This Privacy Policy (“Policy”) supplements our Conditions of Carriage, and any other documents referred to within. Please read this Policy carefully as it contains important information on who we are, how and why we collect, store, use and share any personal information that you provided to us, whether through our website, by post, by telephone or mobile, in person (for example in booking office and on board), social media, through our apps or when you otherwise communicate with us. It also explains your rights in relation to your personal information and how to contact us or supervisory authorities in the event you have a complaint. If you have any questions or comments about this Policy, you can contact us by using the details set out below in section 13 (Data Protection Office) of this Policy.
NorthLink Ferries (“NorthLink Ferries”, “we”, “us”) are operated by Serco Limited, a company incorporated in England and Wales with Company Number 00242246 and having its registered office at Serco House, 16 Bartley Wood Business Park, Bartley Way Hook, Hampshire, RG27 9UY.
NorthLink Ferries is committed to protecting your privacy. Below we explain how we use any passenger information and how we protect your privacy.
For the purpose of the Data Protection Act 2018 (the “Act”); any other applicable laws relating to the protection of personal data and the privacy of individuals (all as amended, updated or replaced from time to time); and this Policy, we are one of the data controllers (independent of Transport Scotland) of your personal data for the purpose of providing the NorthLink Ferries services. This means that when we process your personal data, we are responsible for looking after and protecting your data. We are registered as a data controller with the UK’s Information Commissioner’s Office and our registration number is Z574698.
Please note, our site may provide links to third party websites. NorthLink Ferries is not responsible for the conduct of third-party companies linked to the website and you should refer to the privacy notices of these third parties as to how and why they may handle your personal information.
The personal data you provide to us or that are collected by us is used for service and operational purposes, for example making reservations, processing payments, producing tickets, fulfilling statutory requirement, protecting yourself and others. The types of personal data we may collect, store and use includes:
Please note, you do not have to provide your personal information to us. However, if you do not provide your personal information which we ask for we may not be able to: process a reservation for you; or provide our services to you; or respond to enquires that you may have.
NorthLink Ferries complies with the PCI DSS. We have in place robust controls surrounding the storage, transmission and processing of cardholder data that we handle.
Special Category and Sensitive Data
NorthLink Ferries does not systematically seek to collect, store or otherwise use special category personal data (for example information relating to your health or ethnicity), however we may on occasion handle such data where, for example, a passenger may: (i) require assistance for a disability; (ii) wish to declare specific medical conditions or dietary requirements; or (iii) share sensitive details in their communications with us.
Where special category personal information is involved, we will handle that information in accordance with applicable laws, including where:
Children’s data
Our services may be booked directly and used by individuals aged 16 years or over. However, we do not directly or knowingly collect or solicit personal information directly from anyone under the age of 16 or knowingly allow such persons to provide us with their personal information without parent or guardian consent. Parent, school and tours (or equivalent) may book to travel with us and may provide limited information about the children travelling with their group.
If you are under 16, do not send any information about yourself to us, including your name, address, telephone numbers, or email address, unless you have your parent’s or guardian’s permission. In the event we learn that we have collected personal information from anyone under the age of 16, and do not have a parent or guardian’s consent, we will delete that information as quickly as possible. In the event that we do hold personal data about children, we will handle that data in accordance with the terms of this Privacy Policy.
The circumstances in which we may collect personal data about you includes when:
We will only collect, use and share your personal information where we are satisfied that we have an appropriate legal basis to do so. The purposes for which we may use your personal data and the legal basis on which we may perform such processing are set out below.
Where necessary to the performance of a contract with you, or take steps linked to a contract
Where you give us consent
For purposes which are required by law
Where necessary for Serco’s or third parties legitimate interests and where the interests are not overridden by your data protection rights, such as:
We use cookies on our site. Cookies are small text files that are downloaded onto your device when you visit a website. Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our website. For detailed information on the cookies we use and the purposes for which we use them, please see our Cookie policy.
We may use your personal information to send you updates (by email, text message, telephone or post) about our services including e-newsletters, exclusive offers, events, promotions or products that we believe will be of interest to you where you have consented to such communication.
You can subscribe to our marketing list by selecting the option to receive marketing communications when booking on our website.
We will always treat your personal information with the utmost respect and never sell your information or share with other organisations without your prior permission for marketing purposes. We will take steps to limit direct marketing to a reasonable and proportionate level and only send you communications which we believe may be of interest or relevance to you.
You have the right to opt out of receiving marketing communications by:
If you choose not to receive updates about our services, we will be unable to keep you informed of any new products, exclusive offers, events or promotions that may interest you.
We currently have closed circuit television (CCTV) operating in our terminals, freight yards and on our vessels for (but not limited to): (i) public and worker health and safety; (ii) security; and (iii) crime prevention and detection. For these reasons, the information processed may include visual images of personal appearance and behaviours, and in certain circumstances various sound recordings of workers, passengers and general members of the public who were in the immediate vicinity of the area under surveillance.
We display signs to inform visitors and workers that they are under surveillance and there may be video and/or sound recording in operation. This information is kept in secure environments and access is restricted to NorthLink Ferries designated workers.
We will only disclose personal information to a third party in very limited circumstances, or where we are permitted or required to do so by law. The third parties to whom we provide your personal data include:
We may transfer your personal information to third parties in connection with a reorganisation, restructuring, merger, acquisition, sale or transfer of assets, or in the event there is a change of operator for NorthLink Ferries or in the event that there is a hand back of the operation to the customer (Transport Scotland on behalf of the Scottish Ministers). In such cases, we will take the appropriate steps to make sure that such transfer is in accordance with the applicable data protection law(s).
Less commonly, we may process and share your personal data where it is needed to protect your interests (or someone else’s interests) and you are not capable of giving your consent.
We also impose data protection obligations on contracted third parties to ensure they can only use your data when providing services to NorthLink Ferries for the purposes listed above. These third parties cannot pass your details on to any other parties unless instructed to by NorthLink Ferries.
Transferring Your Personal Information Globally
The personal information that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”) (for example, in the USA). It may also be processed by workers operating outside the EEA who work for us or for one of our service providers or we may share personal information with other companies within Serco Group located outside the EEA.
In the event, your personal information may need to be transferred outside of the EEA, we will take appropriate steps to ensure that transfers of personal data are in accordance with applicable law(s) and carefully managed to protect your privacy rights and interests and transfers are limited to countries which are recognised as providing an adequate level of legal protection, or where we are satisfied that alternative arrangements are in place to protect your privacy rights. Our standard practice when transferring personal data outside the EEA is to:
We will co-operate with any regulators as required by law to ensure that we remain transparent about the way we handle your personal information.
NorthLink Ferries takes precautions including administrative, technical and physical measures to safeguard your personal information against loss, theft and misuse, as well as against unauthorised access, modification, disclosure, alteration and destruction. We protect personal data using a variety of security measures including (but not limited to): password protected access; data back-up; encryption; firewalls; and secure storage facility with appropriate security restrictions.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Please ensure that any passwords which you are given or created by you to access our services are kept secure and safe.
We will store your personal information for as long as is reasonably necessary for the purposes for which it was collected, as explained in this Privacy Policy. Where your information is no longer needed, we will ensure that it is disposed of in a secure manner. If you would like further details about our retention policies, please email us at [email protected]
Listed below are the general criteria we use to determine how long we will keep your personal information, where upon we will either delete or anonymise the data:
In some circumstances we may store your personal information for longer periods of time, for instance where we are required to do so in accordance with contractual, legal, regulatory, tax and/or accounting requirements.
You have legal rights in connection with personal information.Under certain circumstances, by law you have the right to:
Please note, to ensure security of personal information, we may ask you to verify your identity before proceeding with any such request. We may also charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive.
If you would like to exercise any of these rights, please submit your requests to the Data Protection Office as detailed below. Subject to legal and other permissible considerations, we will make every effort to honour your request promptly to inform you if we require further information in order to fulfil your request. We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we have to others, or if we are legally entitled to deal with the request in a different way.
We have appointed a Data Protection Officer (DPO) to oversee compliance with this Privacy Policy. If you have any questions about this Privacy Policy or how we handle your personal information, please address to:
Data Protection Officer Serco Ltd Enterprise House 18 Bartley Wood Business Park Bartley Way RG27 9XB
Alternatively, please email [email protected] or call +44 (0)1256 745900.
We ask that you please first attempt to resolve any issues or concerns with us first, although you have a right to contact the Information Commissioner’s Office at any time and file a complaint where you believe there have been an infringement of data protection laws.
The contact details for the ICO are available at: https://ico.org.uk/concerns or via telephone: 0303 123 1113. The Information Commissioner’s Office will then investigate your complaint accordingly.
We may amend this Policy from time to time to keep it up to date with legal requirements and the way we operate our business. Please regularly check this page for the latest version of this Policy. If we change this Policy, we will post the details of the changes on this page. Any changes will be effective when posted and your continued use of this site will indicate your acceptance of these changes. If we make significant changes to this Policy, we may notify you of these via our home page or by email and/or post.
This Policy was last reviewed and updated in June 2021.