Privacy and Cookie Notice


Privacy Notice: How We Deal with your Personal Information

The North York Moors National Park Authority is a ‘Data Controller’ as defined by Article 4(7) of the General Data Protection Regulations (GDPR). This means that the Authority has a duty of care towards the personal data that it collects and uses.

This privacy policy explains how we  use personal data fairly, keep it secure, make sure it is accurate and uphold your rights as a data subject.

What?

Personal information, or personal data, is defined as any information relating to a living individual who can be identified from that data or from that data in conjunction with other data held by the Authority.

In the course of our work we may hold personal information about individuals – this could include general details of name and address, or may be more detailed and in some instances “sensitive/special”, for example financial or health status, racial origin etc.

Why?

The “lawful basis” for the North York Moors National Park Authority processing personal information is in the provision of services and functions in the public interest or in the exercise of official authority; or in the performance of a contract; or for compliance with a legal obligation.

We process personal information in the course of carrying out our core functions to conserve and enhance the natural beauty, wildlife and cultural heritage of the North York Moors, and to promote the opportunities for the understanding and enjoyment of the area by the public.

We also process personal data to enable us to promote our services, to maintain our accounts and records, to support and manage our staff. We also carry out some “discretionary” activities for which we might ask for personal details, for example marketing, retail, surveys for which consent will be sought before storing personal details.

How?

Under the requirements of current data protection legislation (GDPR) we will ensure that personal data is processed fairly and lawfully, and only used for the purposes for which it was obtained; and that the rights of data subjects are properly respected.

When collecting personal information from you, we will tell you how this information is to be used, and will not use your details for other purposes without your consent.

We will ensure that the information is processed and filed in a secure way and that access to the information is restricted to those who need to use it for the purposes for which it was collected.

We will keep the information up to date and will not keep it for longer than necessary.

To ensure that we provide you with an efficient and effective service we will sometimes need to share your information with our partner organisations that support the delivery of the service you may receive. We may also need to supply your information to organisations we have contracted to provide a service to you.

We will only ever share your information if we are satisfied that our partners or suppliers have sufficient measures in place to protect your information in the same way that we do, and, where appropriate, Information Sharing Agreements are completed showing the rules to be adopted by the various organisations involved in the sharing exercise.

We will never share or sell your information for marketing purposes.

These principles and requirements should be seen in the context of other relevant legislation including the Human Rights Act 1998 and the Freedom of Information Act 2000.

Cookies

How we use cookies

Changes in the law mean that from 26 May 2011 we need your permission to save cookies on your device. Cookies are small files which are sent to your browser (for example Chrome or Safari) and stored on your device. They only identify your device and not you personally.

We encourage you to accept the cookies our website uses as they help us to improve the user experience and can make your visit more efficient but you can choose to delete or block cookies.

To delete cookies or reject cookies

If you do not want to receive cookies from this website, select cookie settings under the privacy settings in your browser options, then add our domain to the list of websites you do not want to accept cookies from. Under settings you can also delete individual cookies or any cookies that your browser has stored.

Details of the cookies we use are provided below. Please note that we cannot control cookies used by other parties, for example Google or YouTube, so we recommend that you read their Privacy Policies as well.

Website session / functional cookies

These cookies are set by our website's content management system and enables us to login and administer the site.

NamePurposeExpires
__cf_bmThis allows us to protect the site from malicious traffic.1 hour
dxp-sessionidThis helps us remember you as you navigate the site.1 hour
SQ_SYSTEM_SESSIONThis allows the site to differentiate between user visits to make the website work.When you close your browser
AWSALBCORS and AWSALBUsed for load balancing.When you close your browser
PHPSESSIDThis cookie is native to PHP and enables websites to establish a user session.When you close your browser
browser_version_alertFunctional cookie used to check your web browser type and version.1 day
xsrf-tokenA functional cookie protecting users and applications from Cross-Site Request Forgery (CSRF/XSRF) attacks.When you close your browser
Google Analytics / web analytics cookies

These cookies are used to help record your use of this website. They are used to collect statistics about site usage such as when you last visited the site. This information is then used to improve the user experience on our website. The Google Analytics cookies contain randomly generated IDs used to recognise your browser when you read a page. The cookies contain no personal information and are used only for web analytics.

NamePurposeExpires
_utma This cookie tracks whether you have visited the website before. 2 years after your last visit
_utmb This cookie establishes a ‘user session’ and tracks which pages you look at on this visit to the website. 30 minutes after your last visit
_utmc This cookie is connected with _utmb. When you close your browser
_utmz This cookie tracks whether you have come to the website from a search engine, another website or have typed the web address directly into your browser. 6 months after it was last set
_ga This cookie is used to distinguish users. 2 years after it was last set
_gcl_auCookie placed by Google Tag Manager to store and track conversions.3 months
Cookies that help with our communications and marketing

Our organisation utilises Force24’s marketing automation platform. Force24 cookies are first party cookies and are enabled at the point of cookie acceptance on this website. They allow us to understand our audience engagement thus allowing better optimisation of marketing activity. The Force24 cookies will remain on a device for 1 year unless they are deleted.

All links within emails and SMS messages sent from the Force24 platform contain a unique tracking reference, this reference help us identify who clicked an email for statistical purposes.

NamePurposeExpires
f24_autoId This is a temporary identifier on a local machine or phone browser that helps us track anonymous information to be later married up with f24_personid. If this is left anonymous it will be deleted after 6 months . Non-essential, first party, 1 year, persistent.
f24_personId This is an ID generated per individual contact in the Force24 system to be able to track behaviour and form submissions into the Force24 system from outside sources per user. This is used for personalisation and ability to segment decisions for further communications. Non-essential, first party, 1 year, persistent.
Cookies for social media

We have a number of social media accounts:

All these sites use cookie technology. For more information, please visit the pages below:

Other Tracking

We also use similar technologies including tracking pixels and link tracking to monitor your viewing activities.

Device & browser type and open statistics

All emails have a tracking pixel (a tiny invisible image) with a query string in the URL. Within the URL we have user details to identify who opened an email for statistical purposes.

Your Rights

The GDPR provides the following rights for individuals:

1. The right to be informed
2. The right of access
3. The right to rectification
4. The right to erasure
5. The right to restrict processing
6. The right to data portability
7. The right to object
8. Rights in relation to automated decision making and profiling.

If you would like to submit a Data Subject Access Request (DSAR) then this can be done by email or post, with a subject line of “Subject Access Request” to the below:-

general@northyorkmoors.org.uk

Customer Services
North York Moors National Park Authority
The Old Vicarage
Bondgate
Helmsley
YO62 5BP

You will also need to validate your identity (so that we can be certain that only you have access to your personal data). You can do this either by attending the Authority office in person or by providing us with copies of your ID.

Need further information?

If you would like to discuss anything further, or would like to see the Authority’s Data Protection Policy, please contact the Authority by email on general@northyorkmoors.org.uk or by telephone 01439 772700.

The Authority has appointed Peter Williams as Data Protection Officer, contact details are: Telephone No: (01439) 772700 E-mail address: p.williams@northyorkmoors.org.uk

You may also want to complain to the Information Commissioner’s Office (the Data Protection regulator) about the way in which the Authority has handled your personal data. You can do so by contacting:

Email: casework@ico.gsi.gov.uk
First Contact Team
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 03031 23 1113

Further information is also available from the Information Commissioner’s Office at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 01625 545 745; or visit the website ico.gov.uk

back to top