Privacy Policy
1. IMPORTANT INFORMATION AND WHO WE ARE
2. THE DATA WE COLLECT ABOUT YOU
3. HOW IS YOUR PERSONAL DATA COLLECTED?
4. HOW WE USE YOUR PERSONAL DATA
5. DISCLOSURES OF YOUR PERSONAL DATA
10. GLOSSARY
1. Important information and who we are
2. The data we collect about you
- Identity & Contact Data includes name, username or similar identifier, age and/or date of birth and gender, billing address, delivery address, email address and telephone number(s).
- Financial Data includes bank account and payment card details.
- Transaction Data includes details about payments to and from you and other details of goods and services you have purchased from us
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Site.
- Usage Data includes information about how you use our Site, goods and services purchased on our Site.
- Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
3. How is your personal data collected?
- Direct interactions. You may give us your Identity & Contact Data and Financial Data by signing up for an account, placing an order for goods or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
-
- place an order for goods or services;
- create an account on our Site (or update your account details);
- request marketing to be sent to you;
- enter a competition, promotion or survey; or
- give us feedback or contact us by post, phone, email or otherwise (we will keep a copy of the correspondence).
- Automated technologies or interactions. As you interact with our Site, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our cookie policy for further details.
- Third parties or publicly available sources. We may receive personal data about you from various third parties and publicly available sources as set out below:
- Technical Data from analytics providers such as Google.
- Identity & Contact Data, Financial Data and Transaction Data from providers of technical, payment and delivery services.
- Identity & Contact Data from publicly available sources (such as Companies House and the Electoral Register)
4. How we use your personal data
- Where we need to perform the contract we are about to enter into or have entered into with you.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal obligation.
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest | How long do we store the data for? |
To register you as a new customer, set up and manage your account and to manage our relationship with you including: (a) communicating with you in relation to orders, in response to queries or complaints and in relation to surveys, market research, prize draws and/or competitions (b) notifying you about changes to our terms or privacy policy (c) asking you to take part in a survey or market research (d) enable you to take part in a prize draw, competition or complete a survey or market research |
(a) Identity & Contact Data (b) Usage Data (c) Marketing and Communications Data |
(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (keep our records up to date, study how customers use our goods and services, to develop them and grow our business and to promote our business, brand, goods and services) |
Current year plus 6 years |
To process and deliver your order including: (a) Manage payments, fees and charges (b) Collect and recover money owed to us |
(a) Identity & Contact Data (b) Financial Data (c) Transaction Data (d) Marketing and Communications Data |
(a) Performance of a contract with you (b) Necessary for our legitimate interests (to recover debts due to us) |
Current year plus 6 years |
To administer and protect our business and our Site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
(a) Identity & Contact Data (b) Technical Data |
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) (b) Necessary to comply with a legal obligation |
Current year plus 6 years |
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you |
(a) Identity & Contact Data (b) Usage Data (c) Marketing and Communications Data (d) Technical Data |
Necessary for our legitimate interests (to study how customers use our goods and services, to develop them, to grow our business and to inform our marketing strategy) | Current year plus 6 years |
We may randomly monitor and record communications made to us, including by e-mail or telephone or use copies of your communications with us to protect the interests of our business and our customers and for staff training and quality purposes. |
(a) Identity & Contact Data (b) Usage Data (c) Marketing and Communications Data (d) Technical Data |
(a) Necessary for our legitimate interests (maintaining customer/ service quality standards, detection of and/ or prevention of crime and to ensure that our employees comply with legal obligations and our policies and procedures (including our customer relations practices). | Current year plus 6 years |
To make suggestions and recommendations to you about goods or services (and offers) that may be of interest to you |
(a) Identity & Contact Data (b) Technical Data (c) Usage Data (d) Marketing and Communications Data |
Necessary for our legitimate interests (to develop our goods/services and grow our business) | Current year plus 6 years |
- contacting us at any time at: personaldatarequests@thomasridley.co.uk ; or
- click unsubscribe in any email communication we send you.
5. Disclosures of your personal data
- Internal Third Parties as set out in the Glossary.
- External Third Parties as set out in the Glossary.
- Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.
6. International transfers
- Where we transfer data to our group company based in New Zealand, we will do so on the basis that New Zealand has been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.
- Where we transfer data to our group company based in South Africa or we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
- Where we use providers based in the US, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
- Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
7. Data Security
8. Data Rentention
9. Your Legal Rights
- Request access to your personal data
- Request correction of your personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing your personal data
- Request transfer of your personal data
- Right to withdraw consent
10. Glossary
- Service providers who provide IT and system administration services.
- Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
- HM Revenue & Customs, regulators and other authorities.
- Third parties, where we are required to do so by the Courts or to comply with other legal, statutory and/or regulatory obligations including accounting and taxation requirements.
- Payment providers for the purpose of handling payments.
- Police, law enforcement agencies or other authorised bodies to prevent and/or detect crime.
- Data analysis or direct marketing companies for purpose of providing you with relevant advertising or marketing and/or perform services on our behalf (on an aggregated/anonymised basis)
- If you want us to establish the data's accuracy.
- Where our use of the data is unlawful but you do not want us to erase it.
- Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
- You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.