such personal data will be transmitted to Google in the United States of America. This personal data may be stored by Google in the United States of America, and they may pass this on to third parties.
Section C) Your Rights to Control Your Data
Rights of the data subject (“you”).
You have the following rights to control your data according to GDPR principles:
Right of confirmation – this means the ability to find out from us if we are processing data about you.
Right of access – this means the ability to see what data is being held about you (also called Subject Access Request). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
Right of rectification – this means the ability to change or alter any incomplete or inaccurate data we hold about you.
Right to erasure – this means the ability to be removed from our databases/ systems where: there is no good reason for us continuing to process it, you withdraw your consent, we are unlawfully holding your personal data or we should erase your data to comply with applicable EU law. You have a right to ask us to delete or remove your personal information where you have exercised your right to object to processing.
Right to restriction of processing – this means the ability to limit or suspend what personal data is processed.
Right to data portability – this means the ability to move the data to another supplier
Right to object – this means the ability to prevent your personal data being processed in a certain way or remove consent. There is a specific provision to be able to object separately to data profiling.
To exercise your rights to any of the above, please contact us via email at: firstname.lastname@example.org
Alternatively, there are other actions you can take as a user of our websites to limit the amount of personal data we may process:
Do not consent or remove consent:
- Where we capture personal data on forms, we will be introducing opt-in boxes so that you can tell us if you want to hear from us for marketing purposes. If you don’t consent, you won’t hear from us, unless it’s related to the service we provide you.
- Most marketing communications, especially electronic communications, where practical will provide the ability to opt-out of further marketing communications.
Prevent or remove web tracking:
- Access our website using an anonymous/ incognito browser window
- Deny the setting of cookies by adjusting your web browser settings:
o Cookie settings in Internet Explorer
o Cookie settings in Firefox
o Cookie settings in Chrome
o Cookie settings in Safari web and iOS.
- Object to the collection of data by Google Analytics
o Download and install a browser add-on: https://tools.google.com/dlpage/gaoptout
o More information: https://www.google.com/intl/en/policies/privacy/ http://www.google.com/analytics/terms/us.html
- We will always aim to help you when you wish to exercise your rights but in some instances we may have lawful grounds to reject your request.
- We will investigate any request you make without undue delay and in any event within one month of receipt of your request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests. We shall inform you of any such extension within one month of receipt of the request, together with the reasons for the delay.
- In the event that we decide to not take action on the request, we will inform you of the reasons for not taking action.
- Lodging a complaint with the supervisory authority: if you do not agree with a decision we make in relation to a rights request or believe that we are in breach of applicable data protection laws, then you can lodge a complaint with a data protection supervisory authority in USA. You can contact the data protection supervisory authority for The Mexico using its contact details on its website www.scubadivinglav.com
- Updates to this Policy
We recommend that you check for updates to this notice from time to time but we will notify you directly about changes to this notice or the way we use your personal data when we are legally required to do so.