We are the controller of the personal data provided to us for the purposes of applicable data protection legislation.
2. What personal data do we collect?
By personal data we mean identifiable information about you, such as your name,email address, postal address, mobile and home telephone number and your IP address.
Information you provide to us
From time to time you may provide to us personal data. This may be because you:
- complete our Stockist Application Form;
- purchase products from us;
- use the Live Chat facility on our website;
- supply goods or services to us;
- subscribe to receive marketing information from us through our Sign Up Form or otherwise;
- apply to work with us; and/or
- otherwise contact us including with queries, comments or complaints.
You may provide personal data to us directly, or to us through our social media platforms.
All personal data that you provide to us must be true, complete and accurate. If you provide us with inaccurate or false data, and we suspect or identify fraud, we will record this and we may also report this to the appropriate authorities.
At our request, you shall promptly provide evidence of your identity.
When you contact us by email or post, we may keep a record of the correspondence and we may also record any telephone call we have with you.
Information we automatically collect about you
When you use our website, we automatically collect and store information about your device and your activities. This information could include:
- technical information about your device such as type of device, web browser or operating system;
- your preferences and settings such as time zone and language;
- how long you used the website and which services and features you used.
Information we receive from others
If we reasonably believe that any of the personal data you have provided to us is inaccurate, we may receive further personal data from third parties, confirming or otherwise, your identity.
We may also receive information about you from:
- your employer or colleagues, if you purchase products from us or sell products or services to us;
- our or your payment providers, if you purchase products from us or sell products or services to us;
- your references, if you apply for a job with us.
3. Lawful use of your personal data
- consent (where you choose to provide it);
- performance of our contract with you;
- compliance with legal requirements; and
- legitimate interests. When we refer to legitimate interests we mean our legitimate business interests in the normal running of our business which do not materially impact your rights, freedom or interests.
In particular, we shall send you marketing information if you provide your consent by subscribing to receive such information.
If you purchase products from us, or supply products or services to us, we shall process your personal data in order to comply with our obligations and exercise our rights under the terms and conditions governing such purchase/supply.
We may from time to time need to use your personal data to comply with any legal obligations, demands or requirements, for example, as part of anti-money laundering processes or to protect a third party’s rights, property, or safety. In certain circumstances, we may be required by law to disclose your personal information to third parties such as government bodies, law enforcement agencies, and data protection regulators.
We may also use your personal data for our legitimate interests including:
- to improve our services;
- in connection with, or during negotiations of, any merger, sale of assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or into another company;
- to deal with any customer services you require;
- for audit purposes; and
We may also use aggregate information and statistics for the purposes of monitoring website usage in order to help us to develop our website and products. We may also provide such aggregate information to third parties. These statistics will not include information that can be used to identify you.
4. Who do we share your data with?
For our legitimate interests, we may share your personal data with our service providers, sub-contractors and agents that we may appoint to perform functions on our behalf and in accordance with our instructions,including IT service providers, payment providers, accountants, auditors and lawyers. We currently use MailChimp to send our marketing communications, and Tawk.to to manage our Live Chat facility.
We shall provide our service providers, sub-contractors and agents only with such of your personal data as they need to provide the service for us and if we stop using their services, we shall request that they delete your personal data or make it anonymous within their systems.
From time to time we may provide your information to our customer service agencies for research and analysis purposes so that we can monitor and improve the products that we provide.
5. Where we hold and process your personal data
Some or all of your personal data may be stored or transferred outside of the UK or the European Economic Area (the EEA) for any reason, including for example, if our email server is located in a country outside the UK or EEA or if any of our service providers are based outside of the UK or EEA.
Where your personal data is transferred outside the UK or EEA, it will only be transferred to countries that have been identified as providing adequate protection for personal data or to a third party where we have approved transfer mechanisms in place to protect your personal data – for example, by entering into the European Commission’s Standard Contractual Clauses, or by ensuring the entity is Privacy Shield certified (for transfers to US-based third parties).
We shall process your personal data in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. In particular, access is restricted to employees who need to know your personal data, and we use appropriate password protection and appropriate strong encryption electronic measures within our electronic data management systems.
However, unfortunately, because of the nature of electronic storage, we cannot promise that your personal data or any other data you provide to us will always remain secure. If there is a security breach, we will do all that we can as soon as we can to stop the breach and minimise the loss of any data.
We may use your personal data such as your name and email address to send you marketing communications if you have consented to receive them. We may also use your personal data such as your name and email address to send you marketing communications for our legitimate business interests if you have purchased products from us.
You can choose to no longer receive marketing emails from us by sending an email with Subject UNSUBSCRIBE GARCON WINES to email@example.com. Please note that it may take us a few days to update our records to reflect your request.
If you ask us to remove you from our marketing list, we shall keep a record of your name and email address to ensure that we do not send to you marketing information. We will still contact you as necessary in relation to any other relationship we have with you, for example, if you purchase products from us.
8. Your rights
You have a number of rights under applicable data protection legislation. Some of these rights are complex, and not all of the details have been included below. Further information can be found here.
- Right of access: You have the right to obtain from us a copy of the personal data that we hold for you.
- Right to rectification: You can require us to correct errors in the personal data that we process for you if it is inaccurate, incomplete or out of date.
- Right to portability: You can request that we transfer your personal data to another service provider.
- Right to restriction of processing: In certain circumstances, you have the right to require that we restrict the processing of your personal information.
- Right to be forgotten: You also have the right at any time to require that we delete the personal data that we hold for you, where it is no longer necessary for us to hold it. However, whilst we respect your right to be forgotten, we may still retain your personal data in accordance with applicable laws.
- Right to stop receiving marketing information: You can ask us to stop sending you information about our services.
We reserve the right to charge an administrative fee if your request in relation to your rights is manifestly unfounded or excessive.
9. Retention of personal data
However, we may also be required to retain personal data for a particular period of time to comply with legal, auditory or statutory requirements, including requirements of HMRC in respect of financial documents.
Last updated: October 2019