- Browse our website (www.rohan.co.uk);
- Use the services available through our website, for example if you place an order, create an account, sign up to receive our marketing communications or enter any of our competitions;
- Shop in a Rohan retail store; or
- Send us feedback or interact with us in connection with any of the above.
You have the right to object to us processing your personal data on the basis of our legitimate interests or for direct marketing purposes (including any related profiling we do to help ensure that our marketing is relevant to your interests). For more information about your right to object and how you can exercise it, see the section 'Your privacy rights'.
1. About us
We are the “data controller” of your personal data, which means that we determine the purposes and the means of use of the personal data we collect about you for the purposes of applicable data protection law (which includes the UK General Data Protection Regulation or “GDPR”).
2. What personal data we collect
Personal data is any information which identifies you personally whether directly (for example, your name) or indirectly (for example, information about your use of our website, products and services).
We collect the following personal data about you:
Basic contact details:
We ask you to provide us with your name, title, postal address, email address and telephone number if you purchase any products on our website. We may also collect some or all of these basic contact details if you create an account on our website, sign up to receive our marketing communications (whether in store or on our website), enter any of our competitions, complete a survey or send us feedback, or contact or correspond with us;
We ask you to provide us with your shipping address and billing address if you purchase any products on our website. We also ask you to provide your payment card details – this information is processed by our third party payments service provider and not retained by us;
We keep a record of your purchase history (including the date, time and value of each purchase and, if you choose to make a purchase for delivery to one of our Rohan retail stores, the store from which you collect your purchase);
Account login details:
If you decide to create an account on our website, we keep a record of your account login details (such as your username) in case you need reminding of these in the future;
Information you provide through correspondence, feedback and competitions:
We collect any additional personal data that you may provide to us from time to time if you contact us by email, letter or telephone, through our website or a social media platform or by any other means. In addition, we collect any additional personal data that you may provide to us if you send us feedback or enter any of our competitions;
Information about how you use our website and services:
Information you provide when using our store finder:
We collect your postcode or use basic location technology to assist you in locating our stores. This data is not retained by us;
Information provided by our third party partner stores:
You can sign up to receive our marketing communications through some of our third party partner stores in the UK. If you do this, those third parties will share with us the contact details they have collected from you, as well as details of the Rohan products you have purchased at their store, so that we can send you information about similar products and services we offer;
Information provided by our third party analytics providers:
We may combine information you have provided to us with additional information shared with us by our third party analytics providers, where we both have a lawful basis to do so. This includes information we receive from Experian Ltd ("Experian"), who we engage from time to time to check whether your information is still valid; and
Information provided by our third party marketing partner:
From time to time Experian also provides us with the names and postal addresses of other individuals who Experian thinks will be interested in Rohan products so that we many send postal marketing to those individuals. This only happens where we and Experian have a lawful basis for this processing of personal data.
We use the data described above for the purposes set out in the 'How we use your personal data' section below.
3. How we use your personal data
We use your personal data for the following purposes:
To process your orders and returns
We use your personal data to process any orders and returns you make in accordance with our terms and conditions.
To manage and administer your account
If you create an account with us, we use your personal data to identify you as a new or returning customer, and to manage and administer your account. This includes keeping a record of your account login details (such as your username) in case you need reminding of these in the future.
To communicate with you about your orders and the services we provide to you
To deliver direct marketing (involving profiling to tailor our communications to your interests)
Our marketing communications
Where you have given your consent or where we have a justifiable reason for doing so (and are permitted to do so by law – see further below), we will use your contact details to send you marketing communications by email and post about Rohan products, services, special offers, promotions, competitions and events that we think may be of interest to you.
You can unsubscribe or opt out of receiving our marketing communications at any time by:
- Getting in touch with us using the contact details set out in the section How you can contact us below;
- Using the “Unsubscribe” link in our emails; or
- Updating your marketing preferences in your account with us (if you have chosen to create one).
If we collect your contact details in the course of you purchasing any products from us, provided you have not opted out, we are permitted by law to send you emails about similar products and services we offer. We may also send you post. We will always give you the option to opt out of receiving this information from us at the time we collect your contact details. Even if you don’t opt out at that stage, you can always choose to opt out at a later stage by following the steps above.
Our use of profiling to send tailored marketing communications and to identify other individuals who might also be interested in Rohan products
We want to ensure that the marketing communications we send to you are relevant to your interests. Consequently, we undertake analysis and profiling of the information you provide to us as well as your purchase history and other information we collect about how you use our website and services. This information helps us build a profile of you, meaning that if you sign up to receive marketing communications from us, you are more likely to receive information about Rohan products, services, special offers, promotions, competitions and events that we think are more relevant to you and your interests. It also means that we don’t send the same marketing communications to all of our customers, so you may not receive the same offers as another customer.
In connection with this, your personal data is shared with Experian for the purposes of managing a service called Club Canvasse, a home shopping and direct retailer data co-operative of which Rohan Designs Limited are members. By sharing information on what customers buy and pooling that with contributions from other members of the co-operative, the service allows Rohan Designs Limited to better understand our customers and to communicate with you more effectively. Please note, your personal information is not shared with any of the other members of the co-operative, and only aggregated data on the number and value of purchases is provided to members e.g. we will receive a report which states how many customers who have bought from us in the last 0-12mths, and who have also bought from other members of the co-operative in the last 0-12mths, or the last 24mths, last 36mths etc. To understand more please click through to Experian’s website to understand more about their marketing services.
We also use profiling to help us identify other individuals with similar characteristics to our existing customers who might also be interested in Rohan products, so that we may send postal marketing to those individuals.
The legal ground for us using profiling to tailor our marketing communications to your interests and to identify other individuals who might also be interested in Rohan products so that we may send postal marketing to those individuals is that it is in our legitimate interests to do so, having taken into account whether your interests and fundamental rights and freedoms are overridden by this type of processing. See Legal grounds for using your personal data for more information about our legitimate interests. If you don’t agree with us using profiling for these purposes, you can let us know (see How you can contact us). If you do object, we won't be able to continue to send you tailored marketing communications, which means you will receive less information from us and the information you receive from us may not be as relevant to you. We also won’t be able to identify other individuals who might also be interested in Rohan products based on the personal data we have collected about you.
Email interaction technology
To manage, administer and improve our website and deliver relevant online advertising
We also use the information we collect about you based on your use of our website and services to:
- Manage and administer our website and for internal operations, including for troubleshooting, data analysis, testing and statistical purposes;
- Improve the products and services we offer you through our website;
- Help ensure that you get the best from our website by making it as easy and intuitive as possible for you to use;
- Help keep our website safe and secure;
- Make suggestions and recommendations to you and other users of our website about products or services that may interest you or them; and
- Measure and understand the effectiveness of our advertising campaigns, and deliver relevant advertising to you.
To provide and improve customer support
We use your personal data to be able to provide and improve the customer support we provide to you (for example, where you have questions about our products and services or to assist you in locating our stores).
To run our competitions
If you choose to enter a competition that we run, we need to use your contact details and any other personal data that you provide at the time of entry so that we can manage the competition and let you know if you've won! If we ask for any other personal data as part of the competition, we will let you know at the time of entry exactly how we will use it.
To respond to communications or enquiries from you, and address complaints and disputes
We use the personal data we hold about you to help us respond to any enquiries or complaints you have made, or address any dispute which may arise in the course of us providing our products and services to you.
Please note that if you contact us through a social media platform, please see the privacy statements of the social media platforms you use for details of how they use your personal data, who they share it with and how you can manage your privacy settings with them.
To conduct market research
We may invite you to be involved in market research. If you accept our invitation, we will use your feedback to improve our website and the products and services available through it. If you tell us that you don't want to be contacted for this purpose, or you don't accept our invitation, we will respect this choice and it won't affect your ability to access and use our website or interact with us in other ways.
To provide other services requested by you from time to time
We process your personal data to provide any other services requested by you from time to time, as described at the time we collect the data.
To maintain our records and improve data accuracy
We process personal data in the course of maintaining and administering our internal records. This includes processing your personal data to ensure that the information we hold about you is kept up to date and accurate. To help us achieve this, from time to time we may allow a third party analytics provider, Experian, to access certain records we hold about you (for example, your contact details) to check whether the information is still valid.
To conduct business analytics and reporting
We may aggregate the data we hold about you on an anonymous basis with other data for analytical and reporting purposes.
To comply with our legal obligations and to detect, prevent and investigate other actual or suspected violations of law or misuse of our website
In certain circumstances, we use your personal data only to the extent required in order to enable us to comply with our legal obligations, including to detect, prevent and investigate fraud or to facilitate the exercise of your consumer rights. In addition, we may need to use your personal data to detect, prevent and investigate any other actual or suspected violations of law or misuse of our website.
4. Legal grounds for using your personal data
Applicable data protection law requires us to only process your personal data if we satisfy one or more legal grounds. These are set out in law and we rely on a number of different grounds for the processing we carry out, depending on the purposes of the processing. These are as follows:
Necessary for the performance of a contract and to comply with our legal obligations
Much of the personal data we collect about you is necessary for the performance of certain contracts between us. This includes most of the information you provide to us when completing transactions with us, creating an account on our website, or entering any competitions that we run from time to time, in order that we can comply with our terms and conditions for the use of our website, for the sale of our products and for the operation of any competitions.
In certain circumstances, we also use your personal data only to the extent required in order to enable us to comply with our legal obligations, including to detect, prevent and investigate fraud or to facilitate the exercise of your consumer rights.
Necessary for the purposes of our legitimate interests
It is sometimes necessary to collect and use your personal data for the purposes of our legitimate interests as a business, which are to:
- Provide our customers with products and services that are as useful and beneficial as possible, including by personalising our contact with customers and telling customers about special offers and promotions that we think might be relevant to our customers and their interests;
- Inform customers who purchase any products from us of similar products and services we offer (provided they have not opted out of this);
- Increase our customer base and sales by sending postal marketing to individuals who have been identified as having similar characteristics to our existing customers;
- Develop and improve our website to enhance the customer experience;
- Safeguard the security and effective operation of our website;
- Better understand our customer base by engaging with customers and conducting research into, and analysis of, how customers interact with us and use our website and the services available through it so that we can improve those services as well as our product selection, marketing activities and communications (all of which could also benefit you); and
- Ensure effective operational management and internal administration of our business, including in relation to document retention, compliance with regulatory guidance and exercise or defence of legal claims.
To help us achieve these outcomes, we profile your personal data, including by combining the data we collect about how you use our website and services with other information we hold about you.
Please note that where we wish to rely on this legal ground, we are required by law to conduct balancing tests to determine whether our legitimate interests are overridden by your interests or your fundamental rights and freedoms. We may continue to process your personal data on the basis of our legitimate interests only if we determine that your interests, rights and freedoms are not overridden by our legitimate interests.
We have considered these matters and where we think there is a risk that your interests or fundamental rights and freedoms may be affected we will not process your personal data unless there is another legal ground for us to do so (either that we have obtained your consent to the processing or it is necessary for us to perform our contract with you or to comply with our legal obligations).
Please contact us if you would like further information regarding our balancing tests (see How you can contact us).
In certain limited circumstances, we also process your personal data after obtaining your consent to do so for the purposes of:
- Sending you marketing communications about Rohan products, services, special offers, promotions, competitions and events (unless we have a justifiable reason for sending you marketing communications without your consent, and are permitted to do so by law, as explained in the section How we use your personal data above);
- Collecting market research data; and
- Assisting you to find your nearest Rohan stores.
You don’t have to provide your consent, and can withdraw it at any time.
5. Who we disclose your personal data to
We may from time to time need to disclose your personal data to third parties in order to provide you with our services and ensure the effective operation of our website and Rohan retail stores. The providers of such services are granted access to certain personal data to the extent necessary for them to perform the services that we request. Any personal data that is processed by third parties must be processed in accordance with applicable data protection law and subject to contractual obligations, including regarding security and confidentiality. The third parties are:
BigCommerce, which hosts our web platform and send order related emails;
Vario Press Limited, which sends out postal marketing on our behalf;
Klaviyo, a marketing service provider, which assists us with our marketing activities, including sending you email marketing on our behalf;
More2 Ltd, which assist us with our marketing and advertising activities, including by helping us analyse and profile our customer database to determine how we can improve the effectiveness of our marketing and advertising campaigns. More2 Ltd also interacts with Experian on our behalf in connection with the postal marketing we send to potential new customers;
Google, to assist you in finding your nearest Rohan stores
Experian, which provides us with analytics and marketing services – see the further detail provided in the section How we use your personal data under the headings "To deliver direct marketing (involving profiling to tailor our communications to your interests)" and "To maintain our records and improve data accuracy";
Review sites, which send out review requests on our behalf and
organisations which help us deliver our products to you, including payment service providers and courier companies.
We may also disclose your personal data:
- If we buy or sell any businesses or assets, to the buyer or seller (or prospective buyer or seller) and/or their advisers; and
- If we are under a duty to disclose or share your personal data in order to comply with (and/or where we believe we are under a duty to comply with) any legal obligation, or in order to protect the rights, property or safety of our business, our customers or others. This includes, in specific cases, sharing information with law enforcement or regulatory agencies, or authorised third parties, in response to a verified request relating to a criminal investigation or actual or suspected violation of law, misuse of our website or breach of contract that may expose us and/or any customer or third party to legal risks or liability.
Additionally, where you have consented to cookies:
- We allow third parties such as Google to set Google Analytics cookies on your device to assist us with the improvement and optimisation of our website. Google Analytics cookies collect information such as items clicked on, web pages viewed and any web pages where users are encountering download error messages from time to time; and
- We allow third parties who help us carry out our advertising activities (Google, Facebook, Bing, AWIN and Impact) to set their cookies on your device in order to show you relevant online advertising. These third parties collect information about you (such as the web pages you’ve viewed, products you’ve put in your shopping basket and the links you’ve clicked through) in order to select and serve relevant adverts to you.
6. International transfers of personal data
The personal data we collect about you is stored by us on secure servers located within the European Economic Area (“EEA”) and processed by us in the UK.
We do this by ensuring that at least one of the following safeguards is implemented:
- EU-US Privacy Shield: We use certain service providers, which are based in the United States or otherwise process your personal data in the United States (Google and Facebook). Pursuant to GDPR Article 45, your personal data is transferred by these service providers to the United States on the basis of their self-certification under the Privacy Shield framework, which requires them to provide similar protection to personal data shared between the European Union and United States. For further details, see European Commission: EU-US Privacy Shield.
- Standard data protection clauses adopted by the EU Commission: Pursuant to GDPR Article 46(2), where required we use specific contracts approved by the European Commission, which give personal data the same protection it has within the EEA. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
Please contact us if you would like more information about the countries to which your personal data is transferred and the specific safeguards that are used to protect your personal data when it is transferred outside the EEA (see How you can contact us).
7. How long we keep your personal data for
We retain your personal data for no longer than is necessary for the purpose(s) for which it was collected. What this means in practice will vary between different types of data. When determining the relevant retention periods, we take into account factors including:
- Legal obligation(s) under applicable law to retain data for a certain period of time;
- Statute of limitations under applicable law;
- The warranty period for any products you have purchased from us;
- Potential or actual disputes; and
- Guidelines issued by relevant data protection authorities.
Otherwise, we securely erase your personal data from our systems when it is no longer needed.
8. Your privacy rights
The table in this section below explains what rights you have with regard to your personal data. These rights are not absolute and are subject to certain exceptions and qualifications.
For more information about your rights or if you would like to exercise any of your rights, you are welcome to contact us using the contact details set out below under How you can contact us.
Please note that if you ask us to stop using your personal data in a certain way or erase your personal data, and this type of use or personal data is required by us in order to facilitate your use of our website or services in any way, you may not be able to use our website or services as you did before. This does not include your right to withdraw your consent to receiving marketing communications from us, which you can do so at any time without restriction.
|Privacy Rights||What does this mean?|
|3. Right to rectification||You have the right to require us to rectify any personal data that we hold about you if it is inaccurate or incomplete. Please contact us if you believe that any personal data we hold about you is inaccurate or incomplete. If you have an account with us, you can also view and update your basic contact details and marketing preferences at any time by logging into your account on our website.|
|4. Right to erasure||This is also known as ‘the right to be forgotten’ and, in simple terms, enables you to request the erasure of the personal data that we hold about you where: * the personal data is no longer necessary for the purpose it was originally collected/processed; * you withdraw your consent (where consent was previously provided and required for us to process the data); * you object to the processing, as long as there are no overriding legitimate grounds for us to continue the processing; * we’ve been processing your personal data unlawfully, or * your personal data has to be erased in order to comply with a legal obligation. This is not a general right to erasure; there are exceptions. For example, we have the right to continue using your personal data if such use is necessary for compliance with our legal obligations or for the establishment, exercise or defence of legal claims.|
|5. Right to restrict processing||You have the right to restrict further processing of your personal data where: * you consider the personal data we hold to be inaccurate, in which case we have to restrict any processing while we verify the accuracy of your personal data; * the processing we are carrying out is unlawful and you request us to restrict processing, rather than erasing your personal data; * we no longer need the personal data, but you need it to establish, exercise or defend a legal claim; or * we are considering our legitimate interests for processing your personal data to which you have objected. When processing is restricted, we can still store your personal data, but may not process it further without your consent (unless processing is required in connection with legal claims, to protect another person’s rights or on important public interest grounds).|
|6. Right to data portability||You have the right to obtain and reuse the personal data that we hold about you in a structured, commonly used and machine-readable format, and (where technically feasible) to have such information transmitted to another "data controller" where: * this is personal data you provided to us (i.e. not any other information); * we are processing such data on the basis of your consent or to perform a contract with you; and * the processing is carried out by automated means.|
|7. Right to object to processing||You have the right to object to processing in the following circumstances: * where the processing of your personal data is based on our legitimate interests. However, If we can show compelling legitimate grounds for processing your personal data which override your interests, rights and freedoms, or we need your personal data to establish, exercise or defend legal claims, we can continue to process it. Processing of your personal data will be restricted while we make this assessment. Otherwise, we must stop using the relevant personal data; or * where your personal data is processed for direct marketing purposes (including profiling related to such direct marketing).|
|8. Right to withdraw consent to processing||If you have given your consent to us to process your personal data for a particular purpose (for example, to send you marketing communications), you have the right to withdraw your consent at any time (although if you do so, it does not mean that any processing of your personal data up to that point is unlawful).|
|9. Right to make a complaint to the data protection authority||You have the right to make a complaint to the Information Commissioner’s Office (ICO) if you are unhappy with how we have handled your personal data or believe our processing of your personal data does not comply with applicable data protection law. The contact details of the ICO are set out below under How you can contact us.|
9. How you can contact us
If you would like to exercise your privacy rights or if you are unhappy with how we have handled your personal data, please contact us by:
- emailing: email@example.com;
- writing to: Rohan Designs Limited, Brunleys, Kiln Farm, Milton Keynes MK11 3HR, UK; or
- calling: 0800 840 1411 or +441908 517901 if calling from outside the UK.
If you’re not satisfied with our response to any enquiry or complaint or believe our use of your personal data does not comply with applicable data protection law, you can make a complaint to the Information Commissioner’s Office (ICO) by:
- writing to: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF;
- calling: 0303 123 1113; or
- submitting a message through the ICO’s website at: www.ico.org.uk.
10. Children’s personal data
We do not knowingly collect personal data from children under the age of 16. If you become aware that your child or any child for which you have parental responsibility has provided their personal data to us without your consent, please contact us using the contact details set out above under 'How you can contact us'.
11. Links to other websites