Privacy Notice for John H Lunn (Jewellers) Ltd - (Lunn’s Jewellers)
We want you to know that when you use our organisation you can trust us with your information. We are determined to do nothing that would infringe your rights or undermine your trust. This Privacy Notice describes the information we collect about you, how it is used and shared, and your rights regarding it.
We are registered with the Information Commissioner’s Office (ICO) as a Data Controller for the personal data that we hold and process. Our registered address is 7-21 Queen’s Arcade, Belfast, BT1 5FE our registration number is Z5260390.
The vast majority of the information that we hold about you is provided to us by yourself when you seek to use our services. We will tell you why we need the information and how we will use it.
Our Lawful Basis for processing your information
The General Data Protection Regulation (GDPR) requires all organisations that process personal data to have a Lawful Basis for doing so. The Lawful Bases identified in the GDPR are:
- Consent of the data subject
- Performance of a contract with the data subject or to take steps to enter into a contract
- Compliance with a legal obligation
- To protect the vital interests of a data subject or another person
- Performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
- The legitimate interests of ourselves, or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject.
Examples of legitimate interests include:
- Where the data subject is a client or in the service of the controller;
- Transmission within a group of undertakings for internal administrative purposes;
- Processing necessary to ensure network and information security, including preventing unauthorised access;
- Processing for direct marketing purposes, or to prevent fraud; and
- Reporting possible criminal acts or threats to public security.
Our Lawful Basis is performance of a contract and our Legitimate Interest is that you are a client, or have been a client of John H Lunn (Jewellers) Ltd.
We use your information to:
- Provide goods, services, deliveries, quotations, and information, for example, catalogues and newsletters;
- Process or support payments and deposits for goods, special orders and services;
- Conduct data analysis, testing, and research (including for product development), and to monitor and analyse usage and activity trends;
- Maintain the safety, security and integrity of our services and to protect our business and your account from fraud and other illegal activities;
- Direct your enquiries to the appropriate department, sales professional, service and customer support staff;
- Investigate and address your concerns;
- Communicate with you about products, services, promotions, studies, surveys, news, updates and events;
- Process promotions/competitions, including prizes, and send you information about our services and those of our business partners;
- Investigate or address legal proceedings relating to your use of our services/products, or as otherwise allowed by applicable law;
- Respond to your queries and refund requests;
- Protect our customers, premises, assets and staff from crime, through the operation of CCTV systems in our stores which record images for security. We do this on the basis of our legitimate business interests.
- Send you communications required by law or which are necessary to inform you about our changes to the services we provide you. For example, updates to this Privacy Notice, product recall notices, and legally required information relating to your orders.
- Send you communications required as part of our legitimate business interests to inform you of product becoming available for collection.
Where any part of our processing includes automated decision-making, for instance in deciding to offer retail finance, we ensure that the proposed decisions are reviewed by a member of staff before being applied. You will always be able to get an explanation for the decision and to challenge it if you are unhappy with it.
We collect and process both personal data and special categories of personal data as defined in the GDPR. This includes:
- Phone number;
- Payment or bank details;
- Date of birth;
- Location details;
- Device IP address;
- Details of your internet connection and browser;
- Details of your interactions with us in store or, online;
- Billing/delivery address;
- Details of orders, repairs, valuations, insurance estimates and receipts;
- Copies of documents you provide to prove your age or identity where the law requires this;
- Details of your visits to our websites;
- Personal details which help us to recommend items of interest;
- Payment card information;
- Your comments and product reviews;
- Your image may be recorded on CCTV when you visit a shop;
- Your social media username, if you interact with us through those channels, to help us respond to your comments, questions or feedback;
We may share your personal data with:
- Delivery partners such as Royal Mail & FedEx
- Our Business Partners
- The general public when we contribute to a public forum such as Facebook, Instagram or Twitter;
- Our legal advisors in the event of a dispute or other legal matter;
- Law enforcement officials, government authorities, or other third parties to meet our legal obligations;
- Any other party where we ask you and you consent to the sharing;
- IT companies who support our website and other business systems;
- Direct marketing companies who help us manage our electronic communications with you.
- Data insight companies to ensure your details are up to date and accurate.
Transfers to third countries and international organisations
In certain circumstances such as registering your watch guarantee, we may transfer personal data to third countries such as Switzerland or international organisations using the identified safeguards. We have satisfied ourselves that such transferred data is fully protected and safeguarded as required by the General Data Protection Regulation.
We retain your personal data while you remain a customer unless you ask us to delete it. Our Retention and Disposal Policy (copy available on request) details how long we hold data for and how we dispose of it when it no longer needs to be held. We will delete or anonymise your information at your request unless:
- There is an unresolved issue, such as claim or dispute;
- We are legally required to; or
- There are overriding legitimate business interests, including but not limited to fraud prevention and protecting customers' safety and security.
The General Data Protection Regulation gives you specific rights around your personal data. For example, you have to be informed about the information we hold and what we use it for, you can ask for a copy of the personal information we hold about you, you can ask us to correct any inaccuracies with the personal data we hold, you can ask us to stop sending you direct mail, or emails, or in some circumstances ask us to stop processing your details. Finally, if we do something irregular or improper with your personal data you can seek compensation for any distress you are caused or loss you have incurred.
You can find out more information from the ICO’s website https://ico.org.uk/your-data-matters/ and this is the organisation that you can complain to if you are unhappy with how we deal with you.
Accessing and Correcting Your Information
You may request access to, correction of, or a copy of your information by contacting us via mail or in person at John H Lunn Jewellers, 7-21 Queen’s Arcade, Belfast, BT1 5FE; by phone at 44 2890 329799 or via email at firstname.lastname@example.org
You may opt out of receiving emails and other messages from our organisation by following the instructions in those messages.
- Validate users;
- Remember user preferences and settings;
- Determine frequency of accessing our content;
- Measure the effectiveness of advertising campaigns;
- Analyse site visits and trends.
We will occasionally update our Privacy Notice. When we make significant changes, we will notify you of these through either mail or email. We will also publish the updated Notice on our websites.