General data privacy information
As of 25 May 2018 the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on protection of natural persons with regards to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – the “GDPR”) has entered into force.
As part of our GDPR compliance policy we want to be completely clear about what data we hold about you and how we use it.
As our client and/or business partner you will be receiving the communication relating to your orders, responses to your requests and inquiries as well as messages relating to the conclusion and/or performance of contracts with our company. The processing of your personal data such as e.g. name, address, email address, phone number and – for business contacts - company details and the function within the company - will be necessary to conclude contracts, realize orders and/or develop business cooperation. This information will be processed based on the contractual grounds, as per Art. 6.1. a) of the GDPR. If we do not receive such data, in most cases we will not be able to realize the orders or the cooperation.
If you provide us with us the consent to send you marketing information - we would like to contact you with valuable insights through email updates or to invite you to events from time to time. We will predominantly do this electronically and sometimes via post.
If you change your mind at any time, you can update your preferences by clicking on 'Manage preferences' at the bottom of any marketing email or by emailing us at email@example.com. The above tools will enable you to exercise your right to withdraw your consent to process your personal data by our company. Furthermore, you have the right to access, rectify or erase your personal data in our data base as well as object to processing of your personal data, subject to the provisions of the GDPR.
The personal data controller in the above cases is: Graff Cosmetics, with its registered address at 2 Market Street Shrewsbury, Shropshire
If you do wish to opt out of receiving any further marketing communications, we'd still welcome you to follow our social media pages by clicking on the icons below to allow you to keep sight of what we're up to.
We will do our best to protect your personal data and our internal policies have been implemented in order to ensure this. However, should you have any additional requests, you may contact us as firstname.lastname@example.org or lodge a complaint with ICO (Information Commissioner’s Office) which is the supervisory authority competent for the territory of the United Kingdom in terms of personal data protection.
Information we may collect from you on our Media
We may collect and process the following data submitted to us via internet solutions:
If we ask you for your contact details for future marketing use, we will process the contact details you provide to us, although you have the option to opt-out of such use. This information will be processed based on the contractual grounds, as per Art. 6.1. a) of the GDPR.
If you contact us, we may keep a record of your email or other correspondence, including any content that you submit to our staff via Media, for example through the “Contact Us” function. This information will be processed based on the contractual grounds, as per Art. 6.1. f) of the GDPR.
We may collect information about your device including, where available, your IP address, operating system and browser type, for system administration and to report aggregate information. This is statistical data about our users’ browsing actions and patterns, and does not identify any individual.
If you are providing us with personal information about any other person, you confirm that you have obtained his or her consent and made him or her aware of this policy before providing the information to us.
To enhance your experience, the Media use “cookies.” Cookies are text files we place in your computer's browser to store your preferences. Cookies, by themselves, do not tell us your e-mail address or other personally identifiable information unless you choose to provide this information to us by, for example, registering to use the Media. However, once you choose to furnish the Media with personally identifiable information, this information may be linked to the data stored in the cookie.
Where we store your personal data
In order to be able to offer you Klarna’s payment options, we will pass to Klarna certain of your personal information, such as contact and order details, in order for Klarna to assess whether you qualify for their payment options and to tailor the payment options for you.
Uses made of the information
We use information we hold in the following ways:
To ensure that content on the Media is presented in the most effective manner
To carry out our obligations in connection with any transactions you enter into via the Media
To allow you to participate in interactive features of our service, when you choose to do so
To notify you about changes to our service
To provide you with information and offers that we or selected third parties feel may interest you
We will only contact you by electronic means (email or SMS) with information about goods and services similar to those which were the subject of a previous sale to you. If you are a new customer, and where we permit selected third parties to use your data, we (or they) will contact you by electronic means only if you have consented to this.
If you do not want us to use your data for marketing purposes, or to pass your details on to third parties for marketing purposes, please tick the relevant box situated on the form on which we collect your data. You may also contact us with such requests by email at email@example.com.
Disclosure of your information
We may disclose your personal information to any member of our Group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006, to our licensors, in particular Shopify, and to relevant third parties for the purpose of fraud protection and credit risk reduction.
Your right to restrict the processing of your personal data
Your personal data will be processed by us for the time necessary for processing your orders and for providing you with the product updates and marketing information which you requested.
You have the right to ask us not to process your personal data for marketing purposes. We will inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by ticking/unticking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by writing to: Graff Cosmetics 2 Market Street Shrewsbury, Shropshire
Please note that in certain cases we will not be able to erase your data – in particular in the cases which require additional legal steps to protect the legitimate interests of our company as the data controller such as claims management or financial documentation required by laws.
Our site contains links to and from the websites of our licensors, including Shopify, advertisers and other third parties. If you follow a link to any of these other websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies or for these third party websites. Please check these policies before you submit any personal data to these websites.
Access to your personal data
The Data Protection Act 1998 of the United Kingdom gives you the right to check that your personal data is being processed lawfully (“subject access right”). Your subject access right can be exercised in accordance with that Act.
Any subject access request must be made in writing to: Graff Cosmetics, 2 Market Street Shrewsbury, Shropshire and shall be free of charge for the first request you file with us in this regard; further requests may be subject to a fee of £10 to meet our costs in providing you with details of any personal data we hold about you as a cost of managing such requests.