Privacy Notice

Araca Merch Europe Limited

Araca Merch Europe Limited ("we", "us" and "our") is committed to protecting your privacy. This privacy notice sets out how your personal data is collected, used and shared and tells you about your rights in relation to your personal data. This includes personal data we process when you visit or purchase goods from our webstores (each a "website").

Who is responsible for your personal data?

We are responsible for your personal data.

If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the us using the information set out below.

This website is not intended for children, and we do not knowingly collect data relating to children.

The types of personal data we collect

We may collect, use, store and transfer different kinds of personal data about you:

·                         Identity and Contact Data: includes name, marital status, title, billing address, delivery address, email address and telephone number.

·                         Payment and Transaction Data: includes payment card details, details about payments to and from you and other details of products you have purchased from us.

·                         Technical Data: includes [internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website].

·                         Profile and Usage Data: includes your feedback and survey responses, and information about how you interact with and use our website and products.

·                         Marketing and Communications Data: includes your preferences in receiving marketing from us and our third parties and your communication preferences.

How we collect personal data

We use different methods to collect personal data including when you:

·                         Fill in online forms or correspond with us by post, phone, email or otherwise or order goods using our website. In this case, we collect Identity and Contact Data, Payment and Transaction Data, Profile and Usage Data, and Marketing and Communications Data.

·                         Use our website and we automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies [, server logs] and other similar technologies. [We may also receive Technical Data about you if you visit other websites employing our cookies.] Please see our cookie notice for further details.

How we use personal data

Legal basis

Under data protection law, we can only use your personal data if we have a proper reason, which will be:

                     where you have given consent;

                     to comply with our legal and regulatory obligations;

                     for the performance of a contract with you or to take steps at your request before entering into a contract; or

                     for our legitimate interests or those of a third party.

A legitimate interest is when we have (or a third party has) a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. We will carry out an assessment when relying on legitimate interests, to balance our interests (or those of the relevant third party) against your own.

Purposes for which we will use your personal data

We have set out below, in a table format, a description of all the ways we plan to use the various categories of your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Purpose/Use

Type of data

Legal basis

To register you as a new customer

Identity and Contact

 

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to allow us to register customers)

 

To process and deliver your order including to:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(a) Identity and Contact

(b) Payment and Transaction

 

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to recover debts due to us)

 

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy notice

(b) Dealing with your requests, complaints and queries

(a) Identity and Contact

(b) Profile and Usage

(c) Marketing and Communications

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and manage our relationship with you

 

To enable you to complete a survey

(a) Identity and Contact

(b) Profile and Usage

(c) Marketing and Communications

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to study how customers use our products, to develop them and grow our business)

 

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

(a) Identity and Contact

(b) Technical

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation

 

To deliver relevant website content and online advertisements to you and measure or understand the effectiveness of the advertising we serve to you

(a) Identity and Contact

(b) Technical

(c) Profile and Usage

(d) Marketing and Communications

 

Necessary for our legitimate interests (to study how customers use our products, to develop them, to grow our business and to inform our marketing strategy)

 

To use data analytics to improve our website, products, customer relationships and experiences and to measure the effectiveness of our communications and marketing

(a) Technical

(b) Profile and Usage

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

To send you relevant marketing communications and make personalised suggestions and recommendations to you about goods or services that may be of interest to you based on your Profile and Usage Data

(a) Identity and Contact

(b) Technical

(c) Profile and Usage

(d) Marketing and Communications

Depending on the circumstances:

(a) Consent, having obtained your prior consent to receiving direct marketing communications

(b) Necessary for our legitimate interests (to carry out direct marketing, develop our products and grow our business)

Please see 'Direct marketing' below for further information about our legal basis for marketing communications.

 

To carry out market research through your voluntary participation in surveys

(a) Identity and Contact Data

(b) Payment and Transaction Data

(c) Marketing and Communications Data

 

Necessary for our legitimate interests (to study how our products are used and to help us improve and develop our products).

 

To fulfil our legal obligations, and to establish, exercise or defend legal claims

(a) Identity and Contact

 (b) Marketing and Communications

(a) Necessary for our legitimate interests (to allow us to fulfil our legal obligations and to protect and defend legal claims)

(b) Necessary to comply with a legal obligation

 

Direct marketing

We may ask for your consent for direct marketing communications. If we ask for your consent and you provide consent, this will be our lawful basis for marketing communications. In other cases, and provided we are able to do so under applicable data protection law, we may rely on legitimate interests to send marketing communications.

In either case, you can opt out of marketing. Please see below for further information.

We may also analyse your personal data to form a view as to which services and offers may be of interest to you so that we can then send you relevant marketing communications.

Third-party marketing

We will get your express consent before we share your personal data with any third party for their own direct marketing purposes.

Opting out of marketing

You can ask to stop sending you marketing communications at any time.

If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.

Cookies

For more information about the cookies we use and how to change your cookie preferences, please see our Cookie Notice.

Disclosures of personal data

We may share your personal data where necessary with third parties for the purposes set out in the table above. This includes:

·                         Our suppliers and service providers, including [payment service providers, warehouses and delivery companies, marketing agencies, website hosts, and website analytics providers].

·                         Our group companies, including Araca Merchandise L.P. (our "Group Companies").

·                         Lawyers and other advisors.

·                         Our bank(s) and insurer(s).

·                         Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

International transfers

We share your personal data with our Group Companies. This will involve transferring tour personal data outside the UK to the USA.

Whenever we transfer your personal data to countries that do not provide the same level of protection for personal data as countries in the UK and which are not recognised by the UK as providing an adequate level of protection for personal data, we always ensure that a similar degree of protection is afforded to it by ensuring that safeguards are implemented. For transfers to our Group Companies, we have entered into an International Data Transfer Agreement. To obtain a copy of these contractual safeguards, please contact us (see "Contact us" below).

Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Data retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

In some circumstances you can ask us to delete your data: see "Legal rights" below for further information.

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

Legal rights

You have a number of rights under data protection law in relation to your personal data.

You have the right to:

·                         Request access to your personal data (commonly known as a "subject access request").

·                         Request correction of the personal data that we hold about you.

·                         Request erasure of your personal data in certain circumstances.

·                         Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests).

·                         Object at any time to the processing of your personal data for direct marketing purposes (see "Opting out of marketing" above for details of how to object to receiving direct marketing communications).

·                         Request the transfer of your personal data to you or to a third party.

·                         Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

·                         Request restriction of processing of your personal data.

If you wish to exercise any of the rights set out above, please contact us (see "Contact us" below).

No fee usually required

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Contact us

You can contact us by post or email if you have any questions about this privacy notice or the information we hold about you, to exercise a right under data protection law or to make a complaint.

Our contact details are shown below:

Our contact details

Araca Merch Europe Limited

Elsley Court, 20-22 Great Titchfield Street, London, United Kingdom, W1W 8BE

privacy@araca.com

 

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

Changes to this privacy notice and informing us about changes

We keep our privacy notice under regular review, and we may update or change it at any time, including to reflect changes to the way we process your personal data or if there are changes to applicable law.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example if you have a new address.

Third-party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy notices. When you leave our website, we encourage you to read the privacy notice of every website you visit.