The type of personal information we collect
We currently collect and process the following information:
- Personal identifiers, including name, email address and telephone numbers.
- Addresses.
- If you pay using a card, we DO NOT collect your payment details. Rather, these are processed by our card payment provider, Zettle, who’s Privacy Policy you can find at https://www.zettle.com/gb/legal/privacy-policy.
How we get the personal information and why we have it
Most of the personal information we process is provided to us directly by you for one of the following reasons:
- Fulfilling orders, and keeping records relating to these orders to fulfil our regulatory requirements
- Emails for marketing purposes, to keep you informed of our products and sales venues.
How we use the personal information
We use the information that you have given us as above.
Other than for card payment processing identified above, we will not share your information with anybody else, for any purposes.
Under the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing this information are:
(a) Your consent. You are able to remove your consent at any time. You can do this by by sending an email to [email protected], with the Subject ‘Remove Data Consent’
(b) We have a contractual obligation
(c) We have a legal obligation.
How we store your personal information
Your information is securely stored in our systems, the data is encrypted.
We keep your personal information used for orders for seven years, in order for us to comply with our obligations to keep financial records and supporting information.
We will only keep your personal information provided for marketing and communication purposes until you ask us to stop, or until we stop sending out such marketing and other related communications. At that point we will remove your information from our system, and take reasonable efforts to remove it from any backups taken. All backups will expire within 3 months at which point your data will automatically be removed.
Your data protection rights
Under data protection law, you have rights including:
Your right of access – You have the right to ask us for copies of your personal information.
Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances.
Your right to object to processing – You have the the right to object to the processing of your personal information in certain circumstances.
Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us by email to [email protected] if you wish to make a request.
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us by sending an email to [email protected], with the Subject ‘Data Usage Complaint’.
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO’s address:
Information Commissioner’s Office,
Wycliffe House,
Water Lane,
Wilmslow,
Cheshire,
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
