We take your privacy very seriously, the following outlines all the information you need to know.
BHS INTERNATIONAL UK DIGITAL LIMITED
WEBSITE PRIVACY NOTICE
We at BHS.com respect your privacy and are committed to protecting your personal information at all times in line with GDPR (General Data Protection Regulation) guidelines.
As controllers of your data, we want you to be clear on what information we collect, how we collect it, and why. Here we have set out how we use your personal information to allow us to effectively function as an online business, and let you know your legal rights in relation to your data – including how you can withdraw your consent to our use of it at any time.
THE INFORMATION WE COLLECT
We collect and use your personal information for the following purposes:
Fulfil your online orders
Provide you with a better shopping experience
Help us to make our messaging more relevant to you
Make informed improvements to our website
Meet our legal responsibilities
To achieve this, we may collect, use, store and/or transfer the following personal details:
Identity Data - Name, title, date of birth and gender
Contact Data - Billing address, delivery address, email address and phone numbers
Financial & Transaction Data - Bank account and payment card details, details about payments to and from you and other details of products and services you have purchased / ordered from us
Technical Data - Internet protocol (IP) address, browser type and version, device, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
Profile Data - Details of your username and password for registered users of BHS.com; purchases made by you, survey responses, feedback or complaints which you have communicated to us; and details which you have provided in relation to taking part in any competition we have run.
Usage Data - Information about how you use our website, including pages and details of any product preferences.
Marketing and Communications Data - Your email address and preferences in receiving marketing promotions and/or newsletters from us and/or any third parties and your communication preferences. This includes the links clicked on within newsletters.
Where we need to collect personal information from you to fulfil the terms of our contract (for example; to deliver your order to you), and you are unable to provide the appropriate data requested, we may not be able to complete the contract and may have to cancel your order. We will notify you if this is the case at the time.
HOW YOUR INFORMATION IS COLLECTED
We will mainly collect personal information about you through our website or via post, phone, email, social media or any other means of communication. This includes personal information you provide when you:
Order / purchase our products or services
Create an account on our website
Subscribe to receive our newsletters
Enter a competition or survey
Provide us with any feedback or other communications
We may also collect information about you from our other third-party service providers, such as our customer service team, professional advisers, analytics providers, advertising networks, search information providers, fraud prevention and credit reference agencies and providers of technical, payment and delivery services.
HOW WE USE YOUR INFORMATION
We will only use your personal information where we have a relevant and lawful basis for doing so. Most commonly, we will use your personal information in the following circumstances:
Where we need to perform the contract we are about to enter into or have entered into with you (e.g. completing delivery of an order).
For the purpose of fulfilling a legitimate interest of the business (including those of a third party) which is not at an expense of your fundamental rights.
Where we need to comply with any legal obligation or regulatory requirement.
We may also use legitimate interest as a lawful basis for providing you with marketing communications. We have listed our legitimate interests below where appropriate. The table below sets out a description of the main ways we use your personal information and which of the relevant lawful grounds for processing we rely on to do so.
Purpose / Activity
Lawful grounds for processing
Creating an account and registering you as a new customer.
Performance of a contract with you.
Processing and delivering your order(s) including storing order details, managing and processing all payments, fees and/or charges and collecting and recovering any sums owed to us.
Necessary for the performance of a contract with you.
Necessary for our legitimate interests in processing payments made by our customers and recovering any debts due to us.
Communicating with you for the purposes of providing you with any products or services which you have ordered / purchased from us, notifying you about changes to our services, reviewing and responding to any questions, feedback or other communications submitted by you.
Necessary for the performance of a contract with you.
Necessary for our legitimate interests in operating our business correctly, promoting our products and services effectively, developing and improving our products and services and responding to queries or complaints effectively
To inform you or remind you by email or other means of incomplete tasks on the website, such as abandoned baskets or products viewed, or our Refer-a-friend programme.
Necessary for our legitimate interests in improving the customer shopping experience
Providing you with the opportunity to take part in competitions or promotions.
Necessary for our legitimate interests in promoting our products and services effectively and developing and growing our business.
Providing you with the opportunity to refer our website to a friend, complete surveys and reviewing any survey responses or other communications from you in order to develop and improve our products and services.
Necessary for our legitimate interests in studying how customers use our products and services and developing and improving our products and services.
Administering and protecting our business and website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).
Necessary to comply with our legal obligations.
Necessary for our legitimate interests in operating our business correctly, ensuring the provision of effective administration and IT services, maintaining network security and preventing fraud.
Presenting you with relevant website content and online advertisements and measuring and understanding the effectiveness of the advertising we serve to you.
Necessary for our legitimate interests in studying how customers use our products / services, developing and improving our products / services, keeping our website up to date and relevant, growing our business and informing our marketing strategies.
Using data analytics to improve our website, products / services, marketing, recommendations, customer relationships and experiences.
Necessary for our legitimate interests in defining the types of customers for our products / services, keeping our website up to date and relevant, developing and improving our products / services, growing our business and informing our marketing strategies.
Providing you with marketing materials and promotions and also providing you with suggestions and recommendations about products and services that may be of interest to you.
Necessary for our legitimate interests in developing and promoting our products and services and growing our business. In certain circumstances, we may use consent as a lawful basis for processing personal information for direct marketing purposes.
Please note that we may process your personal information for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you require details about the specific lawful ground we are relying on to process your personal information where more than one lawful ground has been set out in the table.
We may use your personal information to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services, promotions and/or offers may be relevant for you for the purposes of marketing.
MARKETING MATERIAL ISSUED BY US
You will receive marketing materials, such as email newsletters, from us if you have requested this. You may also receive marketing materials from us if you have purchased goods or services from us, or engaged in negotiations with us in connection with our goods or services, or if you have provided us with your details when you entered a competition or registered for a promotion and, in each case, you have not opted out of receiving marketing materials. In these circumstances, we will provide you with marketing materials on the lawful basis that it is necessary for the purposes of our legitimate interests in developing and promoting our products and services and growing our business.
If you have provided us with your details and none of the above circumstances apply, you will only receive marketing materials from us via email or text message in circumstances where you have provided an opt-in consent which confirms that you want to receive such marketing from us. In these circumstances, you have the right to withdraw your consent at any time to the use of your personal information for marketing purposes.
THIRD PARTY MARKETING
We will obtain your express opt-in consent before we share any of your personal information with any third party for marketing purposes. If you have provided your consent to third party marketing, you have the right to withdraw your consent at any time to the use of your personal information for such marketing.
You have the right to object at any time to the processing of your personal information for direct marketing purposes. If you object to such processing, we will cease to process your personal information for direct marketing purposes.
You can ask us or third parties to stop sending you marketing materials at any time by: (i) following the opt-out links on any marketing communication, email message or email newsletter sent to you; or (ii)contacting us by email at email@example.com or by telephone at 0333 733 1000.
HOW LONG WE RETAIN YOUR INFORMATION
We will retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
DISCLOSURES OF YOUR INFORMATION
We may need to share your information with various third parties which provide services to us or act on our behalf in connection with the operation of our business. In particular, your information may be disclosed to the following categories of third parties:
Other entities in our corporate group.
Professional advisers (including legal advisers and financial advisers), auditors, insurers, bankers, and financial organisations.
Other third party service providers which provide services to us in connection with the operation of our business, including but not limited toIT and system administration services and other technical services, email hosting services, customer order services, customer communication services, data analytics services, fraud prevention and credit reference services, digital marketing and advertising services, logistics and delivery services and payment processing services.
Trade associates and business partners.
Third parties with whom we may enter into negotiations in respect of a commercial agreement, e.g. joint business venture.
Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets.
HM Revenue & Customs or any other public authority or regulatory authority in circumstances where we are required to disclose personal information by law.
We require all third party service providers to respect the security of your personal information and to treat it in accordance with the law. We do not permit our third party service providers to use your personal information for their own purposes and only permit them to process your information for specified purposes and in accordance with our instructions.
INTERNATIONAL DATA TRANSFERS
Please note that there may be instances where it may be necessary for us to transfer your information outside the European Economic Area, e.g. if we use third party service providers from another country. In these circumstances we shall put in place suitable safeguards to ensure that your information is held securely. If you require further information about the safeguards put in place you can request it from us by contacting us by email at the email address set out below.
YOUR LEGAL RIGHTS IN RELATION TO YOUR INFORMATION
Under the GDPR, you have a number of legal rights in relation to the personal information which we hold about you. We respect your legal rights in relation to your personal information and aim to uphold your rights in everything we do. Your legal rights under the GDPR include the following:
Subject access right – You can ask us to provide you with a copy of the personal information which we hold about you and a description of how we use your information.
Right to rectification – If you believe any personal information we hold about you may be inaccurate or incomplete, you can require us to rectify these inaccuracies.
Right to erasure / Right to be forgotten – You can require us to erase your personal information in certain circumstances. However, please note that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Right to data portability – Where we process your personal information using automated means of processing on the basis of your consent or for the purposes of performing a contract with you, you can request that we supply such personal information to another party in a machine-readable format.
Right to restriction of processing – You can require us to restrict or suspend our processing of your personal information in certain limited circumstances.
Right to object to processing – Where we process your personal information on the lawful basis that such processing is necessary for the purposes of our legitimate interests, you have the right to object to us processing your personal information in certain circumstances.
Right to object to processing for direct marketing purposes – You have the right to object at any time to the processing of your personal information for direct marketing purposes. If you object to us processing your personal information for direct marketing purposes, we will no longer process your information for such purposes.
Right to withdraw consent – If we process your personal information on the basis of your consent, you have the right to withdraw your consent at any time to the processing of your personal information. However, please note thatthis will not affect the lawfulness of any processing of your personal information carried out before you withdraw your consent.
HOW TO CONTACT US
Please get in touch if you have any questions about how we use your personal information or you wish to contact us about your legal rights or if you have any complaints or feedback about our use of your personal information. Please contact us at any time by sending an email to us at firstname.lastname@example.org.
If you wish to submit a complaint or express any concerns about our use of your personal information, please contact us in the first instance. We will do our best to resolve your complaint or address your concerns to your satisfaction. However, if you feel that we have not resolved your complaint or addressed your concerns, please note that you have right to make a complaint at any time to the Information Commissioner's Office, the UK supervisory authority for data protection issues.
Please note that we may update this privacy notice from time to time. Any changes to this privacy notice will be posted on our website, and where appropriate, notified to you by email.