For the purpose of and thereafter the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR“) as amended, supplemented or replaced from time to time (“Data Protection Law“), the data controller is Data Manager, Pretty Mama Limited. Enquiries email@example.com.
1. Information we collect from you
We will collect and process the following data about you:
1.1. Information you give us.
This is information about you that you give us by filling in forms on our website (“our site”) or by corresponding with us by phone, e-mail or otherwise. It includes information you provide when you register to use our site, subscribe to our service, search for a product, place an order on our site, participate in discussion boards or other Pretty Mama social media functions, enter a competition, promotion or survey, and when you report a problem with our site, products or services and when you apply for a job via our site. The information you give us may include your name, address, e-mail address and phone number, financial and credit card information. If you provide any information about any other individuals such as friends, family or colleagues, you warrant to us that you are entitled to provide that information to us and to authorise us to process it on the same basis as we will process the rest of the data you provide about yourself.
1.2. Information we collect about you.
With regard to each of your visits to our site we will automatically collect the following information:
- technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform.
- information about your visit, including the full Uniform Resource Locators (URL), clickstream to, through and from our site (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number.With regard to newsletter emails you sign up to receive from us, each email collects:
- Information about you, using industry standard technologies including pixels which will track email opens (if you have images enabled in your email client/mailbox). This is the standard approach for measuring open and click rates, and is used by all email platforms in the market.
- All links in emails are proxied through a link redirection service that records data for each link clicked. This leads to a set of events which includes:
1. Event type (delivery, bounce, open, click, spam complaint, unsubscribe)
2. Email address of the recipient (which you will have provided)
3. IP address of the recipient (in the case of open and click)
4. GEO location based on IP address (city level) (in the case of open and click)
5. Device type (mobile/computer/tablet) and browser (i.e/firefox/chrome/safari).
1.3. Information we receive from other sources.
This is information we receive about you from sources other than directly from yourself, which may include social media such as Linked In, Facebook, and Instagram. We are working closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers).
3. Purposes for which we may process the information
We use information held about you in the following ways:
3.1. Information you give to us.
- to carry out our obligations arising from any contracts entered into between you and us and to provide you with the information, products and services that you request from us;
- to update you with regard to the progress of orders that you have placed;
- to resolve any queries you may have regarding orders that you have placed;
- to administer any loyalty, discount or other such cards or initiatives that we may operate from time to time;
- to initiate any product recalls or provide any important information to you relating to products that we supply;
- to provide you with information about other goods and services we offer that are similar to those that you have already purchased or enquired about;
- to provide you, or permit selected third parties to provide you, with information about goods or services we feel may interest you. If you are an existing consumer customer, we will only contact you by electronic means (e.g. e-mail or SMS) with information about goods and services similar to those which were the subject of a previous sale or negotiations of a sale to you unless you have consented to receive wider communications. If you are a consumer and are not an existing customer, and where we permit selected third parties to use your data, we (or they) will contact you by electronic means only if you have consented to this. If you do not want us to use your data in this way, or to pass your details on to third parties for marketing purposes, please tick as applicable the relevant boxes situated on the form on which we collect your data or notify our in-store staff accordingly when they attempt to collect your information;
- to notify you about changes to our products or services;
- or fraud prevention;
- to ensure that content from our site is presented in the most effective manner for you and for your computer;
- to make decisions as to whether and on what terms to offer credit;
- if you have submitted a job application, in order to evaluate and manage that application, and to manage your employment if you are successful.
Please note that, where you are asked to provide information to us which is of a sort that is necessary to enable us to perform a contract or fulfil a request that you make (e.g. contact, delivery or payment information) it is a requirement for us to enter and perform such a contract or fulfil your request that you provide that information – if you do not do so, we may not be able to perform your contract or fulfil your request.
3.2. Information we collect about you.
We will use this information:
- to administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to improve our site to ensure that content is presented in the most effective manner for you and for your computer;
- to allow you to participate in interactive features of our service, when you choose to do so;
- as part of our efforts to keep our site safe and secure;
- to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you;
- to make suggestions and recommendations to you and other users of our site about goods or services that may interest you or them.
4. Disclosure of your information
4.1. You agree that we have the right to share your personal information:
4.1.1. For administrative purposes, any of our group undertakings, as defined in s1161(5) of the UK Companies Act 2006 and also including any undertaking which is under 50% or more ultimate common ownership with Pretty Mama Limited, provided that they either:
(a) are within the European Economic Area;
(b) are in a country that the European Union has decided has adequate data protection laws in place; or
(c) have provided appropriate data protection safeguards of the sort approved by the European Union and provide effective rights and remedies for you.
Any use by other group members of one group member’s personal data beyond administration will be subject to all the requirements of Data Protection Law. In particular, we may only pass such data to them for their marketing purposes if you have consented to that.
4.1.2. With selected third parties including:
- advertisers and advertising networks that require the data to select and serve relevant adverts to you and others. We do not disclose information about identifiable individuals to our advertisers, but we will provide them with aggregate information about our users. We may also use such aggregate information to help advertisers reach the kind of audience they want to target. We may make use of the personal data we have collected from you to enable us to comply with our advertisers’ wishes by displaying their advertisement to that target audience
- analytics and search engine providers that assist us in the improvement and optimisation of our site
4.2. Additionally, we may disclose your personal information to third parties:
4.2.1. If we outsource any aspect of our business or systems, then we may disclose your personal data to our service provider(s).
4.2.2. In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
4.2.3. If we or a substantial part of our assets are acquired by a third party, in which case personal data held by us about our customers may be one of the transferred assets.
4.2.4. If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply the terms of any agreement or policy to which we are a party, or to protect the rights, property, or safety of our business, our customers, or others. This may include exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
5. Legal basis of processing
5.1. Data Protection Law requires us to meet at least one “legal ground“ for processing, currently set out in Article 6 of the General Data Protection Regulation.
The grounds applicable to the personal data to which this notice relates are:
5.1.1. Where the processing is necessary for us to perform a contract that you are party to, or to take steps at your request prior to entering a contract, that is the ground on which we are processing that data;
5.1.2. Where the processing is necessary for compliance with a legal obligation to which we are subject, that is the ground on which we are processing that data;
5.1.3. Where processing is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, that is the ground on which we are processing that data, provided that your fundamental rights and freedoms which require protection of your data override those legitimate interests (our legitimate interests comprise the management, marketing and promotion of our business, products and services, and the supply of our products and services, and the recruitment and management of staff);
5.1.4. If you have given your consent to our processing the data, that is the basis on which we are processing that data.
If more than one of the above grounds apply to the processing of data in question, the applicable ground will be the one that is set out first above.
5.2. Special categories of personal data
If you provide us with any special categories of personal data (that is to say information as to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health, sex life or sexual orientation or genetic or biometric data) or personal data relating to criminal convictions and offences, then unless you provide that information to us in a recruitment or employment context (in which case please see below) it is a condition of us receiving that information that you expressly consent (and you hereby do) to us processing that personal data for the purposes set out in clause 3. Accordingly, if you do not want us to process any such categories of personal data, please do not provide it to us.
6. Where we store your personal data
6.1. The data that we collect from you will be stored on our servers or those of our service providers. It will not be transferred to, and stored at, a destination outside the UK or the European Economic Area (“EEA”) unless:
6.1.1. to one of our group undertakings to which section 4.1.1 above applies; or
6.1.2. to a processor acting on our behalf which is either (i) within the EEA, or (ii) in a country that the European Union has decided has adequate data protection laws in place, or (iii) has provided appropriate data protection safeguards of the sort approved by the European Union and provide effective rights and remedies for you.
6.2. All information you provide to us is stored on our secure servers.
Any payment transactions will be encrypted using SSL technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential, and for all use made of your account with such password. We ask you not to share a password with anyone.
6.3. Unfortunately, the transmission of information via the internet is not completely secure.
Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted via the internet; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
7. Length of data storage
Our policy is to ensure that personal data is only stored for as long as is necessary for the purposes set out at section 3 above. This may vary according to the type of information and the specific applicable purpose(s).
8. Your Rights
You have the right to object at any time to our processing of your personal information for direct marketing purposes.
Where we process your information based on our legitimate interests
You also have the right to object, on grounds relating to your particular situation, at any time to processing of your personal information which is based on our legitimate interests. Where you object on this ground, we shall no longer process your personal information unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
9. Your other rights
You also have the following rights under data protection laws to request that we rectify your personal information which is inaccurate or incomplete.
In certain circumstances, you have the right to:
- request the erasure of your personal information erasure (‘right to be forgotten’);
- restrict the processing of your personal information to processing to which you have given your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of others.
10. Exercising your rights
Where we have reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm your identity.
12. Changes to this privacy notice
Any changes we make to our privacy notice in the future will be posted on this page. Please check back frequently to see any updates or changes to our privacy notice.
Questions, comments and requests regarding this privacy notice are welcomed and should be addressed to Info@prettymama.co.uk