<h1>DATA PROTECTION POLICY</h1>
<h2>Who we are</h2>
Thank you for visiting CREXCELL Limited’s website, crexcell.com.
Protecting consumer privacy is very important to CREXCELL Limited, and we are committed to ensuring that your privacy is protected. We believe that information used responsibly benefits consumers and the economy, whether it is information we house on behalf of consumers conducting transactions or information we collect on behalf of our business clients.
Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement and compliance with the EU's General Data Protection Regulation (GDPR) 2018.
All our managers are responsible for ensuring their area and that reports comply with this Data Protection Policy. The Data Protection Officer is responsible for overseeing this Data Protection Policy and, as applicable, developing further related policies and guidelines. That post is held by Mike Merritt, and their contact details are at the bottom of this page.
CREXCELL Limited may change this policy from time to time by updating this page. You should review this statement whenever you visit to obtain the most current statement. You may change your choices at any time.
This policy is effective from May 25, 2018, and is reviewed every three years.
<h2>What is covered in this policy</h2>
CREXCELL Limited is committed to doing what is right when it comes to the collection, use, and protection of your personal data. This privacy and cookies policy covers the following:
<li>sets out the types of personal data that we collect. </li>
<li>explains how and why CREXCELL Limited collects and uses your personal data. </li>
<li>explains when and why we will share personal data within the CREXCELL Limited group and with other organisations. </li>
<li>explains your rights and choices when it comes to your personal data. </li>
We want you to be clear about what this policy covers. This policy applies to you if you use our services.
<h3>Using our services means: </h3>
<li>doing business with us online, over the phone, or by using any of our websites or mobile applications.</li>
This policy also applies if you contact us or we contact you about our services. Our business may need to collect and use personal data to provide you with services and for other purposes.
<h2>What personal data we collect and why we collect it </h2>
We may collect the following information:
<li>name, title, and job title. </li>
<li>contact information including full postal address (billing and delivery), email address, and landline and mobile phone numbers. </li>
<li>orders and receipts</li>
<li>demographic information such as postcode, preferences, and interests. </li>
<li>payment information and IP addresses. </li>
<li>details of your visits to our site including, but not limited to traffic data, location data, weblogs and other communication data. </li>
<li>notes made during from conversations with you. </li>
<li> other information relevant to customer surveys and/or offers. </li>
<li> information regarding devices used whilst accessing our sites such as desktop, laptop, or mobile phone, which may also include your IP address. </li>
<h2>Where we collect it from</h2>
CREXCELL Limited collects personal information in order to offer or provide services to our customers. We may obtain this information from various sources:
<li>directly from customer applications, questionnaires, and other materials submitted to us by customers. </li>
<li>from transactions in which CREXCELL Limited and customers are involved. </li>
<li>from click-through activity on our websites. </li>
<li>from a variety of third-party sources, such as our business customers, government repositories, consumer reporting agencies and other financial institutions. </li>
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
When visitors contact us via our contact form, we collect the data submitted, and also the visitor’s IP address and browser user agent string to help spam detection.
<h3>Embedded content from other websites</h3>
If our website is using Google Analytics, it collects information and CREXCELL Limited’s user and event data retention controls setting will be 24 months for data that is associated with user identifiers, including cookies and advertising ids. Google Analytics Data Retention controls set the amount of time before user-level and event-level data stored by Google Analytics is
automatically deleted from Analytics’ servers. You can opt out of Google Analytics by installing a Google Analytics opt-out browser add-on at the Google Analytics opt-out page (https://tools.google.com/dlpage/gaoptout).
<h2>What we do with the information we gather</h2>
We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
<li>for internal record keeping. </li>
<li>go improve our products and services. </li>
<li>go send promotional emails about new products, special offers or other information which we think you may find interesting using the email address which you have provided. </li>
<li>go contact you for market research purposes by email, phone, fax, or post. </li>
<li>to customise the website according to your interests. </li>
<h3>How we use your personal data</h3>
Data protection states that we can only use or share your personal data obtained if and when we have a legitimate reason to do so. These can be:
<li>Contract: The personal information provided to us allows us to complete our contractual agreement of processing and fulfilling your order. For sending emails, promotional material about services we provide that may be of interest to you. </li> <li>Consent: Your agreement for us to use your personal data in this way. </li> <li>Legitimate interests: For CREXCELL Limited to manage our business and provide our customers with the best services and the highest level of customer service and care. That is, transferring of your data to third-party partners. </li> <li>Legal obligation: Statutory or other legal requirements to share your information. That is, if requested to by law. </li>
If you choose not to share your personal data with us or refuse certain contract permissions, it may result in us not being able to provide some services that you may require. That is, if we have no consent to contact you we may not be able to let you know when an out of stock item is back in inventory. <ul> <li>Reasons for using your personal information: Setting up your account.
<ul> <li>Our reason for use: Legitimate Interest. </li>
<li>Our explanation of legitimate interest: For accurate and efficient processing of your details. </li>
<ul> <li>Reasons for using your personal information: Processing your order / payment.
<ul> <li>Our reason for use: Fulfilling our contractual obligations / Legitimate Interest. </li>
<li>Our explanation of legitimate interest: Without this information we cannot process your order and comply with our contractual obligation. </li>
</ul> </li> </ul>
<li>Reasons for using your personal information: Notify you of your order status.
<ul> <li>Our reason for use: Legitimate Interest. </li>
<li>Our explanation of legitimate interest: To be efficient in delivering updates on your order status throughout. To improve our service. </li>
</ul> </li> </ul>
<ul> <li>Reasons for using your personal information: Managing your account / customer service / queries / refunds / customer complaints. Including transfer to third-parties who undertake customer services, communication on our behalf.
<li>Our reason for use: Legitimate Interest / Contractual Obligations / Legal Obligation. </li>
<li>Our explanation of legitimate interest: Handling customer contacts in an effective and efficient manner. Up-to-date record-keeping. We may keep your details for a reasonable time afterwards to fulfil obligations of refunds and similar activities. Help improve processes and services we provide. Comply with legal obligations or regulations. </li>
</ul> </li> </ul>
<li>Reasons for using your personal information: Marketing communications, online advertising, special offers, new lines and sales.
<li>Our reason for use: Legitimate Interest. </li>
<li>Our explanation of legitimate interest: Improving customer interaction. Service development. Improve website look and functionality to attract and retain customers. </li>
<li>Reasons for using your personal information: Website and service enhancement notifications that may be of interest.
<ul> <li>Our reason for use: Legitimate Interest. </li>
<li>Our explanation of legitimate interest: Improving customer interaction. Product and service development. Improve website look and functionality to attract and retain customers. </li>
<ul> <li>Reasons for using your personal information: Maintain network and security (protect our business).
<ul> <li>Our reason for use: Legitimate Interest. </li>
<li>Our explanation of legitimate interest: For the security of our network and to help maintain confidentiality and safety of your personal information stored by us. Update and safeguard your account. You may opt out of hearing from us by post or email communications. </li>
<h3>Sharing your personal details with others</h3>
CREXCELL Limited may work with trusted suppliers and businesses for the provision of our services, IT companies for our business website support, or payment processing services to provide an excellent level of customer service. Some examples of third parties with whom we may share your data include:
<li>Third-party companies: To guarantee the delivery of our services we supply companies with limited information. This could be your full name, address, contact telephone numbers, and notes provided by you. </li>
<li>IT companies: These are businesses that design, help, and support our website and other business systems. </li>
<li>Payment processing companies: These could be trusted payment processing providers to take and manage your payments securely. We will only supply them with limited information relevant to the successfully process your payment. </li>
<li>Marketing companies: We may work with marketing companies to manage emails / electronic communications, surveys, and product review requests. </li>
<li>Social media sites / Google: This is to show products that may be of interest to you and is based on marketing consent ad acceptance of cookies on our website. </li>
<li>Fraud management and prevention: We may ourselves, or if requested to by law enforcement bodies, process and share your personal data or information regarding fraudulent or potentially fraudulent activity to protect our business and to comply with laws in place to prevent fraud and money laundering. Fraud prevention agencies have a right to store your personal data for different periods of time. In some cases, they are permitted to hold your data for up to 6 years. </li>
<li>International transfer of your personal data out with the EU: Information provided to us by you may on occasion be transferred to a “third country” which is out with the EU. Although the personal data we hold is stored in the UK, on occasion our IT web designer and host may have to speak to IT departments located in other countries for support. We also work with partners/suppliers that may use cloud-hosted technology. Data security is key, and we ensure partners conform to appropriate accreditations. We will contractually ensure the confidentiality and security of your personal data at all times if and when we transfer any information out with the EU. </li></ul>
Your rights: Your personal data is protected by legal rights. You have a legal right to request for your personal data held by is to be erased, amended or to be made accessible to you. You can also object to the processing of your personal data by us.
A cookie is a small file which asks permission to be placed on your computer's hard drive. Once you agree, the file is added, and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website to tailor it to customer needs. We only use this information for statistical analysis purposes, and then the data is removed from the system.
Overall, cookies help us provide you with a better website by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies. However, declining cookies may prevent you from taking full advantage of the website.
<h3>Third-party tracking cookies</h3>
We allow selected third parties who assist us with marketing to place cookies when you visit our site to assist us with target marketing of relevant ads. The sites we use are Google Analytics, Facebook Connect, and Google Tag Manager. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on at the Google-Analytics-opt-out page (https://tools.google.com/dlpage/gaoptout).
<h2>Links to other websites</h2>
Our website or mobile apps may contain links to other websites operated by other organisations that have their own privacy policies. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites, and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
<h2>How long we retain your data</h2>
We keep your personal data for the duration of the period you are a customer of CREXCELL Limited. We retain your data only for as long as necessary in accordance with applicable laws. On the closure of your account, we may keep your data for up to 6 years after you have cancelled your services with us. We may not be able to delete your data before this time due to our legal and/or accountancy obligations. We may also keep it for research or statistical purposes. We assure you that your personal data shall only be used for these purposes stated herein.
<li>Period data held: The law requires us to hold personal data we have for a reasonable length of time (as stated above) or delete it sooner. </li>
<li>Exercise your rights: You have the right to request your data to be erased (where it applies). All data not permitted for any other reason or by law will be erased. </li>
<li>Bringing or defending a legal claim: We will retain your personal information for the duration of the proceedings and until we are sure no further appeals are possible. </li>
<h3>Data retention of comments</h3>
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.
<h4>What rights you have over your comments data</h4>
If you have an account on this site or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
<h4>Where we send your comments data</h4>
Visitor comments may be checked through an automated spam detection service.
<h2>How we protect the confidentiality of personal consumer information</h2>
CREXCELL Limited limits access to personal information to those employees of CREXCELL Limited and its affiliates who need it to fulfil their business responsibilities.
Employees must adhere to CREXCELL Limited privacy policies. Employees violating these policies may be subject to disciplinary action, up to and including dismissal.
Vendors and other outside contractors we engage are subject to our contractual requirements to ensure that sensitive personal information is safeguarded.
<h3>Our appropriate security safeguards</h3>
We are committed to ensuring that your information is secure and have procedures in place to effectively detect, report, and investigate a personal data breach.
To prevent unauthorised access or disclosure, alteration or destruction, we use suitable physical, electronic, and managerial procedures to safeguard and secure the information we collect online.
The appropriate security safeguards may include encryption, physical access security, and other appropriate technologies. CREXCELL Limited continually reviews and enhances its security systems.
<h2>Quality of information collected</h2>
CREXCELL Limited employs appropriate measures to assure the quality of information we collect directly from consumers.
Where CREXCELL Limited collects information directly from consumers or sources other than our business customers, we permit them, if possible, to dispute or correct any erroneous or out-of-date personally identifiable information. Of course, this correction would not be possible if the information is proprietary to one of our business customers, reflects historical transaction information, or if correction would violate the privacy or legal rights of a third party. Where applicable, we abide by laws related to such information.
<h2>Controlling your personal information</h2>
You may choose to restrict the collection or use of your personal information in the following ways:
<li>whenever you are asked to fill in a form on the website, look for the box that you can click to indicate that you do not want the information to be used by anybody for direct marketing purposes. </li>
<li>if you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by writing to or emailing us at the address below. </li>
We will not sell, distribute, or lease your personal information to third parties unless we have your permission or are required by law to do so. We may use your personal information to send you promotional information about third parties which we think you may find interesting if you tell us that you wish this to happen.
<h2>What are your rights over personal data held</h2>
Data Subject Rights: You are entitled at any time to request any of the following information or amendments. For further detailed information, please visit the Information Commissioners Website at www.ico.org.uk.
<li>Right of access: The right to request full access to your personal information held by us and information relating to how we process this data. </li>
<li>Right to rectifications: The right to obtain without undue delay the rectification of inaccurate or incomplete personal data completed. </li>
<li>Right to erasure (‘right to be forgotten’): The right to simply have your personal data held by us erased. To do this, contact us. </li>
<li>Right to restriction of processing: The right to restriction of processing of the processing of personal information. <
<li>Right to data portability: The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services. </li>
<li>Right to object: The right to object to the processing of your personal data. </li> <li>Rights about automated decision making and profiling: Automated individual decision-making (making a decision solely by automated means without any human involvement); and profiling (automated processing of personal data to evaluate certain things about an individual). </li></ul>
<h3>Accessing and updating your data</h3>
If you believe that any information we are holding on you is incorrect or incomplete, you can correct factual errors in your personally identifiable information by sending us a written request, by email or post to the address below, that credibly shows error. We reserve the right to independently verify claims. To protect your privacy and security, we will also take reasonable steps to verify your identity before making corrections. We reserve the right to assess a service charge for providing you with any information in connection with your request.
You have the right to access the information we hold about you. You may request details under the EU's General Data Protection Regulation (GDPR) 2018. A small fee will be payable. If you would like a copy of the information held on you, please write to the address below.
<h2>Our contact details</h2>
Mike Merritt Data Protection Officer (DPO)
CREXCELL Limited, PO Box 28647, Edinburgh EH4 9ER
Telephone: 07753 749543