Toppsta’s Privacy Notice
At Toppsta, we take privacy very seriously. This notice explains how we treat your personal information when you give it to us and includes detail on your rights connected with this.
1. Who we are
Magnocarta Limited (trading as “Toppsta”) is the data controller of your personal data. We are responsible for its security and for the way in which we use it.
If you have any questions about this privacy notice or your rights, please contact us using the details set out below.
We are Magnocarta Limited (trading as “Toppsta”). Our registered address is Toppsta, Suite 272, 266 Banbury Road, Oxford OX2 7DL
We have been registered with the Information Commissioner’s Office since we began in September 2014 and have a Tier 1 certification, with registration number A8011087.
If you need to get hold of us for any reason in connection with your personal data, please email us at [email protected]
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns about data protection before you approach the ICO so please contact us in the first instance.
Changes to the privacy notice and your duty to inform us of changes
This version was last updated on 8th September 2021.
2. The information we collect about you and why we collect it
We do not ask you to disclose any more personal information than is reasonably necessary to enable you to participate in any Toppsta activity and to improve our online services. Below, we list the types of data we collect and explain why we collect it from you.
Are you under 13?
We do not collect information from anyone under 13. If you are under 13 you need to:
- Ask a parent or guardian to agree to our website terms and conditions; and
- Ask a parent to open an account on your behalf and set you up with a profile so that you can review books on the website.
If you would like to enter a Giveaway, someone aged 13 or above will need to enter on your behalf.
If you are invited to join our Video Review panel and would like to send us video book reviews featuring your children, we ask that these are emailed to us by a parent or guardian and that any parent or guardian agrees to our Video Terms and Conditions and complies with our Video Review Guidelines before sending anything to us.
Type of Data
What the information contains
How we use it
includes real name, user name (how you would like your name to be published), email address, gender, children’s usernames (how you would like their names to be published) and ages.
So you can set up an account with us and submit your book reviews and otherwise in accordance with our terms and conditions
Giveaway Entrant Data
includes name, email address and delivery address.
So that we can enter you into the prize draw and send you a prize if you win and otherwise in accordance with our terms and conditions
includes any review that you submit on our website or otherwise, where the review expresses your opinion or your child’s opinion.
In accordance with our terms and conditions
any requests to receive our newsletter and your email address
So that we can send you our newsletter at your request – you can opt out at any time by following the unsubscribe link in our message to you.
includes information about how you use our website.
So that we can analyse how visitors use our website to help us improve it.
includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
So that we can analyse how visitors use our website to help us improve it.
Business Contact Data
includes name, email address, role and company of individuals who we work, together with any email correspondence in which we express opinions, in the course of business.
So that we can run our business.
includes any video content that you submit on behalf of your child where the video expresses your child's opinion and your child's first name and age
We only use this Video data in accordance with our Video Terms and Conditions and with your express consent.
3. How is your personal data collected?
We use different methods to collect data from and about you including through:
· Direct interactions. We collect the majority of your data when you choose to give this to us on our website or by email or otherwise in the course of conducting business with us.
4. Disclosures of your personal data
We will need to share your personal data as below for the purposes set out in paragraph 2 above.
· All personal information is stored through an IT service company with servers based in the US.
· We share Newsletter Data with our email management company.
· We share Giveaway Data with our publisher partners where the publisher administers the giveaway.
· We share Video Data as explained in more detail in our Video Terms and Conditions.
· We may share Technical and Usage Data with analytics providers which may have servers based in the US to analyse website activity.
· We may share data with third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
5. International transfers
Our IT service company has servers based in the US and our email management company is based in the US. This involves a transfer of your personal information outside the European Economic Area (EEA).
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring that either:
· we have a specific contract with that processor in a form approved by the European Commission which ensures that service provider gives your personal data the same protection it has in Europe; or
· if the provider is based in the US, it is a member of the US Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
6. Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to our employees, agents or business partners who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
7. Data retention
How long will you use my personal data for?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
If you are a User or a Giveaway entrant, or if you have submitted any Video Data, you can ask us to delete your information or your child's information at any time.
If you are a Giveaway entrant, we will delete your information 2 weeks after a giveaway competition has ended. If you send us a Video Review and we decide not to use it, we will delete it from our systems.
If you are a User, we will automatically delete your account 5 years after it has become inactive, unless you ask us to do that sooner.
In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
8. Your legal rights
You have the right in certain circumstances to:
· Request access to your personal data (a "data subject access request").
· Request correction of the personal data that we hold about you.
· Request erasure of your personal data.
· Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms.
· Request restriction of processing of your personal data.
· Request the transfer of your personal data to you or to a third party.
For more information on these rights and when they apply is available here:
You will not have to pay a fee to access your personal data (or to exercise any of the other rights).
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.