Privacy & Cookies Policy

About this policy

 

This policy describes how we use your personal data when you use our website https://www.kellingheath.co.uk or our ‘Kelling Heath Explorer’ App, or when you purchase our goods or services. We have provided this policy to ensure that you understand what personal data we may collect and hold about you, what we may use it for and how we keep it safe. You have legal rights to access the personal data that we hold about you and to control how we use it which are also explained.

You can read, print and save this whole policy.

We are Timewell Properties Limited (company number 00747225, registered address Bankside 300, Peachman Way, Broadland Business Park, Norwich, Norfolk, NR7 0LB) trading as Blue Sky Leisure.

You can contact us in writing at Blue Sky Leisure, Mill House, 11 Meridian Way, Meridian Business Park, Norwich, Norfolk NR7 0TA or by emailing data.protection@blueskyleisure.co.uk. If you would like to speak to us please call us on 01493 781100.

Please refer to the sections on Your rights to know what personal data we hold and to control how we use it and How to make a complaint for further contact information.

We collect:

  • personal data that you provide to us. There are lots of ways in which you may share your personal data with us via Kelling Heath, for example, you might complete the contact form on the website, register with the app, use the online booking system, purchase a holiday home at Kelling Heath, make contact by telephone, email, or in person with an enquiry, post on social media sites, or provide your details when booking or using facilities at Kelling Heath. The personal data that you provide to us may include your name, address, e-mail address and phone number, financial and credit card information, and details of family members and other members of your party, and any other information supplied in the ‘enquiry’ section of our contact forms.
  • personal data that we receive from third parties. If we work with other businesses or use sub-contractors these parties may collect personal data about you which they will share with us. For example, we may have your name and contact details passed to us by a third party website. If you have a holiday booked with us, but the booking was not made in your name, we will request details of your name and date of birth (if you are under 18) from the person who makes the booking.
  • personal data about your use of our website and our app. This is technical information and includes details such as your IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, as well as details of how you navigated to our website and where you went when you left, what pages you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs).

Personal data that you provide to us is used to:

  • process and respond to any enquiries you make
  • process booking requests, deliver confirmations, pre arrival emails and departure confirmation emails, and to generally communicate with you regarding your booking.
  • process holiday home purchases and communicate with you regarding your purchase or potential purchase
  • communicate with you regarding the park, your holiday home, and the park facilities
  • carry out the terms of our agreement regarding your holiday home or visit to our park
  • provide you with the information, products and services that you request from us
  • provide you with marketing information in accordance with your marketing preferences (see How we use your personal data for marketing)
  • manage and administer our business
  • review and improve our goods and services

Personal data that we receive from third parties is combined with the personal data that you provide to us and used for the purposes described above.

Personal data about your use of our website and our app is used to:

  • administer our website and app and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes
  • to improve our website and app to ensure that content is presented in the most effective manner for you and for your computer or mobile device
  • to allow you to participate in interactive features of our service, when you choose to do so
  • as part of our efforts to keep our site safe and secure

Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our website. For detailed information on the cookies we use and the purposes for which we use them see our Cookie policy.

Whilst we always want you to be aware of how we are using your personal data, this does not necessarily mean that we are required to ask for your consent before we can use it. In the day to day running of our business we may use your personal data without asking for your consent because:

  • we are entering into and carrying out our obligations under a contract with you
  • we need to use your personal data for our own legitimate purposes (such as the administration and management of our business and the improvement of our services) and our doing so will not interfere with your privacy rights

In exceptional circumstances we may wish to use your personal data for a different purpose which does require your consent. In these circumstances we will contact you to explain how we wish to use your data and to ask for your consent. You are not required to give consent just because we ask for it. If you do give consent you can change your mind and withdraw it at a later date.

Please refer to the section on How we use your personal data for marketing to read about marketing consents

You are not under a legal obligation to provide us with any of your personal data but please note that if you elect not to provide us with your personal data we may be unable to provide our goods or services to you.

You have a legal right to know what personal data we hold about you – this is called the right of subject access. You can exercise this right by sending us a written request at any time. Please mark your letter “Subject Access Request” and send it to us using the details in the Who we are and how you can contact us section.

You also have rights to:

  • prevent your personal data being used for marketing purposes (see How we use your personal data for marketing for further details)
  • have inaccurate personal data corrected, blocked or erased
  • object to decisions being made about you by automated means
  • object to our using your personal data in ways that are likely to cause you damage or distress • restrict our use of your personal data
  • require that we delete your personal data
  • require that we provide you, or anyone that you nominate, with a copy of any personal data you have given us in a structured electronic form such as a CSV file

You can find full details of your personal data rights on the Information Commissioner’s Office website at www.ico.org.uk.

We do not make use of automated decision making or profiling.

We share your data with the following people in the day to day running our business:

  • • other businesses which are part of the Blue Sky Leisure group. This includes Blue Sky Leisure and Woodhill Park all of which are owned by us.
  • any business partners, suppliers and sub-contractors we work with to provide you with goods or services that you have requested from us, to specifically include Mosaic Spa and Health Clubs Ltd (registered company number 07468623) (‘Mosaic’), who operate the spa facilities at Kelling Heath. We provide Mosaic with your name, address and plot number so that you have access to those facilities.

We may also share your personal information with third parties on a one-off basis, for example, if:

  • we sell or buy any business or assets (including our own), in which case we will disclose your personal data to the prospective seller or buyer of such business or assets
  • we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our booking and hiring conditions and other agreements; or to protect the rights, property, or safety of our customers, ourselves or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction

We take every care to ensure that your personal data is kept secure. The security measures we take include:

  • only storing your personal data on our secure servers
  • encrypting any payment transactions made through our website
  • ensuring that our staff receive regular data security awareness training
  • keeping paper records to a minimum and ensuring that those we do have are stored in locked filing cabinets on our office premises
  • maintaining up to date firewalls and anti-virus software to minimise the risk of unauthorised access to our systems
  • enforcing a strict policy on the use of mobile devices and out of office working

Please remember that you are responsible for keeping your passwords secure. If we have given you (or you have chosen) a password which enables you to access certain parts of our website or app, you are responsible for keeping this password confidential. Please do not to share your passwords with anyone.

Unfortunately, sending information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of personal data sent to our website; you send us personal data at your own risk. Once we have received your personal data, we will use strict procedures and security features (some of which are described above) to try to prevent unauthorised access.

We will add your details to our marketing database if:

  • you make an enquiry about our goods or services
  • you buy our goods or services
  • you have told a third party that you would like them to pass us your contact details so that we can send you updates about our goods and services
  • you have registered an account on our website and/or our app and have indicated during the sign up process that you are happy to receive marketing communications

We may send you marketing communications by email, telephone and post. You can ask us to only send you marketing communications by particular methods (for example, you may be happy to receive emails from us but not telephone calls), about specific subjects or you may ask us not to send you any marketing communications at all.

You can check and update your current marketing preferences at any time by calling or emailing us using the details set out in the Who we are and how you can contact us section above.

We may send you marketing materials relating to other businesses within the Blue Sky Leisure group which we think may be of interest to you. These include Woodhill Park and Blue Sky Leisure. We may also send you marketing materials relating to Mosaic Spa and Health Clubs Limited – Mosaic operate the spa facilities at Kelling Heath and also at Imagine Spa Blofield – any marketing material you receive will come directly from us (not Mosaic).

We will only share your personal data with third parties for marketing purposes if you provide us with your consent to do so by ticking a box on a form we use to collect your personal data.

Personal data collected via Kelling Heath may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”) by us or by our sub-contractors. Where we, or our sub-contractors, use IT systems or software that is provided by non-UK companies, your personal data may be stored on the servers of these non-UK companies outside the EEA.  We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.

The below table shows how data is currently transferred outside of the EEA:

Description of supplier

Reason for transfer

Destination to which data is transferred

Safeguards implemented

RMS RMS is a cloud based service which we use for reservation management and online booking. USA Registered with the EU – US Privacy Shield

We only keep your personal data for as long as we actually need it. In practice this means that we will keep:

  • your name and contact details for 10 years after the date of your last stay at Kelling Heath
  • a record of the services (including a copy of your full customer file) we provide to you for 10 years after the date of your last stay at Kelling Heath
  • complaint records for 10 years

Please note that we may anonymise your personal data or use it for statistical purposes. We keep anonymised and statistical data indefinitely but we take care to ensure that such data can no longer identify or be connected to any individual.

If you are unhappy with the way we have used your personal data please contact us to discuss this using the contact details set out in the Who we are and how you can contact us section above.

You are also entitled to make a complaint to the Information Commissioner’s Office which you can do by visiting www.ico.org.uk. Whilst you are not required to do so, we encourage you to contact us directly to discuss any concerns that you may have and to allow us an opportunity to address these before you contact the Information Commissioner’s Office.

We will review and update this policy from time to time. This may be to reflect a change in the goods or services we offer or to our internal procedures or it may be to reflect a change in the law.

The easiest way to check for updates is by looking for the latest version of this policy on our website or you can contact us (see Who we are and how to contact us) to ask us to send you the latest version of our policy.

Each time we update our policy we will update the policy version number shown at the bottom of the policy and the date on which that version of the policy came into force.

This is policy version 1 which came into effect on 10 May 2018.

Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. By continuing to browse the site, you are agreeing to our use of cookies.

A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer’s hard drive.

We use the following cookies:

  • Strictly necessary cookies. These are cookies that are required for the operation of our website. They include, for exa mple, cookies that enable you to log into secure areas of our website, use a shopping cart or make use of e-billing services.
  • Analytical/performance cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
  • Functionality cookies. These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
  • Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.

You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

Cookie Name Purpose More information
_ga   Performance This cookie name is asssociated with Google Universal Analytics – which is a significant update to Google’s more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports. By default it is set to expire after 2 years, although this is customisable by website owners.

 

_gat   Performance This cookie name is associated with Google Universal Analytics, according to documentation it is used to throttle the request rate – limiting the collection of data on high traffic sites. It expires after 10 minutes.

 

_gid   Performance This cookie name is asssociated with Google Universal Analytics. This appears to be a new cookie and as of Spring 2017 no information is available from Google. It appears to store and update a unique value for each page visited.

 

__atuvc   Functionality This cookie is associated with the AddThis social sharing widget which is commonly embedded in websites to enable visitors to share content with a range of networking and sharing platforms. It stores an updated page share count.

 

__atuvs   Functionality This cookie is associated with the AddThis social sharing widget which is commonly embedded in websites to enable visitors to share content with a range of networking and sharing platforms. This is believed to be a new cookie from AddThis which is not yet documented, but has been categorised on the assumption it serves a similar purpose to other cookies set by the service

 

 

Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical/performance cookies or targeting cookies.

You block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our site.

Except for essential cookies, all non-essential cookies will expire after an hour.

Information about the European Commission’s Online Dispute Resolution Platform for the resolution of disputes can be found at: http://ec.europa.eu/odr.