Privacy Notice

This Privacy Notice provides details of the personal data we collect from you, what we do with it, how you might access it and who it might be shared with.

Our Contact Information (Data Controller)

Boho Betty UK

Unit 66, Basepoint Business Centre

Caxton Close

Andover, Hampshire SP10 3FG

United Kingdom

Telephone 01264 326 442

Company Email: info@boho-betty.com

What we do with your personal data

We process personal data only for the purpose for which they are collected. The purpose is dependent on whether you use only our website, or additionally, our services. If you use our services you are required to register and we collect your personal data. We use this personal data for the provision of the service or the performance of the contract. We may use your personal data for other similar purposes, including marketing and communications, but that will only occur in the case we have your consent or another legal justification for doing so.

From our Customers and Prospects, we process and retain personal data for the following purposes and periods, with the applicable legal basis.

Processing purpose

Legal basis

Retention period

To process orders and deliver the required customer care service

we have a contract with the data subject

for as long as contract and legal obligations require

To improve user experience and deliver more relevant services and information

it is in our legitimate interest (or that of a third party)

until consent is withdrawn

Fulfilment of orders on behalf of third party retailers

it is in our legitimate interest (or that of a third party)

for as long as contract and legal obligations require

To inform customers of related products

it is in our legitimate interest (or that of a third party)

until consent is withdrawn

To inform enquirers of our products and related news

we have data subject's consent

until consent is withdrawn

 

From our Trade Customers we process and retain personal data for the following purposes and periods, with the applicable legal basis.

Processing purpose

Legal basis

Retention period

To fulfil wholesale orders

we have a contract with the data subject

for as long as contract and legal obligations require

To verify 'trade' customers and to provide them with trade account access

we have data subject's consent

until consent is withdrawn

 

From our suppliers and contractors, we process and retain personal data for the following purposes and periods, with the applicable legal basis.

Processing purpose

Legal basis

Retention period

Business operations

we have a contract with the data subject

for as long as contract and legal obligations require

Financial management

we have legal obligation

for as long as contract and legal obligations require

 

From our employees, we process and retain personal data for the following purposes and periods, with the applicable legal basis.

Processing purpose

Legal basis

Retention period

To administer employees

we have a contract with the data subject

for as long as contract and legal obligations require

To pay staff

we have a contract with the data subject

for as long as contract and legal obligations require

For computer and software maintenance

we have a contract with the data subject

for as long as contract and legal obligations require

To provide references to prospective employers of former staff

we have data subject's consent

until consent is withdrawn

To process job applications

we have data subject's consent

until consent is withdrawn

To service legal obligations for tax and HR practices

we have legal obligation

for 6 years

 

What personal data do we collect?

The personal data we collect depends on whether you just visit our website or use our services. If you visit our website, you do not need to provide us with any personal data. However, your browser transmits some data automatically, such as the date and time of retrieval of one of our web pages, your browser type and settings, your operating system, the last web page you visited, the data transmitted and the access status, and your IP address.

If you use our services, personal data is required to fulfill the requirements of a contractual or service relationship, which may exist between you and our organization.

We collect:

  • Name
  • Contact information including telephone and address
  • IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use
  • Email address
  • Employer
  • Location Information
  • Spending Record

We collect your personal data from the following indirect sources

Data subject type

Personal data type

Indirect source name

Customers from third party retailers

Name, Email, Address, Location Information, Spending Record

Amazon

Customers from third party retailers

Name, Email, Address, Location Information, Spending Record

SilkFred

Who might we share your personal data with?

To maintain and improve our services, your personal data may need to be shared with or disclosed to service providers, other Controllers or, in some cases, public authorities. We may be mandated to disclose your personal data in response to requests from a court, police services or other regulatory bodies. Where feasible, we will consult with you prior to making such disclosure and, in order to protect your privacy, we will ensure that we will disclose only the minimum amount of your information necessary for the required purpose.

We transfer personal data to the following organisations and countries:

Data subject type

Organisation name

Type

Location

Customers and prospective customers

The Rocket Science Group LLC d/b/a MailChimp

Processor

USA

Customers

PayPal (Europe) S.à.r.l. et Cie, S.C.A.

Processor

USA

Customers

Stripe

Processor

USA

Customers and suppliers

GoDaddy Email Server

Processor

USA

Customers and suppliers

KFS Accountants Limited

Joint Controller

United Kingdom

Customers

Stitch Labs

Processor

USA

Employee/Prospective Employee

Jools UK Ltd

Processor

United Kingdom

Customers and suppliers

Xero (UK) Limited

Processor

New Zealand

Customers

Shopify International Limited.

Processor

EU/EEA

Customers

Convoy Digital Marketing

Joint Controller

United Kingdom

Customers

Royal Mail/Click n Drop

Processor

United Kingdom

Customers

Shopify Payments (Canada) Inc.

Processor

Canada

Customers

Barclays Merchant Services

Processor

United Kingdom

Customers

DHL Deutsche Post

Processor

EU/EEA

Customers

Trans Global

Processor

EU/EEA

When a Processor or Controller is in a country outside the EU, we apply the necessary safeguards which may include, confirming whether the EC approves of transfers to the country, whether we need to use the EC's model contracts or, if the transfer is internal to our organisation, commitment to Binding Corporate Rules. Details of these safeguards may be obtained by contacting us directly.

How do we safeguard your personal data?

We limit the amount of personal data collected only to what is fit for the purpose, as described above. We restrict, secure and control all of our information assets against unauthorised access, damage, loss or destruction; whether physical or electronic. We retain personal data only for as long as is described above, to respond to your requests, or longer if required by law. If we retain your personal data for historical or statistical purposes we ensure that the personal data cannot be used further. While in our possession, together with your assistance, we try to maintain the accuracy of your personal data.

How can you access your personal data?

You have the right to request access to any of your personal data we may hold. If any of that information is incorrect, you may request that we correct it. If we are improperly using your information, you may request that we stop using it or even delete it completely.

If you would like to make a request to see what personal data of yours we might hold, you may make a request from our company website.

Where you have previously given your consent to process your personal data, you also have the right to request that we port or transfer your personal data to a different service provider or to yourself, if you so wish.

Where it may have been necessary to get your consent to use your personal data, at any moment, you have the right to withdraw that consent. If you withdraw your consent, we will cease using your personal data without affecting the lawfulness of processing based on consent before your withdrawal.

Our Data Protection Officer

Tania Buckley

Telephone 01264 326 442

Company Email: info@boho-betty.com

Our Supervisory Authority

You have the right to lodge a complaint with any Supervisory Authority. See our Supervisory Authority contact details below

INFORMATION COMMISSIONER’S OFFICE

United Kingdom
Water Lane, Wycliffe House 
Wilmslow - Cheshire SK9 5AF 
 international.team@ico.org.uk 
+44 1625 545 745 
www.ico.org.uk