PRIVACY NOTICE
Last updated: 29/07/22

This notice (“Privacy Notice”) sets out how A Collected Man Limited processes your personal data in connection with our business, including the provision of our Website at www.acollectedman.com (“Website”), and the products that we and third party sellers sell (“Products”) and the services that we provide (“Services”) through our Website or otherwise.

We will update this Privacy Notice from time to time to reflect any changes or proposed changes to our use of your personal data, or to comply with changes in applicable law or regulatory requirements. We may notify you by email of any significant changes to this Privacy Notice, but we encourage you to review this Privacy Notice periodically to keep up to date on how we use your personal data. If we update this Privacy Notice, we will update the effective date at the top of the page.

Your access to and use of our Website, including your account page and any secure area, is subject at all times to our Website . In addition, your purchase of Products and your receipt of Services from us will be subject to our Consignment Terms, Fixed Price Terms or Auction Terms; please refer to our Website Terms of Use for further information about when these terms will apply.

1. Purpose of this privacy notice

This Privacy Notice explains our approach to any personal data that we might collect from you or which we have obtained about you from a third party, and the purposes for which we process your personal data. This Privacy Notice also sets out your rights in respect of our processing of your personal data.

When we talk about “personal data”, we mean any information which relates to an identified or identifiable living individual. Individuals might be identified by reference to a name, an identification number, location data, an online identifier (such as an IP address) or to other factors that are specific to them, such as their physical appearance.

This Privacy Notice is intended to assist you in making informed decisions when using our Website and Services. Please take a moment to read and understand it. It should be read in conjunction with our Cookie Notice.

This Privacy Notice only applies to the use of your personal data obtained by us, whether from you directly or from a third party. It does not apply to personal data collected by third parties during your communications with those third parties or your use of their products or services (for example, where you follow links to third party websites over which we have no control, or you purchase goods or services from those third parties).

2. About Us

The Website is operated by A Collected Man Limited  (“A Collected Man”, “we”, “us, “our”). A Collected Man is the data controller responsible for your personal data. A Collected Man is registered in England and Wales (Company No: 08929257) and has its registered office at Suite 1, 3rd Floor, 11-12 St James's Square, London, United Kingdom, England, SW1Y 4LB.

3. How to contact us

If you have any questions about this Privacy Notice or want to exercise your rights as a data subject set out in this Privacy Notice, please contact us by emailing legal@acollectedman.com.

4. What personal data we collect

In providing our Website and making available the Products and Services, we may collect and process different types of personal data about you. The types of personal data we collect depends on who you are, how you use our Website and which Products and Services you receive, and includes some or all of the following (as applicable):

 

Identity Data

First name; last name; unique identifiers that we assign to your account; account passwords.

Contact Data

Delivery address; email address; telephone number.

Profile Data

Any ‘know your customer’ or ‘KYC’ information that we may collect, including identification documents (such as an ID card, passport, residence permit or driving licence) and personal data contained in such documents, including country of issue, nationality, date of birth and address; photos and images that identify you (e.g. selfies that we ask you to take to verify your identity or any other images that you provide to us); any relevant publicly available information in connection with KYC checks; any other data that you volunteer during our dealings with you (e.g. if you contribute to our journal or to publications on our Site).

Transaction Data

Details about payments made between you and us, including bank account details, payment information and billing address; details of Products that you purchase through the Website; details of goods that you sell through our Services; details of any of our promotions or competitions that you participate in.

Enquiry and Feedback Data

The content of any messages you send using our Contact Us Form or that you otherwise submit to us, or any survey responses that you submit to us.

Technical Data

IP address; device and user agent information (your browser type and operating system); general geolocation derived from your IP address (country, postcode).

Observed Data

Data that is observed about your use of our Website or interaction with our emails and/or data that we infer through your use of the Website and our Services. This data may include: details of when your current or previous sessions started; the referrer URL (web page that you were on when you clicked a link that sent you to our Website); information about the pages of our Website that you have visited and any Products that you have purchased or shown an interest in (including any products that you have added to your Watchdrawer or Wishlist).

Marketing and Communications Data

Any marketing or services communications preferences that you have provided to us.

 

5. How we collect and receive personal data

We collect and receive personal data using different methods:

Personal data you provide to us

You may give us your personal data directly, for example, when you register for an account or purchase Products on our Website, contact us, or subscribe to receive our marketing communications.

Personal data we observe and collect through Website use

When you access and use our Website, we may collect Technical Data and Observed Data. We may collect this personal data by using cookies and other similar technologies (see the Insight and Analysis section for further information).

Personal data that is supplied to us by third parties or is publicly available

We may collect or receive personal data, including Profile Data, about you from third parties or from publicly available information. Such third parties may include third parties that provide services to us so that we can provide our Website and our Services.

 

6. Who we collect personal data about

We collect and process personal data from the following people:

Website visitors

If you browse our Website or register an account on our Website, we will collect and process your personal data in connection with your interaction with us and our Website.

Customers

If you buy Products or receive our Services, we may collect and process your personal data in connection with the supply of the Products or our supply of the Services.

People who contact us

If you directly contact, provide feedback, or submit a complaint to us through our Website, surveys or otherwise, we will collect and process your personal data in connection with your interaction with us.

People who work for our suppliers

If you work for one of our suppliers and have responsibility for administering your organisation’s account with us or handling our orders, we will process your personal data in connection with your organisation’s relationship with us.

Visitors to our physical locations

If you attend our offices or other locations, we may process personal data that you volunteer or that we otherwise collect in connection with your visit. For example, you may volunteer personal data when signing in as a guest. CCTV footage may also be collected for security purposes.

Job applicants

If you apply for a job with us, whether through the Website or otherwise, we will collect and process your personal data in connection with your application.

 

7. How we use your personal data

We use your personal data for the purposes set out in this section. If we wish to make any changes to these purposes, or if we wish to use your personal data for any purpose that is not listed in this section, we will notify you using the contact details we hold for you.

Use of our Website

To facilitate use of our Website

When you use our Website, we collect and process Technical Data to provide the Website to you, including to make sure we are providing the correct version of the Website.

Our legal basis for processing

It is in our legitimate interest to use personal data in such a way, to ensure that we provide access to our Website in a secure and effective way.

If you register and access an account on our Website

You may be required to register an account with us in order to gain access to certain features and functionality of our Website and/or to receive access to certain Services from us. Account applicants will need to complete the registration form and may be asked to provide Identity Data, Contact Data and Profile Data. We will use this data in order to process your registration, to protect our Website and Services against fraudulent activity, and for account verification. Once your account is registered, we will process your Identity Data and Profile Data to identify you when you log in to your account and access secure areas of our Website. We will also process certain Marketing and Communications Data so that we can administer your account and contact you about your account. We will also collect and process Observed Data and Technical Data when you use certain features and functionality on our Website. This data helps us understand how you use our Website so that we can improve it.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you, or it is in our legitimate interest to use your personal data in such a way to ensure that we provide access to the Website and our Services in a secure and effective way.

If you interact with our social media pages

If you click on one of the social media links on our Website or otherwise interact with our social media pages such as on Instagram or YouTube (including interacting with any ‘like’ or similar embedded features on our Website or social media accounts), we and the relevant social media platform may collect Technical Data and Observed Data relating to such interaction.

For more information about how we use the Observed Data, please see the Insight and Analysis section.

The relevant social media platform may also be a controller in respect of the personal data that is collected via your use of our social media pages and may use that personal data for additional purposes. For details of how the relevant social media platform uses your personal data, please see the privacy policy of the relevant social media platform.

Our legal basis for processing

It is in our legitimate interest to use personal data in the ways described above, to promote our Website, and the Products and Services via social media. For information about the legal basis that we rely on to use Observed Data, please see the Insight and Analysis section below.

If we interview you for our journal or your otherwise contribute to publications on our Site

If we interview you for a journal article that we publish on the Site or if you contribute in any other way to publications we publish on our Site, we may record our interview or our communications with you in order to produce the content that we publish on our Site. We may publish the personal data that you contribute (which may include certain of your Identity Data and Profile Data) as part of the published content and to credit you for your contribution. If you provide photographs or other images in support of your contribution, we may publish one or more of those images alongside your interview.

Our legal basis for processing

Where we use your content in connection with interviews, articles or other content that we publish on our Site, it is in our legitimate interest to use any personal data that you provide to us, to produce the content and publish it on our Site.

 

Product and Service fulfilment

To supply Products and Services to you

We collect and maintain personal data that you submit to us for the purpose of supplying Products and Services that you have purchased or requested via our Website.

The personal data we process may include certain of your Identity Data, Contact Data, and Transaction Data (as applicable).

We process this information so that we can fulfil the supply of the Products and Services, fulfil any contractual obligations that we owe in respect of the supply of the Products and Services, and to maintain our records of transactions.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Products and Services, or it is in our legitimate interest or a third party’s legitimate interest to use personal data in such a way to ensure that we provide the Products and Services in an effective, safe and efficient way.

We may maintain records of relevant transactions to comply with legal obligations that we owe, or to establish, exercise or defend any legal claims in connection with the supply of the Products and Services.

 

Enquiries and feedback

To handle any communication that you submit about our Website or the Products and Services, and to improve our Website, the Products and Services

There are various ways in which you are able to contact us, including by email, telephone or the Contact Us Form on our Website. In addition, from time to time we may invite you to complete surveys to provide feedback about us.

When you contact us or otherwise provide feedback to us, we will collect and process your Enquiry and Feedback Data, together with any Identity Data, Contact Data, Transaction Data or Technical Data that is relevant to your communication.

We will use such data to help us to identify and resolve any issue that you have or to otherwise respond to your communication, and to monitor and improve our Website, Products and our Services (including to assist with the selection of future product and service lines).

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Products and Services, or it is otherwise in our legitimate interest to use your personal data in the ways described above to ensure that we are able to help you with your enquiry, provide a high standard of service, and improve our Website, Products and Services.

To train our personnel

We may use Enquiry and Feedback Data, and data relating to how our personnel have responded to your communication or survey response, to evaluate how we have handled your enquiry or feedback and to train our personnel in respect of their handling of enquiries and feedback. 

Our legal basis for processing

It is in our legitimate interest to use the personal data provided by you so that we can train our personnel to ensure that they handle enquires and feedback effectively and provide a high standard of customer service.

 

Prize draws, prize competitions and other promotions

If you participate in one of our promotions

From time to time, we may run prize draws, prize competitions and other promotions on our Website and/or on our social media accounts. For the purposes of administering such promotions, we may process your Identity Data, Contact Data, Transaction Data and any other personal data relevant to your promotion entry.

Our promotions are subject to separate terms and conditions, which you may be required to accept as a condition of entry.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you (e.g. the promotion terms and conditions) or it is in our legitimate interest to use your personal data to enable us to administer our promotion fairly and effectively and to ensure that we comply with self-regulatory codes governing the operation of promotions.

 

Insight and Analysis

To help us to personalise our Website, Services and content, and to understand more about the users of our Website and our Services

We and our third-party partners use cookies, web beacons, pixel tags and other similar technologies (which we generically refer to as “Cookies”) or may otherwise collect Observed Data through your use of our Website and Services and any emails that you receive from us. Please see our Cookie Notice for further information, including details of our third-party partners.

We and our third-party partners use Observed Data and Transaction Data to personalise your experience on the Website and to personalise the content that we deliver to you through our advertising and marketing activities referred to in the Advertising and Marketing section.

In addition, we and our third-party partners may use Observed Data and Transaction Data on an aggregated basis or in a way that does not directly identify you, for the following purposes:

·       to understand more about the users of our Website and Services and to analyse and improve our Website, the Products and our Services;

·       to count users who have visited our Website or opened an email to learn what parts of our Website are of most interest to users, to measure the effectiveness of our content, and to understand what features and functionalities our visitors like to see;

·       to help us understand the type of advertising and marketing content that is most likely to appeal to our visitors and customers; and

·       to help us with the selection of future product and service lines, Website design and to remember your preferences.

In some of our email messages, we use a “click-through URL” linked to certain websites administered by us or on our behalf. We may track click-through data to assist in determining interest in particular topics and measure the effectiveness of these communications.

Our legal basis for processing

Where your data is collected through the use of non-essential cookies, we rely on consent to collect your personal data and for the onward processing purpose. Please see our Cookie Notice for further details.

Where we use Observed Data and Transaction Data in connection with our advertising and marketing activities, please see the Advertising and Marketing section for details of the legal basis that we rely on.

In other cases, it is in our legitimate interest to use Observed Data and Transaction Data to understand more about and to improve our Website, Products and Services.

 

Advertising and Marketing

This section describes how we may use your personal data to show you advertising when you visit or use other websites and/or online services or in connection with marketing that we send to you.

The advertising and marketing described in this section may include personalised and non-personalised content. Personalised advertising and marketing has been specifically tailored to you and will include content that we think is most relevant to you, based on Transaction Data and Observed Data. Please see the Insight and Analysis section for more details about how we may collect Observed Data.

In some cases we may be joint controllers with third parties in respect of this activity – please see the   section below for further information.

The advertising and marketing activities that we undertake are as follows:

To send you marketing communications by email

We use your Identity Data, Contact Data and Marketing and Communications Data to send you (or the organisation you represent) marketing communications by email. Our marketing will include press releases and information about us, our Website, our Products and Services, and the offers and promotions we offer from time to time.

Our marketing communications may include personalised and non-personalised marketing. Personalised marketing has been specifically tailored to you and will include content that we think is most relevant to you, based on Transaction Data and Observed Data. Please see the Insight and Analysis section for more details about how we may collect Observed Data.

Non-personalised marketing is marketing that is not tailored to you.

Our legal basis for processing

It is in our legitimate interest to use your personal data for marketing purposes, for example to decide what marketing content we think may appeal to you.

However, we will only send marketing communications to you by email where we have permission to do so (for example when you have consented to receiving marketing when you sign up to our newsletter or if we collect permission to send you marketing when you purchase Products or use our Services).

In addition, please see the Insight and Analysis section to learn about the legal basis that we rely on to collect Observed Data via the use of Cookies.

Online advertising through third-party tools

Our third party advertising partners may provide tools that we can use to display our advertisements to people who we think are more likely to be interested in our Website, the Products and Services.

For example, an advertising partner may have determined that you are someone who is likely to be interested in luxury goods, using data that they have collected about you (which we do not receive). If we want to display our advertising to people interested in luxury goods on third party websites that use the services of our advertising partner, we may ask our advertising partner to display our advertising to you.

Our legal basis for processing

If you are someone who has seen this advertising, it is in our legitimate interests that the relevant third party advertising partner uses the data that you have provided to it to advertise our Website, the Products and our Services, although please note that we do not receive this data and you should exercise your rights in respect of such data in accordance with the privacy notice of the relevant online service that displays our advertising to you.

Online advertising through Observed Data

We and our third party partners may use Observed Data to display advertising or other data that is collected through your interactions with third party websites and services, to provide you with, and analyse the effectiveness of, advertising when you visit or use other websites and/or services.

Our legal basis for processing

Please see the Insight and Analysis section to learn about the legal basis that we rely on to collect data via the use of Cookies.

Where we use your personal data to display online personal advertising to you, we rely on the consent that you have provided in respect of the collection of such data, or it is otherwise in our legitimate interests to promote our Website, the Products and our Services to you.

Our third-party partners may rely on a different lawful basis in respect of their use of your personal data. As set out in our Cookie Notice, please read the privacy notice of the relevant third-party provider.

Customer Match Advertising

We may share your Contact Data (usually your email address, in an encrypted or ‘hashed’ form) with third-party providers of social media platforms and other similar services, such as Facebook and other similar platforms (“Platforms”), so that the third-party provider can try to “match” your data with the registration data of the relevant Platform.

Where there is a successful match, our advertising will be displayed to you when you use the relevant Platform (e.g. on your Facebook newsfeed). This is known as “customer match” or “custom audience” advertising because we “customise” the audience that we want to reach on the relevant Platform.

In some cases, we may also share your Contact Data with third-party providers in order to exclude you from seeing our advertising (because we are trying to reach people that are not yet our customers).

Some of the advertising that you see may be personalised to you. The data that we use to personalise our advertising, such as your Technical Data and Observed Data, will not be provided to the third-party providers of the Social Platforms. Please see the Insight and Analysis section to learn more about how we personalise advertising to you.

This activity is also subject to the privacy choices you have elected to make on the relevant Platforms.

Our legal basis for processing

It is in our legitimate interests to use your personal data as described above in order to promote our Website, the Products and our Services to you when you use the relevant Platforms.

Lookalike Advertising

Where we have displayed our advertisements to people as described above, we may also ask our third party advertising partners to find people that share similar interests and characteristics to those persons, which will be based on information that the third party advertising partner has collected about you and those similar persons (which we do not receive).

This is known as “lookalike” audience advertising because we are trying to show our advertising to people who “look like” our Website users, and other persons that are likely to be interested in our advertising.

If you are someone who has seen this advertising, please note that this activity is based on data that you have provided to the relevant third party (which we do not receive) and is also subject to the privacy choices you have elected to make on such third-party services.

Our legal basis for processing

Please see the sections above for details of the lawful basis that we rely on to display our advertising to persons that we think are most likely to be interested in our Website, the Products and our Services.

It is in our legitimate interests to further use your personal data to request that our third party advertising partners find other people who share similar interests and characteristics with you (and therefore who are also most likely to be interested in our Website, the Products and our Services).

If you are someone who has seen this advertising, it is in our legitimate interests that the relevant third party advertising partner uses the data that you have provided to it to advertise our Website, the Products and our Services, although please note that we do not receive this data and you should exercise your rights in respect of such data in accordance with the privacy notice of the relevant online service that displays our advertising to you.

 

Recruitment

If we use your personal data in connection with our recruitment activities

We use your personal data for recruitment purposes, in particular, to assess your suitability for any of our positions that you apply for, whether such application has been received by us online, by email or by hard copy and whether submitted directly by you or by a third-party recruitment agency on your behalf. We also use your Identity Data and Contact Data to communicate with you about the recruitment process, to keep records about our recruitment process and to comply with our legal and regulatory obligations in relation to recruitment.

We will process any personal data about you that you volunteer, including during any interview, when you apply for a position with us. We may also process your personal data obtained from any third parties we work with in relation to our recruitment activities, including without limitation, recruitment agencies, background check providers, credit reference agencies and your referees.

The personal data we process may include your Identity Data, Contact Data, details of your education, qualifications and employment history, any other personal data which appears in your curriculum vitae or application, any personal data that you volunteer during an interview or your interactions with us, or any personal data which is contained in any reference about you that we receive. Such information may also include special categories of personal data (such as information about your health, any medical conditions and your health and sickness records) and information relating to criminal convictions and offences if that information is relevant to the role you are applying for.

We also use your personal data for the purposes of reviewing our equal opportunity profile in accordance with applicable legislation. We do not discriminate on the grounds of gender, race, ethnic origin, age, religion, sexual orientation, disability or any other basis covered by local legislation. All employment-related decisions are made entirely on merit.

Our legal basis for processing

Where we use your personal data in connection with recruitment, it will be in connection with us taking steps at your request to enter into a contract we may have with you or it is in our legitimate interest to use personal data in such a way to ensure that we can make the best recruitment decisions.

We will not process any special (or sensitive) categories of personal data or personal data relating to criminal convictions or offences except where we are able to do so under applicable legislation or with your explicit consent.

 

Receipt of products and services from our suppliers

If we have engaged you or the organisation you represent to provide us with products or services

If we have engaged you or the organisation you represent to provide us with products or services (for example, if you or the organisation you represent provide us with services such as IT support or financial advice), we will collect and process your personal data in order to manage our relationship with you or the organisation you represent, to receive products and services from you or the organisation you represent and, where relevant, to provide the Products and our Services to others. The personal data we collect from you may include your Identity Data and Contact Data and any other personal data you volunteer which is relevant to our relationship with you or the organisation you represent.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you or the organisation you represent, or it is in our legitimate interest to use personal data in such a way to ensure that we have an effective working relationship with you or the organisation you represent and are able to receive the products and services that you or your organisation provides, and provide the Products and our Services to others, in an effective way.

 

Security

If we need to use your personal data in connection with the administration of our security measures

We have security measures in place at our premises, including CCTV and building access controls. There are signs in place showing that CCTV is in operation. The images captured are securely stored and only accessed on a need to know basis (e.g. to look into an incident). CCTV recordings are typically automatically overwritten after a short period of time unless an issue is identified that requires investigation (such as a theft).

We may require visitors to our premises to sign in on arrival and where that is the case we will keep a record of visitors for a short period of time. Our visitor records are securely stored and only accessible on a need-to-know basis (e.g. to look into an incident).

Our legal basis for processing

It is in our legitimate interests to process your personal data so that we can keep our premises secure and provide a safe environment for our personnel and visitors to our premises.

 

Business administration and legal compliance

If we need to use your personal data to comply with our legal obligations or in connection with the administration of our business

We may use your personal data: (i) to comply with our legal obligations; (ii) to enforce our legal rights; (iii) to protect the rights of third parties; and (iv) in connection with a business transition such as a merger, reorganisation, acquisition by another company, or sale of any of our assets.

Our legal basis for processing

Where we use your personal data in connection with a business transition, to enforce our legal rights or to protect the rights of third parties, it is in our legitimate interest to do so. For all other purposes described in this section, we have a legal obligation to use your personal data to comply with any legal obligations imposed upon us, such as a court order.

We will not process any special (or sensitive) categories of personal data or personal data relating to criminal convictions or offences except where we are able to do so under applicable legislation or with your explicit consent.

  

8. If you fail to provide your personal data

Where we are required by law to collect your personal data, or we need to collect your personal data under the terms of a contract we have with you, and you fail to provide that personal data when we request it, we may not be able to perform the contract we have or are trying to enter into with you. This may apply where you do not provide the personal data we need in order to provide the Products and Services you have requested from us or to process an application to register an account. In these circumstances, we may have to cancel your application or the provision of the relevant Products and Services to you, in which case we will notify you.

9. How we obtain your consent

Where our use of your personal data requires consent, you can provide such consent at the time we collect your personal data following the instructions provided, or by informing us using the contact details set out in the How to Contact Us section above.

10. Third-party links

This Privacy Notice only applies to personal data processed by us through your use of our Website and/or in connection with our business operations. However, from time to time, our Website may contain links to third-party websites and services. We have no control over these websites and services and this Privacy Notice does not apply to your interaction with the relevant third parties.

When you use a link to go from our Website to another website (even if you don’t leave our Website) or you request a service from a third party, your browsing and interactions on any other websites, or your dealings with any other third-party service provider, is subject to that website’s or third-party service provider’s own rules and policies. For example, our Website invites you to connect with us on social media platforms such as Facebook and Instagram. When you click on the links we provide to such third-party platforms, you will be transferred from our Website to the relevant third-party platform and the privacy notice (and other terms and conditions) of that platform will apply to you.

We do not monitor, control or endorse the privacy practices of any third parties. We encourage you to become familiar with the privacy practices of every website you visit or third-party service provider that you use in connection with your interaction with us and to contact them if you have any questions about their respective privacy notices and practices.

11. Sharing personal data

We only share personal data with others when we are legally permitted to do so. When we share personal data with others, we put contractual arrangements and security mechanisms in place to protect the personal data shared and to comply with our data protection, confidentiality and security standards and obligations.

When processing your personal data, we may need to share it with third parties (including other entities within our group of companies), as set out in the table below. This list is non-exhaustive and there may be circumstances where we need to share personal data with other third parties.

Third-party suppliers who provide applications/ functionality, data processing or IT services

We share personal data with third parties who support us in providing our Website and help provide, run and manage our internal IT systems. Such third parties may also include, for example, providers of information technology, cloud-based software-as-a-service providers, identity management, website design, hosting and management, data analysis, data back-up, security and storage services. The servers powering and facilitating that cloud infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them. We also share your personal data with third-party service providers to assist us with insight analytics. These providers are described in our Cookie Notice.

Payment providers and banks

We share personal data with third parties who assist us with the processing of payments and refunds.

Delivery and courier companies

We share personal data with suppliers who assist us in the delivery of our Products and Services to our customers.

Advertising partners

We share personal data with third party advertising partners, including those set out in the Joint Controller Activities section below and in our Cookie Settings tool. This data is used to provide you with, and measure the effectiveness of, online personalised advertising and for other advertising related activities.

Third-party email marketing and CRM specialists

We share personal data with specialist suppliers who assist us in managing our marketing database and sending out our email marketing communications and account-related communications.

Third-party suppliers who assist us in conducting KYC checks

We share personal data with specialist suppliers, including Sum and Substance Limited, who assist us in carrying out KYC checks on our behalf.

Third-party suppliers who assist us in administering our promotions

We share personal data with specialist suppliers who assist us in administering our prize draws, prize competitions and other promotions.

Third-party suppliers who assist us in producing interviews for our Site

We share personal data with specialist suppliers who assist us by transcribing interviews that we record, as part of producing articles and other content for our Site.

Recruitment agencies and related organisations

We share personal data with external recruiters, third-party providers that undertake background checks on our behalf and other entities within our group of companies.

Auditors, lawyers, accountants and other professional advisers

We share personal data with professional services firms who advise and assist us in relation to the lawful and effective management of our organisation and in relation to any disputes we may become involved in.

Law enforcement or other government and regulatory agencies and bodies

We share personal data with law enforcement or other government and regulatory agencies or other third parties as required by, and in accordance with, applicable law or regulation.

Other third parties

Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, or to establish, exercise or defend legal rights. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.

 

12. Joint controller activities

We are joint controllers with Facebook Ireland Limited (“Facebook”) in respect of some of the activities described in the Advertising and Marketing section, where these activities involve advertising to you on Facebook.

We and Facebook have entered into Facebook’s Controller Addendum (available here) to determine our and Facebook’s respective responsibilities for compliance with data protection obligations in respect of these activities. We are responsible for providing the information set out in this Privacy Notice (in particular, the information set out in the Advertising and Marketing section). Facebook is responsible for giving effect to your data subject rights (see the Your rights as a data subject section) in respect of these activities.

For further information about how we and Facebook use your personal data in connection with these activities, including the legal basis Facebook relies on and the ways to exercise your data subject rights against Facebook, please see Facebook’s Data Policy at https://www.facebook.com/about/privacy.

13. Transfers outside the UK and the European Economic Area (“EEA”)

Where necessary in order to provide our Website and our Products and Services, we will transfer personal data to countries outside the UK and the EEA.

Non-EEA countries do not have the same data protection laws as the UK and the EEA. In particular, non-EEA countries may not provide the same degree of protection for your personal data, may not give you the same rights in relation to your personal data and may not have a data protection supervisory authority to help you if you have any concerns about the processing of your personal data. However, when transferring your personal data outside the UK or the EEA, we will comply with our legal and regulatory obligations in relation to your personal data, including having a lawful basis for transferring personal data and putting appropriate safeguards in place to ensure an adequate level of protection for the personal data. We will take reasonable steps to ensure the security of your personal data in accordance with applicable data protection laws.

When transferring your personal data outside the UK or the EEA, we will, where required by applicable law, implement at least one of the safeguards set out below. Please contact us if you would like further information on the specific mechanisms used by us when transferring your personal data outside the UK or the EEA.

Adequacy decisions

We may transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission and/or the UK Government (as applicable).

Model clauses

Where we use certain service providers, we may use specific standard contractual clauses approved by the European Commission and/or the UK Government which give personal data the same protection it has in Europe and/or the UK.

 

14. How long we keep your personal data

In respect of personal data that we process in connection with the supply of our Products and Services, we may retain your personal data for up to six years from the date of supply of the relevant Products and Services and in compliance with our data protection obligations. We may then destroy such files without further notice or liability.

Where we process personal data in connection with the registration and use of an account on our Website, we may retain your personal data for up to six years from the date that the relevant account is terminated (and in compliance with our data protection obligations). We may then destroy such files without further notice or liability.

Where we process any other personal data, we will retain relevant personal data for up to three years from the date of our last interaction with you (and in compliance with our data protect obligations). We may then destroy such files without further notice or liability.

If any personal data is only useful for a short period (e.g. for a specific activity, promotion or marketing campaign), we will not retain it for longer than the period for which it is used by us.

If you have opted out of receiving marketing communications from us, we will need to retain certain personal data on a suppression list indefinitely so that we know not to send you further marketing communications in the future. However, we will not use this personal data to send you further marketing unless you subsequently opt back in to receive such marketing.

15. Confidentiality and security of your personal data

We are committed to keeping the personal data you provide to us secure and we have implemented information security policies, rules and technical measures to protect the personal data under our control from unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss. In addition, all our employees and data processors (i.e. those who process your personal data on our behalf) are obliged to respect the confidentiality of the personal data of all users of our Website and those who purchase our Products and Services.

16. Personal data of minors

Our Website is not intended for use by, or targeted at, minors (individuals under the age of 18) and we do not knowingly collect personal data of minors. However, this does not prevent minors from providing personal data to us. If we do collect personal data of minors, we will comply with all applicable laws and regulations relating to the processing of personal data of minors.

If you are under the age of 18, you must not use our Website or purchase Products and Services from us and you must not provide us with any personal information. If we discover that we are holding the personal data of a minor, we will delete that information as soon as possible. Please contact us if you have reason to believe that a minor may have submitted personal data to us (see the How to contact us section above).

17. Your rights as a data subject

You have certain rights in relation to the personal data we hold about you. These rights include the right: (i) to obtain copies of your personal data; (ii) to have your personal data corrected or deleted; (iii) to limit the way in which your personal data is used; (iv) to object to our use of your personal data; (v) to transfer your personal data; (vi) not to be subject to decisions based on automated processing (including profiling); and (vii) to complain to a supervisory authority. If you would like to exercise any of these rights, please contact us using the details set out in the How to Contact Us section above.

Your right of access

If you ask us, we will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data (along with certain other details). If you require additional copies, we may charge a reasonable fee for producing those additional copies.

Your right to rectification

If the personal data we hold about you is inaccurate or incomplete, you are entitled to have it rectified. If we have shared your personal data with others, we’ll let them know about the rectification where possible. If you ask us, where possible and lawful to do so, we will also tell you who we’ve shared your personal data with so that you can contact them.

Your right to erasure

You can ask us to delete or remove your personal data in some circumstances, such as where we no longer need it or where you withdraw your consent (where applicable). If we have shared your personal data with others, we will let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we will also tell you who we have shared your personal data with so that you can contact them directly.

Your right to restrict processing

You can ask us to “block” or suppress the processing of your personal data in certain circumstances such as where you contest the accuracy of that personal data or you object to us processing it for a particular purpose. This may not mean that we will stop storing your personal data but, where we do keep it, we will tell you if we remove any restriction that we have placed on your personal data to stop us processing it further. If we’ve shared your personal data with others, we’ll let them know about the restriction where it is possible for us to do so. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we’ve shared your personal data with so that you can contact them directly.

Your right to data portability

You have the right, in certain circumstances, to obtain personal data you have provided to us (in a structured, commonly used and machine-readable format) and to reuse it elsewhere or to ask us to transfer it to your chosen third party.

Your right to object

You can ask us to stop processing your personal data, and we will do so, if we are: (i) relying on our own or someone else’s legitimate interest to process your personal data, except if we can demonstrate compelling legal grounds for the processing; or (ii) processing your personal data for direct marketing purposes.

Your rights in relation to automated decision-making and profiling

You have the right not to be subject to a decision when it is based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for the entering into, or the performance of, a contract between you and us.

Your right to withdraw consent

If we rely on your consent (or explicit consent) as our legal basis for processing your personal data, you have the right to withdraw that consent at any time. You can exercise your right of withdrawal by contacting us using our contact details in the How to Contact Us section above or by using any other opt-out mechanism we may provide, such as an unsubscribe link in an email.

Your right to lodge a complaint with the supervisory authority

If you have a concern about any aspect of our privacy practices, including the way we have handled your personal data, please contact us using the contact details provided in the How to Contact Us section above. You can also report any issues or concerns to a national supervisory authority in the Member State of your residence or the place of the alleged infringement. You can find a list of contact details for all EU supervisory authorities at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.

As we are incorporated in the United Kingdom, our regulatory authority is the Information Commissioner’s Office (“ICO”). Contact details for the ICO can be found on its website at https://ico.org.uk.