Customer Privacy Notice

This privacy notice tells you what to expect us to do with your personal information.

Contents

  1. Contact details

  2. What information we collect, use, and why

  3. Lawful bases and data protection rights

  4. Where we get personal information from

  5. How long we keep information

  6. Who we share information with

  7. How to complain

Contact details

Email:

jake@southwestsaunas.com

What information we collect, use, and why

We collect or use the following information to provide services and goods, including delivery:

Names and contact details

Addresses

Date of birth

Purchase or account history

Payment details (including card or bank information for transfers and direct debits)

Account information

Information relating to loyalty programmes

Website user information (including user journeys and cookie tracking)

Information relating to compliments or complaints

We collect or use the following information for the operation of customer accounts and guarantees:

Names and contact details

Payment details (including card or bank information for transfers and direct debits)

Purchase history

Account information, including registration details

Information used for security purposes

Marketing preferences

We collect or use the following information for service updates or marketing purposes:

Names and contact details

Marketing preferences

Purchase or viewing history

Website and app user journey information

Records of consent, where appropriate

We collect or use the following information to comply with legal requirements:

Name

Contact information

We collect or use the following personal information for dealing with queries, complaints or claims:

Names and contact details

Address

Payment details

Account information

Purchase or service history

Witness statements and contact details

Relevant information from previous investigations

Customer or client accounts and records

Financial transaction information

Information relating to health and safety

Correspondence

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are in brief set out below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. You can read more about this right here.

Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. You can read more about this right here.

Your right to erasure - You have the right to ask us to delete your personal information. You can read more about this right here.

Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. You can read more about this right here.

Your right to object to processing - You have the right to object to the processing of your personal data. You can read more about this right here.

Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. You can read more about this right here.

Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. You can read more about this right here.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide services and goods are:

Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

Our lawful bases for collecting or using personal information for the operation of customer accounts and guarantees are:

Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

Our lawful bases for collecting or using personal information for service updates or marketing purposes are:

Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Our lawful bases for collecting or using personal information for legal requirements are:

Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.

Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Where we get personal information from

Directly from you.

Data retention - how long we keep information

We will only retain your personal data for as long as is reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements.

When we destroy your personal information, we will make our best efforts to do so in a way that prevents it from being restored.

Who we share information with

Data processors:

Payroll processor

This data processor does the following activities for us: they process our payroll information

HR records

This data processor does the following activities for us: they store our HR records

Email marketing processor

This data processor does the following activities for us: they store our email marketing list and process our email marketing. 

We will not share, sell or rent your personal data to third parties so they can market their services to you. In the following limited circumstances, we may share personal data with third parties who will act as separate or joint controllers:

  • Squarespace. We process your personal information with that joint controller for the following reason: Squarespace, our hosting and email marketing services provider, when you interact with our Website and communicate and transact with us via our Website (lawful basis: legitimate interests or contract).

  • Stripe. We process your personal information with that joint controller for the following reason: our payments provider, when you make online payments (lawful basis: legitimate interests or contract).

  • Professional advisors acting as processors or joint controllers including auditors/accountants based in the UK (lawful basis: legitimate interests or legal obligation)

  • HM Revenue & Customs, regulators and other authorities acting as processors or joint controllers based in the UK (lawful basis: legal obligation)

  • We may be obliged to disclose your personal data to comply with a law, order or request of a court, government authority, other competent legal or regulatory authority or any applicable code of practice or guideline (lawful basis: legal obligation)

While our starting position is always to keep personal data within the UK or European Economic Area (‘EEA’), we use third parties whereby some or all of your personal data may be stored outside of the European Economic Area (‘EEA’). You are deemed to accept and agree to this by using our Website and providing information to us. Where we do store data outside the UK or EEA, we will take all reasonable steps to ensure that your data is treated as safely and securely as it would be under GDPR. We only work with companies who are committed to data security and have satisfactorily documented data security policies and processes.

Social media: If you are using South West Saunas social media, please remember that those social media engines have their own functionality, terms and privacy policies. Please ensure you have read these carefully and have checked your personal settings to ensure you are happy with how your information will be used by these social media engines. South West Saunas may make use of these functions but does not control them and is not responsible for them.

Others we may share personal information with:

Insurance companies

Relevant regulatory authorities

External auditors or inspectors

Organisations we’re legally obliged to share personal information with

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:           

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint