(1) What information do we collect?
We may collect, store and use the following kinds of personal information:
(a) information about your computer and about your visits to and use of this website (including [your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation]);
(b) information relating to any transactions carried out between you and us on or in relation to this website, including information relating to any purchases you make of our goods or services (including Name, address, postcode, and purchase history);
(c) information that you provide to us for the purpose of registering with us (including name and email address);
(d) information that you provide to us for the purpose of subscribing to our website services, email notifications and/or newsletters (including name and email address);
(e) any other information that you choose to send to us;
A cookie consists of a piece of text sent by a web server to a web browser, and stored by the browser. The information is then sent back to the server each time the browser requests a page from the server. This enables the web server to identify and track the web browser.
We may use both “session” cookies and “persistent” cookies on the website. We will use the session cookies to: keep track of you whilst you navigate the website. We will use the persistent cookies to: enable our website to recognise you when you visit.
Session cookies will be deleted from your computer when you close your browser. Persistent cookies will remain stored on your computer until deleted, or until they reach a specified expiry date.
Most browsers allow you to reject all cookies, whilst some browsers allow you to reject just third party cookies. For example, in Internet Explorer you can refuse all cookies by clicking “Tools”, “Internet Options”, “Privacy”, and selecting “Block all cookies” using the sliding selector. Blocking all cookies will, however, have a negative impact upon the usability of many websites[, including this one].]
(3) Using your personal information
We may use your personal information to:
(a) administer the website;
(b) improve your browsing experience by personalising the website;
(c) enable your use of the services available on the website;
(d) send to you goods purchased via the website, and supply to you services purchased via the website;
(e) send you email notifications which you have specifically requested;
(f) send to you our newsletter marketing communications relating to our business which we think may be of interest to you by post or, where you have specifically agreed to this, by email or similar technology (you can inform us at any time if you no longer require marketing communications);
(g) deal with enquiries and complaints made by or about you relating to the website;
Where you submit personal information for publication on our website, we will publish and otherwise use that information in accordance with the licence you grant to us.
We will not without your express consent provide your personal information to any third parties for the purpose of direct marketing.
In addition, we may disclose your personal information:
(a) to the extent that we are required to do so by law;
(b) in connection with any legal proceedings or prospective legal proceedings;
(c) in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk);
(5) Security of your personal information
We do not store credit card details nor do we share customer details with any 3rd parties
We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information.
We will store all the personal information you provide on our secure (password- and firewall- protected) servers. All electronic transactions you make to or receive from us will be encrypted using SSL technology. 
Of course, data transmission over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.
[You are responsible for keeping your password and user details confidential. We will not ask you for your password (except when you log in to the website).]
(6) Policy amendments
(7) Your rights
You may instruct us to provide you with any personal information we hold about you. Provision of such information will be subject to:
(a) the payment of a fee (currently fixed at £10.00); and
(b) the supply of appropriate evidence of your identity [(for this purpose, we will usually accept a photocopy of your passport certified by a solicitor or bank plus an original copy of a utility bill showing your current address)].
We may withhold such personal information to the extent permitted by law.
You may instruct us not to process your personal information for marketing purposes[, by sending an email to us]. In practice, you will usually either expressly agree in advance to our use of your personal information for marketing purposes, or we will provide you with an opportunity to opt-out of the use of your personal information for marketing purposes.
(8) Third party websites
The website contains links to other websites. We are not responsible for the privacy policies or practices of third party websites.
(9) Updating information
Please let us know if the personal information which we hold about you needs to be corrected or updated.
(11) Data controller
The data controller responsible in respect of the information collected on this website is the Great Central Railway.
Our data protection registration number is Z6618600.
 “Personal information”: for day-to-day purposes, it is best to assume that all information which relates to a living individual constitutes personal information. (We use “personal data” and “personal information” interchangeably in this template.)
 The rules concerning cookies are set out in Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended). Regulation 6 provides that:
"(1) Subject to paragraph (4), a person shall not store or gain access to information stored, in the terminal equipment of a subscriber or user unless the requirements of paragraph (2) are met.
(2) The requirements are that the subscriber or user of that terminal equipment—(a) is provided with clear and comprehensive information about the purposes of the storage of, or access to, that information; and (b) has given his or her consent.
(3) Where an electronic communications network is used by the same person to store or access information in the terminal equipment of a subscriber or user on more than one occasion, it is sufficient for the purposes of this regulation that the requirements of paragraph (2) are met in respect of the initial use.
(4) Paragraph (1) shall not apply to the technical storage of, or access to, information—(a) for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network; or (b) where such storage or access is strictly necessary for the provision of an information society service requested by the subscriber or user."
 As a general rule, where you plan to use personal information you have collected for the purpose of direct marketing, this should be made clear on the page where the information is collected, and you should ensure that this only happens if users opt-in to the marketing (e.g. “Click here if you would like us to send you information by email about products which we think will interest you...”). There are however exceptions to this general rule. There are also rules about the content of direct marketing communications. If you are in any doubt about complying with your legal obligations in relation to direct marketing, you should seek professional advice.
 It is good practice to also say what you will not do with personal information (within reason).
 You should insert details of any payment services provider(s) you use here. If you don't collect payments on your website, you can delete this section.
 There is an obligation upon data controllers to store personal data securely. You should provide details of your security measures here.
 Changes to the policy – in particular as to permissible uses of personal data – may not be retrospective. In other words, if you collect personal information on one basis, you cannot, simply by changing the terms of your policy, go on to legitimately use that information on a different basis.
 You should include a postal address as well as an email address.