The purpose of this policy is to explain to you how we control, process, handle and protect your personal information while browsing or using this website, including your rights under current laws and regulations.
If you do not agree to the following policy you may wish to cease viewing / using this website.
Policy key definitions:
We use an Ecommerce ERP/ CRM System called Plentymarkets, to centrally process all data. It is a secure software as a service hosted in The Dublin Amazon Web Service Cloud(AWS) .
Under the GDPR (General Data Protection Regulation) we control and / or process any personal information about you electronically using the following lawful bases.
|Purpose||Description||Data Categories||Affected Parties||Lawful basis for processing including basis of legitimate interest|
|Order Process/ Account Registration|| |
When you register an account or place an order via the online store or respectively via a connected marketplace (e.g. Amazon, eBay). Customer data is saved in the following areas of our plentymarkets back end:
Name, form of address, title, password (encrypted), email addresses, invoice address, different delivery address (if applicable), date of birth (optional), telephone numbers (optional), company name (optional), VAT number (optional), order data, item data
Interested parties, customers /
Payment service providers, shipping service provider, our email service provider,
Amazon Web Services
Art. 6 Par. 1 lit. b) GDPR
|Order Processing & Shipment||To process an order (including shipment, return management, credit notes etc.), data is saved in the plentymarkets back end and – if in use – in the plentymarkets app.||Name, form of address, title, email addresses, invoice address, different delivery address (if applicable), date of birth (optional), telephone numbers (configurable), company name (optional), VAT number (optional), order data, item data, payment data||Customers / Shipping service providers, fulfilment service providers||Art. 6 Par. 1 lit. b) GDPR|
|Payments||We offer three major ways of payment. a) payment in one of our stores b) Payment via one of our connected marketplaces, e.g. eBay or Amazon c) online via the webstore hosted on plentymarkets secured system. In none of the above scenarios are we retaining any of your payment card information, which is only held by our payment service providers||Name, form of address, title, email addresses, invoice address, different delivery address (if applicable), date of birth (optional), telephone numbers (configurable), company name (optional), VAT number (optional), order data, item data, payment data||Customers / Payment service Providers||Art. 6 Par. 1 lit. b) GDPR|
|User Management||Only Selected and trained staff has access to your data from within our premises and via the plentymarkets system and is only used for the processing of orders and eventual follow up by telephone or email if we have a query pertaining your order. A password secured user login to the plentymarkets system is required.||Name, email address, user name, user ID, password (encrypted),||Employees / Amazon Web Services||Art. 6 Par. 1 lit. b) GDPR|
|Customer Communication||For communication with customers, we use the plentymarkets support ticket system. The system connects from Plentymarkets to our external email service to provide you a way of communicating with us by email.||Name, form of address, title, email address, invoice address, different delivery address (if applicable), date of birth (optional), telephone numbers (optional), company name (if applicable), VAT number (if applicable), order data, item data||Customers, interested parties, employees/ E-Mail Service provider||Art. 6 Par. 1 lit. b) GDPR|
If, as determined by us, the lawful basis upon which we process your personal information changes, we will notify you about the change and any new lawful basis to be used if required. We shall stop processing your personal information if the lawful basis used is no longer relevant.
Under the GDPR your rights are as follows.
You also have the right to complain to the ICO [www.ico.org.uk] if you feel there is a problem with the way we are handling your data.
We handle subject access requests in accordance with the GDPR.
Some cookies are required to enjoy and use the full functionality of this website.
Special Cookies that we use are;
We ensure the security of any personal information we hold by using secure data storage technologies and precise procedures in how we store, access and manage that information. Our methods meet the GDPR compliance requirement.
Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible and we use regular Malware Scanning.
Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive information you supply is encrypted via Secure Socket Layer (SSL) technology.
We implement a variety of security measures when a user places an order enters, submits, or accesses their information to maintain the safety of your personal information.
All payment transactions are processed
We have provided some further explanations about user privacy and the way we use this website to help promote a transparent and honest user privacy methodology.
Under the GDPR we use the consent lawful basis for anyone subscribing to our newsletter or marketing mailing list. We only collect certain data about you, as detailed in the "Processing of your personal date" above. Any email marketing messages we send are done so through an EMS, email marketing service provider. An EMS is a third party service provider of software / applications that allows marketers to send out email marketing campaigns to a list of users.
Email marketing messages that we send may contain tracking beacons / tracked clickable links or similar server technologies in order to track subscriber activity within email marketing messages. Where used, such marketing messages may record a range of data such as; times, dates, I.P addresses, opens, clicks, forwards, geographic and demographic data. Such data, within its limitations will show the activity each subscriber made for that email campaign.
Any email marketing messages we send are in accordance with the GDPR and the PECR. We provide you with an easy method to withdraw your consent (unsubscribe) or manage your preferences / the information we hold about you at any time. See any marketing messages for instructions on how to unsubscribe or manage your preferences, you can also unsubscribe from all mailslists, by following the highlighted link, otherwise contact our provider..
Our EMS provider is; [Clever Reach]. We hold the following information about you within our EMS system;