We respect your privacy and are committed to protecting your personal data. This privacy policy tells you how we collect and process your personal data which you provide to us or which we collect from other sources.
It is important that you read this privacy policy together with any other privacy information we may provide to you on occasion so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
Important Information and Who We Are
Norwich Sunblinds Limited is the data controller responsible for your personal data. We have appointed a Data Protection Officer who is responsible for overseeing our compliance with data protection law. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact us using the details below.
Email address: [email protected]Postal address: FREEPOST NC1013, PO Box 65, Norwich, NR6 6BR
Telephone number: 0800 9889398
We are part of the ASHI Group. For information about how the ASHI Group processes personal data, please see the Group privacy policy.
Our website includes links to other websites, plug-ins and applications owned and managed by third parties which may collect information about you. When you link to other websites, we encourage you to read their own privacy policies.
The Data We Collect About You
Personal data means any information about an individual from which that person can be identified. It does not include anonymous data where the identity has been removed.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Identity Data |
Name, title and date of birth. If you visit one of our showrooms, depots or offices, this will include CCTV footage which may be captured of you. |
Contact Data |
Billing address, delivery address, email address and telephone numbers. |
Financial Data |
Bank account and payment card details. |
Transaction Data |
Details about payments to and from you and other details of products and services you have purchased from us. |
Technical Data |
IP address, device make and model, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website. |
Profile Data | Purchases or orders made by you, your interests, preferences, feedback and survey responses. |
Usage Data |
Information about how you use our website, products and services. |
Marketing and Communications Data |
Your preferences in receiving marketing from us and your communication preferences. |
We may also collect about information about your health if there is something we need to know in order to adjust our sales and delivery process so that you are treated with appropriate care and kept you safe when we visit your home, or deliver and install our products there.
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
How is Your Personal Data Collected?
You may give us your Identity, Contact and Financial Data when you contact us by any means to enquire about or purchase our products or services, book an appointment, request marketing material to be sent to you, enter a competition, promotion or survey, give us feedback or contact us for any reason.
We will also automatically collect Technical Data about your device, browsing actions and patterns when you interact with our website. We collect this data by using cookies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our Cookie Policy for further information.
We will also receive personal data about your from various third parties, such as website analytics providers (as described in our Cookie Policy), third party payment services providers and delivery services providers.
Finally, we may receive your Identity and Contact Data from the Post Office’s National Change of Address Database, the National Deceased Register, the Telephone Preference Service, Mail Preference Service, our chosen supplier of personal data accuracy services or any similar external data lists we may cross reference either to keep the personal data we hold about you up to date or to ensure that we only communicate with you where we are allowed to do so.
How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data where we need to perform the contract we are about to enter into or have entered into with you, where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests, or where we need to comply with a legal obligation that we are subject to.
Our purposes for using personal data
We have set out below a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. Where our legal basis is legitimate interests we have described the relevant interest.
Purposes for which we will use your personal data
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
---|---|---|
To register you as a new customer or register your interest in our products and services. |
(a) Identity
(b) Contact |
Performance of a contract with you |
To visit your property in order to provide you with a quote for our products or services |
(a) Identity
(b) Contact (c) Marketing and Communications |
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to follow up on your interest and provide you with the information you need to decide whether you would like to purchase from us |
To process and deliver your order including:
(a) Manage payments, fees and charges (b) Collect and recover money owed to us |
(a) Identity (b) Contact (c) Financial (d) Transaction |
(a) Performance of a contract with you (b) Necessary for our legitimate interests (to recover debts due to us) |
To manage our relationship with you | (a) Identity (b) Contact (c) Profile (d) Marketing and Communications |
(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services) |
To enable you to partake in a prize draw, competition or complete a questionnaire or survey | (a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications |
Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business) |
To administer and protect our business and our website(s) (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | (a) Identity (b) Contact (c) Technical |
(a) Necessary for our legitimate interests
(for running our business, provision of administration
and IT services, network security, to prevent fraud and in
the context of a business reorganisation or group
restructuring exercise) (b) Necessary to comply with a legal obligation |
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences | (a) Technical (b) Usage |
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
To operate CCTV in our premises | (a) Identity | Necessary for our legitimate interests (to ensure the safety of you and our people). |
To make suggestions and recommendations to you about goods or services provided by us and other companies within our group that may be of interest to you | (a) Identity (b) Contact (c) Technical (d) Usage (e) Profile (f) Marketing and Communications |
(a) your consent where applicable (b) Necessary for our legitimate interests (to develop our products/services and grow our business) |
To introduce or refer you to other companies in our group which provide products which you have expressed an interest in. | (a) Identity (b) Contact (c) Profile |
Your consent |
To introduce or refer you to other companies in our group which provide products which you have expressed an interest in. | (a) Identity (b) Contact (c) Profile |
|
To conduct customer research | (a) Identity (b) Contact (c) Transaction (d) Profile (e) Usage |
Necessary for our legitimate interests (to use customer research to improve our products and services) |
To display case studies and / or testimonials through any Marketing channels | (a) Usage | Your consent |
To display case studies and / or testimonials through any ASHI Group Marketing channels | (a) Usage | Your consent |
To refer you to other companies within the Anglian Group where you have expressed interest in their products or services and enable them to communicate with you in relation to those products and services. | (a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications |
Your consent |
Marketing
You will receive marketing communications from us if you have: (a) subscribed to our offers and updates and consented to receive them or; (b) if you have requested information from us or purchased products or services from us and you have not opted out of receiving marketing communications.
You may opt out of receiving marketing from us at any time, either by following the opt-out link in any electronic marketing message or by emailing:
With your consent, we will share your personal data with members of the ASHI Group so that they may send you information about products and services which may be of interest to you. You may withdraw your consent to receive such marketing material at any time.
Cookies
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our website(s) may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy.
Disclosures of Your Personal Data
We may share your personal data with the third parties set out below for the purposes set out in this privacy policy. We take steps to ensure that these third parties look after your personal data to the same standard that we do.
- Service providers who provide IT and system administration services and services platforms.
- Other companies within our group which provide goods and services which we understand you to be interested in.
- Service providers based in the UK to whom we may subcontract the delivery and installation of your product.
- Delivery companies.
- Our professional advisers including lawyers, bankers, auditors and insurers.
- HM Revenue & Customs, regulators and other authorities.
- Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets or from whom we may seek to acquire other businesses. Any new owners may use your personal data in the same way as set out in this privacy policy.
- Third parties to perform as measurement services on our behalf.
International Transfers
We do not transfer your personal data outside the UK. If this changes, we will update this privacy policy.
Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and any applicable legal or regulatory requirements.
Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to:
Request access to your personal data (commonly known as a “data subject access request”).
Request correction of the personal data that we hold about you.
Request erasure of your personal data where we no longer have a good reason to process it.
Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes.
Request restriction of processing of your personal data.
Request the transfer of your automated personal data to you or to a third party in a structured, commonly used, machine-readable format.
Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
For more information about your rights, please see:
www.ico.org.uk/for-the-public/.
You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please do contact us in the first instance.
If you wish to exercise any of the rights set out above, please contact our Data Protection Officer.