GDPR Privacy and Cookies Policy
Privacy Policy
Introduction
Here at Sally Bean Couture (“We”), the protection of your data and your privacy is central to our customer experience. We are committed to protecting and respecting your privacy and appreciate that you do not want the personal information that you entrust us with, to be distributed indiscriminately. For this reason, we want to be clear with you, the client, in relation to what data we collect; how we collect your data; how that data is used; and the ways you can manage the way we collect and use your personal data.
The steps taken to ensure that we are respecting the above are outlined in this policy. We would encourage you to read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
By visiting www.sallybean.co.uk. (the “Website”) or by visiting Sally Bean Couture boutique/ studio for the purchase or sampling of products or for interacting with our content and/or services; or by contacting our Team, you acknowledge that you have read this Privacy Policy and that you are accepting and consenting to the practices described in this policy as well as consenting to our use of cookies in accordance with the terms of this policy.
You must be at least 16 years old to use the Site and Applications. If you are under 16 or a minor in your country or state of residence, please ask your parent or legal guardian to provide their information for you.
We reserve the right to change this privacy policy from time to time by changing it on the Site.
Our Privacy Policy was last updated in December 2019.
Our position
The Sally Bean Couture website is owned by Sally Bean.
For the purposes of the Data Protection Act 1998 and the General Data Protection Regulation 2016, we (Sally Bean) are the data controller. The data controller is responsible for ensuring that your data is held securely, that you are given accurate information about how your data is used, and that your rights regarding your data are respected.
Sally Bean Couture will ensure that all information protection and customer legislation standards are met when handing any of your personal information.
What is gdpr?
The General Data Protection Regulations, (GDPR), apply from 25 May 2018, creating consistent data protection rules across Europe. It applies to companies that are based in the EU and global companies that process personal data about individuals who are based in the EU. At Sally Bean, we shall ensure that we do not just observe the requirements of the GDPR for those users based in the EU, but that we adopt the GDPR principles of transparency, control and accountability for all our users across the globe.
The GDPR gives our Users certain rights when using our Services, which include the right to:
- be informed
- access
- rectification
- erasure
- withdraw consent
- restrict processing
- data portability
Our commitment to you is that we will:
- Process data lawfully, fairly and in a transparent manner
- Collect data for specified, explicit and legitimate purposes (mostly to provide services to you)
- Never sell or pass your data onto anyone else
- Ensure your data is processed and stored securely and is kept up-to-date
You will always:
- Have access to the data stored on you
- Be able to correct any inaccuracies in the data
- Be able to erase your data and restrict its processing where it doesn’t conflict with obligations to regulatory bodies, e.g. HMRC
- Know that as technology changes we will constantly review and update our processes to
- ensure we’re always protecting your data
What is our legal basis for processing your personal data?
Under the law we must have a legitimate reason for using your personal data. We may not collect, store or use data about you where there isn’t a legitimate reason for doing so. We have broken this into 3 sections:
- Necessary for the performance of a contract
- Legitimate Interest
- Information delivered to us with your consent
Processing your personal data
Legitimate Interest
The processing of your personal data by Sally Bean or a third party may be undertaken if we have a legitimate interest to do so. In our case this includes:
- where we have a legitimate interest to use your data, provided that proper care is taken in relation to your rights and interests
- For the purposes of providing our customers with information about our services and other relevant marketing material as well as to monitor usage in order to improve those services from time to time.
- Ensuring that any data is stored and transferred securely and in a way that protects against the unlawful use, destruction or loss of your personal data.
- Sharing your personal information as part of a business sale, re-organisation or similar transaction.
- We use data to ensure that the content of our website is presented to you and your device as effectively as possible
- To ensure that our marketing communications are relevant to your interests If this is our reason for using your data, we must make sure that our interests do not override yours and that you are entitled to object to this use of your data
Where we have a legal basis to use your information without consent (as we’ve described above), this Privacy Policy fulfils our duty to process personal data fairly and lawfully and in a manner that you would expect given the nature of our relationship with you, by giving you appropriate notice and explanation of the way in which your personal data will be used.
By Consent
Where we process your personal data by relying on your consent to do so, we shall ensure that such consent is:
- freely given by you i.e. when you submit a ‘Contact Us’ form on our website.
- specific with regards to what processing we wish to undertake so that you are fully informed;
- unambiguous and given by a clear affirmative action.
We may also obtain personal information where you “like” us, create posts or otherwise interact with our pages on social media platforms and may in response, use this information to communicate with you or provide relevant content via those social media platforms about our products, events and promotions where permitted to do so in accordance with applicable laws. We may also repost and share social media posts that you are tagged in with relation to our business at Sally Bean Couture.
Please refer to the privacy policies of the social media platforms for information about how they collect and use your personal information.
What Information Could We Collect?
This Privacy Policy is applicable exclusively to our site, and not to other websites that may be viewed via links present on this site.
The site www.sallybean.co.uk is managed by Sally Bean, By Appointment Only, Boston Road, London W7. Telephone 0796095565.
We will ensure your data is kept safe.
So that we are both clear, this Privacy Policy will explain why we require your ‘personal data’ and how it will be used
1. We will only use your personal data to enhance your experience.
2. We will protect your personal data.
3. We will always communicate clearly in a way in which is easily understood.
4. We will not spam. You will be able to decide how often you hear from us.
5. We will only keep your information when necessary – if we do not need to use your personal data, we will delete it. We will keep your details on file for a minimum of 10 years or until we no longer need it.
At Sally Bean Couture we view it of high importance to protect the privacy and security of our customers. If you have any questions, please contact us at mail@sallybean.co.uk.
- How your information will be used by us
We will be using your personal data in different ways and the function we perform will depend on the information we require.
We will be using your name and contact details to:
- Send you messages via post, text, whatsapp or email. We must use this data to contact you.
- Send you information and updates. We do this, so we can keep you up to date with details such as our latest promotions or designer events. We will only do this if you give us your explicit permission.
- To manage and protect our site security, particularly to detect and prevent fraud.
- Sally Bean Couture makes beautiful made to measure garments, we take a record of personal measurements, family member names, wedding dates, friends who in the past and future are getting married. Your home address and family member addresses and hold these on file along with personal fitting notes.
- To enable us to provide you with the best journey possible, it is imperative for us to retain this personal information to create your wedding gown and give you the service. We hold this information on file for a minimum of 10 years.
We will be using your contact history with us to:
This will be what you have said to us and the conversations we have had previously, e.g. on the phone or on email.
- To provide you our best customer service when you contact us in the future, as we hope to assist you better with this information.
We will use information about the device you use to view our site:
This will be information you give us when you browse our site, including your IP address and device type and, if you choose to share it with us, your location data, as well as how you use our website.
- This will help us to protect our site.
- This will enable us to improve our site and set default options for you.
We will use information from accounts you link to us:
This will be in instances where you link your Twitter, Facebook or other social media accounts to us.
- This will allow us to provide you with product recommendations we believe you may like.
- This will permit you to log in easily without creating an account with us, making your purchase simpler.
We will use your responses to promotions, competitions and surveys:
- This is for the purpose of completing these tasks, as we will require your details for our promotions, competitions and surveys to function.
*Please note, you are not obliged to provide this personal data to us. However, if you don’t, you may not be able to buy from our site, and we may not be able to provide you with our optimal overall customer experience tailored to you. But, the most important thing is you have a choice whether you want us to have this data or not and can easily inform us if you change your mind at any point after consenting to providing your data.*
We also anonymise and accumulate personal information (so that it does not identify you) and use it for purposes including research, data analysis and improving our site. We also share this information with third parties.
Your personal data will be processed using IT and electronic tools, mainly via electronic and automated means or we will use paper documentation e.g. through our order forms.
- How we will use your data if you’re only browsing our site
When users visit and view the site, we do not generally collect personal data, save as to “browsing data”. The platform which the site is made available to users automatically records some browsing data, such as the name of the internet access provider, the site of origin, pages visited, date and duration of the visit, etc. Such information allows you to access the site and use certain services, though this browsing data may also be aggregated and then used by us anonymously to test that the site is functioning properly.
- Sharing your data
We will not sell any of your personal individual data which we hold to third parties – this includes but is not limited to your name, address, email address or payment information.
However, there are times when it will be necessary to share your data. This is our statement which explains the categories of third parties we will share your data with in order to deliver our services to you:
- Companies that are involved in getting your order to you, i.e. suppliers, courier services, independent seamstress and payment service providers.
- Companies who provide us services which help our business function such as marketing agencies, advertising partners and website hosts.
- Credit reference agencies and fraud prevention agencies if necessary, so we can help tackle fraud.
- Companies approved by you, such as social media sites (if you choose to link your accounts to us).
In any case, we undertake to provide such third parties only with the data necessary to perform the duties and activities assigned to them. We also undertake to do everything in our power to ensure that these companies use the data received exclusively for the purposes indicated by us and in compliance with the applicable regulations on personal data processing.
- Marketing
If, at the time of registering for your account or processing your order with us, you opt-in and consent to our marketing messages, we will send you information via email and text to keep you up to date of new promotions and help you see our products.
If you no longer want to receive marketing messages, you can easily stop them at any time. You may object to any further use of your personal information, such as for direct marketing purposes, by contacting us using the contact details available on our website or writing to us at mail@sallybean.co.uk. You are also free at any time to opt-out of receiving such communications by responding to any promotional email to unsubscribe. You will then be opted-out of this marketing.
Once you do this, we will update your account to ensure that you don’t receive further marketing messages. Please note that, it might take up to 72 hours for our systems to be updated, so you might get messages from us while we process your request. Stopping marketing messages will not stop service communications (such as order updates).
- Your rights
Under the General Data Protection Regulations (GDPR) you are provided statutory rights, we are obliged to inform you these rights include:
- The right to be informed about how your personal information is being used (as per our Privacy Notice).
- The right to access the personal information we hold about you (this is by a free subject access request).
- The right to rectify inaccurate personal information we hold about you.
- The right to request that we delete your data, or stop processing it or collecting it, in some circumstances.
- The right to stop direct marketing messages, which is explained at paragraph 4, and to withdraw consent for other consent-based processing at any time.
- The right to complain to your data protection regulator — in the UK, the Information Commissioner’s Office.
If you wish to exercise any of these rights, have a complaint, or just have questions, please contact us.
- Connection to third-party websites and services
This site may contain banners, advertising messages and advertisements of third parties. By accepting the offers from such third parties, you may access these web pages at your own risk as they are not linked to the provisions in this Privacy Policy.
- Changes to this document
This Privacy Policy may be reviewed and amended in order to comply with new legal provisions or altered procedures for data processing. We will promptly inform you of any update by publishing it in this section of the site and if significant changes are made we will contact you at the email address you have provided to send a copy, so you are able to see any changes to the Privacy Policy before continuing to use our service.
- Security
We employ security measures to protect your personal information from access by unauthorised persons and against unlawful processing, accidental loss, destruction and damage, however, the transmission of information using Wi-Fi networks and cellular data networks may not be completely secure and we cannot guarantee the security of data transmitted to us using our website.
- Keeping your data
We will store your data for as long as you hold an account with us, as long as is needed to provide our service to you, or (in the case of any contact you may have with us) for as long as is necessary to provide support. We will store your personal data securely for the duration of your contract with us and 10 years + after the date of the goods being provided to you.
If reasonably necessary or required to meet legal or regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions, we may also keep hold of some of your information as required.
Please refer back to this page for any future updates to GDPR law and changes to our working practices.
- Cookies policy
Cookies are small files of data that are downloaded onto your electronic device used to access websites. Cookies allow a website to recognise a user’s device and help your browser navigate through the website by allowing you to log in automatically or remembering settings you selected during earlier visits (among other functions). Cookies do not harm your computer. If you would like to learn more about cookies in general, you can visit www.allaboutcookies.org.
Cookies help us to provide you with a good experience when you browse this website. We do not use cookies to collect or record information such as your name, address or payment details.
We use cookies on this website for the following main purposes:
- for technical purposes essential for the operation of this website.
- to distinguish you from other users of this website, so we can personalise your shopping experience; and
- to collect statistical information about how visitors use this website, so we can improve the way this website works and measure the success of competitions and campaigns.
Most web browsers automatically accept cookies. Unless you have adjusted your browser settings so that it will refuse cookies, cookies will be set when you access this website. By using and browsing this website, you consent to cookies being used in accordance with this Cookie Policy. If you do not consent, you must either disable cookies or refrain from using this website.