Data protection and privacy

We are passionate about providing teachers with the best materials, about which we will send you details and free samples to save you time and budget.

We have determined in accordance with General Data Protection Regulation (GDPR) that we shall process your personal data in our legitimate interests for the purpose of informing those we genuinely understand will be interested in, and may benefit from, our product - but, in so determining, we completely and properly respect your rights as a data subject and allow (see below) for you to rectify the data we hold about you and, if you wish, to have your data deleted from our systems.

In placing an order with us - either directly or through your school – we are required to process personal data to correctly process and supply you with goods or services as part of that transaction and the contractual fulfilment of the order. Part of this data will also be retained as an historic record with the school account. See Historic order data retention below.

Data collection

We collect data about you when you register with us or place an order for products or services. The data we collect consists of your:

We may also collect the name and contact email and / or phone number of your school’s finance officer. This data may be provided by yourself or through your finance department when an order is placed. We also collect data when you voluntarily complete customer surveys or provide feedback. The data collected is legitimately used to process your order, manage your account, for credit control and to inform you about our relevant products and services.

In addition to data directly provided, we may collect data about you through publicly available information, such as, and usually, your school’s website.  We do not collect residential data and shall only ever interact with you through your “work” details.

Managing your preferences

By creating an active account with us, you are able to log in to our website and access the My Account area. Here, you can check the data stored about you and edit anything that is incorrect or out of date. You may also change your preferences to receive email or catalogues by post from us.

Password privacy

The password you choose in registering on our website will never be known or disclosed. Passwords are encrypted on our servers and accessed through secure SSL HTTPS web browser protocols.

You are able to reset your password should you forget it, and on logging in to the website for the first time following such an event, you should choose a new secure and memorable password. Passwords should be complex, with a minimum of 8 characters comprising uppercase, lowercase and numeric characters.

Data retention and destruction

We will retain your personal data for a period of 5 years of inactivity from the date of collection at which point the data shall be deleted unless we revalidate that data by visiting your school's website prior to that date or subject to a hard bounce back email address notification from your school’s mail host.

Should you leave a school or change job roles, you will be able to update your details via the My Account area on the website. We will endeavour to keep your data up to date and maintain the accuracy of your data through regular revalidation.

Unsubscribing your data from our system can done through our marketing emails, by direct email to sales@pgonline.co.uk or via the My account area on our website. This will remove your complete record from our system. Please see Historic order data retention below.

Historic order data retention

Should you place an order with us for free or paid materials, your name, the date of the order and the order items will be recorded along with the school profile as an historic record of materials ordered on behalf of and licenced to the school. This minimal data will still be retained in the event that your personal account data is deleted from our systems.

Data Subject Access Requests

A Data Subject is a person or entity about whom we store data. Registered users may view the data we hold about them via the My Account area on our website. As a data subject, if you would like access to a record of the data we hold about you or your school, you are welcome to complete a Data Subject Access Request or DSAR. For details see Data collection above.

The DSAR service will be free unless it is manifestly unfounded, excessive or repetitive. We will duly correct or change any subject data, or if so desired, we will remove your data from our system. Submitting a DSAR can be done by post to our Data Controller at the Head Office address below, by direct email to privacy@pgonline.co.uk or via the My account area on our website. At your request, we will remove your complete record from our system. Please see Historic order data retention above.

Trusted third party Processors

We are obliged to share your data with other companies or organisations that help us to provide our products and services to you on our behalf or to process payment. Each of these organisations are bound by agreements to comply with our and their obligations. We do not share, rent or sell your information to any third party or other company outside of this exhaustive list.

Accounting and finance

Your details will be processed by our online invoicing, credit control and order processing provider in order to complete and process any order from you

Website hosting

Your details are held securely online by our web host in order to provide you with our services and manage your school discount levels and communication preferences

Distribution

Our distributors process your name, role and school address details in order to fulfil and deliver any physical textbooks

Mailing house

Your name, role and school address details will be processed by our mailing house in order to send you physical catalogues or free textbooks by post.

Site security

While we make reasonable attempts to exclude Trojans, viruses, worms and other malicious or destructive computer code from our website, we cannot guarantee such exclusion. We give no assurance (whether express or implied), assume no obligation and accept no liability in relation to these matters. You are strongly recommended to take all appropriate safeguards before using the website or downloading any information or content.

Our website is protected by SSL https encryption. Any locally stored data is encrypted and transmitted across our network securely. Data stored on our servers is securely protected including the encryption of passwords and other sensitive data.

Data controller

The full details of the data controller are:

PG Online Ltd
The Old Coach House
35 Main Road
Tolpuddle
Dorset
DT2 7EW

We are registered with the Information Commissioner’s Office. www.ico.org.uk Registration number: ZA330748