Privacy Policy

1. Introduction

At the Scottish Surfing Federation, we are fully committed to protecting your personal data and respecting your privacy rights. This Privacy Policy outlines how we collect, use, store, and protect your information when you interact with our website, scottishsurfingfederation.com. We are dedicated to maintaining the confidentiality, integrity, and security of your personal information and to complying with all relevant data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), where applicable.

2. Scope of This Policy and Data Controller Role

This Privacy Policy applies to all users of the website scottishsurfingfederation.com and any other associated digital services we offer. The Scottish Surfing Federation operates as the data controller with respect to the personal data collected via this website. As the data controller, we determine the purposes and means of processing your personal data.

3. Categories of Personal Data Processed

We may process the following categories of personal data:

– Usage Data:
Includes data about your interaction with scottishsurfingfederation.com, such as your IP address, browser type and version, device type, pages visited, time spent on pages, session durations, referring URLs, and other diagnostic data collected via analytical tools.

– Account Data:
Personal information provided when creating an account or registering for events, including your full name, postal address, email address, phone number, and similar identifiers.

– Profile Data:
Includes your interests, preferences, surfing skill level, purchase history, event attendance, and behavioral patterns on our website.

– Communication Data:
Includes records of your communications with us, such as emails, enquiry forms, support requests, and correspondence history.

– Technical Data:
Pertains to technical settings and configurations of the devices you use to access our website, including operating system, device identifiers, screen resolution, and language settings.

– Transaction Data:
Includes information related to purchases made through scottishsurfingfederation.com, such as order details, payment card information (processed via secure third-party providers), billing address, and delivery details.

– Preference Data:
Includes your responses to marketing preferences, product/service interests, newsletter signups, competition entries, and cookie consent choices.

4. Legal Bases for Processing Your Data

We rely on the following legal bases to process personal data:

– Contractual Necessity:
To fulfill any contractual obligations, such as processing your event registration, shipping a product, or providing digital services.

– Legitimate Interests:
To improve our services, administer the website, perform analytics, prevent fraud, and promote Scottish Surfing Federation events, where such interests do not override your fundamental rights.

– Consent:
For direct marketing activities, personalized ads, non-essential cookies, and where local law requires consent as a basis for data processing.

– Legal Obligation:
For complying with applicable legal requirements or responding to lawful requests from competent authorities.

5. Your Data Protection Rights

Subject to local data protection laws, you have the following rights with respect to your personal data:

– Right of Access:
You may request access to the personal data we hold about you.

– Right to Rectification:
You may request correction of inaccurate or incomplete information.

– Right to Erasure:
You can request that we delete your personal data, subject to lawful grounds for retaining such data.

– Right to Restrict Processing:
You may ask us to limit the way we use your data in certain circumstances.

– Right to Data Portability:
You have the right to receive personal data concerning you in a commonly used format and transmit it to another controller.

– Right to Object:
You may object to processing based on legitimate interests or for direct marketing purposes.

To exercise these rights, please contact us at [email protected].

6. Security Measures

We have implemented a range of technical and organizational security measures designed to safeguard your personal data from unauthorized access, alteration, disclosure, or destruction. These include but are not limited to encryption, user access controls, secure server environments, regular system audits, employee privacy training, and robust backup protocols.

7. International Data Transfers

Where necessary, we may transfer your personal data outside your country or region, such as to third-party service providers based in jurisdictions with differing data protection laws. In such cases, we ensure proper data protection safeguards, including the use of Standard Contractual Clauses approved by the European Commission or equivalent legal mechanisms.

8. Data Retention

We retain personal data for no longer than necessary for the purpose it was collected. Retention periods vary based on the nature of the data:

– Usage and Technical Data: Retained for up to 26 months for analytics and diagnostics.
– Account and Profile Data: Retained as long as your account remains active, and for up to 6 years thereafter for legal or audit purposes.
– Communication and Support Data: Retained for 3 years after your last interaction.
– Transaction Data: Retained for 7 years in compliance with financial and tax record obligations.
– Marketing Preference Data: Retained until you revoke your consent or request erasure.

9. Cookie Policy

Our website uses cookies and similar technologies to enhance functionality and provide a better user experience. We categorize cookies as follows:

– Essential Cookies:
Necessary for the operation of scottishsurfingfederation.com, such as enabling secure logins and page navigation.

– Functional Cookies:
Enable features like language selection, saved preferences, and enhanced accessibility.

– Analytics Cookies:
Collect information about how visitors use our site to help us improve performance and user experience. Data is anonymized or pseudonymized before processing.

– Performance Cookies:
Assess system load, page speed, and provide technical diagnostics to improve the responsiveness of the website.

10. Cookie Management and Legal Compliance

In compliance with GDPR and CCPA, visitors can manage cookie preferences through our Cookie Consent banner upon first visit and through browser settings thereafter. We provide affirmative opt-in for non-essential cookies and honor Do Not Track (DNT) signals where technically feasible.

You can update your cookie preferences or withdraw your consent at any time by revisiting the cookie settings via our website footer or sending a request to [email protected].

11. Children’s Privacy

Our services are not directed to children under the age of 13, and we do not knowingly collect personal data from children under this age. If you believe that a child under the age of 13 has provided us with personal data, please email us at [email protected], and we will take steps to delete such information promptly.

12. Policy Updates

We reserve the right to update this Privacy Policy from time to time in order to reflect changes in data processing practices, regulatory developments, or improvements to our website. Where material changes are made, we will notify users through appropriate channels, such as on-site banners or by email. Your continued use of scottishsurfingfederation.com following such changes constitutes acknowledgment of the updated policy.

13. Contact Us

If you have any questions, concerns, or complaints regarding your privacy or this Privacy Policy, please contact us using the following details:

Email: [email protected]
Website: https://scottishsurfingfederation.com

We are committed to resolving any concerns in a respectful and timely manner.

This Privacy Policy reflects our ongoing commitment to data protection, user privacy, and full compliance with all applicable laws, including the GDPR and CCPA. For any further enquiries, please contact [email protected].