WHO AM I?
I am an Associate of PPLSI Limited, a company registered in England and Wales under number 11011302, whose registered office and main trading address is at 4220 Nash Court, Oxford Business Park, Oxford, OX4 2RU, United Kingdom (“LegalShield UK”). LegalShield UK is a supplier of membership plans providing subscription services including legal support and privacy protection services.
- when you visit or use a website or any mobile application owned or operated by LegalShield (the “Sites”), including opening and using an online user account, regardless of where you visit or use the Sites from; and/or
- which we otherwise receive or collect from you in the course of our operations and customer services (including using our products and services). It also describes certain privacy rights and data protection laws that may apply to you.
For the purpose of the Data Protection Legislation, LegalShield UK and LegalShield US are each “data controllers” of any personal information that you provide to me or that I collect from you. This means that LegalShield UK and LegalShield US are each responsible for deciding how each of them holds and uses your personal information. There may also be processing activities for which LegalShield UK and LegalShield US will be joint data controllers in that they may jointly determine the purposes and means by which your personal data is processed by them.
For certain data processing activities LegalShield US may act as a data processor for LegalShield UK.
I am a “data processor” of any personal information that you provide to me or that I collect from you. This means that I will only process your personal data for the purposes of the development and conduct of my business as a LegalShield Associate and in accordance with the instructions of LegalShield.
For purposes of the GDPR, LegalShield US, in its capacity as a controller, identifies Legal Shield UK, 4220 Nash Court, Oxford Business Park, Oxford, OX4 2RU, United Kingdom, as its representative in the European Union.
If you become a Member of LegalShield and subscribe to one of our Plans then as part of the process of subscribing to a Plan you will receive a data processing notice from the Service Provider of that Plan. Our Plan Service Providers are also data controllers in their own right in respect of your personal data.
DATA PRIVACY MANAGER
LegalShield UK has appointed the following individual as its data privacy manager:
Mike File, Pre-Paid Services, Inc. One Pre-Paid Way Ada, Ok 74820.
Email [email protected]
WHAT PERSONAL DATA IS COLLECTED FROM YOU?
I will only collect personal data about you that is required to serve the purpose or purposes for which it was collected. The type of personal data collected will depend upon whether you are a Member, a prospective Member or a site visitor, the purpose for which the data is required, and LegalShield’s legal and regulatory obligations. I will only collect your personal data as a data processor on behalf of LegalShield. Your personal data may be collected in a number of ways, including when you communicate or register with me through the Sites, or by telephone, post, or e-mail.
Please note that LegalShield may process your personal data without your knowledge or consent where this is required or permitted by law.
If you are a Member then the information that I collect from you on behalf of LegalShield may include the following:
- contact details (including name, postal address, email addresses and telephone numbers)
- contact details for other individuals entitled to use the product(s) you have purchased and your relationship to those individuals (if applicable);
- your date of birth and the dates of birth of other individuals entitled to use the product(s) you have purchased (if applicable);
- a copy of your driver’s licence, passport, or other suitable documentation to identify you and any other individual covered by the product(s) you have purchased;
- your credit card or debit card details if you make a purchase or pay subscription/membership fees for a product;
- your username and password for your online membership account with LegalShield UK;
- if you choose to use a social media single sign-on service, such as Facebook Connect, information from your social media account such as your name and email address and other information from your public profile to authenticate you;
- information about the product(s) you are purchasing and your use of the product(s);
- any information you send to me, including information relating to the matters about which you may contact a Plan Service Provider; and
- information as required by regulatory “know your customer,” anti-money laundering or proceeds of crime legislation — some of this information may be requested or obtained from third-party sources.
Users of the Sites
If you are a user of the Sites then the information that I collect from you on behalf of LegalShield (including when you interact with features of the Sites or request information) may include the following:
your name and contact details (i.e., address, home and mobile phone numbers, email address);
- your username and password;
- anything you download from the Sites;
- any information that you input into the Sites.
LegalShield uses "cookies" on the Sites. A cookie is a small file of letters and numbers that is placed on your computer's hard drive when you visit certain websites. Cookies may be used, for example, to identify whether you have visited a website before or if you are a new visitor and to help identify website features in which you may have the greatest interest. Cookies may enhance your online experience by saving your preferences while you are visiting a particular site. For more information please visit: http://www.allaboutcookies.org/.
The Sites are not intended for children and we do not knowingly collect data relating to children via the Sites.
WHY IS YOUR PERSONAL DATA COLLECTED?
LegalShield collects and processes your personal data in connection with its business and to pursue its related legitimate interests and rights, including the promotion and marketing of its products and services.
All personal data collected is processed in compliance with relevant Data Protection Legislation.
Purpose and Lawful Basis for Processing
When processing your personal data, the purposes for which and the lawful bases upon which your personal data is processed include the following, to the extent that they apply to you:
- to fulfil LegalShield’s contractual obligations to you;
- to perform and optimise the customer services provided to you and to other Members, on the basis of LegalShield’s legitimate interest in performing and optimising such services;
- to support LegalShield’s business processes including its information technology, electronic communications and electronic documents storage, management and transmissions, to fulfil its contractual obligations toward you, or, if not applicable, on the basis of LegalShield’s legitimate interests including to optimise the customer services provided to you and to other Members by supporting supporting business operations, administration, IT services, and network security, and to prevent fraud;
- to safeguard your personal data and our IT system with appropriate security, on the basis of LegalShield’s legitimate interest in such security;
- to exchange information, conduct due diligence, and answer your initial questions, on the basis of taking steps required to enter into a contract with you, or for the purposes of LegalShield’s legitimate interest in protecting its legal rights and a third party’s legalrights, or, if not applicable, on the basis of your consent (which will be separately obtained from you before or at that time);
- to keep you up-to-date with news that may be of interest to you, on the basis of LegalShield’s legitimate interest in using your personal data for marketing purposes or, if not applicable, on the basis of your consent (which will be separately obtained from you before or at that time);
- to present the Sites and site content in the best possible way for you and on your computer or otherdevice, on the basis of LegalShield’s legitimate interests in keeping the Sites updated and relevant, to develop its business, operations, and marketing strategy;
- for business transactions such as a merger, acquisition by another company, or sale of all or a portion of LegalShield’s assets on the basis of its legitimate interest in the sale or expansion of its business operations; and/or
- to comply with LegalShield’s legal and regulatory requirements (including the need to prevent and combat money laundering).
Where the processing of your personal data is based on your consent only, you have the right to withdraw this consent at any time. LegalShield will then erase your personal data or otherwise put it beyond use and will stop processing it.
I will only process your personal data for the purposes of the development and conduct of my business as a LegalShield Associate in my capacity as a data processor for LegalShield. This may include processing your personal data for purposes necessary for the performance of a contract with and to enable LegalShield to comply with its legal obligations.
If you fail to provide certain information when requested, LegalShield or I may be unable to perform a contract entered into with you, or may be prevented from complying with our legal obligations.
You may receive marketing communications from LegalShield if you are a Member or if you have given your consent or where it is pursuing a legitimate interest and has a lawful right to do so and, in each case, you have not opted out of receiving that marketing. You can ask LegalShield to stop sending you marketing messages at any time by following the unsubscribe links on any marketing message sent to you or by emailing [email protected] at any time.
HOW LONG IS YOUR DATA HELD?
LegalShield will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, legitimate administrative or operational purposes, and any reporting requirements.
The retention period is determined by the nature and duration of your relationship with LegalShield, local laws, contractual obligations, LegalShield’s reasonable business requirements, and your expectations and requirements. To determine the appropriate retention period for personal data, LegalShield will consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which your personal data is processed, whether those purposes can be achieved through other means, and the applicable legal requirements.
When it is no longer necessary to retain your personal data, LegalShield will securely delete or, in some circumstances, anonymise your personal data (so that it can no longer be associated with you and is no longer treated as personal data), in which case LegalShield may use this information indefinitely without further notice to you.
If you request that LegalShield stops sending you marketing materials, it will keep a record of your contact details and appropriate information to enable it to comply with your request not to be contacted again.
SHARING YOUR PERSONAL DATA
To provide its products and services and effectively run its business, LegalShield needs to transfer and share your personal data. Transfer and sharing of personal data will occur to:
- the Plan Service Providers as necessary for LegalShield to provide its services and for the Plan Service Providers to provide you with their services,
- other third party service providers used by LegalShield ;
- LegalShield US in the United States, or
- to public and regulatory bodies in the event we are required to do so.
Some of these transfers will involve international transfers of your personal data outside the European Economic Area (EEA) and data centers or those of our service partners or public and regulatory bodies.
Categories of recipients
Your personal data may be transferred to any of the following categories of recipients:
- LegalShield’s Plan Service Providers and their third party service providers;
- other vendors, suppliers or other third parties used by LegalShield in connection with the provision of its products and services including administrative, payment processing, IT, marketing, printing, shipping, fulfilment, web tools, fraud prevention, services as required to obtain the services needed to operate its business or to provide products and services to Members;
- LegalShield US in the United States;
- professional advisers including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services and
- public authorities if required to do so by law or legal process, in response to a request from government authorities, or if LegalShield believes that disclosure is necessary to prevent personal harm or financial loss.
All third party service providers are required to take appropriate security measures to protect your personal information and are not allowed to use your personal data for their own purposes. LegalShield only permits them to process your personal data for specified purposes and in accordance with its instructions. This excludes LegalShield’s Plan Service Providers who will process your personal data as data controllers for their own purposes.
International transfers of your personal data
LegalShield UK and LegalShield US share infrastructure, personnel and providers of services in connection with the provision of their services and the conduct of their marketing activities. LegalShield US also provides certain customer and support services to LegalShield UK. As a result, LegalShield US will receive or have access to and will process your personal data.
The LegalShield Plan Service Providers may use third party service providers as their data processors outside the EEA, and their processing of your personal data may involve a transfer of your personal data outside the EEA.
LegalShield’S third party service providers may be based outside the EEA so their processing of your personal data as data processors may involve a transfer of your personal data outside the EEA.
Whenever LegalShield transfers your personal data outside of the EEA it will ensure a similar degree of protection is afforded to your personal data by ensuring that at least one of the following safeguards is implemented:
- LegalShield will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission; or
- Where LegalShield transfers you personal data to a data controller outside of the EEA in a country that has not been deemed to provide an adequate level of protection for personal data by the European Commission (which includes a transfer by LegalShield UK to LegalShield US in the United States), LegalShield will use the ‘controller to controller’ model contract clauses approved by the European Commission which give personal data the same protection it has in the European Union;
- Where LegalShield transfers you personal data to a data processor outside of the EEA in a country that has not been deemed to provide an adequate level of protection for personal data by the European Commission (which includes a transfer by LegalShield UK to LegalShield US in the United States), LegalShield will use the ‘controller to processor’ model contract clauses approved by the European Commission which give personal data the same protection it has in the European Union.
If LegalShield wishes to transfer your personal data outside of the EEA but has not implemented one of the above safeguards then it will separately obtain your consent to that transfer.
Where a Plan Service Provider uses a third party service provider outside the EEA, LegalShield requires them (and they are required by law) to implement appropriate safeguards with those third party service providers to ensure that your personal data is afforded a similar level of protection as it would be afforded in the EU.
Please contact me or LegalShield if you want further information on the specific mechanisms used when transferring any of your personal data out of the EEA.
LegalShield places great importance on the security of all personally data associated with its Members and visitors to the Sites. LegalShield has put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered, or disclosed. For example, any personal data you provide to me will be processed on LegalShield’s secure servers. LegalShield’s secure server software encrypts the information to protect your data against unauthorised access.
In addition, access to your personal information is limited by LegalShield to those persons who have a business need to know. They will only process your personal information under LegalShield’s instructions, and they are subject to a duty of confidentiality.
LegalShield has put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where it is legally required to do so.
YOUR RIGHTS IN RELATION TO YOUR PERSONAL DATA
Depending on the facts and circumstances related to the personal data collected or obtained about you – including, for example, the nature of the information processed or where you are located or reside – you may have rights regarding the personal data held about you under relevant Data Protection Legislation. These may include the right to request information about, or access to, the personal data held, and rights to complain about how your personal data is handled. LegalShield is committed to honouring your legal rights whilst ensuring that such rights are exercised in accordance with LegalShield’s own legal and ethical obligations.
Right to request
Under certain conditions, you may have the right to request from LegalShield, among other things:
- access to certain information concerning your personal data and the way LegalShield is processing it;
- the correction of inaccurate or incorrect personal data;
- the erasure or the restriction of inaccurate, incorrect personal data or personal data unlawfully processed;
- to stop certain processing, at any time, on grounds relating to your particular situation, including profiling, and to stop any processing, at any time, where it relates to direct marketing;
- to receive your personal data in a structured, commonly used and machine-readable format, enabling you to transmit the personal data to another data controller.
For more information on the full extent of your rights or to exercise your rights, please contact our data privacy manager by mail or e-mail at the addresses indicated above with a brief explanation of your request. When exercising any of those rights, please let us:
- have enough information to identify you;
- have proof of your identity and address (a copy of your driver’s license or passport and a recent utility or credit card bill); and
- know the information to which your request relates.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request to speed up our response.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
Right to withdraw consent
In the limited circumstances where you may have provided your consent to the collection, processing, and transfer of your personal information for a specific purpose – for example, in relation to direct marketing you have indicated you would like to receive from LegalShield – you have the right to withdraw your consent for that specific processing.
You can exercise this option at any time by contacting LegalShield’s Data Privacy Manager either by post: [Mike File, Pre-Paid Services, Inc. One Pre-Paid Way Ada, Ok 74820] or by email: [email protected] Once LegalShield has received notification you have withdrawn your consent, LegalShield will no longer process your information for the purpose or purposes you originally agreed to, unless LegalShield has another legitimate basis for doing so in law.
If you would like to unsubscribe from any electronic marketing communication you can also click on the ‘unsubscribe’ button at the bottom of the relevant communication. It may take up to 10 days for this to take place.
Right to complain
Legalshield and I hope that we can resolve any query or concern you raise about LegalShield’s use of your personal data. However, if you believe that your personal data is not being lawfully processed by LegalShield under applicable Data Protection Legislation, you may lodge a complaint with the Information Commissioners Office (the UK’s supervisory authority for data protection): https://ico.org.uk