PRIVACY POLICY
Last updated July 13, 2024
Choosing to shop with us means you’ve placed trust in us to handle your personal data responsibly. This privacy policy helps you to understand how we use your personal data and who we share it with. This applies whenever your share your data with us; for example if you contact us with a query or where you tell us that you would like to receive marketing communications from us.
We change the terms of this privacy policy from time to time and you should check it regularly. The last updated date is shown at the beginning of the document. If we make any material changes we will take steps to bring it to your attention
When we say “we”, “our” or “us” in this policy we are referring to Creedos Ltd.
The company named within the T&Cs on the website is the data controller of your personal data, which means we are responsible for deciding how and why your personal data is used. We are also responsible for making sure it is kept safe, secure and handled legally.
We sometimes work with other organisations in connection with some of the processing activities described in this privacy policy, such as social media platforms. Where that data is collected and sent to other organisations for processing that is for a common purpose, we will be making decisions together in relation to that particular processing and will be ‘joint data controllers’ with the organisations involved. As joint data controllers, we and the other organisations involved in making these decisions will be jointly responsible to you under data protection laws for this processing.
We operate to the highest standards when protecting your personal data and respecting your privacy. If you have any questions about your personal data, or how we use it, you can contact our Data Protection Officer via email at (email) or by writing to our registered office at the following addresses:
UK registered address: Address
YOUR RIGHTS
You have a number of “Data Subject Rights”, we have explained below what they are and how you can exercise them. You can read more about these rights on the UK Information Commissioner’s Office website at ico.org.uk/for-the-public, or on your local Data Protection Authority website.
Right of access –You have the right to request a copy of the personal data that we hold about you.
Right to rectification –If you think any of your personal data that we hold is inaccurate, you have the right to request it is updated. We may ask you for evidence to show it is inaccurate.
Right to erasure– (also known as the right to be forgotten) – You have the right to request that we delete your personal data that we hold..
Right to restriction of processing–You have the right to request we restrict or suppress the personal data we hold about you.
Right to data portability –You have the right to ask us to electronically transfer your personal data to another organisation in certain circumstances.
Rights with regards to automated decision making, including profiling – You have the right not to be subject to a decision that is based solely on automated processing if the decision affects your legal rights or other equally important matters and to object to profiling in certain situations, including for direct marketing.
Right to withdraw Consent – Where we are relying on your consent for processing you can withdraw or change your consent at any time.
The above rights may be limited in some circumstances, for example, if fulfilling your request would reveal personal data about another person, if you ask us to delete data which we are required to have by law, or if we have compelling legitimate interests to keep it. We will let you know if that is the case and will then only use your data for these purposes. You may also be unable to continue using our services if you want us to stop processing your personal data.
If you have any general questions or want to exercise any of your rights, please see the “how you can get in touch” section of this privacy policy. In order to maintain the security of our customers’ personal details, we may need to request proof of identity before we disclose personal data to you in response to any request.
We encourage you to get in touch if you have any concerns with how we collect or use your personal data. You have the right to lodge a complaint directly with a Data Protection Authority. The Data Protection Authority in the UK, where we are based, is the Information Commissioner’s Office (ICO), you can contact the ICO here: ico.org.uk/make-a-complaint. Our main supervisory authority in the EU is the Data Protection Commission (DPC) based in the Republic of Ireland, you can contact the DPC here: forms.dataprotection.ie/contact
THE LAWFUL BASES WE USE TO PROCESS DATA
We will only ever process your data if we have a lawful basis to do so. The lawful bases we rely on are:
- Contract – This is where we process your data to fulfil a contractual arrangement we have made with you or because you have asked us to carry out a service before entering into a contract.
- Consent –This is where we have asked you to provide permission to process your data for a particular purpose.
- Legitimate Interests – This is where we rely on our interests as a basis for processing. Generally this is to provide you with the best products and services in the most secure and appropriate way, but not where our interests are overridden by your interests.
- Legal Obligation –This is where we have a statutory or other legal obligation to process the data, such as to comply with regulatory requirements and/or requests.
- Vital interests –This is where the processing of personal data is necessary to protect someone’s life.
THE DATA WE COLLECT AND HOW WE USE IT
We collect and use the data that you provide to us directly, for example; when you register for an account; we use cookies and other similar technologies to collect data from your devices when you interact with our advertising or use our website (you can find out more information in the “Cookie Policy” section below); we keep records when you speak to our customer service teams; we use CCTV in our stores for security monitoring and market research purposes; we take personal data from a number of third parties to help us manage your account and improve your shopping experience.
To process any orders that you place with us and to facilitate any returns Lawful basis: Contract
- We take payment details to process payment for any credit or debit card orders you place with us. We share these details with our chosen payment processors.
- We use your account data plus your chosen delivery address details to; deliver your purchases and keep you informed of their status, and to process any returns including (where appropriate) collecting the item from you.
- Additionally, where you consent our chosen payment processors may store your payment card details at your request to speed up your checkout in the future.
To provide you with access to an account Lawful basis: Contract
- To register an account with us we capture data such as your name, contact and delivery information, and a password to protect your account (account data). We use the same data on an ongoing basis to manage and provide secure access to your account, and provide you with the services you request.
To provide customer service to you Lawful basis: Legitimate Interest in providing customer support
- We record calls and and keep correspondence (customer service records) when you contact our customer service teams or interact with us on social media. Using these customer service records is necessary to manage your queries or complaints effectively, for quality monitoring, for the defence of any claims and to continually improve our services.
- We may use automated machine learning systems to generate responses when you communicate with our customer contact centres. This helps us to resolve common queries quickly, provide you with a more efficient service and reduce the average response time for our customers.
To personalise and improve your experience when you shop Lawful basis: Consent/Legitimate Interest in providing relevant and personalised experiences when you shop with us
- We keep a record of how you interact with our website or app and any marketing you are exposed to. We use this data, along with purchase history across the NEXT Group, demographics, account data and third party data. We do this so we can create a profile about you, which helps us to tailor your shopping experience, to show you products and offers from across our brands that we think you will be most interested in, and find ways to improve our stores, apps and websites.
- We use your account data, information about the devices you use to access our sites and your interactions with us to operate personalised features across our websites, apps and communication.
To inform you about products and services that may interest you Lawful basis: Consent
- We use technologies such as cookies within digital marketing networks, ad exchanges and social media networks such as Facebook’s Custom Audience to get relevant marketing messages across to you and other customers. We share aggregated and anonymised data about the customer segments we are interested in reaching with advertising partners, so they can focus on showing adverts to those who are most likely to be interested in our products, services and offers, and to prevent them showing you irrelevant or repetitive advertisements.
- We share limited data with selected suppliers to enable them to identify new prospective customers on our behalf and to prevent us repeatedly advertising products or services you have already bought.
Lawful basis: Legitimate Interest in assessing how and where to place advertising
- We receive data on how you interact with our adverts and content on third party websites and social media platforms (such as Google or Facebook) which it is necessary to use to tailor and personalise the products and services that are displayed to you.
To personalise and engage with you on social media Lawful basis: Consent/Legitimate Interest to personalise the marketing and services we provide to you
- We use your personal data to engage with you on social media.
- We place targeted advertising in social media. You may receive advertising based on data about you that we have provided to a social media platform, or allowed it to collect using cookies on our website or code in our applications (or a combination of the two). For some of our marketing campaigns, we may use this data to exclude you from receiving advertising, if we believe it will not be relevant to you.
- You may also receive advertising because, at our request, the platform has identified you as falling within a group whose attributes we have selected or a group that has similar attributes to the individuals whose details it has received from us (or a combination of the two).
- We view statistical data and reports regarding your interactions with the pages and accounts we administer on social media platforms.
- To find out more, please refer to the information provided in the help pages of the platforms on which you receive advertising from us. Please also see the section below for further information regarding our use of social media, including specific platforms and the arrangements we have in place with them.
To keep in touch with you Lawful basis: Consent/Contract
- When you agree to receive marketing we will keep you up to date with news of products and services including store events, offers, promotions and sale data. We may send you marketing via email, SMS or post, depending on your preferences. You can unsubscribe from marketing at any time through the “my account” or using the link in every email that we send to you.
Lawful basis: Legitimate interest in marketing to you and keeping customers updated
- Where we are permitted to market to you without consent, we will update you on the latest similar products and services sold on our websites or in our stores that we think you will be interested in.
- When we send you communications we use records of how you interact with our website and any other marketing we have sent to you, along with purchase history, to personalise the marketing we send you so it is relevant and interesting.
- When we respond to any communications and queries from you if you contact us via any of our customer contact channels, including when we interact with you through the chat function on our websites or apps.
- We use your account data to notify you about important service messages, such as material changes to this policy, product recalls or information about your account.
To ensure the Website and the services we offer you operate properly Lawful basis: Consent
- We use cookies and other similar technologies to keep track of your preferences when using our site.
- We use cookies and similar technologies to help us understand how you use the site, this allows us to optimise your shopping experience and continually improve our site
Lawful basis: Legitimate Interest in planning and delivering efficient operations and to prevent and detect crime or fraudulent activity
- We use data for logistics planning, demand forecasting, management information, dealing with errors on our site, and general research and development as it is necessary to keep the business running efficiently.
- We gather data about the devices you use to access our sites (desktop and mobile) for example your IP address and device type, to ensure the site is secure and works across multiple platforms.
To develop and improve our products, range and services Lawful basis: Legitimate Interest in understanding our customers’ needs and behaviours to provide a better experience
- We share insights about our customers (in an anonymised and aggregated format) with the companies whose products we sell. This is necessary to help them better understand the different profiles of our customers, focusing on those who buy their products or are interested in them.
- We may contact you to take part in customer satisfaction surveys, if you respond we collect your feedback and contributions (customer feedback). We use this data to develop the services we offer.
- We use data about how you browse and engage with our website to improve our websites.
- We use all data, including third party data in the development of new products, services and systems to ensure they work as expected and will be useful to our customers.
To prevent and detect crime and other incidents Lawful basis: Legitimate Interest in keeping our customers and staff safe, reducing theft and fraud
- When you register an account, or contact our customer contact centres we use your account, application and purchase history data as they are necessary to confirm your identity.
- We use device identifiers, IP addresses and account numbers in fraud prevention and investigation, as they are necessary to maintain network and data security.
To fulfil our legal obligations Lawful basis: Legal obligation
- We use your data to ensure we comply with any requirements imposed on us by law or court order, including disclosure to law or tax enforcement agencies and authorities or pursuant to legal proceedings.
- We use your account data, order history and payment history to assist in monitoring for fraudulent transactions or suspected money laundering.
- We will maintain records to meet regulatory and tax requirements.
- We will use your account data to contact you in connection with product recalls or other similar product quality issues and to comply with our legal obligations in connection with the sale of age restricted products.
OUR USE OF SOCIAL MEDIA
We use a number of different social media platforms to communicate with you and to promote products and services. We process your personal data using these platforms in a variety of ways, as follows:
Pages/accounts. We use your personal data when you post content or otherwise interact with us on our official pages and accounts on Facebook, Instagram, Pinterest, Snapchat, TikTok, LinkedIn, X (formally Twitter) and other social media platforms. We also use the Page Insights service for Facebook, Instagram, Pinterest, TikTok, Snapchat and X to view statistical data and reports regarding your interactions with the pages and accounts we administer on those platforms and their content. Where those interactions are recorded and form part of the data we access through these page insights services, we and the relevant platform are joint data controllers of the processing necessary to provide that service to us.Cookies. We use cookies and similar technologies in our website to collect and send data to social media platforms about actions you take on our website and applications. I
COOKIE POLICY
What are cookies?
- Cookies are small text files that are stored on your computer, mobile device or other web enabled device when you visit one of our websites or apps. Cookies allow us to “remember” your actions or preferences over a period of time, or they may contain data related to the function or delivery of our websites. We also use the term “cookie” to describe similar technologies such as pixels or tags.
What do we use cookies for?
Some cookies are required by our site to enable you to transact whilst other cookies enable us to give you an enhanced, personalised web experience. We use cookies for the following purposes:
- To allow you to securely sign in to your account, so that you can use “My Account” features such as order information, making payments and viewing statements.
- To store the content of your online shopping bag whilst you browse the site and to complete an order.
- To record the areas of the website that you have visited, products you have viewed and time spent browsing, as well as the products you purchased. We use this data to help make the websites more user friendly, develop our website design and to continuously improve the quality of the service we provide.
- To distribute visitors to our websites evenly across platforms to ensure the content is served at the fastest possible speed.
- Provide relevant products and services to you when you come to the websites and ensure that relevant marketing material is provided to you.
- Detect and prevent fraud and other crimes.
What cookies do we use?
We use the following cookies on our websites and apps:
- Strictly necessary Cookies. These cookies are necessary for the website to function and cannot be switched off. They are used, for example, to make sure your transaction is secure, to enable you to log in to the secure areas of your account, such as your order history and to add items to your basket. Blocking these cookies through your browser will mean that some parts of our website won’t work.
- Performance Cookies or analytical Cookies. These cookies allow us to monitor visitors to our websites and ensure it is performing correctly. We use this data to measure overall performance, improve your website experience and improve the design of our website.
- Functionality Cookies. These cookies enable enhanced functionality on our website, such as allowing you to add to favourites or remember your language preferences.
- Onsite Targeting: Marketing and Personalisation Cookies. These cookies are placed by us and are used to help us to build an understanding of your interests (for example by understanding what products you have browsed on our website) and show you products, services and advertisements relevant to you whilst you are on the website. These cookies make it possible for us to personalise your experience on the websites and (if you are subscribed) in our email marketing.
- Off Site Targeting: Marketing and Personalisation Cookies. These cookies are placed by our advertising and marketing partners (including social networks). These help us to build an understanding of your interests (for example by understanding what products you have browsed on our website) and show you products, services and advertisements relevant to you. These cookies make it possible for us to ensure that you don’t see irrelevant, duplicate or multiple ads from us in a short period of time. We do want to prevent ads continuously re-appearing and annoying you.
Can I turn off or block cookies?
We use cookies to ensure that we provide the best possible standard of service to our online customers. You can change your cookie preferences at any time by clicking on “Manually Manage Cookies” at the bottom of the page. You can then adjust the available sliders to on or off, then click “Confirm my choices”. If you choose not to consent to the use of cookies your experience of our website may be impaired and many integral aspects of the website, including (but not limited to) adding items to your shopping bag and accessing your account, will not work.
Alternatively, most web browsers allow some control of most cookies through the browser settings. To find out more about how to manage cookies, including how to delete cookies, visit www.allaboutcookies.org
HOW LONG WE KEEP YOUR DATA FOR
We keep your personal data as long as you are a customer of ours and generally for up to 7 years afterwards to comply with legal requirements. During that time we take steps to remove any personal data as soon as we no longer need it.
We consider you a customer:
- for 2 years from the point you last made a purchase from our website using a non-credit account, or
- during any time we are managing a customer service request from you.
THIRD PARTIES WE SHARE WITH AND RECEIVE DATA FROM
We work with a number of trusted third parties to provide you high quality goods and services. Anybody we work with is subject to stringent security and data protection assessments before we begin to do business with them and on an ongoing basis.
We always make efforts to anonymise data and only pass over personal data that is absolutely necessary for the purposes it is being processed. We always do so securely.
We have contracts in place with all suppliers that help us to ensure security and privacy of your personal data, these are reviewed and updated regularly and always in line with data protection laws.
- Delivery Partners – Helping us to deliver the goods you order to you including our brand partners that dispatch and deliver goods to you directly.
- IT Companies – Supporting us in maintaining our website and other business systems including; providing phone lines, data storage facilities, and providing and supporting Cloud based infrastructure used in providing our products and services.
- Marketing Companies and Online Advertising – Helping us to manage our electronic communications to you and to help us show you the advertising you are most likely to be interested in, companies that provide marketing and advertising assistance (including management of email marketing operations, mobile messaging services such as SMS, and services that deploy advertising on the internet or social media platforms, such as Facebook and Google) as well as analysis of the effectiveness of our advertising and communications campaigns.
- We use technologies such as cookies, pixels, and device IDs within digital marketing networks, ad exchanges and social media networks such as Facebook’s Custom Audience to get relevant marketing messages across to you.
- Consumer profiling organisations – These organisations provide demographic or other data to help better understand customers’ demographics, lifestyles or shopping.
- Payment processors – Payment card processors to process credit and debit card payments and store payment data.
KEEPING YOUR PERSONAL DATA SECURE
We always ensure that personal data is secure by continuously developing our security systems and training for our employees. We have implemented appropriate technical and organisational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of processing, in accordance with applicable law.
THIRD PARTY APPS, WEBSITES AND SERVICES
If you use any third party apps, websites or services to access our services, your usage is subject to the relevant third party’s terms and conditions, cookies policy, and privacy policy. For example, if you interact with us on social media, your use is subject to the terms and conditions and privacy policies of the relevant social media platform (Facebook, X etc.). The same applies if you use third party services, like Amazon’s Alexa. In certain cases we may be required to share your personal data, in relation to transactions and usage of the services, with the relevant third party.
HOW YOU CAN GET IN TOUCH
If you would like to exercise any of your rights mentioned within this privacy policy you can submit these through our privacy portal.
Alternatively, should you need to contact our Data Protection Officer please email: admin@creedos.co.uk or you can write to:
UK registered address:
Prince Of Wales House Salmon Fields Business Village, Royton, Oldham, England, OL2 6HT