Last updated: 30th July 2020
ABOUT THIS POLICY
1.2 This Policy also sets out the rights that you have in relation to the Personal Data that we process about you and how you can exercise them.
1.3 We treat compliance with privacy obligations seriously. This is why we have developed this Policy, which describes the standards that we apply to protect Personal Data.
1.4 For the purposes of this Policy, Box of Heat Limited (“HEAT”, “we”, “our”, “us”) Registered Office at 10 Philpot Lane, London, England, EC3M 8AA, acts as the data controller for the Personal Data that is collected via the Site. As a data controller, HEAT is responsible for ensuring that the processing of Personal Data complies with applicable data protection law, which includes the General Data Protection Regulation.
1.5 Please take the time to read this Policy carefully. If you have any questions or comments, please contact us via email at email@example.com.
WHAT PERSONAL DATA DOES HEAT COLLECT AND WHY?
2.1 The types of Personal Data that we may collect about you, and the reasons why we process it, include:
2.2 Please note that the information you provide on our Site may be necessary for contractual purposes and for us to comply with our legal obligations. Without such information, we may not be able to process your order or to answer your queries.
2.3 We may also collect certain information automatically from your device. Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location) and other technical information. We may also collect information about how your device has interacted with our Website, including the pages accessed and links clicked.
2.4 Collecting this information enables us to better understand the visitors who come to our Website, where they come from, and what content on our Website is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors.
WHO DOES HEAT SHARE YOUR PERSONAL DATA WITH?
3.1 We may disclose your Personal Data to the following categories of recipients:
3.1.1 to our group companies for purposes consistent with this Policy, and in particular, so that they may contact you regarding products and services that may be of interest to you where you have given your consent. We take precautions to allow access to Personal Data only to those staff members who have a legitimate business need for access and with a contractual prohibition of using the Personal Data for any other purpose.
3.1.2 to our third party vendors, services providers and partners who provide data processing services to us, or who otherwise process Personal Data for purposes that are described in this Policy or notified to you when we collect your Personal Data. This may include disclosures to third party vendors and other service providers we use in connection with the services they provide to us, including to support us in areas such as IT platform management or support services, infrastructure and application services, marketing, data analytics.
3.1.3 to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;
3.1.4 to our auditors, advisors, legal representatives and similar agents in connection with the advisory services they provide to us for legitimate business purposes and under contractual prohibition of using the Personal Data for any other purpose;
3.1.5 to a potential buyer (and its agents and advisers) in connection with any proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your Personal Data only for the purposes disclosed in this Notice;
3.1.6 to any other person if you have provided your prior consent to the disclosure.
HOW WE PROTECT YOUR PRIVACY
4.1 We will process Personal Data in accordance with the following principles:
4.1.1 Fairness: We will process Personal Data fairly. This means that we are transparent about how we process Personal Data and that we will process it in accordance with applicable law.
4.1.2 Lawfulness: We will process Personal Data only on lawful grounds.
4.1.3 Purpose limitation: We will process Personal Data for specified explicit and legitimate purposes, and will not process it in a manner that is incompatible with those purposes, unless permitted by applicable data protection laws.
4.1.4 Data minimization: We will process Personal Data that is adequate, relevant and limited to what is necessary to achieve the purposes for which the data are processed.
4.1.5 Data accuracy: We take appropriate measures to ensure that the Personal Data that we hold about you is accurate, complete and, where necessary, kept up to date. However, it is also your responsibility to ensure that your Personal Data is kept as accurate, complete and current as possible by informing us promptly of any changes or errors. You should notify us of any changes to the Personal Data that we hold about you (e.g. a change of address).
4.1.6 Data security: We use appropriate technical and organisational measures to protect the Personal Data that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your Personal Data. In particular, all data is protected according to the varying levels of risks through physical measures, such as secure areas, technical measures, such as encryption, and organisational measures such as employee security through vetting and supervision.
4.1.7 Limited Retention: We keep your Personal Data in a form that allows us to identify you for as long as necessary to achieve the purposes for which we are processing your data and do not store your data for longer, unless we must comply with applicable laws.
DATA STORAGE, RETENTION & DELETION
5.1 We retain Personal Data we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements).
5.2 When we have no ongoing legitimate business need to process your Personal Data, we will either delete or anonymise it or, if this is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible.
INTERNATIONAL TRANSFERS OF DATA
6.1 Your Personal Data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country.
6.2 We have taken appropriate safeguards to require that your Personal Data will remain protected in accordance with this Policy.
7.1 In some instances, we may use your Personal Data in order to better understand your preferences and to provide customized products or services to you. However, we do not make any decisions based solely on automated processing of such data, which either produce legal effects that concern you or similarly significantly affect you.
8.1 The services we provide on this Website are not intended for individuals below the age of 18. If you are under 18, please do not use or register on this Website.
YOUR DATA PROTECTION RIGHTS
9.1 You have the following data protection rights:
9.1.1 If you wish to access, correct, update or request deletion of your Personal Data, you can do so at any time by contacting us using the contact details provided under the “How to contact us” heading below.
9.1.2 In addition, in certain circumstances, as stipulated in the applicable data protection legislation, you can object to the processing of your Personal Data, ask us to restrict processing of your Personal Data or request portability of your Personal Data. Again, you can exercise these rights by contacting us using the contact details below.
9.1.3 If we have collected and process your Personal Data with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your Personal Data conducted in reliance on lawful processing grounds other than consent.
9.1.4 You have the right to opt-out of marketing communications we send you at any time. You may unsubscribe from our newsletters or marketing notifications at any time by selecting the unsubscribe option in the "Email Preferences" section of your account, or by clicking the unsubscribe link at the bottom of every newsletter email. To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us using the contact details provided below.
9.1.5 If you have a complaint or concern about how we are processing your Personal Data then we will endeavour to address such concern(s). If you feel we have not sufficiently addressed your complaint or concern, you have the right to complain to a data protection authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority.
9.2 We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
LINKING TO OTHER WEBSITES
10.1 The Site may contain hyperlinks to websites owned and operated by third parties. These websites have their own privacy policies and we urge you to review them. They will govern the use of Personal Data you submit whilst visiting these websites.
10.2 We do not accept any responsibility or liability for the privacy practices of such third party websites and your use of such websites is at your own risk.
UPDATES TO THIS POLICY
11.1 We may update this Policy from time to time in response to changing legal, technical or business developments. When we update our Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Policy changes if and where this is required by applicable data protection laws.
11.2 You can see when this Policy was last updated by checking the “last updated” date displayed at the top of this Policy.
HOW TO CONTACT US
12.1 If you have any questions or concerns about our use of your Personal Data, please contact us via email at firstname.lastname@example.org.