Who we are
In order to provide our Services and Websites to you and to promote our business, we will need to collect and process certain personal information about you. We are committed to protecting the privacy of our customers in accordance with applicable data protection laws, including the General Data Protection Regulation (together, “Data Protection Laws”).
The person in charge of data protection at The Pure Package is Helen McCracken
conditions under which we provide our Services and Websites to you.
Under applicable Data Protection Laws, we will be the “data controller” of the personal information that we collect about you in connection with your use of our Services or Websites.
When we collect information
We will collect personal information about you in these circumstances:
- When you create an account or fill in forms on our Websites
- When you contact us by phone, email or otherwise interact with us or provide information to us
- When you order any Services from us
- When you subscribe to notifications, emails, newsletters or other communications
- When you redeem a benefit, enter a promotion, competition or survey
- When you submit payment information to us
- When you visit our Websites
What information we collect
We may collect the following types of personal information about you:
- Your name
- Telephone number
- Email address
- Delivery address
- Personal information about your dietary needs, relevant medical conditions, allergies and other requirements, goals and preferences related to our Services
- Some limited demographic information relevant to our Services
- Payment card details (see below Credit and Debit Card Information)
- We may also derive some information about you when you visit our Websites or open emails that we send to you, including general user information about your computer and your visits (including your IP address, location, browser, operating system, referral source, length of visit and the pages you visit). This information can be facilitated by cookies (see our Cookies policy below)
How we use your information
We may use the personal information we collect in a number of ways, including:
- Identifying you and managing your account and relationship with us
- Processing your orders
- Discussing and advising you in relation to your requirements
- Better understanding who our customers are and what they want
- Improving our Services and Websites
- Promoting our similar goods and services to you
- Managing our business, including for accounting and auditing purposes
- Maintaining our Websites and IT systems
- Dealing with any complaints or legal disputes involving you or our suppliers
- Preventing fraud
Lawful basis on which we use your information
We will only ever use your personal information as permitted under Data Protection Law, which means one or more of the following will always apply:
- To perform our contractual obligations
- To comply with our legal and regulatory obligations
- In pursuing our legitimate interests or those of a third party (for example, conducting our business in an efficient and compliant manner) and where your interests and fundamental rights do not override these interests
- Where you have given clear and valid consent to such use.
We do not sell or share your personal information with third parties for their own marketing purposes.
When we share your information with others
We may work with others as part of providing our Services and Websites and may need to share your information with them as follows:
- To our employees, officers, insurers, professional advisors and agents to the extent that it is reasonably necessary to do so for the above permitted purposes;
- To our third-party suppliers and subcontractors to help us provide our Services and Websites to you and for other legitimate business reasons. These third parties include:
- our delivery team
- our hosting service
- our customer relationship management system (CRM) provider
- our printers and PR team
- other third party subcontractors and service providers involved in our business
- To our regulators and law enforcement agencies
- In the context of the possible sale or restructuring of our business
We require all third parties to respect the confidentiality of your personal information. All our service providers are required to take appropriate security measures to protect your personal information. We do not allow them to use your personal data for their own purposes, but only for specified purposes and in accordance with our instructions.
Credit and Debit Card Information:
We need your credit or debit card information (card number, expiry date, billing address & postcode, name on card & CSV number) to process your payments. All such information will only be transmitted using secure servers according to industry protocols. We will not use this information for any purpose other than to process your payments. Your CSV number will not be stored once payment has been successful.
This type of information cannot be linked to an individual customer. We may share aggregated anonymous information with our partners, clients and advertisers. This is not linked to any personal information that can identify any individual person.
We may use a “cookie” or your IP Address to recognise your computer via our website. Cookies are small pieces of information that are stored by your browser on your hard drive. They can inform us of the pages you visit, and your preferences, which enables us to provide you with a better online experience.
You have the ability to accept or decline cookies by modifying the settings in your browser. However, you may not be able to use all the interactive features of our site if cookies are disabled. To find out how to enable/disable cookies see www.allaboutcookies.org
Third Party Sites and Services
Our Websites may contain links to third party websites. Please be notified that we cannot be held responsible for the privacy practices of other websites. We encourage all visitors to be aware and read the privacy statements of each and every website that collects personally identifiable information.
Where your information is stored
Your information will be held at our offices in London and our main hosting data centres for our Websites are located in the United Kingdom.
Transfers to third countries and safeguards
How we keep your personal information safe
We will safeguard your information in our custody. We have developed and will maintain adequate security procedures to safeguard personal information against loss, theft, copying, and unauthorised disclosure, use or modification. Access to personal information is restricted to employees and authorised service providers who need it to perform their work. We also regularly review our information collection, storage and processing practices, including physical security measures, to guard against unauthorised access to systems.
Retention of Records
We will do our best not to keep your personal information for longer than necessary to facilitate your use of the Services and Websites, other than as required by law. We will regularly review the information that we hold and delete unnecessary information from our systems.
Unless you request otherwise, we may retain information that will make providing our Services and Websites to you more convenient and safer, such as your dietary preferences and requirements and important allergy and health information in relation to previous orders, but you have the right to ask us to delete any information that we hold about you – see the Your Rights section below.
When your personal information is no longer required, it will be destroyed either by shredding or other approved destruction methods to prevent unauthorised parties from gaining access to the information during and after the process.
You have several rights as a data subject as summarised below:
- Access: You have the right to obtain confirmation as to whether your personal information is being processed by us and, if it is, to access your information and details of how we process it, as long as this does not adversely affect the rights and freedoms of others.
- Rectification: We will rectify any errors in the personal information we hold on request.
- Erasure: You may ask us to erase your personal information from our systems in the following situations:
- The information is no longer necessary in relation to the purpose for which it was collected;
- You withdraw your consent on which the processing is based and where there is no other legal ground for the processing;
- You object to the processing and there are no overriding legitimate grounds for the processing;
- The information has been unlawfully processed;
- The information has to be erased for compliance with a legal obligation to which we are subject.
- Right to restrict processing: You have the right to restrict our processing on specified grounds.
- Notification: Where you have asked us to rectify, erase or restrict processing of your information, we shall communicate the same to each recipient to whom your information has been disclosed, unless this proves impossible or involves disproportionate effort, in which case we shall let you know.
- Data portability: You have the right in specific circumstances where processing is based on consent to receive your information in a structured, commonly used and machine-readable format and have the right to transmit the information to another controller without hindrance, provided that our processing is carried out by automated means.
- Right to object: In certain circumstances you have the right to object to our processing of your information, including in relation to profiling, direct marketing or scientific or historical research purposes.
- Right to complain to a supervisory authority: You are entitled to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk in relation to our use of your personal data.
You also have the right to object to automated decision-making, including profiling, but we do not use your information for these purposes.
How to exercise your rights
To exercise any of your other data subject rights, please contact us (see Contacting Us):
- You may request a copy of information undergoing processing, subject to evidence of your identity (normally a certified copy of your passport plus an original copy of a utility bill showing your current address). The first copy shall be provided without charge, but reasonable administration fees shall be charged for additional or subsequent copies.
- We shall respond to your requests without undue delay and in any event within one month unless we need to extend such period by up to two further months in specific circumstances.
- Please note that if you delete or restrict your account or required information, this may prevent you from making full use of our Services or Websites.
What happens if a data breach occurs
Whilst we endeavour to keep your personal information safe, we have an internal investigation procedure in case of data protection security breaches.
In the event of data theft, we may suspend access to our servers, emails and online systems and take other urgent steps to prevent further unauthorised access to information.
If we believe that our data has been compromised, we will report the issue to the Information Commissioner’s Office (ICO) at www.ico.org.uk.
We will notify you without delay if we believe a data breach is likely to result in a significant risk to your rights and freedoms. Any notification will describe in clear and plain language the nature of the personal data breach and contain all required information.
Opting out (or Unsubscribing) from communications
To opt out or unsubscribe from communications from Pure Package, please send an email to firstname.lastname@example.org and your request will be dealt with.
Policy last revised: 25 May 2018