1. Who we are
We will collect and process personal information in accordance with the General Data Protection Regulation EU 2016/679 (GDPR), Data Protection Act 2018 and The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) (“the Data Protection Regulations”). For the purpose of the Data Protection Regulations, the Data Controller is Brit-Stitch Limited.
· Brit-Stitch Limited’s websites (www.brit-stitch.com other web pages and communications linking to this policy;
· When you contact us by email, telephone, fax, post or in person;
· When you post content or contact us through Social Media;
· When you purchase products and services via our website, telephone, email, fax, post or in person.
2. Personal information that we collect
Brit-Stitch Limited may collect personal information about you in several different ways.
2.1 Information that you provide us
Whenever you interact with Brit-Stitch Limited, you may be asked to provide us with information relating to you. For example:
· When you purchase a product from us, whether via our website, by phone, email, fax, post, or in person, we will collect certain personal information such as your title, name, job role, postal address, email address, telephone number, delivery contact details, invoice contact details and payment card details, so that we can process and fulfil your order;
· When you contact our sales/customer service department (e.g. via email, telephone, fax, post or in person) to make an enquiry, request a quotation or for general assistance, we will keep information about the communication, including your title, name, address, job role, telephone number, email address, product(s)/service(s) you enquired about, the reason why you contacted us and the advice/information we gave you;
· When you visit us at a public event, such as a trade show/exhibition or participate in one of our surveys, competitions or prize draws, we may ask for information, such as your business card, name, job role, address, telephone number, email address and product or service interests/preferences.
2.2 Information we may collect from other sources
We may also collect information from publicly available sources and third parties, provided the receipt of such information is in accordance with applicable laws. We may combine such information with other information we receive from or about you. For instance:
· When you seek to open an account with us, we may carry out credit and financial checks to ensure that you have a suitable credit rating;
· When carrying out business-to-business sales calls, we may use business contact details that are publicly available.
2.3 Information we may collect in relation to social media platforms
If you use any of our social media pages e.g. Instagram, Twitter and Facebook, we may receive information relating to your social media accounts.
For instance, if you ‘like’, ‘Instagram’ or similar one of our pages on a social media site, we may receive information about your social media profile, depending on your social media account privacy settings.
This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.
We will never ask for personal or sensitive information through social media platforms and encourage you to contact us through primary communication channels such as telephone or email, if you wish to discuss sensitive details.
Read more about social media platforms’ privacy policies by clicking the following links:
2.4 Information we may collect when you use the Brit-Stitch Limited website –www.brit-stitch.com – and other online facilities
Our website provides Brit-Stitch Limited with information about your use of the site, including:
· Details of the content that you view and interact with. For example, when you use our website, we may collect information about your visit, such as your browser software and which pages you view;
· Server logs, which hold information about your use of our website, such as your IP address, browser information, HTTP client request information and the time and location of your activities and domain.
This information is generally collected using digital identifiers such as a browser cookie or your IP address. These identifiers are used to distinguish the information provided by your browser or device from that of another user’s browser or device.
Email communication you have with us may be monitored and logged.
3. How we use the information that we collect
Brit-Stitch Limited may use the information it collects for the following purposes:
3.1 Service provision
When we use personal information to offer our products and services to you, the processing is based on an agreement between you and Brit-Stitch Limited. In this context, we may use personal information to:
· Provide you with a product or service you have requested, including checking that a payment is not made fraudulently and delivering your purchase to you;
· Provide customer care, warranty, returns and other after-sales services (such as complaint handling);
· Facilitate and process your requests for information when you contact us about Brit-Stitch Limited and its products and services.
3.2 Product and service development
We work continuously to improve our products and services. We base this processing on our legitimate interests to develop our products and services to better meet customer requirements. In this context, we may use personal information to:
· Ask for your opinions on Brit-Stitch Limited’s products and services and conduct product surveys;
· Develop and improve new and existing Brit-Stitch Limited products and services.
When we use personal information for marketing purposes, we either base the processing on our legitimate interests to understand our customers, keep you up-to-date about Brit-Stitch Limited’s latest products and services, or on your prior explicit consent, e.g. when you sign up to receiving our e-newsletters or to joining our marketing mailing list.
We may use your information to:
· Provide you with newsletters and other communications by post, email and/or telephone, if you have provided your prior consent or if you have purchased or enquired about purchasing from us a similar product or service that the e-newsletter/communication relates to. See the Marketing communications section below for further details;
· Conduct prize draws, competitions and other promotional offers;
· Publish or promote elsewhere any product/service reviews, comments or content you have uploaded to our website or to any social media pages that are publicly visible to link to.
We may use information collected from monitoring our website and emails for security purposes, e.g. to prevent spam or to prevent or stop an attack on our systems and networks. This information may be passed to the police or to other appropriate authorities. We base this processing on our legitimate interests to protect you and our company, systems, employees and partners, or on a legal obligation to cooperate with competent authorities.
3.5 Fraud prevention and investigation
We may also use personal information to comply with applicable laws, regulations and court orders and to comply with valid legal information requests from such bodies. We may use your personal information to enforce or defend the legal rights of Brit-Stitch Limited or the terms and conditions of any Brit-Stitch Limited product or service. In this case, we base the processing on a legal obligation to which Brit-Stitch Limited is subject or on our legitimate interest to defend our legal rights.
Please note that when we process your personal information for legitimate interests, we will ensure that we consider and balance any impact upon you and your rights under the Data Protection Regulations.
If, as determined by us, the lawful basis upon which we process your personal information changes, we will notify you about the change and any new lawful basis to be used, if required. We shall stop processing your personal information if the lawful basis used is no longer relevant.
4. Sharing information about you
4.1 Sharing of information by Brit-Stitch Limited
Brit-Stitch Limited will not disclose your personal information to third parties for their own independent marketing or business purposes without your consent. However, we may disclose your personal information to the following:
4.1.1 Our third-party service providers
We may use third-party service providers (as data processors) to process information on our behalf for the purposes outlined above. For example, for delivering packages, sending postal mail and emails, analysing usage of our website, tracking effectiveness of our marketing campaigns, providing marketing assistance (e.g. market research), administering our website, managing our internal Information and Communications Technology (ICT) systems, processing credit card payments, checking credit ratings.
Our service providers operate only in accordance with our instructions, in line with this policy, and are subject to appropriate confidentiality and security obligations. Examples of third-party service providers we use include:
Administrative Services –
We use our sister company, Peter Jones (ILG) Limited to carry out administrative activities such as sales processing, marketing, customer services, accounts and dispatch.
Email Marketing Services (EMS) providers –
We use web-based MailChimp to assist us in sending emails to you in accordance with your marketing preferences.
We hold the following information about you within our EMS systems:
– organisation name
– email address
– IP address
– subscription time and date
All personal details relating to subscriptions and email marketing campaigns are held securely and in accordance with Data Protection Regulations.
Read more about their privacy policies by clicking the following links:
Analytic Service Providers –
ICT Service Providers –
We use external ICT service providers to monitor and support our ICT servers and ICT security, to provide web hosting and to supply and support our database software.
4.1.2 Legal and business purposes
We may use and/or disclose information about you to third parties such as:
· Government bodies and law enforcement agencies to prevent fraud, to comply with the law and to meet a reasonable request from such bodies;
· Professional advisors and other agencies to enforce or defend the legal rights of Brit-Stitch Limited or the terms and conditions of any Brit-Stitch Limited product or service;
· A third-party purchaser or seller, and its and our professional advisors, in connection with a corporate event such as a merger, business acquisition or insolvency situation.
4.1.3 Anonymous statistics
We may prepare anonymous, aggregate or generic data (including “generic” statistics) for several purposes as outlined above. We believe that you cannot reasonably be identified from this information, therefore we may share it with any third party (such as our partners, industry bodies, the media and/or the public).
4.2 International transfers of your information
Brit-Stitch Limited is a UK-based business providing services across Europe and worldwide.
Your personal information is predominantly stored and processed within the European Economic Area (EEA) in line with related Data Protection Regulations.
In limited cases, we may transfer personal data that we collect from you to third-party data processors based in the US. When we transfer personal information to these third parties, we rely on the EU-US Privacy Shield, which imposes stronger obligations on US companies to protect Europeans’ personal data. The Privacy Shield requires the US to monitor and enforce more robustly and to cooperate more with European Data Protection Authorities.
5. Marketing communications
When you provide us with contact details, such as when you purchase a product or contact our sales and customer services department, you may be given the opportunity to opt-in to (or in certain cases where applicable law allows, opt-out of) receiving various newsletters and other communications by post, email and/or telephone from Brit-Stitch Limited. These communications may include, for instance, details about Brit-Stitch Limited’s latest products and services, including improvements, special offers and industry events such as trade fairs and exhibitions in which you may be interested. We may (based on our legitimate interests) contact you without your prior consent, if the marketing communication relates to similar products and services that you have previously purchased or enquired about purchasing.
Brit-Stitch Limited may also use your information to personalise and to target more effectively its marketing communications as set out in this policy. You have the right to object to this kind of personal information processing at any time you wish to do so by contacting us using the details in the “Contact us” section below.
You can change your marketing communication preferences at any time:
· If you would like to unsubscribe from an email sent to you, follow the ‘unsubscribe’ link and/or instructions usually placed at the bottom of the email. Please note, however, that:
– If you use more than one email address to purchase with or to contact Brit-Stitch Limited, you will need to unsubscribe separately for each email address;
– This method will only unsubscribe from newsletters or other communications that you have received. You should contact us using the details in the “Contact us” section below to opt-out of all our marketing communications or to change your marketing communication preferences.
Please note that we may occasionally send you important information about Brit-Stitch Limited products and services that you are using or have used (such as order confirmations, product safety announcements and service changes). These emails are not affected by your marketing communication preferences.
6. Security of your information
Brit-Stitch Limited has put in place appropriate physical and technical measures to protect your personal information from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including where appropriate:
· Using Secure Sockets Layer (SSL) encryption when collecting or transferring sensitive information, such as credit card details (SSL encryption is designed to make the data unreadable by anyone but us);
· Limiting access to the information we collect about you (for instance, only those of our personnel who need your information to carry out our business activities are allowed access);
· Putting in place physical, electronic, and procedural safeguards in line with industry standards.
We have been assessed as complying with the government-backed Cyber Essential Scheme. At the time of testing, our ICT defences were assessed as satisfactory against a commodity-based cyber-attack.
Please note, that although we take appropriate steps to protect your personal information, no website, online application or transmission of data, computer system or wireless connection is completely secure and therefore we cannot guarantee the security of your personal information.
7. Cookies and web beacons
Our website uses industry-wide technologies, such as “cookies” and “web beacons”, to collect information about its use. For instance, these technologies may tell us which visitors clicked on key elements (such as links or graphics) on a website or recognise your browser the next time you visit our website.
To manage the cookie settings on this website, click the “Cookie Settings” button:
Email marketing messages that we send may contain tracking beacons/tracked clickable links or similar server technologies to track your activity within email marketing messages. Such marketing messages may contain a range of data such as times, dates, IP addresses, opens, clicks, forwards, geographic and demographic data. This information is used to refine future email campaigns and supply you with more relevant content, based around your activity.
8. Your information rights
You have several rights in relation to your personal information that you can choose to exercise at any time. We have provided a basic overview of those rights below:
8.1 Your right of access
You have the right to ask us for copies of your personal information. This right always applies. There are some exemptions, which means you may not always receive all the information we process. You can read more about your right of access here.
8.2 Your right to rectification
You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. This right always applies. You can read more about your right to rectification here.
8.3 Your right to erasure
You have the right to ask us to erase your personal information in certain circumstances. You can read more about your right to erasure here.
8.4 Your right to restriction of processing
You have the right to ask us to restrict the processing of your personal information in certain circumstances. You can read more about your right to restriction of processing here.
8.5 Your right to object to processing
You have the right to object to processing if we can process your personal information because the process forms part of our public tasks or is in our legitimate interests. You can read more about your right to object here.
8.6 Your right to data portability
This only applies to personal information you have given us. You have the right to ask that we transfer the information you gave us from one organisation to another or to give it to you. The right only applies if we are processing information based on your consent or under, or in talks about entering into a contract and the processing is automated. You can read more about your right to data portability here.
You are not required to pay any charge for exercising your rights. We have 30 days to respond to you from receipt of a written request from you regarding the exercise of your rights.
If you would like to exercise any of the above rights regarding the information held on you, please contact us using the Contact Us details shown at the bottom of this policy.
If you feel that your personal information has not been handled correctly or you are unhappy with any response from us, you have the right to lodge a complaint with the Information Commissioner’s Office (the UK regulator responsible for data protection). The contact details can be found at http://www.ico.org.uk or you can call 0303 123 1113.
9. Retention of personal information
We will only retain your personal information for as long as is reasonably necessary for the various purposes set out in this policy or to otherwise comply with any applicable laws and regulations concerning the mandatory retention of certain types of information. When your personal information is no longer required for the purpose it was collected or as required by applicable law, it will be deleted in accordance with applicable law.
10. Third-party links to other sites
Our website, emails and social media pages may contain links to other third-party websites that are not operated by Brit-Stitch Limited.
While Brit-Stitch Limited tries to link only to safe and relevant sites that share Brit-Stitch Limited’s high standards and respect for privacy, we are not responsible for the content, security or privacy practices of any externally linked websites. We strongly recommend that you take the time to review the privacy and cookie policies of any third parties to which you provide personal information, to find out how your information may be used.
You should note that you click on external links at your own risk and we cannot be held liable for any damages or implications caused by visiting any external links or shortened links mentioned. Despite our best efforts to ensure only safe and genuine URLs are published, many social media platforms are prone to spam and hacking.
11. Children’s privacy
Brit-Stitch Limited considers a child to be anyone under the age of 16. We do not knowingly seek or collect personal information from or about children without the consent of a parent or guardian.
If we become aware that personal information that has been submitted to us relates to a child without the consent of a parent or guardian, we will use reasonable efforts to:
· Delete that personal information from our files as soon as possible;
· Ensure, where deletion is not possible, that this personal information is not used further for any purpose, nor disclosed further to any third party.
Any parent or guardian with queries regarding our processing of personal information relating to their child should contact us using the details provided in the “Contact us” section.
We will provide notice to you if these changes are material and, where required by applicable law, we will obtain your consent. We will provide this policy by email or by posting notice of the changes on this website.
13. Contact us
If you need further assistance, you can contact us on:
Data Privacy Manager
Unit 1 Thomas Industrial Estate,
Lower Monk Street
Monmouthshire NP7 5LU
Tel: + 44 (0) 1873 852742
(9am to 5pm, Monday to Thursday (offices closed for lunch between 12.30pm and 1.30pm); 9am to 12.30pm, Friday).
Date last updated: 25th October 2018