The rules on processing of personal data are set out in the General Data Protection Regulation (the “GDPR”). Any questions regarding this Policy and our privacy practices should be sent by email firstname.lastname@example.org or by writing to Exosuit Limited, 70, Wilson Street, London EC2A 2DB.
1. WHO ARE WE?
We’re Exosuit. We are classed under the GDPR regulations as a data controller. That means we decide how your personal data we receive is processed and for what purposes. Our registered address is 37, Warren Street, London W1T 6AD. For all data matters please email email@example.com.
2. HOW DO WE COLLECT INFORMATION FROM YOU?
We obtain information about you when you use our website, for example, when you use our online store, register to join Exosuit, contact us about products and services, or if you register to receive one of our regular newsletters.
3. WHAT TYPE OF INFORMATION IS COLLECTED FROM YOU?
The personal information we collect might include your name, address, email address, phone number, IP address, and information regarding what pages are accessed and when. If you purchase a product from us, your card and other payment information is not held by us, it is collected by our third-party payment processors, who specialise in the secure online capture and processing of credit/debit card transactions, as explained below.
4. HOW IS YOUR INFORMATION USED?
We may use your information to:
Process orders that you have submitted through our online store;
Process images you post on our website;
Carry out our obligations arising from any contracts entered into by you and us;
Deal with returns or complaints;
Seek your views or comments on the services we provide;
Notify you of changes to our services;
Send you communications which you have requested and that may be of interest to you. These may include newsletters, information about marketing, new projects and new products;
Promote our associated companies’ goods and services;
Process a job application to join Exosuit.
We review our retention periods for personal information on a regular basis. We will hold your personal information on our systems for as long as is necessary for the relevant activity, or as long as is set out in any relevant contract you may hold with us.
5. WHAT IS OUR LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA?
Our lawful basis for processing your general personal data under article 6 of GDPR is as follows;
Consent of the data subject – We will directly ask for your consent to process data;
When you sign up for our regular newsletter on our website.
Processing necessary for the performance of a contract with the data subject or to take steps to enter into a contract – We will collect and use your personal data in the following circumstances:
When you make a purchase on our website so that we can process your payment, confirm transaction details (typically via email) and arrange delivery of the goods and services.
Processing necessary for the purposes of the legitimate interests of the data controller or a third party, except where such interests are overridden by the interests or fundamental rights or freedoms of the data subject:
We will use your personal data, such as your sizing, to improve the fit of our products;
We will also use your personal data, such as your sizing, to help us calculate the popularity of products and sizes.
6. WHO HAS ACCESS TO YOUR INFORMATION?
Exosuit requires access to personal information such as name, address, phone and email details in order to process your purchases, deliveries and returns. It is important to note:
We will not sell or rent your information to third parties;
We will not share your information with third parties for marketing purposes.
Third Party Service Providers working on our behalf: We may pass your information to our third-party service providers, agents, subcontractors and other associated organisations for the purposes of completing tasks and providing services to you on our behalf (for example to process website payments, or to arrange delivery of products to you). However, when we use third party service providers, we disclose only the personal information that is necessary to deliver the service. Please be reassured that we will not release your information to third parties beyond Exosuit and its member associations for them to use for their own direct marketing purposes, unless you have requested us to do so, or we are required to do so by law, for example, by a court order or for the purposes of prevention of fraud or other crime.
When you make a purchase through the website, your payment is processed by a third-party payment processor, who specialises in the secure online capture and processing of credit/debit card transactions. If you have any questions regarding secure transactions, please contact us.
7. YOUR CHOICES
You have a choice about whether or not you wish to receive information from us. If you do not want to receive direct communications from us about our exciting products and services, then you can select your choices by ticking the relevant boxes situated on the form on which we collect your information.
We will not contact you for marketing purposes by email, phone or text message unless you have given your prior consent. We will not contact you for marketing purposes by post if you have indicated that you do not wish to be contacted. You can change your marketing preferences at any time by contacting us by email firstname.lastname@example.org.
8. HOW CAN YOU ACCESS AND UPDATE YOUR INFORMATION?
The accuracy of your information is important to us. We’re working on ways to make it easier for you to review and correct the information that we hold about you. In the meantime, if you change email address, or any of the other information we hold is inaccurate or out of date, please email us at email@example.com or write to us at Exosuit Limited, 70, Wilson Street, London EC2A 2DB.
You have the right to ask for a copy of the information Exosuit holds about you (we may charge £10 for information requests) to cover our costs in providing you with details of the information we hold about you.
9. SECURITY PRECAUTIONS IN PLACE TO PROTECT THE LOSS, MISUSE, OR ALTERATION OF YOUR INFORMATION
When you give us personal information, we take steps to ensure that it’s treated securely. Any sensitive information (such as credit or debit card details) is encrypted and protected with the following software 128 Bit encryption on SSL. When you are on a secure page, a lock icon will appear on the bottom of web browsers such as Microsoft Internet Explorer or Google Chrome.
Non-sensitive details (your email address etc.) are transmitted normally over the Internet, and this can never be guaranteed to be 100% secure. As a result, while we strive to protect your personal information, we cannot guarantee the security of any information you transmit to us, and you do so at your own risk. Once we receive your information, we make our best effort to ensure its security on our systems. Where we have given (or where you have chosen) a password which enables you to access certain parts of our websites, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
We may analyse your personal information to create a profile of your interests and preferences so that we can contact you with information relevant to you. We may make use of additional information about you when it is available from external sources to help us do this effectively. We may also use your personal information to detect and reduce fraud and credit risk.
11. USE OF ‘COOKIES’
It is possible to switch off cookies by setting your browser preferences. For more information on how to switch off cookies on your computer, visit our full cookies policy. Turning cookies off may result in a loss of functionality when using our website.
12. LINKS TO OTHER WEBSITES
In addition, if you linked to our website from a third-party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third-party site and recommend that you check the policy of that third-party site.
13. AGE 16 OR UNDER
We are concerned to protect the privacy of children aged 16 or under. We do not process anyone’s data aged under 16 without their parent/guardian’s explicit permission. If you are aged 16 or under‚ please get your parent/guardian’s permission beforehand whenever you provide us with personal information.
14. TRANSFERRING YOUR INFORMATION OUTSIDE OF EUROPE
As part of the services offered to you through this website, the information which you provide to us may be transferred to countries outside the European Union (“EU”). By way of example, this may happen if any of our servers are from time to time located in a country outside of the EU. These countries may not have similar data protection laws to the UK. By submitting your personal data, you’re agreeing to this transfer, storing or processing. If we transfer your information outside of the EU in this way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this Policy.
If you use our services while you are outside the EU, your information may be transferred outside the EU in order to provide you with those services.
15. HOW TO MAKE A COMPLAINT?
To exercise all relevant rights, queries or complaints please in the first instance contact the Exosuit Data Protection Officer via email at firstname.lastname@example.org or write to us at Exosuit Limited, 70, Wilson Street, London EC2A 2DB.
If this does not resolve your complaint to your satisfaction, you have the right to lodge a complaint with the Information Commissioners Office on 03031231113 or via email https://ico.org.uk/global/contact-us/email/ or at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, England.
16. FURTHER PROCESSING
If we wish to use your personal data for a new purpose, not covered by this Data Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions.
17. REVIEW OF THIS POLICY
This Policy was last updated in February 2019.