(a) in the course of the delivery of our general retail services to customers; and
(b) or otherwise in the course of running our business.
1.2 The Company is registered as a data controller (this means we determine the purpose and manner in which your personal data is used) with the Office of the Information Commissioner in Jersey, and our registration number is 66314.
- Data we may collect about you
2.1 We may collect and process personal data about you through various means, including:
o In the course of selling our goods or services to you
o in the course of delivering our retail services to you
o via our website
o when you order from us online
o by email
o by telephone
o by operating security policies and procedures at our premises (e.g. by virtue of our access to CCTV footage recorded at our premises) or CCTV on some of our vehicles. We may process stills or footage which contains images of individuals. CCTV data may be processed by us for the purposes of monitoring building and vehicle security and crime prevention and detection. The legal basis for this processing is our legitimate interests, namely ensuring the safety and security of our staff, premises and property.
o from any competition entries you submit
2.2 The personal data we will ask you to provide may include:
o your name, title and date of birth
o contact information, including telephone number, email address and postal address (including postcode)
o your payment details
o other personal information that we collect in the course of a transaction
o copies of your proof of identity and age
o copies of your proof of address
o a copy of your signature
o your service and order preferences
o the content of any enquiry submitted over our website
2.3 Each time you visit our website, we may automatically collect the following information:
o Web usage information (e.g. IP address), your login information, browser type and version, time zone setting, operating system and platform
o Information about your visit, including the full Uniform Resource Locators (URLs) clickstream to, through and from our website (including date and time), time on page, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks and mouse-overs)
2.4 We may ask you for information when you report a problem with our website.
2.5 If you contact us, we may keep a record of that correspondence.
- How we will use your data
4.1 We will store and use the data you provide or which we gather in order to carry out the activities necessary to process and deliver your online order. We will only do this to:
o prepare your order for delivery
o process and collect payments (including refunds) relating to your order
o provide customer support and respond to and communicate with you about your order, including any requests, questions and comments
o establish and manage your online account
o manage our relationship with you, including by maintaining our database for administration, accounting and relationship and operational management purposes
o complete our contractual obligations to you, including any associated administration
o ensure that our website’s content is presented in the most effective manner for you and your device
o administer our website for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey responses
o allow you to participate in interactive features on our website when you choose to do so
o support our efforts to keep our website safe and secure
o comply with any other professional, legal and regulatory obligations which apply to us or policies that we have in place
o prevent illegal activity or to protect our legitimate interests
4.2 We will not use your personal data in any automated decision-making process without your consent.
- Legal grounds for processing your information
5.1 We will rely on the following legal bases under the Data Protection Law for processing your personal data:
o Performance of, or entry into, a contract
The personal data that we are required to collect in order to comply with our contractual obligations must be provided to us in order for us to meet our contractual obligations to you.
o Compliance with a legal obligation to which we are subject
The personal data we are required to provide to regulatory bodies, and Government agencies and officials including, but not limited, to the Jersey and/or Guernsey Financial Services Commissions.
o Where processing of ‘special category data’ is necessary in the performance of our obligations
In certain circumstances, we may need to process special category data in order to perform our obligations. If this is the case you will be asked to provide your express consent before we agree to provide our services to you.
- Marketing Communications
6.1 We will only send you literature describing our services if you ask for them.
6.2 We will only send you marketing communications if you have consented to receive them when requesting our services, or when you change your marketing preferences though our members’ portal. You do not have to agree to receive marketing communications from us in order to receive any of our services. You can also unsubscribe from receiving marketing materials from us at any time.
6.3 We will never sell or share your personal data with third parties for marketing purposes without your consent.
- Who will have access to your data within the business?
7.2 We take your privacy seriously and have implemented appropriate physical, technical and organisational security measures designed to secure your personal data against accidental loss, destruction or damage and unauthorised access, use, alteration or disclosure.
- Who else might we share your data with?
8.2 We will share your personal data with the following third parties who assist us with administering the provision of our services to you:
o our auditor
o our bank
o regulators, such as the Jersey Financial Services Commissions
o law enforcement agencies
o our insurers
o our website platform provider
o our data processors providing security, email security, data governance, archiving and other IT and business support services including analytics based on anonymised data
o search engine providers that assist us in the improvement of our website
o any third party you ask us to share your data with
8.4 If a business transfer or change of business ownership takes place or is envisaged, we may transfer your personal data to the new owner or a prospective new owner. If this happens, we will inform you of this transfer.
8.5 We may share some broader statistics and customer profiling information with third parties and other entities owned by the Compnay, but all such data will be anonymised, so you would not be identifiable from that data. We will not rent or sell your details to any other organisation or individual.
8.6 To perform our pick-up and delivery services, we may share delivery information with third parties such as shippers, consignees, third party payers and recipients. We may also share personal information with third parties who perform services on our behalf based on our instructions. These third parties are not authorised by us to use or disclose the information except as necessary to perform services on our behalf or comply with legal requirements.
- How do we protect your data?
9.1 We take your privacy seriously and are committed to maintaining the privacy and security of the personal data you provide to us, and the choices you have regarding our collection and use of your personal data.
9.2 We maintain administrative, technical and physical safeguards designed to protect the personal information you provide against accidental, unlawful or unauthorised destruction, loss, alteration, access, disclosure or use. Although we take steps to limit access to our facilities and vehicles to authorised individuals, information that is located on the outside of a package or letter may be visible to others.
9.3 We follow strict security procedures as to how your personal data is stored and used, and who sees it, to help stop any unauthorised person getting hold of it. Once we have received your personal data, we will use strict procedures and security features to try to prevent unauthorised access. Details of these measures are available upon request. We have put in place appropriate security measures to prevent your personal data from being lost, used, accessed, altered or disclosed by accident or without authorisation. In addition, we limit access to your personal data to those officers, employees and contractors who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
9.4 We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
9.5 Unfortunately, the transmission of your personal data via the internet is not completely secure and although we do our best to protect your personal data, we cannot guarantee the security of your data transmitted to us over the internet and you acknowledge that any transmission is at your own risk.
9.6 Our website may, from time to time, contain links to and from the websites of advertisers and partners. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
- How long do we keep your data?
10.1 We will keep your personal data for no longer than is necessary for the purposes we have set out above.
10.2 We will keep your personal data for ten (10) years after the year in which we have provided our services to you, or have last interacted with you.
10.3 If we are required by law to keep any of your personal data for longer, in order to protect your vital interests or the vital interests of another natural person, or in connection with any legal claim we will only keep such data for as long as the law says we must.
10.4 The third parties we engage to provide services on our behalf will keep your data no longer than the periods set out above. If we end our relationship with any third party providers, we will request they securely delete or return your personal data to us.
10.5 We may retain personal data about you for statistical purposes. Where data is retained for statistical purposes it will always be anonymised meaning that you will not be identifiable from that data. We may also retain basic information about you and the services provided for a further ten (10) years after we have provided our services to you, so that we can provide appropriate care and consideration to related persons who may contact us in the future.
- What are your rights?
11.1 You have a number of rights in relation to your personal data under the Data Protection Law. There are circumstances in which your rights may not apply. You have the right to request that we:
o provide you with a copy of the information we hold about you
o update or correct any of your personal information if it is inaccurate or out of date
o erase the personal data we hold about you, if we are providing services to you and you ask us to delete personal data we hold about you, then we may be unable to continue providing those services to you
o refrain from using automated decision-making processes relating to you and/or profiling
o prevent direct marketing or otherwise restrict the way in which we process your personal data
o stop processing your personal data if you have valid objections to such processing
o transfer your personal data to a third party
11.2 We will ask you to provide proof of identity before we show you your personal information. This is so that we can prevent unauthorised access to your personal data.
11.3 For more information on your rights and how to exercise them, or if you would like to make any of the requests set out above, please contact us, using the details below. We will respond to all such requests within the time period required by Data Protection Law.
- Who can you ask for more information?
We are data controllers because we collect personal data about you and determine how and why it will be used. If you have any questions or concerns about how we handle your personal data, you can contact us using any one (or more) of the following:
Data Protection Officer
Dorset Street Stores
15a Dorset Street
Telephone: 01534 872828
Exercising my rights:
To exercise your rights under the Data Protection Law please go to our Enforcing your rights section of our corporate website.
If you are unsatisfied with our response to any data protection issues you raise with us, you have the right to make a complaint to the Office of the Information Commissioner in Jersey.
You can contact them as follows:
Office of the Information Commissioner
5 Castle Street
Tel: 01534 716530