{"id":14,"date":"2018-05-10T09:38:02","date_gmt":"2018-05-10T09:38:02","guid":{"rendered":"https:\/\/lodgemanager.co.uk\/new\/?page_id=14"},"modified":"2018-05-10T09:38:02","modified_gmt":"2018-05-10T09:38:02","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/lodgemanager.co.uk\/?page_id=14","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Security and GDPR<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Security of your data is our first priority and this page outlines some of our operating procedures and security practices.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Definitions<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We, our, us &#8211; Lodge Manager (Mint Solutions UK Ltd).<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">You, your, user &#8211; a person logging on via the Lodge Manager login page.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Support team &#8211; our employees or contractors who have access to provide support to you.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Confidentiality<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We place strict access controls over your data and are committed to ensuring that nobody has access to your data that shouldn&#8217;t.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">If you contact our support team, you will grant them temporary access to your Membership information so that they can provide support to you. Members of our support team are vetted and have strict rules and controls about what they can do with their access, and their usage is monitored. They cannot access your section(s) unless you contact support.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We will only access your information to either contact you to notify you of system maintainence or for the purposes of sending a subscription bill.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Security Features<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Logging<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Usage of our system by users is logged. We track every login, including the time.\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Access<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We have a password policy requiring passwords to be at least 8 characters with two different types of characters. Passwords are stored using a non-reversible method.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">If users forget their credentials, they can only reset their password after receiving an email with a link to reset their password. They are then sent a temporary password which they have to change after loggin in.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Users are automatically logged out of the system after a period of inactivity.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Users are encouraged to periodically review their access control lists to ensure fellow users have the right access.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Infrastructure<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Physical Locations<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Our data is hosting in an EU datacentre and backups are taken of the database.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">All administrative users (those with secretary rights) are responsible for keeping copies of their documents and are setup to receive a monthly email backup of the the member information in CSV format. They can stop this feature by logging into the system and updating their settings.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Data<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We do not share personal data to third-parties with the exception of email providers.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We are not responsible for the data that users add within the system, including its accuracy. This includes, but is not limited to, contents of external links, activities, emails, downloads and attachments.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">The system automatically removes data held on the device when the user no longer has access to the section. In the event of a device being lost, users can contact our support team to tell the device to remove its data when it is next used online.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">A lodge or chapters members data will be removed up to 6 months after their trial has expired or they no longer wish to use the service i.e. lapsed payment. We can of course remove their membership data sooner if they request this.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Encryption<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Our data is encrypted in transit and at rest.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Database backups are encrypted individually and off-site backups have full-disk encryption too.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Our employees&#8217; computers have full-disk encryption (although your data is not stored on employees&#8217; devices).<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Firewalls and Software Patching<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Firewalls are configured according to industry best practices and all unnecessary ports are blocked.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Our server provider performs automated network vulnerability scanning and software patching.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Backups<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">System-wide backups are held for a period of six months.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Legal Jurisdiction<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We operate under the laws of England and Wales.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Data Subject Rights (GDPR)<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Breach Notification<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">We will notify our administrative users of any breach of data via email within 72hrs of identifying the breach.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Right to Access<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Users are able to download information about members if required, and the support team can provide assistance if the downloads are not sufficient.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Right for Erasure<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Users are able to delete all personal data with the exception of the audit trail. Users can contact the support team for &#8216;Right for Erasure&#8217; requests.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Also we will delete a users data\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Data Portability<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Admin Users (with secretary rights) can download personal information abouth their membership in a spreadsheet format.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Privacy by Design<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Our system is always designed with privacy as our top priority. Features are tested manually by our expert development teams, automatically as part of the development &amp; deploy process, and through external security audits.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">GDPR compliance<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Lodge Manager is GDPR compliant &#8211; see above for details of technical and organisational security measures.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Personal data search<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Lodge Manager allows you to view members you have access to, subject to your permission levels.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Personal data deletion<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">Lodge Manager can delete all member data on request from a lodge but if a member is a member in another lodge using the system, the user data will not be fully removed unless requested by that user.<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n<div style=\"color: #222222; font-family: arial, sans-serif; font-size: small;\">\u00a0<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security and GDPR \u00a0 Security of your data is our first priority and this page outlines some of our operating procedures and security practices. \u00a0 Definitions We, our, us &#8211; Lodge Manager (Mint Solutions UK Ltd). \u00a0 You, your, user &#8211; a person logging on via the Lodge Manager login page. \u00a0 Support team &#8211; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/lodgemanager.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/14"}],"collection":[{"href":"https:\/\/lodgemanager.co.uk\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/lodgemanager.co.uk\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/lodgemanager.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lodgemanager.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14"}],"version-history":[{"count":0,"href":"https:\/\/lodgemanager.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/14\/revisions"}],"wp:attachment":[{"href":"https:\/\/lodgemanager.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}