- By email to: firstname.lastname@example.org- By post to: Data Protection Manager, My Uk Company, 24-26 Arcadia Avenue, Dephna House, London, N3 2JU
You have the right to make a complaint at any time to the ICO (www.ico.org.uk). We would, however, like the opportunity to deal with your concerns before you contact the ICO so we encourage you to contact us first and we will look to resolve the matter. Our website may have links to third-party websites, plug-ins and apps. By connecting or clicking on these links please be aware that you may be allowing third parties to share or gather your personal information. We do not have any control over these third-party websites, plug in or apps and we will not be held responsible for their privacy policies – please make sure to read their privacy policies to recognize what personal information they collect about you and the way in which this information is used.
It is imperative that the information we have about you is correct and up to date, please ensure we are aware of any changes to your personal information.
Part 1 of Schedule 1 provides you with the types of personal information we are likely to collect, use, store and transfer. We also collect, use and share aggregated information. However, if we combine aggregated information with your personal information so that it can directly or indirectly identify you, we treat this as your personal information. We do not collect any special classes of personal information.
If we are required by regulation, or under the terms of an agreement we have with you, to collect your personal information and you fail to provide the required information, we may not be able to enter into the agreement with you and therefore we may have to terminate a product or service. We will notify you of this at the appropriate time.
We gather personal information via the following methods:
you may provide personal information when you complete online orders, apply for products/services, subscribe to our services, create a user account, join our newsletter or otherwise or contact us (by letter, telephone or electronic mail).Robotic technology
When you browse or interact with this website, we may automatically collect personal information – this includes technical and usage data. This is done by using cookies, and other related technologies. If you visit other websites that use our cookies, we may also receive technical information about you. Please see our cookie notice here for further details.Publicly available information
we may collect personal information from publicly availably sources [such as Companies House and the Electoral Register and credit reference agencies, based inside the EU./p> third parties
we may receive personal information from: (a)analytics providers based outside the EU (such as Google); (b) advertising networks inside the EU; (c) search information providers inside the EU; and (d) our suppliers such as payment providers, delivery services, website support and maintenance providers.third parties
we may receive personal information from: (a)analytics providers based outside the EU (such as Google); (b) advertising networks inside the EU; (c) search information providers inside the EU; and (d) our suppliers such as payment providers, delivery services, website support and maintenance providers.
We will only use your personal information where there is a lawful basis to do so. Usually, we will use your personal information:
Part 2 of Schedule 1 sets out the legal basis we will rely on to process your personal information. We usually only rely on consent as the legal basis for processing your personal information to send email and SMS marketing messages and you have the right to remove your consent at any time by getting in touch with us. Please be aware that we may process your personal information for more than one lawful basis depending on the precise purpose for which we are using your information.
From time to time, we may examine your personal information to ascertain what products and or services we think may be of interest to you. You will only receive marketing messages from us, if you have requested information from us or purchased services from us, if you provided consent to marketing at the time we collected your personal information and you have not since opted out or removed your consent or if we have another basis to send you the marketing communications. We will ensure to get your express opt in before sharing any of your personal information with other parties for marketing reasons. We do not sell any customer lists, accept advertising or profit from any third party revenue based on the information gathered on this website.
You can remove your consent from receiving marketing emails by clicking the unsubscribe button within the specific marketing message. You can also remove your consent to marketing at any time by contacting our DPM. Even if you remove your consent from receiving marketing messages, we may still use your personal information for other purposes as long as we have a legal grounding to do so.
Your personal information will only be used for the reason it was initially collected for. We will only use your personal information for another reason if that reason is connected to the initial reason. If use of your personal information is required for an unconnected reason, we will inform you and will explain the lawful basis which allows us to use your personal information in this way. Where this is required or allowed by law, we may process your personal information without your knowledge or consent.
We may have to share your personal information with third parties, more details on this can be found in Part 4 of Schedule 1. All third parties are required treat your personal information in accordance with data protection regulations and to respect the security of your personal information. Third party service providers are not authorized to use your personal information for their own aims. Your personal information can only be processed within the specific instructions and for the specified reasons that we prescribe.
When sharing your data with third parties as specified in Part 4 of Schedule 1, we may transfer your data outside the European Union (EU). We work with intermediaries based outside the EU, therefore their processing of your personal data will involve a transfer of data outside the EU. In these circumstances, we ensure your data is protected by ensuring at least one of the following safety mechanisms is in place:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
- We use specific contracts approved by the European Commission which give personal data the same protection it has in Europe with our services providers;
- We may transfer data to US based service providers under the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US.
Please contact our DPM if you require further information on the specific methods used by us in situations where your personal data out of the EU.
Your personal data is held in the highest regard and we do our utmost to ensure it is kept secure. Nonetheless, please note that no security system, however advanced, can provide guaranteed safety all of the time. My Uk Company is dedicated to protecting and securing your personal data, but we are unable to fully promise or license our server security. Also, there may be unfortunate instances where personal data that you provide on this website is seized during Internet communications. We adhere to the qualified industry standards to always protect the personal data. My Uk Company personnel, agents, contractors and other third parties will only be allowed access to your personal information if they require access in order to perform their core business function – we will take steps to limit access to those that do not require access to your personal information. Those accessing your personal information will be subject to a duty of confidentiality. We have procedures in place to deal with any suspected personal information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
MyUkCompany will only store your personal information for as long as necessary to fulfil the purposes we collected your personal information for. This includes for the purposes of fulfilling our legal, accounting, or reporting requirements. Details of retention periods for different aspects of your personal information are available in our retention policy which you can request from us. However, we are legally obligated to keep rudimentary information about our customers (including contact, identity, financial and transaction information) for six years after our business relationship ends, for tax reasons. We may also anonymize your personal information (so that it can no longer be linked to you) for research or statistical purposes. We can use anonymized information indeterminately without further notice to you.
You have certain rights in certain situations under data protection law. These are set out in full in Part 3 of Schedule 1. Please contact our DPM if you wish to exercise any of your legal rights. You will not have to pay a fee to exercise any of your rights. However, if your request is clearly unfounded, repetitive or excessive, we may charge a reasonable fee for this information or refuse to comply with your request. We may request specific information from you to help us confirm your identity when you contact us. This is a security measure to ensure that personal information is not disclosed to any person who does not have the right to receive it. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
billing address, delivery address, email address and telephone numberfinancial information
bank account and payment card detailsidentity information
first name, maiden name, last name, occupation, username or similar identifier, title, date of birth and gendermarketing and communication information
your preferences in receiving marketing from us. Telephone calls may be recorded for security, training and quality purposesprofile information
your username and password, purchase or orders made by you, preferences, feedback and survey responsestechnical information
internet protocol (IP) address, your login information, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our websitetransaction information
details about payments to and from you and other details of products and services you have purchased from us
The lawful basis upon which we may rely on to process your personal information are:consent
you have given your express consent for us to process your personal information for a specific purposecontract
the processing is necessary for us to perform our contractual obligations with you under our contract, or because you have asked us to take specific steps before entering into a contract with youlegal obligation
the processing is necessary for us to comply with legal or regulatory obligationlegitimate interests
the processing is necessary for our or a third party’s legitimate interest e.g. in order for us to provide the best service to you via our website. Before we process your personal information on this basis we make sure we consider and balance any potential impact on you, and we will not use your personal information on this basis where such impact outweighs our interest. Set out below are specific details of the processing activities we undertake with your personal information and the lawful basis for doing this. Purpose/Activity
Purpose/Activityto register you as a new customer
identity & contact - (a) to perform our contract with youto process and deliver your order, manage payments, fees and charges and debt recovery
identity, contact, financial, transaction and marketing & communications - (a) to perform our contract with you (b) as necessary for our legitimate interest in recovering debts due to usto manage our relationship with you, notifying you about changes to our Terms or Privacy Notice and ask you to leave a review
identity, contact, profile & marketing & communications - (a) to perform our contract with you (b) as necessary to comply with a legal obligation (c) as necessary for our legitimate interests in keeping our records updated and analysing how customers use our products/servicesto administer and protect our business and this website (including troubleshooting, information analysis, testing, system maintenance, support, reporting and hosting of information)
identity, contact & technical - (a) as necessary for our legitimate interests in running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise (b) as necessary to comply with any legal obligationsto administer and protect our business and this website (including troubleshooting, information analysis, testing, system maintenance, support, reporting and hosting of information)
identity, contact & technical - (a) as necessary for our legitimate interests in running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise (b) as necessary to comply with any legal obligationsto deliver relevant website content/advertisements to you and measure or understand the effectiveness of our advertising
identity, contact, profile, usage, marketing & communications & technical - (a) as necessary for our legitimate interests in studying how customers use our products/services, to develop them, to grow our business and to inform our marketing strategyto use information analytics to improve our website, products/services, marketing, customer relationships and experiences
technical & usage - (a) as necessary for our legitimate interests to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategyto make suggestions and recommendations to you about goods or services that may be of interest to you, including promotional offers
identity, contact, technical, usage & profile - (a) as necessary for our legitimate interests to develop our products/services and grow our business
You have the following legal rights in relation to your personal information:access your information
you can ask for access to and a copy of your personal information and can check we are lawfully processing itcorrection
you can ask us to correct any incomplete or inaccurate personal information we hold about youerasure
you can ask us to delete or remove your personal information where: (a) there is no good reason for us continuing to process it; (b) you have successfully exercised your right to object (see below); (c) we may have processed your information unlawfully; or (d) we are required to erase your personal information to comply with local law (e) we may not always be able to comply with your request for specific legal reasons, which will be notified to you at the time of your requestobject
you can object to the processing of your personal information where: (a) where we are relying on our legitimate interest (or those of a third party) as the basis for processing your personal information, if you feel it impacts on your fundamental rights and freedoms; (b) where we are processing your personal information for direct marketing purposes In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms and, in such circumstances, we can continue to process your personal information for such purposesrestrict processing
you can ask us to us to suspend or restrict the processing of your personal information, if: (a) you want us to establish the accuracy of your personal information; (b) our use of your personal information is unlawful, but you do not want us to erase it; (c) you need us to hold your personal information (where we no longer require it) as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your personal information, but we need to verify whether we have overriding legitimate grounds to use itrequest a transfer
you can request a transfer of your personal information which is held in an automated manner and which you provided your consent for us to process such personal information or which we need to process to perform our contact with you, to you or a third party. We will provide your personal information in a structured, commonly used, machine-readable formatwithdraw your consent
you can withdraw your consent at any time (where we are relying on consent to process your personal information). This does not affect the lawfulness of any processing carried out before you withdraw your consentwithdraw your consent
you can withdraw your consent at any time (where we are relying on consent to process your personal information). This does not affect the lawfulness of any processing carried out before you withdraw your consent
acting as processors or controllers based in the EEA but also around the world who provide credit and identity checks, advertising and marketing, SEO facilities, bank and merchant account services, payment processing and the delivery of goods and/or documents purchased from usprofessional advisors
joint controllers including lawyers, accountants, auditors and insurers based in the United Kingdom who provide consultancy, banking, legal, insurance and accounting servicesHM Revenue & Customs, regulators and other authorities
acting as joint controllers based in the EEA who require reporting of processing activities in certain circumstancesthird parties
we invite our customers to provide a review of their buying experience using our website. Our customers are given the opportunity to review their experiences of buying products or services on our website. In these instances, your name, email address and order number will be shared provisionally with Trustpilot. Trustpilot will send you a request to write your view and your information will not be stored or shared
information such as statistical or demographic information which may be derived from personal information, but which cannot by itself identify a information subjectcontroller
a body that determines the purposes and means of processing personal informationinformation subject
an individual living person identified by personal information (which will generally be you)personal information
information identifying a information subject from that information alone or with other information we may hold but it does not include anonymized or aggregated informationspecial categories of personal information
information about race, ethnicity political opinions, religious or philosophical beliefs, trade union membership, health, genetic, biometric information, sex life, sexual orientationICO
Information Commissioner’s Office, the UK’s supervisory authority for information protection issues