Privacy Notice

The purpose of this notice is to make you aware of how we will manage and protect your personal data.

You can use the short cut links below to go directly to specific sections.

Who we are Your Rights
Our lawful basis for collecting your data Subject Access Request
What data we collect Deletion of personal information
Sharing information with other data processors Restrict processing of personal information
Keeping your data safe Right to rectification
What we do with your data How to contact us
How long we keep your data Complaints

 

Who we are

ATOC Ltd manages Railcards on behalf of Britain's train companies. ATOC Ltd is the data controller and, as such, is responsible for ensuring the lawful and appropriate handing of all the personal data that you provide in order to purchase a Railcard.  ATOC Ltd's address is 200 Aldersgate Street, London EC1A 4HD.

Railcard and National Rail are trademarks of ATOC Ltd. ATOC Ltd also trades under the name Rail Delivery Group.

To contact us regarding our use of your data, please click here. Alternatively, you can write to us at ATOC Ltd 200 Aldersgate Street, London EC1A 4HD.

Our lawful basis for collecting your data

When you buy a Railcard, you enter into a contract with ATOC Ltd for the provision of the Railcard on behalf of train companies. Therefore, collecting your data is necessary for us to perform the contract with you. 

We will treat your data in an appropriate and lawful manner, in accordance with data protection laws.  

What data we collect

We only collect the data that we need in order to process your application. For all Railcards we collect your name, address, date of birth, email address and contact number. For age specific Railcards we also require details from either a UK driving licence, International Passport or National Identity Card to verify your date of birth. We also collect additional information depending on what Railcard you are purchasing:

  • 16-25 Railcard: we require your photograph. For mature students, we also require confirmation of your attendance at a university/college
  • Disabled Persons Railcard: we require evidence of your eligibility which may include evidence of receiving a government benefit, allowance or medical information
  • Family & Friends Railcard: if you decide to have a second cardholder named on the card, we will need their name.
  • Two Together Railcard: we require the name of the second cardholder and photographs of both you and the second named cardholder

If you choose to have your Railcard delivered to your mobile device, we will require your photograph regardless of the Railcard you are buying. 

If you are buying a Railcard on behalf of another person, we will need their personal details. In this case, we will deem that you have the other person's permission to provide their personal details.

If you choose to enter a voluntary prize draw for either market research or competitions, we will collect your personal email address, your name and postcode and Railcard number.

We use cookies and similar tools across our website to improve your experience and our website's performance. To find out more about cookies, read our Cookie Policy.

Sharing information with other data processors

To fulfil your request for a Railcard, we use a number of suppliers to produce, deliver and administer your Railcard. 

These suppliers are: 

  • Fast Rail Ticketing Ltd (who retail and fulfil the Network Railcard)
  • ESP Group (who retail, fulfil and provide customer support for the 16-25, 26-30, Family & Friends, Two Together, Senior and Disabled Persons Railcard) 
  • Ndata (who capture details from paper application forms)
  • Indicia (who provide our customer database)
  • Intelenet (who provide customer support for Network Railcard)
  • Salesforce (who sends our emails)
  • Rival (who sends renewal reminders by post)
  • Quiet Storm (who provide some of our website pages, including competition and contact forms)
  • BPA Quality (who provide quality assurance on email correspondence with the ESP Group customer support centre)

If you are applying for an age related Railcard, ESP Group will also verify the documents you have provided.

If you participate in a survey with us your survey responses will be processed by our survey supplier (Survey Monkey).

Your personal information may be disclosed to the train companies who run services in your region in order for them to administer and support your use of the Railcard. We also share information with law enforcement agencies on request.

We will not share your details with any other third parties for marketing purposes unless you provide us with your consent. If you consent to marketing, you can find out more about the communications you’ll receive in our Marketing & Contact Policy.

If you enter one of our prize draws for market research or competitions, your entry will be held by our suppliers (Survey Monkey for research and Quiet Storm for competitions). Winners of competitions will be notified using the contact details provided in their entry. Where a prize is being offered by one of our partners, your contact details may be provided to them in order for them to fulfil the prize.

ATOC Limited is updating the way we fulfil requests for Railcards, and some of the suppliers we use to produce, deliver and administer Railcards will be changing soon. In preparation, we are sharing Railcard data with the new suppliers listed below. Once this process is complete, we will stop sharing Railcard data with some of our existing suppliers, and update our Privacy Notice accordingly.

  • Salesforce (who send our emails and will provide our new database)
  • Sapient i7 (who will manage the Salesforce database)
  • Sitecore (who will provide our new website)
  • Jaywing (who will manage the Sitecore website)
  • Mulesoft (who will transfer data between our new website and database)
  • Teleperformance (who will provide customer support for all Railcards)
  • Vodafone (who will provide the telephone service for the Teleperformance customer support centre)

Keeping your data safe

We protect your privacy by ensuring we have the appropriate security measures in place. We ensure that our suppliers process your data in an appropriate, lawful and safe manner, and within the EU only.

If you participate in a survey with us your data will be held with our supplier (Survey Monkey) in the United States under an EU approved data protection framework. It will be anonymised for reporting purposes and then deleted after 30 days.

What we do with your data

We use your data to provide you with the Railcard, and:

  • to provide you with customer support services, for example if you lose your Railcard
  • to send you information about any changes to your Railcard’s terms and conditions
  • to alert you to any changes to this Privacy Notice; and
  • to remind you when your Railcard is due to expire.

We do some analysis on our customer data for sales analysis and marketing research including demographic, geographic and attitude analysis to understand who our customers are in groups rather than as individuals. 

If you enter one of our prize draws for market research or competitions, the data we collect will be kept securely whilst the survey and/or competition is live. The prize draw winner(s) details (first name and county) will be made available after the closing date for 30 days to those sending an email to [email protected] with the subject line of the survey title. Personal details will only be used for the purpose of the prize draw and will be deleted once the winner has been confirmed.

How long do we keep your data?

We keep your data while your Railcard is valid, and for two years thereafter to enable you to renew easily within that period. During this time you may receive other communications from us if you have consented.  

If you have started but not completed a Railcard application, and haven’t purchased a Railcard using an online account with us before, the data you have entered will be held for 30 days to allow you to return to complete your application. After that time it will be deleted.

If you participate in a prize draw for market research or competitions, your entry will be held for 30 days and then deleted.

Your rights

You have several rights to data protection which are set out below. To contact us in relation to your rights regarding how we use your data, please click here to submit a request.

Subject access request

You have the right to request that we give you a copy of the data we hold about you. This is called a ‘Subject Access Request’.

Deletion of personal information

You have the right to request that we delete any data that we hold on you after your Railcard has expired. 

Restrict processing of personal information

You have the right to request that we restrict processing of your information for specific purposes such as direct marketing. However, for the duration that your Railcard is active we will continue to process your data in the way we have set out in this Privacy Notice in order to enable us to fulfil our contract to you.

Right to rectification

If your details are incorrect, incomplete or have changed, you can contact us at any time to change these.   

If you brought your Railcard online, you can update your details by logging onto your online account on the relevant Railcard website and updating them. 

Alternatively, click here and fill out our online form to request changes to the data we hold on you.

How to contact us

To exercise any of your rights, set out above, please click here and fill out our online form or contact us using the details provided below:

Data Protection Lead for Railcards

ATOC Ltd, 200 Aldersgate Street, London EC1 4HD.

Tel: 0207 841 8000.

Please include your name, address and Railcard number, so that we can deal with your request.

Complaints

You have the right to complain about our processing to the Information Commissioner if you believe we are not processing your data in a proper manner - see https://ico.org.uk/concerns/handling/ for more information.

 

Last updated 28 June 2019.