Who is the Data Controller?
Bork & Co.
Data Controller contact details
What is personal data?
Personal data means any information which relates to a living individual who can be identified either directly or indirectly by reference to an identifier such as their name, email address and other personal details such financial details etc.
Why do we process your personal data?
We process your personal data for the following purposes:
- Respond to enquiries or requests that you send us.
- To process and fulfill your order.
- To send you marketing information where we have lawful grounds.
- To help us improve the design and layout of the website, and to ensure that content is presented in the most effective manner for you and for your computer;
- In aggregate form, for statistical analysis and developing our marketing plans;
- To provide you with information about products, services or offers that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes (marketing emails). If you no longer wish to receive marketing emails, please send an email to firstname.lastname@example.org
- To respond to any queries you make;
- To notify you about changes to our products and/or services (service emails).
We do not knowingly process personal data of children under 13.
Improved rights under the General Data Protection Regulation
You have some improved rights under the GDPR.
- Data Subject Access Request: You have the right to access the personal information we may hold about you. On receipt of such a request we will endeavour to respond to you as soon as possible, but at least within one calendar month. You must provide us with 2 forms of personal identity to ensure that we only disclose to you, information which is relevant to you personally. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
- Rectification: You have the right to request that we amend any personal information that may be incorrect or require updating.
- Erasure: You have the right to request that we delete any personal information pertaining to you. Any questions about these rights may be sent to email@example.com
- Data Portability. Under GDPR there is a new right to data portability, primarily designed to make it easier for individuals to switch between service providers. This is unlikely to be relevant to your relationship with Bork & Co.
- The right to restrict processing. Individuals have a right to ‘block’ or suppress processing of personal data. If you decide to do this, we will continue to store the data, but not further process it until we have agreed a solution to the issue you have raised.
We do not collect any special categories of personal data, as defined by the GDPR.
Special categories of data under Article 9 of the GDPR are:
“racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation”
Is data collected from third parties or public domain sources?
Where we collect personal data from third party or public domain sources we provide a means to opt-out or unsubscribe on every message we send you.
What are our grounds for lawful processing?
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to perform the contract, we are about to enter into or have entered into with you.
- Where we need to comply with a legal or regulatory obligation.
- Where we have your consent.
Legitimate Interest: means the interest of our business in conducting and managing our organisation., our staff and our suppliers. We make sure we consider and balance any potential impact on the individuals to whom Legitimate Interest applies (both positive and negative) and your rights before we process your personal data for our legitimate interests and those of our business. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us at firstname.lastname@example.org
Bork & Co does not collect data from third parties.
How do we use your personal data?
How to stop receiving communications
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. We have established the following personal data control mechanisms:
You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time at email@example.com
We will not send marketing communications to individuals who have unsubscribed, opted-out or have otherwise asked us to
stop direct marketing.
Disclosure of your data to third parties and overseas transfers of your data
Is data shared with 3rd parties and if so, who?
- We may have to share your personal data with the parties set out below for the purposes set out in the following information below. External Third Parties are all based in the United Kingdom
- Service providers acting as processors who provide IT and system administration services.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
What cookies do we use?
Strictly necessary Cookies
Generally, these cookies will be essential first-party session cookies. Not all first-party session cookies will fall into the strictly necessary category for the purposes of the Cookie legislation. Strictly necessary cookies will generally be used to store a unique identifier to manage and identify the user as unique to other users currently viewing the website, in order to provide a consistent and accurate service to the user.
These cookies are essential in order to enable you to move around the website and use its features, such as signing-up to receive emails from us.
These cookies generally collect information about how visitors use our website, for instance which pages visitors go to most often, and the pages that they don’t. This helps us to understand and improve the site, so it is easy to use and includes helpful content. They allow us to fix bugs or glitches on the website. These cookies don’t collect information that identifies visitors, so we can’t identify you. For example, we use “Google Analytics” cookies (a web analytics service provided by Google, Inc).
Data security – how we protect your data
We follow appropriate security procedures in the collection, storage and use of your Information so as to prevent unauthorised access by third parties.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
However, unfortunately, the transmission of information via the Internet is not completely secure. We cannot ensure the security of your Information transmitted by you to us via the internet. Any such transmission is at your own risk and you acknowledge and agree that we shall not be responsible for any unauthorised use, distribution, damage or destruction of your Information, except to the extent we are required to accept such responsibility by the GDPR, the Privacy and Electronic Communications Regulations or the Data Protection Act. Once we have received your Information we will use security procedures and features to prevent unauthorised access to it.
How we protect your information
We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorized access, alteration, disclosure or destruction of your personal information and data stored on our website.
External links not covered by this policy
Please remember that when you use a link to go from our website to another website or you request a service from a third party, our Policy no longer applies. Your browsing and interaction on any other website or your dealings with any other third-party service provider, is subject to that website’s or third-party service provider’s own rules and policies. We do not monitor, control, or endorse the information collection or privacy practices of any third parties. We encourage you to become familiar with the privacy practices of every website you visit or third-party service provider that you deal with and to contact them if you have any questions about their respective privacy policies and practices. This policy applies solely to information collected by us through our website or services and does not apply to these third-party websites and third-party service providers.
Data Retention Policy
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
We will keep your personal data in connection with the services/products you have bought for 5 years after the last purchase. We need to retain this data for our own accounting purposes and for legal and tax purposes. In terms of personal data we use for marketing, we will keep this data for as long as we are able to market to you and if you withdraw your consent or opt-out of marketing communications, we will keep your contact details only to ensure that we do not contact you again for marketing purposes.
What to do if you have a concern
Please contact us first on firstname.lastname@example.org and we will do our best to help you. If you are not satisfied you may contact the Regulator of GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, updated 2004 and 2011 is the Information Commissioner’s Office. If you feel you wish to draw the Regulator’s attention to the way and the purposes for which we are processing personal data, you may contact the ICO by clicking on the following link https://ico.org.uk/concerns/