Privacy Policy

 

This Privacy Notice deals with how we collect, handle and use your data within our business. We aim to comply with the General Data Protection Regulation 2016 (GDPR) and the Data Protection Act 2018 in all respects including in the spirit of the need to treat your personal data with respect and to keep it safe. We will only collect and use your personal data in the ways that are described here, and in a way that is consistent with our obligations and your rights under the law.

  1. Who We Are.

Business name: Careaux Ltd

Registered address: Bank Chambers, Belgrave Square, Darwen, BB3 1BU

Trading address if different:

Registered number and where registered: Registered in England & Wales - 10720818

Contact phone: 07931 100344

2. Definitions.

Data subject or “you” or “your”:

A data subject is an “identifiable natural living person who can be directly or indirectly identified in particular by reference to an identifier”. “Identifier” covers almost any information that we might have that could identify you as an individual. It also means that data subjects include employees/associates/ individual customers or individuals within customer organisations – any individual that our organisation holds personal data on.

Personal Data:

This is any information or data relating to a data subject that can be used to identify them or is information relating to them which makes that data personal to the data subject. So, this will include names, addresses, other contact details, date of birth, driver’s license, financial information e.g. credit cards, CCTV, emails, online identifiers (provided by their devices, applications and tools such as IP addresses, cookie identifiers etc.).

Sensitive Personal Data:

This includes race or ethnic origin, religion, philosophical or political opinions, health information, genetic or biometric data, sexual orientation or sex life and trade union membership. Because of the nature of Sensitive Personal Data there are special rules for lawful processing.

Data Controller:

A data controller determines the purposes and means of how your personal data is processed.

Data Processor:

A data processor is any person other than an employee of the data controller who processes the data on behalf of the data controller.

Data Processing:

Data processing covers just about anything that we do with your personal data including both automated electronic processing and manual processing within a structured filling system including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

3. What Does This Notice Cover?

This Privacy Notice explains how we, as the Data Controller/Data Processor, use your personal data, sensitive personal data (or special category data) and how it is collected, how it is held, how it is processed. Please note that we may at times use a third party to process your data, but they will be also bound under the rules of the GDPR that protect your personal data. This notice also explains your rights under the law relating to your data.

4. Where Do We Collect Data From?

We can collect data in the following ways from customers who purchase from us, suppliers who we deal with and from others who interact with us via:

  1. Face to face contact;

  2. Email/text/hard copy forms/telephone;

  3. Information from 3rd parties. This will require your consent with the 3rd party;

  4. Our website. Data may be collected in 2 ways:

    1. Information that you input into forms or in other ways;

    2. Automated data collection via “cookie technology” in order to understand how our website is being used and to provide you with a personalised service when you visit the website. Cookies may gather information about you including details of your operating system, the type of device you are using, browser version, domain name and IP address. It may also include usage and statistics about your interaction with our website. We may then take that information and use 3rd party analytical software or services to analyse it. Cookies identify your browser and other basic information, but they do not identify you as an individual as they are not linked to any personally identifiable information that you submit. You can control the use of cookies at the individual browser level but if you choose to disable them it may limit your usage of our website and full access to some of its functions. For further information on cookies and their use please refer to our cookies policy.

  5. Social media. We may gather information about you from social media sites. Such information will be that which you have willingly shared on the public domain and as such will be outside of the scope of GDPR. However, we will still treat such information as we would any other personal data covered by GDPR.

5. What Personal Data do we Process?

We may process the following Personal Data regarding you:

a) Personal Data:

i. Customers or potential customers who are consumers:

  • Your name

  • Your contact details including email, phone, address, other contact means that you wish to use such as skype, social media etc

  • Financial information relating to payment for products/services

ii. Customers or potential customers who are businesses:

  • Names and contact details of contacts within the business involved in the negotiation of and the performance of any contracts.

iii. Suppliers:

      • Names and contact details of contacts within the business involved in the negotiation of and the performance of any contracts.

b) Sensitive Personal Data:We will not normally process any Sensitive Personal (or Special Category) Data unless required to do so by you as part of a contract

6. Data Protection Principles:

The GDPR sets out 6 principles governing how we must process your personal data – it must be:

  1. Processed lawfully, fairly and in a transparent way.

  2. Only collected for specific legitimate purposes and processed for those purposes only.

  3. Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

  4. Accurate and kept up to date.

  5. Not kept for longer than necessary for its purpose.

  6. Processed securely and confidentially to ensure it is not lost or damaged or destroyed.

7. What Are Your Rights Concerning Personal Data?

Under the GDPR, you have the following rights, which we will always aim to uphold:

  1. The right to be informed about how we collect and use your personal data – this Privacy Notice should tell you everything that you need to know but if you have any further questions then please contact us using the contact details below;

  2. The right of access to your personal data and the right to verify the lawfulness of the processing;

  3. The right to have your personal data rectified to correct inaccurate information or to have it completed if it is incomplete – please contact us using the contact details below;

  4. The right to erasure of your personal data – sometimes known as “the right to be forgotten”. That is the right to have us delete or otherwise dispose of any of your personal data - please contact us using the contact details below;

  5. The right to restrict the processing of your personal data;

  6. The right to data portability so that they can take and use their personal data for their own purposes across different services;

  7. The right to object to use processing your data on for a particular purpose or purposes;

  8. Rights concerning automated decision making and profiling. Please note that [We do not use your personal data in this way] OR [Section 9 explains more about how we use your personal data, including [automated decision-making] and/or [profiling]]

You can obtain further information about your rights from the Information Commissioner’s Office. If you have any cause for complaint about our use of your personal data, you also have the right to lodge a complaint with the Information Commissioner’s Office.

8. What Are The Lawful Justifications for Processing Personal Data?

The GDPR requires us to have a lawful justification to process data. The following is a summary of the possible lawful justifications:

  1. Consent of the data subject. Consent under the GDPR requires it to be:

    1. Freely given;

    2. Specific;

    3. Informed;

    4. Unambiguous.

  2. Processing the data is necessary for the performance of a contract between us and the data subject. This allows the lawful processing of your personal data:

    1. To fulfil our contractual obligations to you: or

    2. Because you have asked us to do something before entering into a contract e.g. providing a quotation for goods or services.

  3. Processing the data is necessary for compliance with a legal obligation. This requires that the legal obligation must be laid down by either UK or EU law.

  4. Processing the data is necessary for the purposes of our “legitimate interests” or those of a 3rd party including wider benefits to society. This requires us to review our legitimate interests and to ensure that they do not conflict with the fundamental rights and freedoms of the data subject.

  5. Processing the data is necessary to protect the vital interests of the data subject or someone else. This is used where we would need to process your personal data to protect either your or another person’s life or wellbeing.

Processing the data is in the public interest.

9. What Are The Additional Justifications For Processing Sensitive Personal Data?

In addition to the justifications given in section 8 for ordinary personal data the GDPR lays down more stringent requirements regarding the processing of your personal sensitive data. In this regard we will only process your sensitive personal data if:

  1. You have freely given us your explicit consent;

  2. Processing is necessary to comply with any legal obligations that we may have;

  3. Processing is necessary to protect your vital interests or those of another living person where you are physically or legally incapable of giving consent;

  4. Processing relates to sensitive personal data which has been manifestly made public by you e.g. posting it on social media;

  5. Processing is necessary for the purposes of preventative or occupational medicine, medical diagnosis or the provision of health and social care.

10. What Justification Do We Have For Processing Your Personal Data?

Under the GDPR, we must always have a lawful justification for using personal data. Your personal data will be used for the following purposes:

  • Providing and managing your account.

  • Supplying our products AND/OR services to you. Your personal details are required in order for us to enter into a contract with you.

  • Personalising and tailoring our products AND/OR services for you.

  • Communicating with you. This may include responding to emails or calls from you.

  • Supplying you with information by email AND/OR post that you have opted-in to (you may unsubscribe or opt-out at any time.


In order to do this, we justify such processing of ordinary personal data on the basis of:

  1. Your consent for any marketing communications which you can withdraw at any time.

  2. It is necessary for the performance of a contract between us.

  3. Because it is in our legitimate interests to process it.


In the event that we are required to process Special Category Data then we will only do so on the basis of the justifications given above together with your explicit consent.

If you require further information on these justifications, then please contact us using the contact details below.

With your permission and/or where permitted by law, we may also use your personal data for marketing purposes, which may include contacting you by email AND/OR telephone AND/OR text message AND/OR post with information, news, and offers on our products AND/OR services. You will not be sent any unlawful marketing or spam. We will always work to fully protect your rights and comply with our obligations under the GDPR and the Privacy and Electronic Communications Regulations 2003, and you will always have the opportunity to opt-out.

11. How Long Will We Keep Your Personal Data?

We will not keep your personal data for any longer than is necessary for the purposes for which it was initially collected. Please refer to our Data Retention and Destruction Policy for more information.

12. How and Where Do We Store or Transfer Your Personal Data?

We will only store your personal data in the UK or the European Economic Area which means that your data will be fully protected under the GDPR or the equivalent jurisdictional law.

13. Sharing Your Personal Data

We will not share any of your personal data with any third parties for any purposes unless:

a) We are required to do so by law;

b) We may contract with the following third parties to supply products AND/OR services to you on our behalf. These may include payment processing, delivery, and marketing. In some cases, those third parties may require access to some or all of your personal data that we hold.

  1. All our website financial transactions are handled through our payment services provider, Stripe or PayPal. You can review their privacy policies at https://stripe.com/gb/privacy or https://www.paypal.com/uk/webapps/mpp/ua/privacy-prev.   We will share information with Stripe and PayPal only to the extent necessary for the purposes of processing payments you make via our website or via other means, refunding such payments and dealing with complaints and queries relating to such payments and refunds.

  2. Squarespace who are our website platform providers and whose privacy policy can be reviewed at https://www.squarespace.com/privacy. Your data will be processed by Squarespace as part of our sales processing and in order to conclude a contract between us.

  3. Mailchimp – we may use Mailchimp as part of our marketing process and their privacy policy can be reviewed at https://mailchimp.com/about/security/ . Mailchimp will only process your data as long as we have your consent to do so and you can withdraw such consent at any time.

If any of your personal data is required by a third party, as described above, we will take steps to ensure that your personal data is handled safely, securely, and in accordance with your rights, our obligations, and the third party’s obligations under the GDPR.

We may contract with third parties (as described above), and those third parties are located outside of the UK or the European Economic Area. If any personal data is transferred to a third party outside of the EEA, we will take suitable steps (including seeking your explicit consent) in order to ensure that your personal data is treated just as safely and securely as it would be within the UK and under the GDPR.

14. Accessing Your Personal Data?

In accordance with the GDPR you are entitled to know:

  1. If we have any personal data concerning you; and if so

  2. What data we hold.

Accessing such data or finding out if we have any data concerning you is known as a “subject access request” (SAR). SARs should be made in writing and sent via either email or post to the contact details given below. We have a standard Subject Access Request form for you to use which can help in making the request clear. However, you do not have to use this form if you do not wish to.

There is normally no charge for a subject access request. However, the law allows us to make a reasonable charge to cover our administrative costs if your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests).

We will respond to your subject access request within 1 calendar month of receiving it. Normally, we aim to provide a complete response, including a copy of your personal data within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress.

15. Cookies Policy

Cookies are small text files that we store on your computer whilst you are visiting our website. There are 4 basic types of cookie:


  1. Session cookies – allow websites to link your actions during a specific session – these cookies expire when the session is ended.

  2. Persistent cookies – these are stored on your device between sessions and they allow your choices and browsing history across the site or across multiple sites to be recorded. These cookies can be used to target advertising. They will remain on your device unless you either delete them or they time expire

  3. First party cookies – these are cookies set by our website.

  4. Third party cookies – these are cookies set by a domain different from our site whilst you are using our site.

Since 2011 there has been a requirement for us to obtain subscribers’ or users’ consent to the use of certain types of cookie. There are 4 categories of cookie that can be used:


1. “Strictly necessary” cookies – these are normally first party session cookies that are essential for you to be able to use all the features of our website. These cookies enable the services that you have requested and as such consent is not required for these. However, the law narrowly defines “strictly necessary” and restricts them to those cookies that store a unique identifier that manages and identifies you in respect of other current users of the site so that a consistent and accurate service can be provided. These cookies will not be used for marketing purposes or for remembering your preferences and ID outside of the current session. Cookies falling into this category on this site are:

Cookie Name: crumb

Purpose/functionality: Ensures visitor browsing - security by preventing cross-site request forgery. This cookie is essential for the security of the web site and visitor.

Duration of operation: Session

Cookie Name: test

Purpose/functionality: Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for G DPR-compliance of the web site.

Duration of operation: Persistent

2. “Statistics” cookies – these are cookies that may be either first or third party, session or persistent and are used to collect information about how you use the site but they do not collect any personal information that could identify you. The information is made anonymous by aggregating it together so that we can improve the performance of the site. Examples may include web analytics, advertising response rates, affiliate tracking, and error management but they should not be used to retarget adverts – if they do then they will need to be classified under category 4 as well. We need your consent for the use of these cookies during your session. Cookies falling into this category on this site are:

Cookie Name: p.gif

Purpose/functionality: Keeps track of special fonts used on the web site for internal analysis. The cookie does not register any visitor data.

Duration of operation: Session

Cookie Name: ss_cvisit

Purpose/functionality: Contains data on the visit. Collects data such as time spent on the web site and web site interaction.

Duration of operation: 1 day

3. “Marketing” cookies: these are cookies that are normally 3rd party persistent (but time limited) cookies that are used to deliver adverts that are more relevant to you by collecting information about your browsing habits. Where these are being used as part of an advertising network that collects browsing habits in order to target relevant adverts to you we will advise you of such. We need your consent for the use of these cookies during your session. Cookies falling into this category on this site are:


Cookie Name: lidc

Purpose/functionality: Used by the social networking service, LinkedIn , for tracking the use of embedded services.

Duration of operation: 1 day

Cookie Name: ss_cid

Purpose/functionality: Collects data on visitors. This information is used to assign visitors into segments, making web site advertisement more efficient.

Duration of operation: 2 years

Cookie Name: ss_cpvisit

Purpose/functionality: Collects data on visitors. This information is used to assign visitors into segments, making web site advertisement more efficient.

Duration of operation: 2 years

Cookie Name: ss_cvr

Purpose/functionality: Collects data on visitors. This information is used to assign visitors into segments, making web site advertisement more efficient.

Duration of operation: 2 years

Cookie Name: ss_cvt

Purpose/functionality: Collects data on visitors. This information is used to assign visitors into segments, making web site advertisement more efficient.

Duration of operation: 2 years

You are in control of the use of cookies. With regards to cookies then you can normally control these via your browser. Most browsers allow you to reject all cookies, whilst some browsers allow you to reject just third-party cookies. Blocking all cookies will, however, have a negative impact upon the usability of many websites, including this one.

If you are happy to continue with our use of cookies as detailed above on this site, then we require your informed consent as we do not rely on “implied consent” as some other sites do. You will therefore have to “Accept Cookies” in order to have full use and functionality of our site.


16. Contact Information

If you wish to contact us about anything to do with your personal data and data protection, including to make a subject access request, please use the following details:

For the attention of: Laura Beattie

Email address: info@careaux.com

Telephone number: 07931 100344

Postal Address: Bank Chambers, Belgrave Square, Darwen, BB3 1BU


17. Changes to this Privacy Notice

We may change this Privacy Notice from time to time to accommodate changes in the law or if we change the way we do business in a way that affects personal data protection.