Croft Mill

Privacy policy

Privacy and Cookie Policy

Last Updated 17/05/2018

Croft Mill UK Ltd is committed to protecting your privacy and takes its respon­sibi­lities regarding the security of customer information very seriously. This privacy policy explains what personal data we collect about you, how and why we use it, who we disclose it to, and how we protect your privacy.

 

1. WHO IS RESPONSIBLE FOR YOUR DATA

Our Privacy Policy applies to the personal data that Croft Mill UK Ltd collects and uses.

References in this Privacy Policy to “Croft Mill or Croft Mill UK Ltd”, “we”, “us” or “our” mean Croft Mill Limited, a company registered in England and Wales:
Croft Mill UK Limited
Croft Mill (UK) Ltd Office Unit 5/
Primet Business Centre 
Colne 
Lancashire 
England 
BB8 8DQ
With registration no 06817088.

We control the ways your personal data are collected and the purposes for which your personal data are used by Croft Mill UK Ltd and are the “data controller” for the purposes of the UK Data Protection Act 1998, EU General Data Protection Regulation (GDPR), PCI-DSS, and European data protection legislation.

Croft Mill UK Limited is registered on the ICO Data Protection Register; Registration Number ZA367441

2. PURPOSE AND LEGAL GROUNDS FOR PROCESSING YOUR DATA 

  • To sell our products to you and carry out any logistics for delivery or return of goods
    This purpose allows Croft Mill UK Ltd to lawfully process your data for legitimate interests (GDPR 6F) and our legal obligations to your country’s tax and revenue authorities.
  • To inform, inspire and engage with you about our fabrics and services
    This purpose allows Croft Mill to seek your consent to process your data for communication, education and marketing purposes (GDPR 1). Without your explicit consent, Croft Mill will not process your data for this purpose.
    The purpose and lawful basis for processing your data may change from time to time, where this policy will be updated.

 

3. CONSENT

From 25th May 2018 your consent will be an explicit action; we will not use defaulted opt-in checkboxes or include your personal data for marketing purposes.

However, by purchasing from us, you enter a contract with us and we will be able to use your personal data to communicate with you about your order.

We will not contact you if you have withdrawn consent, you can grant or withdraw your consent at any time by contacting us at info@croftmill.co.uk

You can opt out from direct marketing by the following means:

  • Following the instruction in each marketing post, there is an unsubscribe link at the bottom of every email.

  • If you prefer, you can also call our Customer Service team and express your preference to not receive marketing communications (Tel. +44 (0)1282 858281) or send an email to info@croftmill.co.uk with the header “Unsubscribe”. We ask that you allow 28 working days to complete any unsubscribe request.

 

4. PERSONAL DATA WE COLLECT ABOUT YOU

When using the term “personal data” in our Privacy Policy, we mean information that relates to you and allows us to identify you, either directly or in combination with other information that we may hold. Your personal data may include for example your name, your contact details, information relating to your purchase (e.g. your order references) or information on how you use our website.

For more information on the parties who may share your personal data with us, please see section 7 below.

Categories of data we collect 

We may collect and process the following categories of information about you:

CATEGORY OF DATA COLLECTED / HELD

WHEN WE PROCESS SUCH DATA

name and surname and your contact details
(email address, telephone number and postal address)

When you create an account on our website
When you purchase our products 
When you take part in our competitions
When you choose an offer we make available on our website
When we undertake market research when you have consented to be included in phone, email or workshop surveys

Information about your transaction, including your payment card details

When you purchase our products or services

The communications you exchange with us (for example, your emails, letters, calls, or your messages on our online chat service)

When you contact Croft Mill or you are contacted by us

Your social media account ID

When you interact with us on social media

When we target social media posts

Your posts and messages on social media directed to Croft Mill

When you interact with us on social media

Your feedback

When you reply to our requests for feedback or participate in our customer surveys


Sensitive personal data 
Information that could reveal your racial or ethnic origin, physical or mental health, religious beliefs or alleged commission or conviction of criminal offences is considered “sensitive personal data” under the UK Data Protection Act 1998 and other data protection laws. We do not collect this data.

 

5. HOW AND WHY WE USE YOUR PERSONAL DATA

We use your personal data for the following purposes:

  • To manage your orders and provide our services to you. When you purchase from us, or seek advice, we use your information to perform our services in relation to your purchase or enquiry, for example to provide you with product, tailor specific advice to your project’s needs

  • To communicate with you and manage our relationship with you. Occasionally we may need to contact you by email and/or telephone for administrative or operational reasons, for example in order to send you confirmation of your purchases and your payments, to notify you when backordered products are available or to advise you of disruption and changes to your orders and deliveries.

  • Please be aware that these communications are not made for marketing purposes and as such, you will continue to receive them even if you opt-out from receiving marketing communications.

  • Your opinion is very important to us, so we may send you an email or SMS to seek your feedback.

  • We will use the communications you exchange with us and the feedback you may provide in order to manage our relationship with you as our customer and to improve our services and experiences for customers.

  • To personalise and improve your customer experience. We may use your personal data in order to tailor our services to your needs and preferences and to provide you with a personalised customer experience. For example, if you inform us about your preferred products, colours or style we will be able to send you inspirational tips and ideas relevant to your interests.

  • If you are in the process of making a purchase under your account and you leave our website before your order has been placed, we may contact you in order to help you easily complete your purchase.

  • To inform you about our news and offers that you may like. We may send you marketing communications, if you have indicated that you are happy to receive these, for example when you create an account on our website or purchase from us in-store and you explicitly agree to receive such communications. You can also request us to send you marketing communications through managing your preferences in your account.

If you are happy to receive marketing communications, we will provide you with news from us such as new products that you may be interested in (competitions, new products, tutorials offers) or services that you may like.

Please note that we do not share your contact details and other personal data with other companies for marketing purposes.

You can choose to opt out from receiving marketing communications at any time, by clicking on the relevant unsubscribe link at the bottom of any marketing related email you may receive from us.

If you prefer, you can also call our Customer Service team and express your preference to not receive marketing communications (Tel. +44 (0)1282 858281) or send an email to info@croftmill.co.uk with the header “Unsubscribe”. We ask that you allow 28 working days to complete any unsubscribe request.

  • To improve our services, fulfil our administrative purposes and protect our business interests The business purposes for which we will use your information include accounting, billing and audit, credit or other payment card verification, fraud screening, security and legal purposes, statistical and marketing analysis, systems testing, maintenance and development.

  • To comply with our legal obligations, for example, our obligation to provide your information to local police agencies.

 

6. REQUESTING ACCESS TO YOUR PERSONAL DATA

Following a successful security process, you have a right to request access to the personal data that we hold about you. This could include purchase information relating to products and services.

If you have questions in relation to your personal data, please contact us at: info@croftmill.co.uk

 

7. Your Rights

Right to portability: 
Whenever Croft Mill processes your personal data, by automated means based on your consent or based on an agreement; you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.

Right to rectification: 
You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed.

If you have a Croft Mill account you can edit your personal data under your account.

Your right to object to processing based on legitimate interest:  
You have the right to object to processing of your personal data that is based on Croft Mill’s legitimate interest. Croft Mill will not continue to process the personal data unless we can demonstrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.

Your right to object to direct marketing:
You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes.

You can opt out from direct marketing by the following means:

  • following the instruction in each marketing emails

  • If you prefer, you can also call our Customer Service team and express your preference to not receive marketing communications (Tel. +44 (0)1282 858281) or send an email to info@croftmill.co.uk with the header “Unsubscribe”. We ask that you allow 28 working days to complete any unsubscribe request.
     

How can you exercise your rights?
We take data protection very seriously and will process any enquiry in a prompt manner, please contact info@croftmill.co.uk

Right to complain with a supervisory authority: 
If you consider Croft Mill to process your personal data in an incorrect way you can contact us. You also have the right to raise a complaint to a supervisory authority.

Right to erasure - You have the right to erase any personal data processed by Croft Mill at any time except for the following situations:

  • you have an on-going matter with Customer Service

  • you have an open order which has not yet been shipped or partially shipped

  • you have an unsettled debt with Croft Mill, regardless of the payment method

  • if you are suspected or have misused our services within the last four years

  • if you have made any purchase, we will keep your personal data in connection to your transaction for book-keeping purposes.

  • Encrypted system backups, held for up to 10 years. It is practically impossible to alter these backup files

  • Our anti-spam and email gateway. We maintain email archiving for security reasons, and your info may be kept in this archive. Access to this gateway is limited to named data controllers for Croft Mill

If you have questions in relation to your personal data, please contact us at: info@croftmill.co.uk

 

8. RIGHT TO RESTRICT PROCESSING

You have a right for your personal data to be stored but not processed. This is achieved through the withdrawal of consent.

You have the right to request that Croft Mill restricts the process of your personal data under the following circumstances:

  • If you object to a processing based Croft Mill’s legitimate interest, Croft Mill shall restrict all processing of such data pending the verification of the legitimate interest.

  • If you have claim that your personal data is incorrect, Croft Mill must restrict all processing of such data pending the verification of the accuracy of the personal data.

  • If the processing is unlawful you can oppose the erasure of personal data and instead request the restriction of the use of your personal data instead

  • If Croft Mill no longer needs the personal data but it is required by you to defend legal claims.

If you have questions in relation to your personal data, please contact us at: info@croftmill.co.uk

 

9. SECURITY OF YOUR PERSONAL DATA

We are committed to taking appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage to personal data.

As described in this Privacy Policy, we may in some instances disclose your personal data to third parties. Where Croft Mill discloses your personal data to a third party, we require that third party to have appropriate technical and organisational measures in place to protect your personal data; however, in some instances we may be compelled by law to disclose your personal data to a third party, such as local police agencies, and have limited control over how it is protected by that party.

The information that you provide to us will be held in our systems, which are located on our premises or those of an appointed third party. We may also allow access to your information by other third parties who act for us for the purposes described in this Privacy Policy or for other purposes approved by you. Your personal data may be accessed by and processed outside the European Economic Area (the European Economic Area being the European Union and Iceland, Liechtenstein and Norway, also referred to as the “EEA”) - including by staff operating outside the EEA who work for us or for one of our suppliers or agents. Where your personal data are transferred outside of the EEA, we require that appropriate safeguards are in place.

We will retain your personal data for as long as we need it in order to fulfil our purposes set out in this Privacy Policy or in order to comply with the law, but for a period no more than 10 years.

 

10. COOKIES OR OTHER TRACKING TECHNOLOGIES

In order to improve our services, to provide you with more relevant content and to analyse how visitors use our website and app, we may use technologies, such as cookies, pixels or tracking software. Please be aware that in most cases we will not be able to identify you from the information we collect using these technologies.

For example, we use software to monitor customer traffic patterns and website usage to help us develop the design and layout of the website in order to enhance the experience of the visitors to our website. This software does not enable us to collect any personal data. In addition, in order to understand how our customers interact with the emails and the content that we send, we use pixels that allow us to know if the emails we send are opened or if the content of our emails is displayed in text or html form.

We also use cookies in our website, mobile app or in our emails. Cookies are small pieces of information stored by your browser on your computer's hard drive. They enable you to navigate on our website or app and allow us to provide features such as remembering aspects of your last flight search to make subsequent searches faster. You can delete cookies if you wish; while certain cookies are necessary for viewing and navigating on our website or app, most of the features will be still accessible without cookies. For more information on how we use cookies and how you can remove them, read our Cookie Policy.

 

11. SHARING YOUR PERSONAL DATA

It may also be disclosed to a third party who acquires us, a member of our Group or substantially all of our assets.

We may also share some of your personal data with, or obtain your personal data from, the following categories of third parties:

  • Suppliers providing services to us in order to help us run our business and improve our services and your customer experience. We may for example share your personal data with the companies who provide deliveries for us. We may also disclose your information to the companies who help us get your feedback on our services. 

    At Croft Mill, we select very carefully our suppliers who process your personal data on our behalf and require that they comply with high security standards for the protection of your personal data.

  • Credit and debit card companies 
    Croft Mill shares some of your personal data, which includes information about your method of payment and purchase value, to the credit or debit card company that issued the card you used to make your booking. In order to ensure the security of your transactions and prevent or detect fraudulent transactions, we may also share your information with our fraud screening partner.

  • Authorities 
    We may disclose your personal data when this is required by the law of any jurisdiction to which Croft Mill may be subject.

Through our website we provide links to third party websites which are subject to separate Privacy Polices. Please be aware that this Privacy Policy does not apply to such websites and Croft Mill is not responsible for your information that third parties may collect through these websites.

 

12. UPDATES TO OUR PRIVACY POLICY

We may make changes to this Privacy Policy from time to time we will update the Privacy Policy and we will publish on our website any new version of this Policy.

 

13. CONTACT INFORMATION

Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to info@croftmill.co.uk