Privacy Policy

Privacy Policy

Introduction

Blue and Grey provides an independent online jewellery and gift boutique, where customers browse and purchase goods directly from our website.

This is our privacy policy. It tells you how we collect, and process data received from you on our site.

If you have any comments on this privacy policy, please email them to suzie@blueandgrey.co.uk

 

Who We Are

Here are the details that the Data Protection Act 1998 says we have to give you as a ‘data controller’:

Our site address is www.blueandgrey.co.uk

Our company name is Blue and Grey

Our registered address is The Old Post Office, Mapledurwell, Hampshire RG25 2NA

Our nominated representative is Suzie Coull

 

What we may collect

We may collect and process the following data about you:

  • Information you put into forms or surveys on our site at any time
  • A record of any correspondence between us
  • Details of transactions you carry out through our site
  • Details of your visits to our site and the resources you use
  • Information about your computer (e.g. your IP address, browser, operating system, etc.) for system administration and to report aggregate information to our advertisers

 

Cookies

We use cookies to distinguish users and improve our site. Please look at our Cookie Policy for more cookie information.

 

How we use what we collect

We use information about you to:

  • Present site content effectively to you
  • Provide information, products and services that you request, or (with your consent) which we think may interest you
  • Carry out our contracts with you
  • Allow you to use our interactive services if you want to
  • Tell you our charges
  • Tell you about other goods and services that might interest you. We will also let other people do this, and we (or they) may contact you.

If you are already our customer, we will only contact you electronically about things similar to what was previously sold to you.

If you are a new customer, you will only be contacted if you agree to it.

If you don’t want to be contacted for marketing purposes, please tick the relevant box that you will find on screen.

Please note: We don’t identify individuals to our advertisers, but we do give them aggregate information to help them reach their target audience, and we may use information we have collected to display advertisements to that audience.

 

Your personal data

So Blue and Grey can deliver an effective service, at times we need to collect and use your personal data. This notice outlines the types of data we use, and how and why we will use it: 

Purpose: To register you as a customer/user

What we need: Your name, delivery address, contact number and email address.

The legal basis for us processing this: Performance of a contract

Where this data will be stored: via a third party (Nexcess server)

How long will we keep this data: For as long as you remain a customer

Where the data is sourced: Directly from you

 

Purpose: To communicate details of products/services to you

What we need: Email address and your communication preferences

The legal basis for us processing this: Your consent to do so

Where this data will be stored: via a third party (Mailchimp service)

How long will we keep this data: For as long as you consent to us processing

Where the data is sourced: Directly from you

 

To deliver our services or products to you

What we need: Name, address, payment details

The legal basis for us processing this: Performance of a contract

Where this data will be stored: via a third party (our payment processing partner, Stripe and PayPal)

How long will we keep this data: Invoices including address will be stored for six years to comply with current UK retention laws.

Where the data is sourced: Directly from you

 

Where we store your data

We may transfer your collected data to storage outside the European Economic Area (EEA). It may be processed outside the EEA to fulfil your order and deal with payment.

By giving us your personal data, you agree to this arrangement. We will do what we reasonably can to keep your data secure.

Payment will be encrypted. If we give you a password, you must keep it confidential. Please don’t share it. Although we try to provide protection, we cannot guarantee complete security for your data, and you take the risk that any sending of that data turns out to be not secure despite our efforts.

 

Disclosure

Disclosing your information

In most instances, we will not disclose your personal data to third parties without your consent. We have the following third-party agreements in place:

If we want to sell our business, or our company, we can disclose it to the potential buyer.

We can disclose it to other businesses in our group.

We can disclose it if we have a legal obligation to do so, or in order to protect other people’s property, safety or rights.

We can exchange information with others to protect against fraud or credit risks.

We may contract with third parties to supply services to you on our behalf. These may include payment processing, search engine facilities, advertising and marketing. In some cases, the third parties may require access to some or all of your data.

 

Your rights

Whilst we are holding or processing your personal data, you have the following rights:

  • Right of access – you have the right to request a copy of the information that we hold about you.
  • Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
  • Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be deleted.
  • Right to restriction of processing – where certain conditions apply you have a right to restrict the processing of your personal data.
  • Right of portability – you have the right to have the data we hold about you transferred to another organisation.
  • Right to object – you have the right to object to certain types of processing such as direct marketing.
  • Right to object to automated processing, including profiling – you also have the right to be subject to the legal effects of automated processing or profiling.
  • Right to judicial review: in the event that (Insert Organisation Name) refuses your request under rights of access, we will provide you with a reason as to why. If you are not satisfied with this you have the right to complain to the relevant supervisory authority (see detail below on Complaints)
  • Where you have consented to processing of your personal data, you have the right to remove this consent at any time

You can exercise these rights at any time by contacting the appropriate individual under ‘Key Contacts’.

You can ask us not to use your data for marketing. You can do this by ticking the relevant boxes on our forms, or by contacting us at any time at suzie@blueandgrey.co.uk

 

Links to other sites

Please note that our terms and conditions and our policies will not apply to other websites that you get to via a link from our site.

 

Key Contacts

Our Data Protection Officer is responsible for helping ensure we treat your personal data appropriately. They can be contacted through the following means:

Data Protection Representative

 

Complaints

If you feel you need to make a complaint about how we are processing your personal data, you can contact the Information Commissioner’s Office as the relevant supervisory authority. You do so through the following means:

 

Changes

If we change our Privacy Policy, we will post the changes on this page. If we decide to, we may also email you.

X