1.4 If you have any questions about how we collect, store and use your personal information, or if you have any other privacy-related questions, please contact our Privacy Correspondent, Rob Bains by email at firstname.lastname@example.org.
2. WHO WE ARE
2.2 A “data controller” determines the purposes and means of processing your personal data.
3. HOW WE COLLECT YOUR PERSONAL INFORMATION
We may collect and process the following information about you:
3.1 Personal information you give to us: this is information about you that you give to us:
- by entering information on one of our websites;
- when visiting a branch;
- via our mobile applications;
- via social media platforms;
- when corresponding with us by phone, email or otherwise;
- by entering competitions run by us;
- by taking surveys undertaken by us or on our behalf;
- when participating in promotional events; and
- when you open an account with us.
3.2 Personal information we collect about you: we may collect the following information:
- details of transactions you carry out through the websites, and your visits to our websites, including, but not limited to, traffic data, location data, weblogs and other communication data, and the resources you access;
- technical information including anonymous data collected by the hosting server for statistical purposes, the Internet Protocol (IP) address used to connect your computer or device to the Internet, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform;
- any personal information which you allow to be shared as part of your public profile or third party social network;
- information you provided to us in response to a survey or competition;
- information resulting from enquiries, quotations or sales whether by phone, email or in person in a branch.
- footage of you from our use of CCTV in and outside our premises and/or the use of camera systems mounted on our vehicles and/or images captured to record delivery of materials to you.
3.3 Personal information we may receive from other sources:
We obtain certain personal information about you from sources outside our business which may include our group companies or other third party companies. We will tell you when we obtain information about you from third party companies.
4. WHAT TYPE OF PERSONAL INFORMATION DO WE COLLECT AND PROCESS ABOUT YOU
4.1 The types of data we hold relating to you are as follows:
- Company for whom you work;
- Email address(es);
- Telephone number(s);
- Your signature;
- Your date of birth;
- Biographical data such as your favourite football team, likes and dislikes etc.;
- Geo-location data when you sign for delivery using a mobile device;
- Credit rating and bank details;
- Credit limit and payment terms;
- Identification data being the information contained in a formal identification document or social security or other unique reference relating to you;
- Sales information relating to the sale of products or services to you or their repair or return;
- Correspondence or other communications with you about our products, services or business;
4.2 Some of the personal information we collect about you, or which you provide to us about you, may be "special categories of personal data". Special categories of personal data include information about physical and mental health, sexual orientation, racial or ethnic origin, political opinions, philosophical belief, trade union membership and biometric data for identification purposes.
5. WHY AND HOW WE USE YOUR PERSONAL INFORMATION
We use the information we hold on you for the following purposes:
- For account administration: including opening up an account, verifying your identity, undertaking credit related searches, invoicing, managing credit limits and payments.
- For managing and performing our contracts with you: including answering enquiries, providing quotations, dealing with plans and specifications, placing orders, delivering goods to you or your customers and dealing with any issues arising including warranty claims.
- For marketing: monitoring your transactions with us to enable us to provide you with the most relevant offers and information to you and marketing to you unless you've told us not to.
- For security: to protect our customers, premises, assets and staff from crime. At some sites we operate CCTV systems, we have cameras mounted on some of our vehicles and we photograph evidence of deliveries.
The legal basis for our uses of your personal information
Type of processing
Our legitimate interests are:
Performance of a contract
The personal information you provide may be processed when it is necessary in order for us to:
Compliance with legal obligations
Where we are under a duty to disclose or share your personal information in order to comply with a request from government or law enforcement officials.
6. OTHERS WHO MAY RECEIVE OR HAVE ACCESS TO YOUR PERSONAL INFORMATION
6.1 We will share your personal information internally with our subsidiaries and associated companies where it is in our legitimate interests to do so. For example, it is in our legitimate interests to provide you with offers from each of our businesses, where they are relevant to you or your business.
6.2 If you ask us not to contact you in future, we will take this as an instruction not to do so in relation to the Business named in your communication and will amend our records accordingly. However, we will continue to use your information to send you details of offers from our other Businesses unless you specifically ask us not to do so.
6.3 We will also share your personal information to third parties in the following circumstances:
- our suppliers, service providers and subcontractors, such as credit reference agencies, fraud prevention agencies, payment processors, suppliers of technical and support services, insurers, logistics providers, manufacturers and cloud service providers, debt collectors, our legal and other professional advisors, including auditors;
- in processing a credit account application, we will supply your personal information to credit reference agencies (CRAs) and they will give us information about you, such as your financial history. We do this to assess creditworthiness and product suitability, check your identity, manage your account, trace and recover debts and prevent criminal activity. We will also continue to exchange information about you with CRAs on an ongoing basis, including about your settled accounts and any debts not fully repaid on time. CRAs will share your information with other organisations. The identities of the CRAs, and the ways in which they use and share personal information, are explained in more detail here;
- companies assisting us in our marketing, advertising and promotional activities;
- search engine and social media companies to target our advertising delivered by using your personal information and to tailor marketing to improve its relevance to you to facilitate targeted and personalised marketing when using search or social media sites (including Google and Facebook);
- third party payment processor in relation to credit/debit card payments;
- fraud prevention agencies if false or inaccurate information is provided to us as part of your use of our services or otherwise, and fraud is identified or suspected;
- if we are under a duty to disclose or share it in order to comply with any legal obligation, to detect or report a crime, to enforce or apply the terms of our contracts or to protect the rights, property or safety of our visitors and customers; and
- when we restructure or sell our business or its assets or have a merger or re-organisation.
6.4 We work closely with various third parties to bring you a range of products and services which are complementary to those which we provide. Any third parties with whom we share your personal information are limited in their ability to use your personal information: they are not entitled to use your personal information for any purpose other than to provide services to us and/or to you. For example, we may share your details with a manufacturer for warranty purposes. We will always ensure any third parties with whom we share your personal information are subject to privacy and security obligations consistent with our practices and with applicable laws.
6.5 International Transfers
6.5.1 The personal information our Businesses use may be stored or accessed by our staff or third party data processors for the purposes listed above, the provision of services to you, or the processing of transactions with you. These third party data processors may be operating outside of the EEA, in India, the USA or elsewhere.
6.5.2 Wherever data is transferred or made available outside of the EEA, we undertake due diligence on the entity accessing or receiving your data to ensure they have put in place appropriate technical and organisational measures to protect and secure your data. We also put in place contractual safeguards in accordance with our obligations under the GDPR. These contractual safeguards limit their ability to use your personal information so it can be used solely to provide services to us and/or to you and not otherwise.
7. HOW LONG WE KEEP YOUR PERSONAL INFORMATION FOR
7.1 We keep your personal information for no longer than necessary for the purposes for which the personal information is processed. The length of time we retain personal information will depend on the purposes for which we collect and use it, or as required to comply with applicable laws, or to establish, exercise or defend our legal rights.
7.2 Further information on the length of time during which we retain your personal information can be found in our Data Retention Policy. We do not retain personal information in an identifiable format for longer than is necessary.
7.3 We may need your personal information to establish, bring or defend legal claims. For example, we will retain your personal information for 7 years in case of any investigation by the tax authorities.
8. YOUR RIGHTS
You have certain rights in relation to your personal information. There is normally no charge for exercising these rights. If you would like further information in relation to these rights, or would like to exercise any of them, please contact us by email at email@example.com at any time. In relation to certain rights, we may ask you for information to confirm your identity and, where applicable, to help us to search for your personal information. Except in rare cases, we will respond to you within one month from receiving your request.
Subject to any exceptions, you may have the right to:
8.1 Access your personal information
8.2 Correct, modify and update your personal information
The accuracy of your information is important to us and we are working on ways to make it easier for you to review and correct the information we hold about you.
In the meantime, if you change your name or address/email address, or you discover any of the other information we hold is inaccurate or out of date, please let us know by contacting us (see section 13).
8.3 Erase your personal information or restrict its processing
You may also ask us to restrict processing your personal information where you believe it is unlawful for us to do so, you have objected to its use and our investigation is pending or you require us to keep it in connection with legal proceedings. In these situations, we may only process your personal information whilst its processing is restricted if we have your consent or are legally permitted to do so, for example for storage purposes, to protect the rights of another individual or company or in connection with legal proceedings.
8.4 Withdraw your consent
Where you have given your consent to our processing of your personal data you may at any time withdraw your consent. Unless we have another legal basis to process your personal data (such as compliance with a legal obligation) we will cease any processing of your personal data following receipt of your notice of withdrawal of consent.
8.5 Object to our use of your personal information
You may object to us using your personal information for direct marketing purposes and we will automatically comply with your request.
8.6 Ask us to transfer your personal information in a structured data file to you or to another service provider if it is technically possible (data portability)
Where we rely on your consent as the legal basis for processing your personal information or need to process it in connection with your contract you may ask us to provide you with a copy of such information in a structured data file. We will provide this to you electronically in a structured, commonly used and machine readable form, such as a CSV file.
You can ask us to send your personal information directly to another service provider, and we will do so if this is technically possible. We may not provide you with a copy of your personal information if it concerns other individuals or we have another lawful reason to withhold such information.
8.7 Lodge a Complaint with the competent supervisory authority and seeking a judicial remedy
If you are concerned about the way we have processed or collected your personal information you have the right to complain to the relevant data protection regulator being the Information Commissioners Office for the UK or the Isle of Man Information Commissioner for the Isle of Man.
9. SECURITY AND CONFIDENTIALITY
Unfortunately, the transmission of information via the Internet is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your information transmitted to our website and any transmission is at your own risk. Once we have received your personal information, we put in place reasonable and appropriate controls to ensure it remains secure against accidental or unlawful destruction, loss, alteration, or unauthorised access.
Each of our websites has a cookies policy on it providing details of the cookies used and how to remove them.
11. LINKS TO OTHER WEBSITES
In addition, if you linked to our website from a third party website, we cannot be responsible for the privacy policies and practices of the owners and operators of the third party website and recommend you check the policy of any third party website.
12.1 We may contact you with marketing information by post, email, SMS or by telephone or with targeted advertising delivered online through social media and platforms operated by other companies by using your personal information, or use your personal information to tailor marketing to improve its relevance to you, unless you object.
12.3 From time to time, we may ask you to refresh your marketing preferences by asking you to confirm you still wish to receive marketing information from us.
12.4 You have the right to opt-out of our use of your personal information to provide marketing to you in any of the ways mentioned above or by contacting us in the ways set out below.
13. CONTACT US
13.2 Our email address for data protection queries is firstname.lastname@example.org.
13.3 If you wish please write to us at International Decorative Surfaces Limited, Parkhouse Interchange, Parkhouse Industrial Estate, Newcastle-under-Lyme, ST5 7FB.