Registered address: 6 St David's Square, Westferry Road, London, England, E14 3WA
Full name of legal entity: DD Wine Ltd
Email address: email@example.com
Personal data, or personal information, means any information about an individual on which basis that person can be identified, excluding data where the identity has been removed (i.e., anonymous data).
We may collect, use, store and transfer different kinds of personal data which are grouped together as follows:
· Identity Data
includes first name, last name and title.
· Contact Data
includes billing address, email address and telephone numbers, information from your device contacts where you have given us permission to access and process such information, including a photo of you.
· Financial Data
includes bank account and card payment details.
· Transaction Data
includes details about payments, and other details of products and services you have purchased from us.
· Technical Data
includes your internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device information such as device ID, device IDFA, and other technology on the devices you use to access our website.
· Profile Data
includes any ID you provide to us, your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
· Usage Data
includes information about how you use our website, products and services.
· Marketing and Communications Data
includes your preferences in receiving marketing from us and our third parties, and your communication preferences.
· Location data
includes location information of your device/you. WWL may collect location information from devices according to the permission provided by your device.
We do not collect any Special Categories of Personal Data ("Sensitive data") about Users such as: details about your race or ethnicity, religious or philosophical beliefs, sex life or sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data.
Please let us know if your personal data changes while using our website. It is important for us to maintain current and accurate personal data. IF YOU FAIL TO PROVIDE PERSONAL DATA
If you fail to provide personal data we request by law, or under the terms of a contract between you and us, we may not be able to perform the contract we have, or are trying to enter into, with you (for example, to provide you with products or services). We may have to cancel a product or service you have ordered. In this case we will notify you immediately. HOW WE COLLECT PERSONAL DATA
Methods we use to collect personal data:
· Direct interactions
. You may give us your Identity, Contact and Financial Data through our website or by corresponding with us by phone, email or otherwise. You provide personal data when you:
o create an account on our website;
o subscribe to our service or publications;
o request marketing to be sent to you;
o enter a competition, promotion or survey;
o give us any feedback.
· Automated technologies or interactions.
for further details.
· Third parties or publicly available sources.
We may receive personal data about you from various third parties including marketing services providers, partner transportation companies and public sources. USAGE INFORMATION
We will only use your personal data as permitted by law. Most commonly, we use personal data in the following circumstances:
· If we have your consent.
· If we act under contract, or are about to enter into one with you.
· If it is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests.
· If we need to comply with a legal or regulatory obligation. PURPOSES FOR WHICH WE WILL USE YOUR PERSONAL DATA
We plan to use your personal data for the following purposes:
· to register you as a new user;
· to manage our relationship with you (including notifying you about changes to our terms or privacy notice, asking you to leave a review or take a survey, user services);
· to administer and protect our business, maintain the safety, security and integrity of our services, for our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data, research, analysis and product development and the provision of IT and system administration services);
· to deliver relevant website content and advertisements to you, and to measure or understand the effectiveness of the advertising we deliver;
· to use data analytics to improve our website, products/services, marketing, user relationships and experiences;
· to make suggestions and recommendations to you about products or services that may be of interest to you;
· to enable you to partake in a prize draw, competition or complete a survey.
Please contact us
if you need details about the specific legal frameworks we reference to process your personal data. MARKETING AND INSIGHTS
We aim to provide you different personal data uses as a choice, particularly regarding marketing and advertising.
We may use your personal data to form a view on what you may want or need, and about your range of interests. It is how we define products, services and offers that could be relevant to you. We name such actions 'marketing'.
You will receive marketing communications from us in following situations:
· if you have requested information from us
· if you have purchased products or services from us
· if you provided us with your details when you entered a competition, or registered for a promotion
· if it is lawful for us to provide such marketing communications to you. THIRD-PARTY MARKETING
We do not automatically share, or use, your personal data with third parties for marketing. We will always ask your expressed consent before we share your personal data with any company outside World Wine List for the purposes of marketing. OPTING OUT
You can prevent us from sending marketing communications at any time by:
· checking or unchecking the relevant boxes to adjust your marketing preferences
· following the opt-out links in any marketing message sent to you
· contacting us at any time. COOKIES
A cookie is a small text file, stored on your device, for the purpose of recognizing your device while you visit our website. Cookies allow our website to reproduce such information as login, language, font size and other settings. Cookie usage enables us to customize our website to your browser, as well as improve our content and provide you with the best possible experience. You can modify your browser so cookies are not stored on your device; however, if you choose not to accept cookies you may not be able to use all the functions of our website.
A cookie may contain text, numbers or e.g. a date, but generally there is no personal data in a cookie. It cannot contain a virus as it is not a program.
We use personal data for the purposes of data collection, or for another compatible reason that might be more effective than the original purpose. If you would like to receive an explanation of the compatibility of the new and the original purpose, please contact us
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law. DISCLOSURES OF YOUR PERSONAL DATA
We may have to share your personal data with the parties set out below for the purposes given above.
· External Third Parties
o Service providers based within and outside the European Economic Area (hereinafter - EEA) who help us to provide products and services to you, to administer and protect our business, maintain the safety, security and integrity of our services on the website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data, research, analysis and product development, and the provision of IT and system administration services).
o Professional advisers: lawyers, bankers, auditors and insurers based within and outside the EEA who provide consultancy, banking, legal, insurance and accounting services.
o Authorities who require reporting of our activities in certain circumstances. If we receive a request for information, we may disclose other Information if we reasonably believe disclosure is in accordance with, or required by, any applicable law, regulation or legal process.
· Third parties to whom we may choose to sell, transfer, merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If the owner of the business changes, then the new owner may use your personal data in the same way as set out in this privacy notice.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes, and only permit them to process your personal data for specified purposes and in accordance with our instructions. INTERNATIONAL DATA TRANSFERS PRIVACY SHIELD
World Wine List may transfer your personal data to countries different from your place of residency.
We ensure a similar level of protection of personal data while transferring it out of the EEA. We ensure at least one of the following:
· We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries
· If we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries
· If we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US. For further details, see European Commission: EU-US Privacy Shield
User accounts with any personal data are protected by a password. You may protect your account and personal data from unauthorized access by choosing and protecting your password appropriately. We also suggest signing off when finishing accessing your account, for the purpose of protecting your personal data. When signing in via a third-party application provider, your password is solely managed by such third-party.
To prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed, we limit access to our employees and other third parties. They will only process your personal data upon our instructions, and they are subject to a duty of confidentiality.
For the purpose of protection, we have implemented measures to deal with any suspected personal data breach and will notify you, and any applicable regulator of a breach, if we are legally required to. YOUR LEGAL RIGHTS
You have the following rights related to your personal data we hold. Please note that these rights are subject to certain exemptions which may be applicable to any request you make. Your right of access
If you ask us to confirm whether we're processing your personal information, and subject to any applicable exemptions, we will provide you a copy of that personal information (along with certain other details) within reasonable time, according to The EU General Data Protection Regulation. If you require additional copies, we may need to charge a reasonable fee. Your right to rectification
You may rectify your personal data if the information we hold is inaccurate or incomplete. We will inform third parties that use your personal data about such a rectification, in accordance with this privacy notice. If you ask us about third parties that we have shared your personal information with, we will send you their information so you may contact them directly, in case it is possible and lawful. Your right to erasure
You can ask us to delete, or remove, your personal data should you choose to withdraw your consent, or if we no longer need it, in accordance with the legal basis on which we have processed your personal information. We will take reasonable steps to inform third parties that you have exercised your right to erasure. If you ask us about third parties that we have shared your personal information with, so that you can contact them directly, we will send you such information in case it is possible and lawful. Your right to restrict processing
Should you contest the accuracy of the personal information we have for you, or you object to us processing it, you can ask us to 'block' or suppress this processing of your personal data. If you ask us about third parties that we have shared your personal information with, we will send you their information so you may contact them directly, in case it is possible and lawful. Your right to data portability
In certain circumstances you have the right to obtain personal information you have provided us with in a machine readable format, and to reuse it elsewhere, or ask us to transfer this to a third party of your choice. Your right to object
We will stop processing your personal data at your request in the following circumstances:
· any situation where your personal information is being used, except where there are legal grounds for processing such information;
· for direct marketing. Your rights in relation to automated decision-making and profiling
You have the right to not accept a decision if it is based on automatic processing, including profiling, should it produce a legal effect, or it similarly significantly affects you, unless such profiling is a requirement of the contract between you and us. Your right to withdraw consent
You can withdraw your consent to us processing your personal information at any time, as your consent is the legal basis upon which use your personal data, as set out above.
To exercise any of the rights above, please send a request to firstname.lastname@example.org
. DATA RETENTION AND ACCOUNT DELETION
While your account is active, we will store your personal data. We also may store some of your personal data to comply with our legal obligations.
You may add, or update, certain information to your account. When you update information, however, we often maintain a copy of the unrevised information in systems back-ups for a period of time until our backup is updated with the latest version.
When you delete your account, we delete the data attached to your account including your username. However, some information may remain in our records after your account has been deleted.
In some cases, we may make your personal data anonymous, and use it for research or statistical purposes. This data would not be associated with you and therefore is not defined as personal data. WHAT WE MAY NEED FROM YOU
To confirm your identity, or to exercise any of your other rights, we may request specific information from you. We provide such actions as a security measure. We may also contact you to ask you for further information in relation to your request to further aid our response. TIME LIMIT TO RESPOND
As a rule, all legitimate requests will be responded to within one month. If your request is particularly complex, or you have made a number of requests, it may take us longer than a month. In this case, we will notify you and keep you updated. NO FEE USUALLY REQUIRED
You will not have to pay a fee to access your personal data, or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these or any other circumstances in accordance with the law. AGE RESTRICTION