This website is operated by DISCOUNT STORE. The privacy of our users is extremely important to us and therefore we encourage all users to read this policy very carefully because it contains important information regarding:
- who we are;
- how and why, we collect, store, use and share personal information;
- your rights in relation to your personal information; and
- how to contact us and supervisory authorities if you have a complaint.
Who we are
DISCOUNT STORE (‘we’, ‘us’, ‘our’) collect, use and are responsible for storing certain personal information about you (‘you’, ‘your’, ‘yours’).
The personal information we collect and use
Personal information is information which you can be identified from (and does not include any anonymised forms of information).
- Types of personal information
We may process the following types of personal information in relation to you:
Email addresses, postal addresses, telephone numbers, and secure bank
details such as full card details.
How your personal information is collected
This section describes how the above types of personal information are collected by us. Your personal information will be collected as follows:
- Personal information obtained from you directly
We will sometimes obtain information from you directly, including when you:
Subscribe to the newsletter, purchase a product, create a user profile, contact
us using the ‘contact us’ chat service.
How many times a user visits the website, which pages a user visit, traffic
update, location data.
- Changes to the way in which we collect your personal information
If we need to obtain personal information in relation to you from any other source that those described above, we shall notify you of this.
How we use your personal information
- General purposes
In general, your personal information will be processed for the following purposes:
To enter a contract for the sale of goods to you and to manage our
business and website so we provide the appropriate marketing to you.
We may monitor communications, and in doing so we may obtain your personal information through this process. We will undertake monitoring in the following circumstances:
All calls and emails will be monitored for order processing; quality assurance;
training; fraud prevention; compliance.
- Use of your information for marketing purposes
We have described above that one of the general purposes for which your data shall be processed is for marketing purposes.
We wish to make you aware that you have the right to object or to opt-out of any direct marketing by:
Unsubscribing using the link contained on all emails.
- Fraud prevention
We will undertake fraud checks via use of your personal information. This will involve sharing and working with Fraud Prevention Agencies. We do so to protect our own commercial interests (which is encompassed within our own legitimate interests as a business).
In general, your information will be used for fraud prevention purposes:
We will use your information for fraud prevention purposes (with fraud
Prevention Agencies) at the outset of any transaction.
Fraud prevention agencies can hold your personal information for different periods of time, the maximum period being six years.
Lawful basis for processing of your personal information
We have described above the purposes for which we may process your personal information. These purposes will at times be justified by UK data protection law.
- General lawful basis
The lawful basis upon which we can process your personal data are:
- Where we have your consent to use your data for a specific purpose;
- Where it is necessary to enter a legal contract with your or to perform obligations under a legal contract with you;
- Where it is necessary to enable us to comply with a legal obligation;
- Where it is necessary to ensure our own legitimate interests of the legitimate interests of a third party (provided that your own interests and rights do not override those interests). Wherever we rely upon this basis, details of the legitimate interests concerned shall be provided to you;
- Where we need to protect your own vital interests (or the vital interests of another person); and/or
- Where it.is needed in the public interest (or where we are acting in our official functions), provided that the task of function has a clear basis in law.
In general, in order to meet the purposes we have described above, we will process your personal information where we have your express consent on each occasion that the data is processed.
2. Lawful bases specifically applicable to marketing
We will only ever use your personal information to send you marketing directly where we have your explicit consent (which will be obtained in a format separate to this policy).
Sharing your personal information
On any occasion where personal information is shared with any third party, we shall only permit them to process such information for our required purposes, under our specific instruction, and not for their own purposes. We are required to enter into a formal legal agreement to enable such sharing to take place.
We do not anticipate that we will need to share your information with any third party. We will notify should this position change.
How long your personal information will be kept
Your personal information will only be kept for a period of time which is necessary for us to fulfil the above purposes.
We envisage that your personal information shall be retained by us for the following:
Inactive accounts- six months; pending orders- seven days; failed orders- seven
days; cancelled orders- seven days; completed orders- six months
After the period described above, your information shall be properly deleted or anonymised.
Keeping your information secure
We will ensure the proper safety and security of your personal information and have measured in place to do so. We will also use technological and organisational measures to keep your information secure. These measures are as follows:
User account access is controlled by a unique username and password, all data
is stored on secure servers, payment details are encrypted using SSL.
We are iSO 27001 certified. This certification assists us in ensuring the safety of your personal information.
We have proper procedures in place to deal with any data security breach, which shall be reported and dealt with in accordance with data protection laws and regulations. You shall also be notified of any suspected data breach concerning your personal information.
Our website is not intended for children (anybody under the age of 18). We do not intend to collect data from children.
Under the UK General Data Protection Regulation, you have several rights free of charge. In summary, those include rights to:
- fair processing of information and transparency over how we use your personal information;
- access to your personal information and to certain other supplementary information that this Privacy Statement is already designed to address;
- require us to correct any mistakes in your information which we hold;
- require the erasure of personal information concerning you in certain situations;
- receive the personal information concerning you which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit this information to a third party in certain situations;
- object at any time to processing of personal information concerning you for direct marketing;
- object to decisions being taken by an automated means which produce legal effects concerning you or similarly significantly affect you;
- object in certain other situations to our continued processing of your personal information, or ask us to suspend the processing procedure for you confirm its assurance of our reasoning for processing it;
- object to processing your personal information where we are doing so in reliance upon a legitimate interest of our own or a third party and where you wish to raise an objection to this ground;
- Otherwise restrict our processing of your personal information in certain circumstances;
- Claim compensation for damages caused by our breach of any data protection laws; and/or
- In any circumstance where we rely upon your consent for processing any personal information, you may withdraw this consent at any time.
For further information on each of those rights, including the circumstances in which they apply see the guidance from the UK Information Commissioner’s Office (ICO) on your rights under the General Data Protection Regulations.
If you would like to exercise any of these rights, please contact Discount Store via the ‘contact us’ form.
The relevant person to contact regarding your personal information is: Tinofara Claudette.
Any requests or questions regarding the use of your personal information should be made to the above-named person via the ‘contact us’ form.