BaxterStorey Limited is committed to protecting and respecting your privacy. We take your privacy very seriously and we ask that you read this Privacy Notice carefully as it contains important information on:
- the personal data we collect about you;
- how we look after your personal data when you visit our website (regardless of where you visit from);
- with whom your personal data might be shared; and
- your privacy rights and how the law protects you.
WHO WE ARE
BaxterStorey Limited is the controller and responsible for your personal data (collectively referred to as BaxterStorey, "we", "us" or "our" in this Privacy Notice).
PERSONAL DATA WHICH WE COLLECT
Personal data provided by you
We collect personal data about you when you:
- register with us on our website;
- purchase or make payments for any of our products or services;
- contact us through our website;
- post material to our website;
- complete customer feedback or surveys;
- participate in competitions;
- open/browse the email campaigns sent by us.
The personal data collected in the above manner may include your:
- full name;
- postal address;
- email address;
- telephone number;
- payment details;
- IP address and the date/time you opened and clicked something within a marketing email.
Special categories of personal data:
We do not proactively collect personal data considered as special category personal data via our website such as health information (e.g. allergen information). However, our website does include text boxes which are designed for you to provide us with certain information and you should be aware that information you freely submit in these boxes may reveal to us certain information that may be considered as special category personal information.
We may ask you to provide us with the above special category personal data, for example to understand any allergen information so that we can cater appropriately for you. We will only collect your special category personal data with your explicit consent. If we request such information, we will explain why we are requesting it and how we intend to use it.
Personal data about other individuals
If you give us information on behalf of someone else, you confirm that the other person has appointed you to act on his/her behalf and has agreed that you can:
- give consent on his/her behalf to the processing of his/her personal data;
- receive on his/her behalf any data protection notices;
- give consent to the transfer of his/her personal data outside the European Economic Area; and
- give consent to the processing of their special category personal data (further details relating to special category personal data is detailed below).
Monitoring and recording communications
We may monitor and record communications with you (such as telephone conversations, online chat communications and emails) for the purpose of quality assurance, managing and responding to complaints and other issues, training, fraud prevention and compliance activities.
HOW WE USE YOUR PERSONAL DATA
We collect information about you so that we can:
- identify you and manage any accounts you hold with us;
- process any orders for goods and/or services which you make with us;
- assist you with your queries in relation to our business;
- conduct research, statistical analysis and behavioural analysis;
- carry out customer profiling and analyse your purchasing preferences (although this is only ever done in an anonymised manner and will not identify you specifically);
- detect and prevent fraud;
- customise our website and its content to your particular preferences;
- notify you of any changes to our website or to our services that may affect you;
- improve our services.
We would like to send you information by email, telephone and text message (SMS) about our products and services, competitions or prize draws and special offers which may be of interest to you.
If you provide us with consent, we will share your details with our other Group companies who may also send you similar marketing messages.
We will only send you marketing messages (or share your details with the third parties listed above) when you click to subscribe on our website or tick the relevant consent box when you provide us with your personal data. If you have consented to receive such marketing from us, or the third parties listed above, you can opt out at any time by using the unsubscribe function on each of our emails or by contacting us directly through the “Contact Us” section of this website.
When we contact you by email, our marketing tool places a pixel (also known as a web beacon) into the email you receive. This enables us to see, for example, if you open the email or click on anything within and is important for us to be able to compare the success of other emails we’ve sent out and to ensure those you further receive are of interest to you (as well as the reasons set out under ‘how we use your personal data’).
WHEN WE MIGHT SHARE YOUR PERSONAL DATA WITH THIRD PARTIES
We do not, and will not, sell any of your personal data to any third party – including your name, address, email address or payment card information. We want to earn and maintain your trust, and we believe this is essential in order to do that.
As an essential part of being able to provide our services to you, we do share your data with the following categories of third parties:
- the vendors selling goods and products through this website for the purposes of the vendors being able to receive, process and deliver orders made by customers through the website;
- other companies within the BaxterStorey group, as different companies within our group are responsible for different venues;
- service providers that help us to get any purchases which you make through our website to you, such as delivery companies, gift voucher printers and payment service providers;
- service providers that help us to run our business, such as marketing agencies, website hosting providers, website developers, providers of wifi access at our venues and newsletter distributors;
- professional advisers including lawyers, bankers, auditors and insurers who provide advice to us when we require it;
- law enforcement agencies in connection with any investigation to help prevent unlawful activity; and
- third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Privacy Notice.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. If you would like any more information about the third parties which we work with to provide our services to you, please contact us on the contact details provided later in this Privacy Notice.
HOW WE ASK FOR CONSENT
In those cases where we need your consent to hold and process your personal data, we will ask you to check a box on any form requiring consent. By checking these boxes you are confirming that you have been informed as to why we are collecting the information, how this information will be used, for how long the information will be kept, who else will have access to this information and what your rights are as a data subject (all of which is set out in this Privacy Notice).
HOW WE KEEP YOUR PERSONAL DATA SECURE
To protect your information, we have policies and procedures in place to make sure that only authorised personnel can access the information, that information is handled and stored in a secure and sensible manner and all systems that can access the information have the necessary security measures in place.
All employees, contractors and sub-contractors receive the necessary training and resources to ensure they understand their responsibilities in relation to all of our policies and procedures.
In addition to these operational measures we also use a range of technologies and security systems to reinforce the policies and procedures, including ensuring that:
- access to personal data is strictly restricted to those employees who need to access this information as part of their role;
- we store your personal data on secure servers and unauthorised external access to personal data is prevented through the use of a firewall;
- information used for reporting and/or customer profiling purposes is anonymised (so that it does not identify you); and
- payment details are encrypted using SSL technology (typically you will see a lock icon or green address bar (or both) in your browser when we use this technology).
To make sure that these measures are suitable, we run vulnerability tests regularly. Audits to identify areas of weakness and non-compliance are routinely scheduled.
HOW LONG DO WE KEEP YOUR PERSONAL DATA
We shall only retain your information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements. If you would like more information about how long we retain specific types of your information, please contact us on the contact details provided later in this Privacy Notice.
TRANSFERS OF YOUR PERSONAL DATA OUT OF THE EEA
All information you provide via our website is stored on our secure servers within the European Economic Area (“EEA”). If any data that we collect from you is transferred to, or stored at, a destination outside the EEA at any time, we will update this Privacy Notice accordingly.
When you link to a social media site via our website, any personal data which you provide them may be transferred or stored outside the EEA. Please check their websites’ privacy notice carefully.
The right to access information we hold about you
At any point you can contact us to request the information we hold about you as well as why we have that information, who has access to the information and where we got the information. Once we have received your request we will respond within 30 days.
The right to correct and update the information we hold about you
If the information we hold about you is out of date, incomplete or incorrect, you can inform us and we will ensure that it is updated.
The right to have your information erased
If you feel that we should no longer be using your information or that we are illegally using your information, you can request that we erase the information we hold. When we receive your request, we will confirm whether the information has been deleted or tell you the reason why it cannot be deleted.
The right to object to processing of your information
You have the right to request that we stop processing your information. Upon receiving the request, we will contact you to tell you if we are able to comply or if we have legitimate grounds to continue. If data is no longer processed, we may continue to hold your information to comply with your other rights.
The right to ask us to stop contacting you with direct marketing
You have the right to request that we stop contacting you with direct marketing.
The right to data portability
You have the right to request that we transfer your information to another controller. Once we have received your request, we will comply where it is feasible to do so.
For your security we may need to verify your identity before we process your instructions above.
COOKIES AND TRACKING
- recognise you whenever you visit this website (this speeds up your access to the website as you do not have to log in each time);
- obtain information about your preferences, online movements and use of the internet;
- carry out research and statistical analysis to help improve our content, products and services and to help us better understand our customer requirements and interests;
- target our marketing and advertising campaigns more effectively by providing interest-based advertisements that are personalised to your interests; and
- make your online experience more efficient and enjoyable.
Consent to cookies
Description of cookies
The table below provides some information on the cookies which we use on our website:
|Type of Cookie||What it does||Why is it used||How long it lasts|
|sid_customer||Encrypted customer identification||Assists with the basket and checkout process||2 weeks|
|hw_subscribe_popup||Newsletter popup||Shows the popup of the newsletter on the website||1 week|
|hw_cookie_law||Cookie law popup cookie||Popup showing cookie law||1 week|
Additional External Cookies
There are a number of cookies used by our partners in order to ensure the smooth running of the BaxterStorey at Home website, these are listed below.
Google Analytics – There are many cookies used by Google Analytics for reporting purposes, these can be viewed here; https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage
Cloudflare – Cloudflare hosting services utilise cookies in order to host the Baxter Storey at Home website, a list of these cookies and their uses can be found here; https://stripe.com/docs/js/appendix/viewport_meta_requirements
Turning off cookies
If you do not want to accept cookies, you can change your browser settings so that cookies are not accepted. If you do this, please be aware that you may lose some of the functionality of this website. For further information about cookies and how to disable them please go to the Information Commissioner’s webpage on cookies: https://ico.org.uk/for-the-public/online/cookies/
TAKE CARE WHEN LINKING TO OUR SOCIAL MEDIA SITES
Our website provides links to our social media sites. Once on any of these social media sites, please take care if you choose to post any information as this will be on a public domain and may be widely accessible. If you would like more information about how any information posted on these sites will be used, please read the sites’ privacy notice carefully.
If you have any queries about this Privacy Notice, need further information about how we use your personal data or wish to lodge a complaint, please contact us by any of the following means:
- email us at: [email protected]
- write to us at: BaxterStorey at Home, 300 Thames Valley Park Drive, Reading, United Kingdom, RG6 1PT.
- contact us using our “Contact us” page on the website.
You also have the right to lodge a complaint with the Information Commissioner’s Office directly. Further information, including contact details, is available at https://ico.org.uk.
CHANGES TO THIS PRIVACY NOTICE
We may change this Privacy Notice from time to time. You should check this Privacy Notice occasionally to ensure that you are aware of the most recent version that will apply each time you access the website.
Where we have made any changes to this Privacy Notice which affects the manner in which we use your personal data, we will contact you by email to inform you of this change.
This Privacy Notice was last updated on [date] 2020.