THE MIGHTY BEETROOT™
The Mighty Beetroot values our customers and respects their privacy. Any information about you is held with the utmost care and security.
In order to provide our site, products and services to you and to promote our business, we will need to collect and process certain information about you. We are committed to protecting the privacy of our customers in accordance with applicable data protection laws, including the General Data Protection Regulation (together, ‘Data Protection Laws’).
Under applicable Data Protection Laws, we will be the ‘data controller’ of the personal information that we collect about you in connection with your use of our products, services and site.
WHEN WE COLLECT INFORMATION
We will collect personal information about you in these circumstances:
- When you fill in any forms on our site
- When you contact us by phone, email, post, in person or otherwise interact with us or provide information to us
- When you attend an event or workshop or when we meet you in the provision of our services
- When you place an order for any products or services or make a booking
- When you subscribe to notifications, emails, newsletters or other communications
- When you redeem a benefit, enter a promotion, competition or survey
- When you submit payment information to us
- When you visit our site
WHAT INFORMATION WE COLLECT
We may collect the following types of personal information about you:
- Your name
- Telephone number
- Email address
- Home or venue address
- Dietary requirements, allergies and preferences
- Other information relevant to your order or booking or use of our services
- Some limited demographic information relevant to our business
- Payment card or billing details
- We may also derive some information about you when you visit our site or open emails that we send to you, including general user information about your computer and your visits (including your IP address, location, browser, operating system, referral source, length of visit and the pages you visit). This information can be facilitated by cookies (see our Cookies policy below)
HOW WE USE YOUR INFORMATION
We may use your information in a number of ways, including:
- Identifying you and managing your relationship with us
- Processing your orders and bookings and notifying you of the status of any orders or bookings
- Sending you newsletters and notifications you have subscribed to
- Discussing and advising you in relation to your purchase of any products or services and our site
- Enhancing and improving our business
- Promoting our similar goods and services to you and inviting you to events, unless you opt out at any time
- Managing our business, including for accounting and auditing purposes
- Maintaining our site and IT systems
- Dealing with any complaints or legal disputes involving you or our suppliers
- Preventing fraud
LAWFUL BASIS ON WHICH WE USE YOUR INFORMATION
We will only ever use your personal information as permitted under Data Protection Law, which means one or more of the following will always apply:
- To perform our contractual obligations
- To comply with our legal and regulatory obligations
- In pursuing our legitimate interests or those of a third party (for example, conducting our business in an efficient and compliant manner) and where your interests and fundamental rights do not override these interests
- Where you have given clear and valid consent to such use.
We do not sell or share your personal information with third parties for their own marketing purposes.
THIRD PARTIES WE WORK WITH
From time to time we may retain the services of other carefully selected partners and suppliers to perform functions on our behalf, which may involve sharing your information with them. Examples of these functions would include third parties involved in:
- Training and demonstrations at our workshops
- Speaking and helping at our events
- Assisting us to process your orders
- Authorising and validating credit or debit card transactions (we use Stripe)
- Providing other payment gateways (e.g. www.Paypal.com)
- Delivery services
- Website hosting and support
- Newsletter distribution
- PR and printing services
- Invoicing, accountancy and legal services
These third parties may be provided with access to your personal details in order to fulfil their main function but we will contractually restrict them from using such information for any other purpose.
In addition, we may disclose your personal information to third parties in the following situations:
- To our regulators and law enforcement agencies
- In the context of a possible sale or restructuring of our business;
- If we or substantially all of our assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets on the same terms and conditions as herein;
- If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms and conditions or other agreements; or to protect the rights, property, or safety of us, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.
All third parties are required to respect the confidentiality of your personal information. They are required to take appropriate security measures to protect your personal information. We do not allow them to use it for their own purposes, but only as we specify and in accordance with our instructions.
THIRD PARTY SITES AND SERVICES
Our site may contain links to third party websites. Please be notified that we cannot be held responsible for the privacy practices of other websites. We encourage all visitors to be aware and read the privacy statements of each and every website that collects personally identifiable information.
WHERE YOUR INFORMATION IS STORED
Your information will be held at our premises in Surrey and our site is hosted within the EEA.
TRANSFERS TO THIRD COUNTRIES AND SAFEGUARDS
HOW WE KEEP YOUR PERSONAL INFORMATION SAFE
We will safeguard your information in our custody. We have developed and will maintain adequate security procedures to safeguard personal information against loss, theft, copying, and unauthorised disclosure, use or modification. Access to personal information is restricted to employees and authorised individuals and companies who need it to perform their work. We also regularly review our information collection, storage and processing practices, including physical security measures, to guard against unauthorised access to systems.
RETENTION OF RECORDS
We will do our best not to keep your personal information for longer than necessary to facilitate your use of our site, products and services, other than as required by law. We will regularly review the information that we hold and delete unnecessary information from our systems.
Unless you request otherwise, we may retain information that will make our relationship more convenient and safer, such as your previous orders, but you have the right to ask us to delete any information that we hold about you – see the Your Rightssection below.
When your personal information is no longer required, it will be destroyed either by shredding or other approved destruction methods to prevent unauthorised parties from gaining access to the information during and after the process.
You have several rights as a data subject as summarised below:
- Access: You have the right to obtain confirmation as to whether your personal information is being processed by us and, if it is, to access your information and details of how we process it, as long as this does not adversely affect the rights and freedoms of others.
- Rectification: We will rectify any errors in the personal information we hold on request.
- Erasure: You may ask us to erase your personal information from our systems in the following situations:
- The information is no longer necessary in relation to the purpose for which it was collected;
- You withdraw your consent on which the processing is based and where there is no other legal ground for the processing;
- You object to the processing and there are no overriding legitimate grounds for the processing;
- The information has been unlawfully processed;
- The information has to be erased for compliance with a legal obligation to which we are subject.
- Right to restrict processing: You have the right to restrict our processing on specified grounds.
- Notification: Where you have asked us to rectify, erase or restrict processing of your information, we shall communicate the same to each recipient to whom your information has been disclosed, unless this proves impossible or involves disproportionate effort, in which case we shall let you know.
- Data portability: You have the right in specific circumstances where processing is based on consent to receive your information in a structured, commonly used and machine-readable format and have the right to transmit the information to another controller without hindrance, provided that our processing is carried out by automated means.
- Right to object: In certain circumstances you have the right to object to our processing of your information, including in relation to profiling, direct marketing or scientific or historical research purposes.
- Right to complain to a supervisory authority: You are entitled to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk in relation to our use of your personal data.
HOW TO EXERCISE YOUR RIGHTS
To exercise any of your other data subject rights, please contact us (see Contacting Us above):
- You may request a copy of information undergoing processing, subject to evidence of your identity (normally a certified copy of your passport plus an original copy of a utility bill showing your current address). The first copy shall be provided without charge, but reasonable administration fees shall be charged for additional or subsequent copies.
- We shall respond to your requests without undue delay and in any event within one month unless we need to extend such period by up to two further months in specific circumstances.
- Please note that if you delete or restrict your account or required information, this may prevent you from making full use of our site, products or services.
WHAT HAPPENS IF A DATA BREACH OCCURS
Whilst we endeavour to keep your personal information safe, we have an internal investigation procedure in case of data protection security breaches.
In the event of data theft, we may suspend access to our servers, emails and online systems and take other urgent steps to prevent further unauthorised access to information.
If we believe that our data has been compromised, we will report the issue to the Information Commissioner’s Office (ICO) at www.ico.org.uk.
We will notify you without delay if we believe a data breach is likely to result in a significant risk to your rights and freedoms. Any notification will describe in clear and plain language the nature of the personal data breach and contain all required information.
Policy last revised: July 12 2019