Privacy Notice

This privacy notice concerns personal data, as processed by Staddon Farm Nurseries both in the office and on the website at https://www.pennysprimulas.co.uk.

Date of Alteration

This privacy notice was last updated on the 06th of June 2018.

Data Controller

For the purposes of this document, Staddon Farm Nurseries is the primary Data Controller. A Data Controller is a person or organisation who determine the purposes and means of processing personal data.

How and Why Your Data is Collected and Used

In order to conduct our business and respond to enquiries we must process the given personal data of all correspondents.

We maintain an e-mail and name based mailing list for an occasional newsletter service solely for those who have expressly signed up.

In order to monitor overall traffic to the website we employ the use of web analytics services which record the IP address of website visitors.

In order that comments may be displayed on the website all given personal data generated by the commenter and the associated IP address of the commenter is stored in an online database.

We provide a user registration facility on the website so that customers can log in to place orders and access account specific content. All given personal data generated by the registration is stored in an online database.

We allow users to place orders on the website, all given personal data and the associated IP address of the customer in reference to each order is stored in an online database. No payment data such as credit card information is stored in this database.

In order to protect the website from malicious web traffic and attacks we employ the use of the Wordfence and Sucuri plugins which record the IP address of website visitors.

We store delivery addresses in an order book and on financial invoice records for the purpose of providing the appropriate ordering service to our customers.

Lawful Basis

We process your personal data under the following lawful basis:

Consent, for personal data generated by mailing list subscriptions.

Contract, for personal data generated by website orders.

Legitimate Interests, for personal data generated by website analytics services, website security plugins, website comments, website registration.

We process personal data generated by correspondence under the lawful basis of legitimate interests and/or contract. Should explicit consent be required and not supplied, we will contact you to confirm.

Data Sharing

Our mailing list is managed by Mailchimp and they, as a Data Processor, store the mailing list data.

Our primary web analytics service is managed by Google and they, as a Data Processor, store the primary website traffic data.

Our website is hosted by Siteground, who also provide a web analytics service, and they, as a Data Processor, store the website’s files, database and website traffic data.

Our website is provided by Linedot Web Design and they, as a third party Data Controller, share access to all data processed on the website as well as the website traffic data.

Data Retention

Unless stated otherwise below, all personal data will be held for as long as Staddon Farm Nurseries remains in business.

Any personal data generated by our primary web analytics service is deleted once it is 26 months old.

Cookie Policy

We use cookies for the following reasons:-

Google Analytics:- to monitor traffic on the website
WordPress:- to allow user, commenter, and shopping cart data to be remembered without re-entering information

You can prevent the setting of cookies by adjusting the settings on your browser.

Children

Our business is not targeted at children and we do not process the personal data of children.

Your Data Rights

In line with GDPR you have the following rights:-

Right to be Informed

You have the right to obtain confirmation as to whether or not your personal data is being processed, where and for what purpose.

Right of Access

You have the right to obtain a copy of the personal data, free of charge, in an electronic format.

Right to Rectify

You have the right to rectify your personal data on our systems should it be either inaccurate or incomplete.

Right to Erasure

Your have the right, in certain circumstances, to ask that your personal data is erased on our systems.

Right to Restrict Processing

You have the right to restrict processing of your personal data in certain circumstances.

Right of Portability

You have the right to request a copy of your personal data or request that we submit it to another Data Controller in a structured, commonly-used, machine readable format.

Right to Object

You have the right to object to the processing of your personal data in certain circumstances.

Rights Related to Automated Processing, Including Profiling

You have the right to be notified, object and request reconsideration of any automated processing or profiling.

For more information on your individual rights under GDPR please see – https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/ .

Privacy Contacts

Should you have any questions or requests in relation to your privacy and/or this privacy notice, or require access to an address you may use the following contact details.

penny@pennysprimulas.co.uk