You may be asked to provide personal data while you are in contact with us. Personal data is information that can be used to identify or contact you. You do not have to provide the personal data that we request, however, if you choose not to, we may not be able to provide you with the services that you have requested.
If we combine personal data with non-personal data, the combined information will be treated as personal data for as long as it remains combined. Personal data does not include data where the identity has been removed (anonymous data).
For the purpose of the General Data Protection Regulations ((EU) 2016/679) and any national implementing laws, regulations and secondary legislation and the Data Protection Act 1998 ("Data Protection Legislation") the data controller is WhiteCirc Ltd a company registered in England and Wales with company registration number 07358303 whose registered office is at; The Vineyards, 36 Gloucester Avenue, Primrose Hill, London NW1 7BB
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:
- Identity Data includes first name, last name and username title. The identity data may be processed for the purpose of setting up your account, processing and delivering your order, managing our relationship with you (including notifying you about changes to our privacy policy and asking you to leave a review), enabling you to enter a competition or complete a survey, administer and protect our business and site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). The legal basis for this processing is the performance of a contract and/or taking steps, at your request, to enter into such a contract and our legitimate interests (namely to recover debts due, keep our records updated, to study how our site is used, for the running of our business, provision of administration and IT services, network security).
- Contact Data includes billing address, delivery address, email address and telephone numbers. The contact data may be processed for the purpose of setting up your account, processing and delivering your order, managing our relationship with you (including notifying you about changes to our privacy policy and asking you to leave a review), enabling you to enter a competition or complete a survey, administer and protect our business and site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). The legal basis for this processing is the performance of a contract and/or taking steps, at your request, to enter into such a contract and our legitimate interests (namely to recover debts due, keep our records updated, to study how our site is used, for the running of our business, provision of administration and IT services, network security).
- Financial Data includes bank account, direct debit and payment card details (type, number, name on card, expiry date and CCV code). The financial data may be processed for the purposes of processing and delivering your order (namely managing payments and charges and collecting monies). The legal basis for this processing is the performance of a contract and our legitimate interests (namely to recover debts due).
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted. All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
- Transaction Data includes details about payments to and from you and other details of magazines, products and services you have purchased from us or our publishers and suppliers. The transaction data may be processed for the purpose of processing and delivering your order. The legal basis for this processing is the performance of a contract and our legitimate interests (namely our interest in the proper administration of our site and business).
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this site. The technical data may be processed for the purpose of administering and protecting our business and site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) and to deliver relevant website content and measure or understand the effectiveness of the advertising we serve to you. The legal basis for this processing is our legitimate interests (namely to grow our business and to inform our marketing strategy).
- Profile Data includes your email and password, purchases or orders made by you, your interests, preferences, feedback and survey responses. The profile data may be processed for the purpose of managing our relationship with you (including notifying you about changes to our privacy policy and asking you to leave a review), enabling you to enter a competition or complete a survey, to make suggestions and recommendations to you about magazines and products that may be of interest to you. The legal basis for this processing is the performance of a contract and our legitimate interests (namely to keep our records updated, to study how our site is used and to grow our business and to inform our marketing strategy).
- Usage Data includes information about how you use our site, magazines, products and services. This usage data may be processed for the purposes of enabling you to enter a competition or complete a survey, to deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you, to use data analytics to improve our website, marketing, customer relationships and experiences and to make suggestions and recommendations to you about goods or services that may be of interest to you. The legal basis for this processing is the performance of a contract and our legitimate interests (namely to study how our site is used and to grow our business and to keep our site updated and relevant).
- Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences. The marketing and communications data may be processed for the purposes of sending you the relevant notifications and/or newsletters. The legal basis for this processing is our legitimate interests and consent.
In addition to the specific purposes for which we may process your personal data set above, we may also process any of your personal data where such processing is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
We may also provide you with information about offers and services that are similar to those that you have already received or we feel may interest you. If you:
- Have already concluded a contract with us, (e.g. if you have purchased a gift card or voucher from us) we will only contact you by electronic means (e-mail or text) with information about offers and services similar to those which were the subject of a previous contract. If you do not want to be on our mailing list, you can opt out at any time by contacting us or unsubscribing by using the links provided in our electronic communications and at the point of providing your details.
- Are a potential new customer (e.g. enquiring about magazines, products or services), we will contact you by electronic means only if you have provided your explicit consent to this. If you are happy for us to use your personal data in this way, please tick the relevant box situated on the website page on which we collect your details. Again, if you do not want us to use your data in this way, you can opt out at any time by contacting us or unsubscribing by using the links provided in our electronic communications.
- If you have placed an item in your online shopping basket, then proceeded through the checkout as far as entering your email address, we may contact you by email with details of the abandoned items. However, we will not send you any further information about offers and services that we feel may be of interest to you unless you have provided your explicit consent.
We use different methods to collect data from and about you including through:
- Direct interactions You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
- order subscriptions, magazines and products;
- create an account on our site;
- subscribe to our newsletters;
- request marketing to be sent to you;
- enter a competition, promotion or survey;
- leave a review or complete a contact form for customer service queries; or
- give us some feedback.
- Automated technologies or interactions As you interact with our site, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies.
- Third parties or publicly available sources We may receive personal data about you from various third parties which include:
- Technical Data from analytics providers such as Google based outside the EU; and
- Contact, Financial and Transaction Data from providers of technical, payment and delivery services.
We may share your personal data with other companies in the Boutiquemags group. This will involve transferring your personal data outside the European Economic Area ("EEA").Some of the third parties which we work closely with are based outside of the EEA so their processing of your personal data will involve a transfer of data outside of the EEA.
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- we will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;
- where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe;
- where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US.
- The above safeguards will always apply to the transfer of your personal data outside the EEA, unless the transfer is to a third party publisher or supplier who is based outside the EEA and the transfer is necessary for the performance of a contract you have entered into with them through our site.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this site may become inaccessible or not function properly. For more information about the cookies we use please please refer to cookie policy