VMDUK Limited, trading as VAST Boardsports, (we or us) is a company registered in England and Wales under company number 12602635. Our registered office is at Unit 5+6 Heol Ffaldau, Brackla Industrial Estate, Bridgend, Wales. UK. CF31 2AJ.
WHAT IS THE PURPOSE OF THIS DOCUMENT?
1.1- We are committed to protecting and respecting your privacy. This privacy notice sets out the basis on which any personal data we collect about users of our website at www.noahboardsports.com (our site) and how that information will be processed by us.
1.2- This privacy notice applies to: visitors to our site who do not register as well as those who do; any customers that purchase our goods and/or services from us via our site or otherwise; and all individual contractors and service providers who provide services to our business (you).
1.3- We are a data controller. This means that we are responsible for deciding how we hold and use personal information about you, and for explaining this clearly to you.
1.5- Please read this privacy notice carefully to understand what we do with your personal information and what rights you have in relation to our activities.
1.6- Our site is not intended for children and we do not knowingly collect data relating to children.
WHAT IS PERSONAL DATA AND OUR LAWFUL BASIS FOR PROCESSING
2.1- Personal data, or personal information, means any information relating to an individual from which that person can be identified. There are special categories of more sensitive personal information which require a higher level of protection (see further at section 3.4 below).
2.2- We will only use your personal information when the law allows us to. Our principle lawful basis for processing is set out in the table below. However, some of our grounds for processing will overlap and there may be several grounds which justify our use of your personal information.
2.3- We may only rely on our legitimate interests (or those of a third party) to process your personal information if your interests and fundamental rights do not override those interests. Where we rely on legitimate interests for our processing, we have set out the relevant interest, below.
2.4- If you are a private individual, we will get your consent before sending third party direct marketing communications to you. You have the right to withdraw consent to marketing at any time by contacting us.
2.5- We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
2.6- Please note that we may process your personal information without your knowledge or consent where this is required or permitted by law.
2.7- Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
DATA WE COLLECT ABOUT YOU
3.1- Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
3.2- We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Identity Data includes first name, last name, username or similar identifier, and may also include marital status, title, date of birth, photograph and gender.
Contact Data includes billing address, delivery address, email address and telephone numbers.
Transaction Data includes details products and services you have purchased from us.
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
Usage Data includes information about how you use our website, products and services.
Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences, how you interact with our digital marketing we collect data to track the pages that you accessed via our website or whether you have opened our emails (emails contain tracking pixels or plug-ins), the date, time and location you accessed the information, your search queries, information on your device (hardware model, operating system version, unique device identifiers, Internet protocol address, hardware settings, browser type, browser language), the date and time of your request and referral URL.
We do not collect financial data - when placing an order you are redirected to a third party service provider who deals with the payment process.
HOW IS YOUR PERSONAL DATA COLLECTED?
4.1- We use different methods to collect data from and about you including through:
4.2- Direct interactions. You may give us your Identity and Contact by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
4.2.1 - apply for our products or services;
4.2.2 - create an account on our website;
4.2.3 - subscribe to our service or publications;
4.2.4 - request marketing to be sent to you;
4.2.5 - enter a competition, promotion or survey; or
4.2.6 - give us feedback, make a complaint or contact us.
4.3- We collect Identity, Contact, Profile and Technical Data from our Social Media accounts:
4.3.2 - @vastboardsports https://twitter.com/vastboardsports
4.3.3 - @vastboardsports https://www.instagram.com/vastboardsports/
4.4- Automated technologies or interactions. As you interact with our website and our marketing emails, we will automatically collect Usage and Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, embedded pixels or plug-ins, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see section 10, below, for further details.
4.5- Third parties or publicly available sources. We may receive personal data about you from various third parties, such as:
4.5.1 - Technical Data from the following parties:
(a) analytics providers such as Google based outside the EU;
(b) advertising networks
(c) search information providers
4.5.2 - Identity and Contact Data from data brokers or aggregators
PURPOSES FOR WHICH WE WILL USE YOUR PERSONAL DATA
5.1- Automated decision-making
5.1.1 - Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention.
5.1.2 - We do not envisage that any serious decisions will be taken about you using automated means, however we will notify you in writing if this position changes.
5.2.1 - We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
5.2.2 - We may use third-party advertising companies or affiliates to display advertisements on our website. These third-party advertising companies or affiliates may separately place or recognise a cookie file on your browser in the course of delivering advertisements to the Site. We cannot see the information collected or stored in third party cookies. We do not provide personal data about you to these third party advertisers or affiliates or to any other third party.
5.2.3 - The provision of your personal data is not required if you only want to visit our website. This means that you may refuse to accept cookies by configuring your web browser accordingly (for more information, refer to the ‘help’ section of your web browser). However, refusing cookies is likely to disrupt your navigation on our website, in particular by preventing you to access to certain parts of it.
5.3- Promotional offers from us
5.3.1 - We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you.
5.3.2 - You will receive marketing communications from us if you have requested information from us or purchased products from us and you have not opted out of receiving that marketing.
5.4- Third-party marketing
We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
5.5- Opting out
You can ask us or third parties to stop sending you marketing messages at any time by logging into the website and checking or unchecking relevant boxes to adjust your marketing preferences orby following the opt-out links on any marketing message sent to you or by contacting us at any time.
SHARING YOUR INFORMATION
6.1- We share your personal information with third party contractors and service providers to the extent necessary to fulfil your order.
6.2- We share your information with other third parties as follows:
6.2.1 - our regulators, professional advisors, insurance provider and auditors;
6.2.2 - HMRC or other government or law enforcement agencies;
6.2.3 - if we sell any business or assets, in which case we may disclose your personal information to the prospective buyer of such business or assets;
6.2.4 - payment service providers when you purchase products via the website;
6.2.5 - if we have a legal obligation to do so; and
6.2.6 - for the purposes of fraud protection and credit risk reduction. The categories of third parties listed above use your personal data for their own purposes and are responsible for their own compliance with data protection legislation.
6.3- We also share your data with third-party service providers who provide services to our business, such as our online transaction processing, order fulfilment provider, marketing and communications providers, website host server, IT support and maintenance service, cloud storage provider and email exchange server, delivery services and other businesses that provide certain services on our behalf. All of our third-party service providers are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow our third-party service providers to use your personal data for their own purposes.
7.1- We have put in place:
7.1.1 - Appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
7.1.2 - Procedures to deal with any suspected data security breach, and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
7.1.3 - All of our employees who have access to your personal data are required to enter into non-disclosure or similar agreements, which imposes obligations on them to comply with our data privacy and confidentiality requirements.
7.1.4 - We require any business partners and third party service providers with whom we may share your personal data to comply with any applicable data privacy and confidentiality requirements.
7.1.5 - We provide data privacy training on a regular basis to our employees and third parties who have access to personal data.
Transferring information outside the EEA
7.2- Any personal information that you submit to us will be held on secure servers, based within the UK or the European Economic Area (EEA).
7.3- If we are required to transfer your information outside the UK or the EEA, we have put in place appropriate measures to ensure that your personal information is treated by those third parties in a way that is consistent with and which respects the EU and UK laws on data protection.
7.4- If you are based outside the UK or the EEA we may transfer personal information to the correspondence address you provide to us to the extent necessary to complete your order. We will take all reasonable steps to ensure that such transfers are secure. By instructing us from outside the UK or EEA you agree that such transfer is necessary for us to complete your order.
7.5- We use Google Analytics to evaluate the performance of our site and improve the service we offer you. We may transfer information about you outside the UK or EEA for this purpose. We will only do so where permitted by law.
7.6- Google Analytics complies with the EU-US Privacy Shield Framework as set out by the US Department of Commerce regarding the collection, use and retention of personal information from European Union member countries. It is subject to enforcement by the Federal Trade Commission. Google, including Google Inc. and its wholly-owned US subsidiaries, has certified that it adheres to the relevant Privacy Shield Principles, including for Google Analytics. For more information about this protective measure, please visit the following: https://www.google.co.uk/intl/en/policies/privacy/frameworks/.
HOW LONG WILL WE KEEP YOUR PERSONAL INFORMATION FOR?
8.1- We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
8.2- To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
8.3- We keep basic information about our customers (including Contact, Identity and Transaction Data) for five years after they cease being customers for tax purposes and for the purpose of any legal claims.
8.4- We keep Identity Data including Ophthalmic Prescription and Medical Data for 10 years in line with the requirements of the General Optical Council.
8.5- In some circumstances you can ask us to delete your data: see your rights below for further information.
8.6- In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
9.1- You have the following rights:
9.1.1 - to be told what we are doing with your personal information. We do this by providing you with this privacy notice;
9.1.2 - to correct or update the personal information we hold about you.
9.1.3 - to object to the processing of your personal information;
9.1.4 - to request a copy of the personal information we hold about you;
9.1.5 - to ask us to delete the information that we hold about you where there is no good reason for us continuing to process it;
9.1.6 - to ask us to stop processing your personal information where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground and where there is no good reason for us continuing to process it;
9.1.7 - to ask us to restrict how we use your personal information for a period of time if you claim that it is inaccurate and we want to verify the position or in some limited other circumstances;
9.1.8 - to ask us to send your personal information to another organisation in a computer-readable format;
9.1.9 - to complain to the Information Commissioner's office if you are unhappy with our use of your personal data: you can do this at https://ico.org.uk/concerns/. Do contact us straight away if you consider that we are not handling your personal information properly so we can try and sort the problem out.
9.2- If we delete your personal information or restrict our use of it, we will not be able to provide our services to you.
9.3- If you want to exercise any of your rights, please contact email@example.com. We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights).
We regularly review our compliance with our Privacy Notice, in particular to make it compliant with new laws and regulations regarding data protection. But, even if this Privacy Notice may change from time to time, we will not reduce your rights under this Privacy Notice without your explicit consent.
Last updated November 2021