DxO Limited, 'we'/ 'us' are committed to protecting the privacy and security of your personal information.
This Privacy Notice describes how we collect and use personal information about you during and after your relationship with us pursuant to the Data Protection (Jersey) Law 2018 (DPJL) and the General Data Protection Regulation (GDPR).
DXO is a "Data Controller", which means we are responsible for deciding how we hold and use personal information. We are also registered with the Jersey Office of the Information Commissioner (JOIC) - Registration 101542
We will comply with data protection law, the principles of which say that the personal information we hold about you must be:
Dxo is accountable to you and the authorities to show compliance with (DPJL) and GDPR, to demonstrate how we are compliant.
We have appointed a DPM to oversee compliance with this Privacy Notice.
If you have any questions about this Privacy Notice or how we handle your personal information, contact the DPM at dpo@practicetoolkit.co.uk
You have the right to make a complaint to the JOIC at any time.
Contact details for these are outlined at the bottom of this Privacy Notice.
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
To explain this to you, we will list our different services when we collect or use additional information about you.
We collect personal information about you when you contact us, engage us to provide a service or provide us with your data for another specific purpose.
DxO does not collect Special Category data from clients.
We assign a suggested access level for each team member based on the information you provide, according to the different roles assigned.
We will only use your personal information when the law allows us to.
Most commonly, we will use your personal information in the following circumstances:
We will only use your personal information for the purposes for which we collected it unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If we need to use your personal information for an unrelated purpose, we will notify you and explain the legal basis that allows us to do so.
We do not pass on information gained from your engagement with us without a clear legal basis for doing so. However, we may disclose your Personal Information to meet legal obligations, regulations, or valid governmental requests.
We use certain third parties, also known as Processors, to provide or support our services. We have appropriate agreements in place with those processors to ensure the safety of your information. For information on these processors, please see the table below. We do not share your information with any processors for direct marketing purposes.
| Processor | Description of processing | Link to Privacy Notice |
|---|---|---|
| AWS | Cloud infrastructure services. | AWS Privacy |
| Logz.io | Logging, monitoring, and observability of systems & applications. | Privacy Policy |
| Okta t/a Auth0 | Authentication services. | Okta Privacy |
| PostHog | User behaviour analytics, Feature Flags, A/B Experiments. | Privacy policy, PostHog style |
| Postmark | Transactional email. | Privacy Policy |
| Propelfwd | Data Protection Managers. They provide advice and assistance with our data protection requirements and have no access to your data. They will only if you put in a data rights request or if we have a data incident/breach. | Privacy Notice - PropelFwd |
| Sentry | Exception handling and monitoring. | Privacy Policy |
| 31 Green | Our IT support with access to our IT systems to allow for patching, maintenance and updates of our vital IT platforms. Also, cybersecurity procedures and management. | Privacy Policy - 31 Green |
Processors are other organisations/services carefully chosen by DxO to process your information correctly and securely. In the case of organisations outside of Jersey, the United Kingdom and the European Economic Area (EEA).
We store all customer data in the London, UK region of AWS. Additionally, we use certain tools such as our error reporting and user analytics platforms that are based in the EU, specifically in Frankfurt, Germany.
We ensure that your privacy rights are respected in line with this Notice, and the same protection is given to your personal data as laid down by the DPJL.
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, altered or disclosed, or accessed in an unauthorised way. In addition, we limit access to your personal information to those staff, agents, contractors and other third parties on a need-to-know basis.
They will only process your personal information according to our strict instructions and are subject to a duty of confidentiality.
Details of these measures may be obtained from our DPM.
We have put in place procedures to deal with any suspected data security breach and notify you and any applicable regulator of a suspected breach where we are legally required to do so.
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, as well as the potential risk of harm from unauthorised use or disclosure of your data. The purposes for which we process your data and whether we can achieve those purposes through other means, and the applicable legal requirements.
You can request our Data Retention Schedule from our DPM if required.
In some circumstances, we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.
The personal information we hold about you must be accurate and current.
Please keep us informed if your information changes during your relationship with us.
Under certain circumstances, by law, you have the right to:
If you want to review, verify, correct or request the erasure of your personal information, object to the processing or request that we transfer a copy of your personal information to another party, contact our DPM atdpo@practicetoolkit.co.uk
You will not have to pay a fee to access your personal information (or exercise any other rights). However, we may charge a reasonable fee if your access request is unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
If you would like to request the information we hold about you, send us a Data Subject Access Request by contacting our DPM on the email dpo@practicetoolkit.co.uk
You can also email in your request or make your request over the telephone verbally to one of our team, whichever way you feel more comfortable.
We will need to request specific information from you to help us confirm your identity and ensure your right to access the information (or exercise any of your other rights).
We will respond to your request without undue delay, but certainly within Four Weeks after satisfactory verification of your identity. In some circumstances, we can apply an eight-week extension to this time frame if the request is complex in nature, and it cannot be answered in the four-week time frame. If this is to happen, we will inform you as soon as possible.
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time.
To withdraw your consent, contact our DPM at dpo@practicetoolkit.co.uk
Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to unless we have another legitimate basis for doing so in law.
We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates.
We may also notify you in other ways from time to time about the processing of your personal information or request you to confirm the accuracy of the information we hold about you.
We want the chance to resolve any complaints you have about how we process your information. You have the right to complain to the JOIC about how we have used your data.
The details for each of these contacts are:
1 Le Pepiniere,
La Rue Du Boulay,
Trinity
Jersey
JE3 5JE
or email dpo@practicetoolkit.co.uk
2nd Floor,
5 Castle Street,
St Helier,
Jersey
JE2 3BT
Telephone +44 (0) 1534 716530 or email enquiries@jerseyoic.org
This privacy policy was last updated on May 20th 2025