Privacy Policy 

The policy: This privacy policy notice is for this website; [uniquearts.ltd.uk] and served by [Unique Arts Limited, 14 Victoria Terrace, BN3 2WB, Hove, England] and governs the privacy of those who use it.

The purpose of this policy is to explain to you how we control, process, handle and protect your personal information while browsing or using this website, including your rights under current laws and regulations.

If you do not agree to the following policy you may wish to cease viewing / using this website.

Policy key definitions:

Processing of your personal data

We use an Ecommerce ERP/ CRM System called Plentymarkets, to centrally process all data. It is a secure software as a service hosted in The Dublin Amazon Web Service Cloud(AWS) .

Under the GDPR (General Data Protection Regulation) we control and / or process any personal information about you electronically using the following lawful bases.

 

Purpose Description  Data Categories Affected Parties Lawful basis for processing including basis of legitimate interest
Order Process/ Account Registration
When you register an account or place an order via the online store or respectively via a connected  marketplace (e.g. Amazon, eBay). Customer data is saved in the following areas of our plentymarkets back end:
  • Registration/Quick registration
  • Guest account
  • My account
  • Shopping cart
  • Checkout
  • Wish list
  • Watch list
  • Order confirmation

Name, form of address, title, password (encrypted), email addresses, invoice address, different delivery address (if applicable), date of birth (optional), telephone numbers (optional), company name (optional), VAT number (optional), order data, item data

Interested parties, customers /

Payment service providers, shipping service provider, our email service provider,

Amazon Web Services

Art. 6 Par. 1 lit. b) GDPR

Order Processing & Shipment To process an order (including shipment, return management, credit notes etc.), data is saved in the plentymarkets back end and – if in use – in the plentymarkets app. Name, form of address, title, email addresses, invoice address, different delivery address (if applicable),  date of birth (optional), telephone numbers (configurable), company name (optional), VAT number (optional), order data, item data, payment data Customers / Shipping service providers, fulfilment service providers Art. 6 Par. 1 lit. b) GDPR
Payments We offer three major ways of payment. a) payment in one of our stores b) Payment via one of our connected marketplaces, e.g. eBay or Amazon c) online via the webstore hosted on plentymarkets secured system. In none of the above scenarios are we retaining any of your payment card information, which is only held by our payment service providers Name, form of address, title, email addresses, invoice address, different delivery address (if applicable),  date of birth (optional), telephone numbers (configurable), company name (optional), VAT number (optional), order data, item data, payment data Customers / Payment service Providers Art. 6 Par. 1 lit. b) GDPR
User Management Only Selected and trained staff has access to your data from within our premises and via the plentymarkets system and is only used for the processing of orders and eventual follow up by telephone or email if we have a query pertaining your order. A password secured user login to the plentymarkets system is required.  Name, email address, user name, user ID, password (encrypted),  Employees /  Amazon Web Services Art. 6 Par. 1 lit. b) GDPR
Customer Communication For communication with customers, we use the plentymarkets support ticket system. The system connects from Plentymarkets to our external email service to provide you a way of communicating with us by email.  Name, form of address, title, email address, invoice address, different delivery address (if applicable), date of birth (optional), telephone numbers (optional), company name (if applicable), VAT number (if applicable), order data, item data Customers, interested parties, employees/ E-Mail Service provider Art. 6 Par. 1 lit. b) GDPR
         

 

If, as determined by us, the lawful basis upon which we process your personal information changes, we will notify you about the change and any new lawful basis to be used if required. We shall stop processing your personal information if the lawful basis used is no longer relevant.

 

Your individual rights

 

Under the GDPR your rights are as follows. 

You also have the right to complain to the ICO [www.ico.org.uk] if you feel there is a problem with the way we are handling your data.

We handle subject access requests in accordance with the GDPR.

Internet cookies

We use cookies on this website to provide you with a better user experience. We do this by placing a small text file on your device / computer hard drive to track how you use the website, to record or log whether you have seen particular messages that we display, to keep you logged into the website where applicable, to display relevant adverts or content, referred you to a third party website.

Some cookies are required to enjoy and use the full functionality of this website.

We use a cookie control system which allows you to accept the use of cookies, and control which cookies are saved to your device / computer. Some cookies will be saved for specific time periods, where others may last indefinitely. Your web browser should provide you with the controls to manage and delete cookies from your device, please see your web browser options.

Special Cookies that we use are;

Data security and protection

We ensure the security of any personal information we hold by using secure data storage technologies and precise procedures in how we store, access and manage that information. Our methods meet the GDPR compliance requirement.

Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible and we use regular Malware Scanning.

Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive information you supply is encrypted via Secure Socket Layer (SSL) technology.
We implement a variety of security measures when a user places an order enters, submits, or accesses their information to maintain the safety of your personal information.
All payment transactions are processed

Transparent Privacy Explanations

We have provided some further explanations about user privacy and the way we use this website to help promote a transparent and honest user privacy methodology.

Third party Disclosure


We do not sell, trade, or otherwise transfer to outside parties your Personally Identifiable Information unless we provide users with advance notice. This does not include website hosting partners and other parties who assist us in operating our website, conducting our business, or serving our users, so long as those parties agree to keep this information confidential. We may also release information when it’s release is appropriate to comply with the law, enforce our site policies, or protect ours or others’ rights, property or safety.

 

Email marketing messages & subscription

Under the GDPR we use the consent lawful basis for anyone subscribing to our newsletter or marketing mailing list. We only collect certain data about you, as detailed in the "Processing of your personal date" above. Any email marketing messages we send are done so through an EMS, email marketing service provider. An EMS is a third party service provider of software / applications that allows marketers to send out email marketing campaigns to a list of users.

Email marketing messages that we send may contain tracking beacons / tracked clickable links or similar server technologies in order to track subscriber activity within email marketing messages. Where used, such marketing messages may record a range of data such as; times, dates, I.P addresses, opens, clicks, forwards, geographic and demographic data. Such data, within its limitations will show the activity each subscriber made for that email campaign.

Any email marketing messages we send are in accordance with the GDPR and the PECR. We provide you with an easy method to withdraw your consent (unsubscribe) or manage your preferences / the information we hold about you at any time. See any marketing messages for instructions on how to unsubscribe or manage your preferences, you can also unsubscribe from all mailslists, by following the highlighted link, otherwise contact our provider..

Our EMS provider is; [Clever Reach]. We hold the following information about you within our EMS system;