Introduction
www.mtbexams.com, its subdomains and Record & Submit App (‘Website’) are provided by MTB Exams Ltd (‘we’/’us’/’our’). In doing so, we may be in a position to receive and process personal information relating to you. As the controller of this information, we’re providing this Privacy Policy (‘Notice’) to explain our approach to personal information. This Notice forms part of our Terms and Conditions, which governs the use of our Website.
We intend only to process personal information fairly and transparently as required by data protection law including the General Data Protection Regulation (GDPR). In particular, before obtaining information from you (including through use of cookies) we intend to alert you to this Notice, let you know how we intend to process the information (including through use of cookies) and (unless processing is necessary for at least one of the 5 reasons outlined in clause 2 below) we’ll only process the information if you consent to that processing. The GDPR also defines certain ‘special categories’ of personal information that’s considered more sensitive. These categories require a higher level of protection, as explained below.
We’ll start this Notice by setting out the conditions we must satisfy before processing your data. However, you may wish to start with this table at clause 4, which summarises what we intend to collect, or this table at clause 8.5, which summarises our use of cookies. The Notice also explains some of the security measures we take to protect your personal information and tells you certain things we will or won’t do. You should read this Notice in conjunction with the Terms and Conditions.
Sometimes, when you take a new service or product from us or discuss taking a new service or product but decide against, we might wish to provide you with further information about similar services or products by email or other written electronic communication. In that situation, we will always give you the opportunity to refuse to receive that further information and if you change your mind please let us know. We’ll endeavour to remind you of your right to opt-out on each occasion that we provide such information.
- Identity and contact details
- Registered number: 07700372
- Registered office: Gable House, 18-24 Turnham Green Terrace, Chiswick, London, W4 1QP
- enquiries@mtbexams.com
- When we’re allowed to collect information from you
We will only collect personal information relating to you if one of the following conditions have been satisfied:
- You have clearly told us that you are content for us to collect that information for the certain purpose or purposes that we will have specified.
- The processing is necessary for the performance a contract/service that we have with you.
- The processing is necessary so that we can comply with the law.
- The processing is necessary to protect someone’s life.
- The processing is necessary for performance of a task that’s in the public interest.
- The processing is necessary for our or another’s legitimate interest – but in this case, we’ll balance those interests against your interests.
- How to consent
- At the point of collecting the information, we’ll endeavour to explain how we intend to use the information and which of these purposes apply. If we rely on consent, we’ll provide you with the opportunity to tell us that you’re happy to provide the information.
- If at any point in time you change your mind and decide that you don’t consent, please let us know and we’ll endeavour to stop processing your information in the specified manner, or we’ll delete your data if there is no continuing reason for possessing it.
- If you don’t consent to a particular bit of processing, we’ll endeavour to ensure that the Website and our service continue to operate without the need for that information.
- Information we expect to collect from you
- We envisage asking for the following types of information from you:
Information type | Purpose and related details | Justification |
Contact information such as your address, email or phone number | We ask for this to fulfill your order and verify your identity when you contact us
We intend to share this data with admin, secretarial support, fulfillment and delivery companies to allow the processing and delivery of your order or exam entries. They will be processing it for our purposes, under our directions and under a contract to ensure compliance with data protection law |
It’s necessary for the performance of a contract with you |
Payment details | We ask for this to process your payment
We intend to share this data with Paypal so we can process your payment, MTB does not store any cardholder data, it is held by established merchant services and payment gateway providers: Paypal. They will be processing it for our purposes, under our directions and under a contract to ensure compliance with data protection law |
It’s necessary for the performance of a contract with you |
Contact information: email | We ask for this to keep you updated with our newsletter and special promotions
We intend to share this data with marketing companies (such as zoho) to help us contact and update our users on special offers and news. They will be processing it for our purposes, under our directions and under a contract to ensure compliance with data protection law |
We’ll ask for your consent |
Teacher/candidate name, instrument date of birth, gender and Qualifications | We ask for this to place on your certificate and to process your exam entries
We intend to share this data with delivery & fulfilment companies so we can produce and send our certificates for your exams. They will be processing it for our purposes, under our directions and under a contract to ensure compliance with data protection law |
It’s necessary for the performance of a contract with you |
Exam Recordings, ID’s, signatures and copies of sheet music | We ask for this to assess and process your exam and to meet regulatory compliance in confirming your identity.
We intend to share this data with examiners, contractors and where required third parties to process and mark your examinations. Where it is shared with a third party they will be processing it for our purposes, under our directions and under a contract to ensure compliance with data protection law. Exam recordings and ID’s will be automatically deleted after 1 year unless they are required for training purposes whereby they will be deleted within 5 years of receipt. |
It’s necessary for the performance of a contract with you |
- We may collect personal information about you from a number of sources, including the following:
- From you when you agree to take a service or product from us, in which case this may include your contact details, date of birth, how you will pay for the product or service and your bank details.
- From you when you contact us with an enquiry or in response to a communication from us, in which case, this may tell us something about how you use our services.
- From documents that are available to the public, such as the electoral register.
- From third parties to whom you have provided information with your consent to pass it on to other organisations or persons.
- If you refuse to provide information requested, then if that information is necessary for a service we provide to you we may need to stop providing that service.
- At the time of collecting information, by whichever method is used, we’ll endeavour to alert you and inform you about our purposes. If at any point you think we’ve invited you to provide information without explaining why, feel free to object and ask for our reasons.
- Exam recordings and ID’s will be automatically deleted after 1 year unless they are required for training purposes whereby they will be deleted within 5 years of receipt.
Using your personal information
-
- Data protection, privacy and security are important to us, and we shall only use your personal information for specified purposes and shall not keep such personal information longer than is necessary to fulfil these purposes. The following are examples of such purposes. We have also indicated below which GDPR justification applies, however it will depend on the circumstances of each case. At the time of collecting we will provide further information, and you may always ask for further information from us.
- To help us to identify you when you contact us. This will normally be necessary for the performance our contract.
- To maintain accurate records of qualifications for compliance purposes and to ensure replacement certificates can be offered on request in performance of our contract.
- To help us to identify accounts, services and/or products which you could have from us or selected partners from time to time. We may do this by automatic means using a scoring system, which uses the personal information you’ve provided and/or any information we hold about you and personal information from third party agencies. We will only use your information for this purpose if you agree to it or in the performance of an agreed contract or service.
- To help us to contact you about important updates regarding our services and products. This will normally be necessary for the performance our contract.
- To allow us to carry out marketing analysis and customer profiling (including with transactional information), conduct research, including creating statistical and testing information. This will sometimes require that you consent but will sometimes be exempt as market research.
- To help to prevent and detect fraud or loss. This will only be done in certain circumstances when we consider it necessary or the law requires it.
- To allow us to contact you by written electronic means (such as email, text or multimedia messages) about products and services offered by us where:
- these products are similar to those you have already purchased from us,
- you were given the opportunity to opt out of being contacted by us at the time your personal information was originally collected by us and at the time of our subsequent communications with you, and
- you have not opted out of us contacting you.
- To allow us to contact you in any way (including mail, email, telephone, visit, text or multimedia messages) about products and services offered by us and selected partners where you have expressly consented to us doing so.
- To keep you up to date with our Newsletter. We will only do this if you have expressly consented to receive these communications.
- We may monitor and record communications with you (including phone conversations and emails) for quality assurance and compliance.
- Before doing that, we will always tell you of our intentions and of the specific purpose in making the recording. Sometimes such recordings will be necessary to comply with the law. Alternatively, sometimes the recording will be necessary for our legitimate interest, but in that case we’ll only record the call if our interest outweighs yours. This will depend on all the circumstances, in particular the importance of the information and whether we can obtain the information another way that’s less intrusive.
- If we think the recording would be useful for us but that it’s not necessary we’ll ask whether you consent to the recording, and will provide an option for you to tell us that you consent. In those situations, if you don’t consent, the call will either automatically end or will not be recorded.
- When it’s required by law, we’ll check your details with fraud prevention agencies. If you provide false or inaccurate information and we suspect fraud, we intend to record this.
- We will not disclose your personal information to any third party except in accordance with this Notice, and in particular in these circumstances:
- They will be processing the data on our behalf as a data processor (where we’ll be the data controller). In that situation, we’ll always have a contract with the data processor as set out in the GDPR. This contract provides significant restrictions as to how the data processor operates so that you can be confident your data is protected to the same degree as provided in this Notice.
- Sometimes it might be necessary to share data with another data controller. Before doing that we’ll always tell you. Note that if we receive information about you from a third party, then as soon as reasonably practicable afterwards we’ll let you know; that’s required by the GDPR.
- Alternatively, sometimes we might consider it to be in your interest to send your information to a third party. If that’s the case, we’ll always ask whether you agree before sending.
- Where you give us personal information on behalf of someone else, you confirm that you have provided them with the information set out in this Notice and that they have not objected to such use of their personal information.
- In connection with any transaction which we enter into with you:
- We may carry out one or more fraud prevention checks with licensed fraud prevention agencies.
- We and they may keep a record of the search. Information held about you by these agencies may be linked to records relating to other people living at the same address with whom you are financially linked.
- If you provide false or inaccurate information to us and we suspect fraud, we will record this and may share it with other people and organisations. We, and other credit and insurance organisations, may also use technology to detect and prevent fraud.
- If you need details of those fraud prevention agencies from which we obtain and with which we record information about you, please write to our Data Protection Manager at MTB Exams Ltd, Gable House, 18-24 Turnham Green Terrace, Chiswick, London, W4 1QP.
- We may need to transmit the payment and delivery information provided by you during the order process for the purpose of obtaining authorisation from your bank or from PayPal.
- We may allow other people and organisations to use personal information we hold about you in the following circumstances:
- If we, or substantially all of our assets, are acquired or are in the process of being acquired by a third party, in which case personal information held by us, about our customers, will be one of the transferred assets.
- If we have been legitimately asked to provide information for legal or regulatory purposes or as part of legal proceedings or prospective legal proceedings.
- We may employ companies and individuals to perform functions on our behalf and we may disclose your personal information to these parties for the purposes set out above, for example, for fulfilling orders, delivering packages, sending postal mail and email, removing repetitive information from customer lists, analysing data, providing marketing assistance, providing search results and links (including paid listings and links) and providing customer service. Those parties will be bound by strict contractual provisions with us and will only have access to personal information needed to perform their functions, and they may not use it for any other purpose. Further, they must process the personal information in accordance with this Notice and as permitted by the GDPR. From time to time, these other people and organisations to whom we may pass your personal information may be outside the European Economic Area. We will take all steps reasonably necessary to ensure that your personal information is treated securely and in accordance with this Notice and the GDPR.
- Data protection, privacy and security are important to us, and we shall only use your personal information for specified purposes and shall not keep such personal information longer than is necessary to fulfil these purposes. The following are examples of such purposes. We have also indicated below which GDPR justification applies, however it will depend on the circumstances of each case. At the time of collecting we will provide further information, and you may always ask for further information from us.
Protecting information
-
-
-
- We have strict security measures to protect personal information.
- We work to protect the security of your information during transmission by using Secure Sockets Layer (SSL) software to encrypt information you input.
- We reveal only the last five digits of your credit card numbers when confirming an order. Of course, we transmit the entire credit card number to the appropriate credit card company during order processing.
- We maintain physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of personally identifiable customer information. Our security procedures mean that we may occasionally request proof of identity before we disclose personal information to you.
- It is important for you to protect against unauthorised access to your password and to your computer. Be sure to sign off when you finish using a shared computer.
-
-
The internet
-
-
- If you communicate with us using the internet, we may occasionally email you about our services and products. When you first give us personal information through the Website, we will normally give you the opportunity to say whether you would prefer that we don’t contact you by email. You can also always send us an email (at the address set out below) at any time if you change your mind.
- Please remember that communications over the internet, such as emails and webmails (messages sent through a website), are not secure unless they have been encrypted. Your communications may go through a number of countries before they are delivered – this is the nature of the internet. We cannot accept responsibility for any unauthorised access or loss of personal information that is beyond our control.
-
Cookies and other internet tracking technology
-
-
- When we provide services, we want to make them easy, useful and reliable. This sometimes involves placing small amounts of information on your computer, which is sent back to us at a later time. These are called ‘cookies’. These cookies are listed in the table at clause 8.5. Some websites don’t use cookies but use related technology for gaining information about website users such as JavaScript, web beacons (also known as action tags or single-pixel gifs), and other technologies to measure the effectiveness of their ads and to personalise advertising content. Multiple cookies may be found in a single file depending on which browser you use.
- Where applicable, this section of the Notice also relates to that technology but the term ‘cookie’ is used throughout.
- Some of these cookies are essential to services you’ve requested from us, whereas others are used to improve services for you, for example through:
- Letting you navigate between pages efficiently
- Enabling a service to recognise your computer so you don’t have to give the same information during one task
- Recognising that you have already given a username and password so you don’t need to enter it for every web page requested
- Measuring how many people are using services, so they can be made easier to use and that there is enough capacity to ensure they are fast
- To learn more about cookies, you may wish to visit: allaboutcookies.org, www.youronlinechoices.eu or www.google.com/policies/technologies/cookies/
- This Website uses, or allows use of, the following cookies:
-
Cookie name | Cookie qualities |
Google Analytics | · To collect anonymised website statistics such as number of website visitors, visitor country, session length, etc.
· Category 2 – performance · Third party: another website is placing the cookie · Session · We’ve removed any information that might identify you in such a way that it should not be possible to reassemble the data · The information will be sent to Google so that they can collate data statistics to allow tracking of our website statistics |
Maxmind Geolocation | · This is required to direct users to the correct regional multi-site and ensure they access the correct products and services for their region. It also ensures with future visits by the user they are automatically placed on the correct region site.
· Third Party · Persistent · Category 1 – Strictly Necessary |
ProctorEdu | · This is only relevant where users are taking a proctored exam. The proctoring service provider is ProctorEdu and cookies are used in the performance of a contracted service.
· Third Party · Session · Category 1 – Strictly Necessary |
CURCY – WooCommerce Multi Currency | · This is required to display the correct currency, pricing and payment methods for our products and services to users for their specific region. This involves Geo-location of users.
· Third Party · Session · Category 1 – Strictly Necessary |
- You have the opportunity to set your web browser to a) accept all or some cookies, b) to notify you when a cookie is issued, or c) to receive no cookies at any time. Option c) means that this Website can’t provide personalised services and you may not be able to take full advantage of all of its features. Refer to your web browser’s ‘Help’ section for specific guidance on how it allows you to manage cookies and how you may delete cookies you wish to remove from your computer. Please note that category 1 cookies that are blocked by a browser may lead to reduced access to our products and services and some contracts/services may be unable to be fulfilled and voided.
- The distinctions referred to in the above table are as follows:
- First party versus third party cookies – we set first party cookies ourselves; third party cookies are set by other entities via our Website.
- Session versus persistent cookies – session cookies only persist for the duration of that visit; persistent cookies last for longer
- Identifying information removed – just because we’ve done this, they will still be personal information if the relevant information can be reassembled
- Categories 1-4 found in the ICC UK Cookie guide, as explained below. Category 1 cookies don’t require the user’s consent, though you must still tell them about the cookies. Categories 2-4 do require their specific and informed consent.
Category 1 | Strictly necessary | These cookies are essential in order to enable you to move around the website and use its features, such as accessing secure areas of the website. Without these cookies services you have asked for, like shopping baskets or e-billing, cannot be provided.
We include in this category cookies that are used only for electronic communication. (The ICC doesn’t refer to these cookies, but the law is the same.) Note that cookies for which another person is the controller will never be necessary for a service requested of you. On the other hand, if you’ve asked another person to send a cookie on your behalf for an essential feature of your website, that would be category 1. |
Category 2 | Performance | These cookies collect information about how visitors use a website, for instance which pages visitors go to most often, and if they get error messages from web pages. This information is only used to improve how a website works. |
Category 3 | Functionality | These cookies allow the website to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. For instance, a website may be able to provide you with local weather reports or traffic news by storing in a cookie the region in which you are currently located. These cookies can also be used to remember changes you have made to text size, fonts and other parts of web pages that you can customise. They may also be used to provide services you have asked for such as a live chat session. |
Category 4 | Targeting and advertising | These cookies are used to deliver adverts more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. They are usually placed by advertising networks with the website operator’s permission. They remember that you have visited a website and this information is shared with other organisations such as advertisers. Quite often targeting or advertising cookies will be linked to site functionality provided by the other organisation. |
- As with any other information we may collect from you, we’ll work to protect the security of your information during transmission by using Secure Sockets Layer (SSL) software to encrypt information you input.
- The Website may include third-party advertising and links to third-party websites. We do not provide any personally identifiable customer personal information to these third-party advertisers or third-party websites except where you’ve consented in accordance with this privacy notice, however as to cookies please see above clause Cookies and other internet tracking technology. Personal information will only be sent
- We exclude all liability for loss that you may incur when interacting with this third-party advertising or using these third-party websites unless you’ve consented in accordance with this privacy notice.
Further information
-
- If you would like any more information or you have any comments about this Notice, please either write to us at Data Protection Manager, MTB Exams Ltd, Gable House, 18-24 Turnham Green Terrace, Chiswick, London, W4 1QP, or email us at enquiries@mtbexams.com.
- Please note that we may have to amend this Notice on occasion, for example if we change the cookies that we use. If we do that, we will publish the amended version on the Website. It’s your responsibility to check regularly to determine whether this Notice has changed.
- You can ask us for a copy of this Notice by writing to the above address or by emailing us at enquiries@mtbexams.com. This Notice applies to personal information we hold about individuals. It does not apply to information we hold about companies and other organisations.
- If you would like access to the personal information that we hold about you, you can do this by emailing us at enquiries@mtbexams.com or writing to us at the address noted above. There is not normally a fee for such a request, however if the request is unfounded, repetitive or excessive we may request a fee or refuse to comply with your request. You can also ask us to send the personal information we hold about you to another controller.
- We aim to keep the personal information we hold about you accurate and up to date. If you tell us that we’re holding any inaccurate or incomplete personal information about you, we will promptly amend, complete or delete it accordingly. Please email us at enquiries@mtbexams.com. You have the right to complain to the Information Commissioner’s Office if we don’t do this.
- You can ask us to delete the personal information that we hold about you if we relied on your consent in holding that information or if it’s no longer necessary. You can also restrict or object to our processing of your personal information in certain circumstances. You can do this by emailing us at enquiries@mtbexams.com or writing to us at the address noted above.
- We will tell you if there is a breach, or a likely breach, of your data protection rights.