Privacy and data security is very important to us at Bodnant Garden Nursery Ltd. We want you to feel confident that your data is safe with us, and to understand that any data we do collect will be with your consent, and not passed on to third parties unless explicitly stated otherwise.
The policy has been developed to help you understand:
The type of data we may collect
How and why we collect and use personal data
The legal bases we use for collecting such information
The rights and choices you have when it comes to your own data
When you are using the Bodnant Garden Nursery website, or are shopping with us, Bodnant Garden Nursery Ltd is the data controller.
2. EXPLAINING THE LEGAL BASES WE RELY ON
The law on data protection (General Data Protection Regulation, or ‘GDPR’) sets out a number of different reasons for which a company may collect and process your personal data, including:
In specific situations, we can collect and process your data with your consent. For example, when you tick a box to receive email communications.
When collecting your personal data, we will endeavour to make it clear which data is necessary for a particular service, and for what purpose.
In certain circumstances, we need your personal data to comply with our contractual obligations. For example, if you order an item from us for home delivery, we will collect your address details to deliver your purchase, and pass them on to our courier.
We can also pass on details of people involved in criminal activity affecting Bodnant Garden Nursery Ltd to law enforcement.
In specific situations, we may require your data to pursue our legitimate interests in a way which might reasonably be expected as part of the running of our business and which does not materially impact your rights, freedom or interests.
For example, we may use your purchase history to make available personalised retail offers.
3. WHEN DO WE COLLECT PERSONAL DATA?
When you visit our website, and use your account to buy products or services, or provide us with your address for home delivery.
When you make an online purchase as a guest (in which case we collect transaction-based data only).
When you create an account with us.
When you purchase a product in store or by phone but don’t have an account.
When you contact us by any means with queries or complaints, etc.
When you fill in any forms. For example, if an accident occurs in store, we may collect your personal data.
4. WHAT SORT OF PERSONAL DATA DO WE COLLECT?
If you buy plants online with us, your name, billing/delivery address, orders, email and telephone number may routinely be collected.
Payment card information (processed securely by shopping portal operator).
Details of your shopping preferences.
5. HOW AND WHY DO WE USE YOUR PERSONAL DATA?
To process any orders you make by using our websites or in store. If we don’t collect your personal data during checkout, we won’t be able to process your order and comply with our legal obligations.
To respond to queries, refund requests and complaints. Handling the information you send us enables us to respond. We may also keep a record of these to inform any future communication with us and to demonstrate how we communicated with you throughout. We do this on the basis of our contractual obligations to you, our legal obligations and our legitimate interests in providing you with the best service possible.
To protect our business and your account from fraud and other illegal activities. This includes using your personal data to safeguard, maintain and update your account. We may also monitor your browsing activity with us to quickly identify and resolve any problems and protect the integrity of our website. We’ll do this as part of our legitimate interest.
For example, by checking your password if you log-in and by using automated monitoring of IP addresses to identify possible fraudulent log-ins from unexpected locations.
To process payments and to prevent fraudulent transactions. We do this on the basis of our legitimate business interests. This also helps to protect our customers from fraud.
With your consent, we will use your personal data, preferences and order history to keep you informed by email about relevant offers, discounts, promotions and products.
To send you communications required by law or which are necessary to inform you about changes to the services we provide. For example, updates to this Privacy Notice.
6. HOW WE PROTECT YOUR PERSONAL DATA
We know how much data security matters to our customers. With this in mind we treat your information with the utmost care and take all appropriate steps to protect it.
We secure access to all transactional areas of our websites using ‘https’ technology.
7. HOW LONG WILL WE KEEP YOUR PERSONAL DATA?
Whenever we collect or process your personal data, we keep it only as long as is necessary for the purpose for which it was collected.
At the end of the retention period, your data will either be deleted completely, or anonymised, for example by aggregation with other data to be used in a non-identifiable way for statistical analysis and business planning.
8. WHO DO WE SHARE YOUR PERSONAL DATA WITH?
We sometimes share your personal data with relevant and trusted third parties.
For example, delivery couriers carrying home delivery products to you, or IT companies supporting our website and processing transactions.
We apply the following policy to these organisations in order to keep your data safe:
We provide only the information they need to perform their specific duties.
They may only use your data for the exact purposes we specify in contact with them.
If we stop using their services, any of your data held by them must be deleted or rendered anonymous.
Examples of third parties we work with:
IT companies who support our website and other business systems.
Operational companies such as delivery couriers.
We do not share your data with third parties for their own purposes.
9. YOUR RIGHTS OVER PERSONAL DATA
You have the right to request:
Access to the personal data we hold about you, free of charge in most cases.
The correction of your personal data when incorrect, out of date or incomplete.
When you withdraw consent or object and we have no legitimate overriding interest, or once the purpose for which we hold the data has come to an end.
That we refrain from using your personal data for direct marketing (either through specific channels, or all channels).
That we stop any consent-based processing of your personal data after you withdraw that consent.
You have a right to request a copy of any information we hold about you at any time, and also to have that information corrected if it is inaccurate.
To ask for your information please contact:
Data Protection Officer
Bodnant Garden Nursery Ltd
Tal y Cafn
Or email the following address with the subject ‘information request’: