1. Introduction

BAFTA albert believes in being open about what data we collect from our users and what we do with it. The UK GDPR sets out comprehensive requirements for all companies handling the personal data of UK citizens. This includes a number of things we must tell you when we collect data from you. We have provided all the information you need as simply and clearly as possible through this Privacy Policy using a question-and-answer format.

2. What data will be collected about me and why?

The data we collect about you depends on how you interact with BAFTA albert and our sites. We have listed the different services we offer below: 

2.1 Newsletter Subscribers
If you subscribe to one of our newsletters then we will need to hold your email address in order to email you. We also ask for a first and last name so that we can make our emails more friendly and job title and sector so we can understand more about who we’re speaking to.  

 

2.2 albert toolkit users
When you sign up to use the albert toolkit we will ask for your first name, surname and email address to create an account for you to access the system. These details are required for us to be able log you in and to be able to send you transactional emails relating to your use of the albert toolkit.We will not use these details for any other purpose. We have a function in the Account Settings area that allows users to request the deletion of their account and personal data. The system can also hold a contact phone number for the first company admin user, but this field is optional. We do not use the data in this optional field for any purpose other than to contact the company admin if an urgent response is required.
 

2.2.1 Evidence
During the carbon action plan process the albert toolkit allows you to upload images, documents and other files to support your claims. You must redact any personal data from these files before uploading them. If any personal data is accidentally uploaded in these files, we will not use this for any purpose other than to validate erasure requests. If your data has been accidentally included then you can contact us as detailed below (see “What rights does GDPR give me?”) to request access to this data, or to request that this data be deleted. Evidence data will automatically be deleted after 7 years of storage.  

 

2.3 Students and Universities
When the albert toolkit is used in an academic context, students are provided with accounts by course administrators from the university. In this case the academic institution is the controller for the student’s personal data and albert is a processor. In this case the processing of students’ data will be governed by a data sharing agreement included as part of the contract between the academic institution and albert. Any students wishing to exercise their rights under the UK GDPR in relation to data held on the albert system should contact their academic institution. Prior to creating an account on your behalf, the course administrator should inform you of their role as controller of your data and how they use the data that will be processed by the albert system. 

 

2.4 Stakeholder Engagement
In our role to convene the industry albert may, from time to time, organise meetings with key stakeholders to discuss vision and strategy. You, or your employer may pass your name and email address details to albert to facilitate meeting arrangements and receive updates on actions arising from the meeting. If your details have been passed to us by your organisation then your organisation should have directed you to this Privacy Policy when they collected your details. Your details will be used to update you about, and/or invite you to take part in any events or initiatives which might be of interest to you or your organisation. We may also share with you third-party activity if BAFTA albert feels it is in BAFTA albert’s legitimate interest to do so.   

 

2.5 Training Attendees
If you attend a course that is run by albert then we will collect your email address, name and surname.  We may also ask about your region, career stage and department.  We require these details in order to be able to contact you to send you details and reminders relating to the training and ultimately, on successful completion of the training, send you your certificate. We may also use these details from time to time send you updates and invitations to promote albert events and initiatives based on your career stage and department, but only when there is legitimate interest to do so.  We use certifier.io to manage training the certification of training attendees, so your name and email address will be passed to Certifier.io. Any data shared with Certifier.io will be governed by Certifier Terms of Service (certifier.io) 

 

2.6 Event Attendees
If you attend an event run by albert we will collect your name, email address and details of your employment for the purpose of promoting future albert initiatives and events. This data will be collected and stored by Eventbrite (details below). When you register to attend an event you are given the option to sign up for the BAFTA albert newsletter or request additional information about specific albert initiatives. If you have indicated that you would like to receive the newsletter, or have expressed an interest in a particular initiative then we will use your name and email address to send you the newsletter and/or information about the initiative you are interested in. 

 

2.7 Suppliers Directory applicants
When you sign up to apply for the Suppliers Directory we will ask for your first name, surname and email address to create an account for you to access the system. These details are required for us to be able log you in and to be able to send you transactional emails relating to your Supplier Directory application status. We will not use these details for any other purpose. The company details you provide on your application for use on the albert website will be publicly available for 12 months from when your application is approved and may be extended for an additional 12 months subject to your Supplier Directory renewal.  

2.8 Studio Sustainability Standard applicants
If you apply to participate in the Studio Sustainability Standard, the names, companies and email addresses of individuals submitting will be held for the purpose of contacting directly about the project.  

The submitted evidence will be shared with external auditors for the purpose of assessing your grade. You must redact any personal data from these files before uploading them. If any personal data is accidentally uploaded in these files, we will not use this for any purpose other than to validate erasure requests. If your data has been accidentally included then you can contact us as detailed below (see “What rights does GDPR give me?”) to request access to this data, or to request that this data be deleted. Evidence data will automatically be deleted after 7 years of storage. Studio Standard Scorecards and industry reports will be kept indefinitely for the purpose of tracking industry progress.  

 

2.9 Miscellaneous Contact Details
During our normal day-to-day operations we receive enquiries and other communications from people by phone, email etc. If you contact us then our systems may store any of the contact details you provide in doing so e.g. your email address. We will use these details to contact you and to pursue albert’s legitimate business interests. We may make a record of discussions we have with you over the phone so that we can provide a consistent and efficient service if you call again. 

 

2.10 Website Analytics
In common with most other websites we use website analytics software which collects data about how people use our websites. However, this is anonymised and cannot be traced back to you. We use this to help make sure our web servers are working well and to see which parts of our websites are most/least popular. This will help us to improve the overall user experience. 

 

2.11 Cookies
The albert website uses a limited number of cookies, to offer a better user experience and to help us analyze traffic on the website. You should have been given the ability to opt out of these when you first arrived at the site. Currently the cookies the website uses are related to functionality around Google Analytics and Vimeo. 

3. Who is responsible for my data?

3.1 Unless you are a student of an academic institution who has signed you up to albert (see Students and Universities above), then albert is the controller for any data we collect about you.  You can contact albert with any questions in relation to how your data is used as follows: 

 

Postal: 

BAFTA albert Data Controller
BAFTA
195 Piccadilly
W1J 9LN 

 

Email: datacontroller@bafta.org 

4. How long will you keep my data for?

4.1 Newsletter Subscriptions
We will retain your name and email address details until you unsubscribe from the Newsletter. Every newsletter we send includes an ‘unsubscribe’ link at the bottom. 

4.2 albert toolkit Data
If you have an account to access the albert toolkit, then your contact details will be retained until your user account is deleted. Depending on your user permissions you may have to contact your company/university albert administrator to get your user account deleted.If you are the albert administrator for a company/university your contact details will be retained whilst your company is registered on the albert toolkit system until your company record is deleted, or an alternative company contact is provided. 

4.3 Training Records
From time to time we are asked to validate if a particular individual has attended a training course. For this reason, we retain training attendance for 3 years after your last session with us. This simply consists of a record of who (name and employment details) has attended our training and when. We will also keep anonymised data ‘job role/training type’ for reporting purposes indefinitely. 

4.4 Event Attendance
Eventbrite stores details of events you have attended. This data is stored in Eventbrite. albert use the tools provided by Eventbrite to delete attendance after 2 years. If you have any questions or concerns about the data stored by Eventbrite please refer to their Privacy policy. At the time of writing of this albert Privacy Policy, the Eventbrite privacy policy was available here: 

https://www.eventbrite.co.uk/support/articles/en_US/Troubleshooting/eventbrite-privacy-policy?lg=en_GB  

 

5. Where will my data be stored?

Your data may be stored on a number of different systems depending on what interactions you have had with BAFTA albert.

Some data will be stored on BAFTA’s own internal systems in our office in London

We also use cloud based services to store and process your data. Some of these cloud providers store data in the United States. In these cases we have reviewed the security and legal privacy safeguards put in place by each service provider. In addition to this, our contracts with these providers include clauses which guarantee that they provide the same safeguards for the data and rights to our members as if the data were stored in the EU. More information about the security measures put in place by these providers is provided in the links below. We may choose to use other service providers in future, if we do they will be bound by the same strict rules which guarantee that the same safeguards are in place, and your rights remain the same. If we change our service providers, then we will update the details on this page so you can always return to this page to see where your data is being stored. 

 

5.1 Eventbrite 

What data: Name, employment details, email address, areas of interest
Purpose: Registering for albert Events and Training 

Data location: USA 

Further information: 

https://www.eventbrite.co.uk/support/articles/en_US/Troubleshooting/eventbrite-privacy-policy?lg=en_GB  

 

5.2 Mailchimp 

What data: Just name and email address 

Purpose: Keeping in touch with members via email 

Data location: USA 

Further information: 

https://mailchimp.com/about/security/  

https://kb.mailchimp.com/accounts/management/about-mailchimp-the-eu-swiss-privacy-shield-and-the-gdpr  

 

5.3 Salesforce 

What data: Name and address details and records of interactions with Stakeholders only 

Purpose: Managing stakeholder engagement 

Data location: USA 

https://help.salesforce.com/article https://drive.google.com/drive/u/0/folders/1fofWR5wcWu7BY58RORVRiVlrzilvJx8u?fbclid=IwAR3-116bV7OSmjNIZYaVGQZCYCtcRaoxZTZaOMNaKCBlW9EMcyX6AU9pyeg&hl=en_GB View?id=Salesforce-Services-Trust-and-Compliance-Documentation&language=enUS&type=1  

 

5.4 AWS 

The albert toolkit system is hosted on Amazon Web Services (AWS) servers in Dublin, Ireland. AWS use a raft of logical and digital security features to keep data stored on their servers secure. These security measures are detailed here: https://aws.amazon.com/security/  

The security and privacy standards provided by AWS are defined in their online Service Terms (found here: https://aws.amazon.com/service-terms/ ). These terms incorporate a specific Data Processing Addendum (found here: https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf). This Addendum includes EU Model Clauses, which were approved by the European Union (EU) data protection authorities, known as the Article 29 Working Party. This means that personal data stored on AWS servers is given the same high level of protection it receives in the EEA.  

 

5.5. Stripe.com 

What data: Name address and payment details 

Purpose: Taking payment where an application or training  fee applies 

Data location: USA 

https://stripe.com/en-gb/privacy 

 

5.6 Certifier.io 

What data: Name, email Address 

Purpose: Providing and validating training badges 

Data Location: Krakow, Poland 

 

5.7 BAFTA Media Technology 

What data: Name, albert role for use of the tool (admin, reviewer, user), email address, details of your activity on the albert toolkit system. Name and email address, details of your activity for Supplier Directory 

Purpose: Operating the albert toolkit platform and sending you email alerts required for the correct functioning of the albert toolkit. Operating the Supplier Directory platform and sending you email alerts required for the correct functioning of the Supplier Directory.  

Data location: UK 

6. Who will have access to my data?

  1. 1 Staff within BAFTA albert whose duties require it will have access to our internal databases and systems. 

The albert toolkit, and the albert Supplier Directory application platform has been developed for albert by a subsidiary of BAFTA called BAFTA Media Technology (BMT). BMT maintain the servers which store all of the albert data. BMT staff have access to these servers, and therefore the data on them for maintenance purposes, but BMT are forbidden by their contract from using any of this data for any other purpose than providing the services for the albert toolkit and the albert Supplier Directory.  

BAFTA albert’s IT systems (email, general file storage etc) are provided and maintained by BAFTA. As a result, data collected about you (e.g. in emails, or other administrative documentation) may be processed by BAFTA. This data exchange is governed by a data sharing agreement between BAFTA and albert. 

Some technical tasks, such as configuring and securing our servers, require specialist expertise. In addition, external audits of Studio Sustainability Standard data, and Suppliers Directory inputs will require data to be accessed from individuals outside of BAFTA albert. We use specialist UK-based contractors to provide these services. These contractors are carefully vetted. All contractors must sign non-disclosure agreements which include a requirement that they keep all albert’s data confidential. 

7. Will you give my data to anyone else?

7.1 From time-to-time companies may ask us which of their employees have attended our training. If you have attended an albert training course and you provided a company name on the registration form then we will pass your name and email address to your employer if they enquire about attendance. 

We will also pass your details to law enforcement agencies if we are required to do so by law.  

We will not pass on or sell your details to anyone else. 

 

8. What rights does GDPR give me?

8.1 Here is a summary of the main provisions of the UK GDPR which are relevant to the type of data we hold about you: 

  • Access: You have the right to view the data we hold about you and to receive copies of this data in digital format. 
  • Accuracy / Rectification: If any of the data we hold about you is incorrect or incomplete then you can provide the correct or complete data and we must update the data we hold. 
  • Erasure: You can request that we erase all the data we hold about you, but this is only available in some situations. 
  • Restriction of processing: In some cases, you can ask us to retain your data but not do anything with it.

9. How do I exercise my GDPR rights?

If you want to exercise any of your rights in relation to data BAFTA albert holds about you then please email: datacontroller@bafta.org or write to the Data Controller at the address given above (see “Who is responsible for my data?”) 

Please provide details in your email/letter of what actions you would like us to take. Depending on the nature of the request and whether your request comes from the email address we have on file for you, we may need to verify your identity so that we don’t give out information to the wrong person or delete the wrong person’s information. In most cases, it helps if you provide a contact phone number so we can validate your identity and discuss the request with you. 

10. What if I have a complaint?

If you are concerned about how we manage your data, or how we have handled a request to exercise your rights, then please get in touch with us to discuss it. To do this please send an email detailing your concerns to datacontroller@bafta.org.If you are still not satisfied with the response you can take your concern to the Information Commissioner’s Office. For details of how to do this please refer to the ICO web site: https://ico.org.uk/