Our policy is to be committed to safeguarding the privacy of your personal data in compliance with the General Data Protection Regulations (GDPR) EU Directive effective from 25th May 2018 and in respect of our website visitors and customers right to privacy and management of cookies.We describe how we manage personal data of our customers to explain how we use your personal data, how it is collected, how it is held, and how it is processed and how it is stored. It also explains your rights under the law relating to your personal data.We only process your personal data in the way you agree to, keep your data for only as long as necessary and you can unsubscribe or request your details are deleted at any time, and keep your data stored securely.
1. What Personal Data Do We Collect?
We may collect the following personal data with your consent:
- Date of birth
- Email address
- Telephone number
- Special occasion dates
- Business name
- Job title
- Payment information
- Financial information including employment details
- Information about your preferences and interests
Your personal data are also obtained directly from the following third parties who manage your data directly:V12 Finance Group – Credit payment plansIntercom – Website live chat
2. How we use your personal data
Under the GDPR, we must always have a lawful basis for using your personal data. This may be because the data is necessary for our performance of a contract with you, because you have consented to our use of your personal data, or because it is in our legitimate business interests to use it:
2.1 Your personal data is generally used for the following purposes:
Enquiry Data - We process your data contained in any enquiry you submit to us regarding our goods and/or services. This data is processed for the purposes of correspondence to provide information for a specific enquiry about our products and services you have expressed an interest in.
Transaction Data - We may process your data relating to transactions, including purchases of goods and services, that you enter into with us and/or through our website or tills. This data is processed for the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract to purchase goods/service, administration required for payment purchase, delivery arrangements and to keep accurate and complete records of those transactions in accordance with financial regulations.
Correspondence Data - We may process data you provide contained in or relating to any communication that you send to us in your letters, emails, or telephone calls. The correspondence data is processed for the purposes of communicating with you, recordkeeping and updates or essential information for administration purposes.
Notification Data - We may process data that you provide with your recorded consent to notify you about our offers, updates to our services, and events. The reason to process this data is to confirm your consent and preferences to deliver our email communications in accordance with the type of information you wish to receive.
Web Publication Data - We process data that you provide with written consent for publication on our website or social media platforms. This data is processed for enabling such publication and administering our website or social media platforms. The reason for this processing is consent for publication and administration of our website or social media platforms.
Web Correspondence Data - We may process data you provide to for communications on the website, there is metadata associated with the communication and our website will generate the metadata associated with communications made using the website contact forms. The correspondence data is processed for the purposes of communicating with you and record-keeping. The reason for this processing is administration purposes and communications with you about an enquiry you have sent.
Web Usage Data - We process data about your use of the Wongs Jewellers website and services. This data includes your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is our analytics tracking system. This data is processed for the purposes of analysing the use of our website and services. The reason for this processing is for our legitimate interests, namely monitoring and improving our website and services.
Web Account Data - We process information in your online web account on our webpage: https://www.wongsjewellers.co.uk/ This data is processed for online purchases of items you have bought or ordered on our website, maintaining security of our website by maintaining back-ups of our databases and communicating with you during the online purchase and delivery of purchased items from our website.
Web Profile Data – We may process information you provide about your personal profile on our website. It is processed for enabling and monitoring your use of our website products and services and consent for the administration needed to maintain our website and provide marketing communications requested by you.
Web Service Data - We may process your personal data that is provided in the course of the use of contacting us on our online web services. The service data may be processed for the purposes of maintaining back-ups of our online databases.
2.2 We may process any of your personal data identified in this policy where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure. The reason for this processing is the protection and assertion of our legal rights, your legal rights and the legal rights of others.
2.3 We may process any of your personal data identified in this policy where necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice. The reason for this processing is for our proper protection of our business against risks.
2.4 In addition to the specific purposes for which we may process your personal data described in this section, we may also process your personal data where such processing is necessary for compliance with a legal obligation to which we are subject.
2.5 Please do not supply any other person's personal data to us, unless we prompt you to do so.
3. How we provide your personal data to our third-party providers
3.1 We may disclose your personal data with your consent to our third party providers who process your data as reasonably necessary to assist in provision of our goods and services, for enquiries/professional advice/orders/purchases/delivery of our goods and services requested by you.
3.2 If any of your personal data is required by a third party, as described above, we will take steps to ensure that your personal data is handled safely, securely, and in accordance with your rights, our obligations, and the third party’s obligations under the law.
3.3 We may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. We may also disclose your personal data where such disclosure is necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
3.4 We may disclose your personal data to our suppliers as reasonably necessary such as our website payment gateway provider (online Payment Service Provider), payment plan provider and website live chat provider for stock enquiries, ordering and delivery purposes.
3.5 Direct financial payment transactions for purchasing our website products are handled by our payment services provider; Braintree. We will share transaction data with this payment services provider only to the extent necessary for the purposes of processing your payments, refunding such payments and dealing with complaints and queries relating to such payments and refunds. You can find information about the payment services providers' privacy policies and practices at https://www.braintreepayments.com/en-gb/legal/braintree-privacypolicy
3.7 Live chat services for asking online questions about our goods and services are handled by our third party provider; Intercom. If you choose to use this service, you enter your name and if agreed your email, for the extent necessary to submit your online queries to us. You can find information about this providers' privacy policies and practices at https://www.intercom.com/terms-and-policies#privacy
4. How long we keep your personal data
4.1 Any personal data that we process shall not be kept for longer than is necessary for the purpose it is required.4.2 We will keep your personal data for a minimum period of 12 months until necessary or upon a request from you to delete your personal data.4.3 Notwithstanding the other provisions of this section, we may retain your personal data where retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
5. How we store or transfer your personal data
5.1 The security of your personal data is essential to us and to protect your data, we take a important measures to be compliant with GDPR.
5.2 We will only store or transfer your personal data in the UK. This means that it will be fully protected under the GDPR. This is because our goods are only available to deliver within the UK (for exclusions see Delivery and Returns; https://www.wongsjewellers.co.uk/deliveryreturns). As members of the ICO, we adhere to data protection guidelines applicable to the UK.
5.3 You acknowledge that personal data that you submit for publication through our website products and services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.
6. How you can access or manage your personal data
If you wish to have a copy of your personal data, update or delete your personal data:
6.1 You may instruct us to provide you with any personal information we hold about you; provision of such information will be subject to: a) the supply of appropriate evidence of your identity (we accept a photocopy of your passport or photo driving license certified by a lawyer or notary or bank plus an original copy of a utility bill valid from the past three months showing your current address).b) the extent permitted by law.
6.2 If you want to know what personal data we have about you, you can ask us for details of that personal data and for a copy of any personal data we hold about you. This is known as a Subject Access Request (SAR).
6.3 All SARs should be made in writing and sent to the email or postal addresses in Part 10. To make this as easy as possible for you, you can download our Subject Access Request Formon our website. You do not have to use this form, but it is the easiest way to tell us everything we need to know to respond to your request as quickly as possible.
6.4 There are no charges applied to meeting SAR requests within reason.
6.5 You may instruct us at any time not to process or restrict processing your personal information. In practice, you will usually either expressly agree in advance to our use of your personal information, or we will provide you with an opportunity to opt-in of the use of your personal information for the specific purpose it will be processed.
6.6 You may be required to show proof of identify prior to any actions taken to provide or change your personal data.
6.7 When personal data is no longer needed, it is deleted permanently and securely.
6.8 You may request deletion of your personal data.
6.9 Upon receipt of a request for deletion, we will record the types and content of your personal data and where it is stored and permanently delete the data (subject to legal obligations and legal compliance) and disposed of confidentially.
6.10 Further information about your rights can also be obtained from the Information Commissioner’s Office or your local Citizens Advice Bureau.
6.11 If you have any cause for complaint about our use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office.
7. Your rights to manage your personal data
7.1 Your principal rights under the GDPR data protection law are:
(a) the right to access; You have the right to confirmation as to whether or not a business may process your personal data and, where they do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, you can be supplied with a copy of your personal data.
(b) the right to rectification;You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.
(c) the right to erasure;In some circumstances you have the right to the erasure of your personal data without undue delay. This can include when personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the processing is for direct marketing purposes; and the personal data have been unlawfully processed. However, there are exclusions of the right to erasure. The general exclusions include where processing is necessary, for example, exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise or defence of legal claims.
(d) the right to restrict processing;In some circumstances you have the right to restrict the processing of your personal data. Those circumstances are when you contest the accuracy of the personal data; processing is unlawful but you oppose erasure; the personal data is not needed for the purposes of the business processing, but you require personal data for the establishment, exercise or defence of legal claims; and you have objected to processing, pending the verification of that objection. Where processing has been restricted on this basis, your personal data may continue to be stored. However, it will only be processed with your consent; for the establishment, exercise or defence of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public interest.
(e) the right to object to processing;You have the right to object to any processing of your personal data on grounds relating to your particular situation, but only to the extent that the legal basis for the processing is that the processing is necessary for the performance of a task carried out in the public interest or in the exercise of any official authority vested in the business; or the purposes of the legitimate interests pursued by the business or by a third party. If you make such an objection, the business will cease to process the personal information unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.You also have the right to object to processing of your personal data for scientific or historical research purposes or statistical purposes on grounds relating to your particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest.The legal basis for any processing of your personal data is by evidenced consent or that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, and such processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.
(f) the right to data portability;You have the right to object to any processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, your personal data will cease to be processed for this purpose.
(g) the right to complain to a supervisory authority; If you consider that any processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.
(h) the right to withdraw consent.To the extent that the legal basis for any processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.
8. About cookies and how we manage them
8.1. A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.
8.2. Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.
8.3. Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies.
8.5. Wongs Jewellers website uses the following standard cookies:CART - The association with the customer's shopping cart.CATEGORY_INFO - Stores the category info on the page to load pages faster.COMPARE - The items in the customer's Compare Products list.CUSTOMER - An encrypted version of the shopper's customer ID.CUSTOMER_AUTH - Indicates if the customer are currently logged in to the store.CUSTOMER_INFO - An encrypted version of the shopper's customer group.EXTERNAL_NO_CACHE - Indicates if caching is disabled or enabled.FRONTEND - The customer's session ID.GUEST-VIEW - Determines if guests can edit their orders.LAST_CATEGORY - The last category visited by the shopper.LAST_PRODUCT - The most recent product viewed by the shopper.NEWMESSAGE - Indicates whether a new message has been received.NO_CACHE - Indicates if the cache can be used to store information.PERSISTENT_SHOPPING_CART - A link to information about the shopper's cart and viewing history.RECENTLYCOMPARED - Items recently compared b the shopper.STF - Information on products the shopper has emailed to friends.STORE - The store view or language chosen by the shopper.USER_ALLOWED_SAVE_COOKIE - Indicates if the shopper allows cookies to be saved.VIEWED_PRODUCT_IDS - The products recently viewed by the shopper.WISHLIST - An encrypted list of products added to the shopper's wishlist.WISHLIST_CNT - The number of items in the shopper's wishlist.
8.8. We use the following third party providers on our website to deliver website services as follows:
8.9. Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version.
8.10. Blocking all cookies will have a negative impact upon the usability of many websites.
8.11. If you block cookies, you will not be able to use all the features on our website.
9. Policy updates
If we make changes to this Policy:
9.1. We may update this policy from time to time by publishing a new version on our website.
9.2. You should check this page occasionally to ensure you are happy with any changes to this policy.1.12. On our website, we will provide a notification of changes to this policy or if you have consented to receive email marketing, any updates will be included in the marketing emails. An option to receive email marketing will be provided in our Web Contact Forms.
10. How to contact us
10.1. We are registered in England and Wales under registration number 06441797, and our registered office is at UNITS 1, 3 & 4 Chicago Buildings, Whitechapel, Stanley Street, Liverpool L1 6DS.10.2. Our contact details:UNITS 1, 3 & 4 Chicago Buildings, Whitechapel, Stanley Street, Liverpool L1 6DS 0151 236 1552 https://wongsjewellers.co.uk/contact/