Disclaimer
Burlington Arcade uses its reasonable endeavours to make sure information on this site is accurate and up to date. The Burlington Arcade cannot take any responsibility for any loss arising out of use of the information on this site and any liability that might arise from the use of this site is hereby excluded to the fullest extent permitted by law.
This site also contains links to external internet websites. Please note that the Burlington Arcade has no control over the contents of these websites and as such cannot accept responsibility for them.
Privacy and Cookie Policy
This Privacy Policy sets out the data processing practices of Burlington Arcade. Please note that all data thus captured will be used and held in accordance with the requirements of the Data Protection Act 2018.
Purpose of processing your personal data
We have set out below a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so
Purpose/Activity
To register you to receive email communications from Burlington Arcade
Purpose of processing
To provide you with information about products and events
Lawful basis
(a) Contract
(b) Consent
Marketing
Where you consent to receive marketing communications about new products, Burlington Arcade news and events from us by signing up via our website, we will collect, use and store your personal information.
We will collect your first name, surname and email address. Although there are spaces on the electrical sign up form for your interests, you do not have to supply all of this information if you would prefer not to do so. By providing this further information it enables us to make your communications more relevant by tailoring them to your interests.
-
Recipients/Categories of Recipients
In carrying out our business including our obligations to you, we may use sub-contractors. These will be selected mailing houses and email marketing agencies. We will ensure that they respect your privacy and abide by all data protection laws.
-
Retention periods
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means.
In terms of personal data we use for marketing, we will keep this data for as long as we are able to market to you and if you withdraw your consent or opt-out of marketing communications, we will keep your contact details only to ensure that we do not contact you again for marketing purposes.
-
Data subject’s rights
You have rights in respect of your personal data. We will need to confirm your identity before we can consider your request so, if you wish to exercise any of these rights, we will need to confirm your identity.
The right to be informed – you have the right to be told about the collection and use of the personal data you provide. This privacy policy sets out the purpose for which we process your personal data, how long we will keep your data, who we will share your data with. If you have any questions on how and why we process your data please contact the DPO. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-be-informed/
Right of access – you have the right to know whether we are processing your personal data, and to a copy of that data. We would need as much information as possible to enable us to locate your data. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/
Right to rectification – you have the right to have any incorrect personal data corrected or completed if it is incomplete. You can make this request verbally or in writing. We will need as much information as possible to enable us to locate your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-rectification/
Right to erasure – this right, often referred to as the right to be forgotten allows you to ask us to erase personal data where there is no valid reason for us to keep it. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/
Right to restrict processing – you have the right to ask us to restrict processing of your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DP at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-restrict-processing/
Right to data portability – you have the right to move, copy or transfer your personal data from one IT environment to another. This right applies to data that you have provided to us and that we are processing on the legal basis of consent or in the performance of a contract and that processing is by automated means. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/
Right to object – you have the right to object to our processing of your personal data based on (i) legitimate interests, or for the performance of a task in the public interests/exercise of official authority (including profiling); (ii) direct marketing (including profiling); and (iii) for purposes of scientific/historical research and statistics.
(i) Legitimate interests/legal task – your objection should be based on your particular
situation. We can continue to process the data if we can demonstrate compelling legitimate grounds which override your interests.
(ii) Direct marketing – you have an absolute right to ask us to stop processing for the purposes of direct marketing. We will action your request as soon as possible.
(iii) Scientific/historical research and statistics – your objection should be based on your particular situation. If we are conducting research where the processing is necessary for the performance of a public task, we can refuse to comply with your objection.
If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-object/
Rights relating to automated decision making including profiling – you have the right in respect of automated decision making, including profiling. Where we carry out solely automated decision making, including profiling, which has legal or similarly significant effects on you, we can only do this if it is in connection with a contract with you, we have a right under law or you have provided your explicit consent. We will tell you if this happens and tell you how you can request human intervention or challenge the decision. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/rights-related-to-automated-decision-making-including-profiling/
-
Processing Based on Consent
Where we process your personal data based on your consent you have the right to withdraw that consent at any time without reason. You can opt-out by using the unsubscribe/opt-out in any marketing we send you and you can contact the DPO at the contact details above.
-
The Right To Lodge a Complaint To The Supervisory Authority
If you are unhappy with any aspect of our handling of your data you can make a complaint to the Information Commissioner’s Office – https://ico.org.uk/concerns/
-
Statutory/contractual requirement to provide personal data
The personal data that you provide to us is necessary for us to carry out the contract you have entered into with us. [If this applies to your business you should explain what personal data this refers to and the consequences of the data subject not providing this.]
-
Third party websites.
Our website may contain links to other websites that are outside our control and are not covered by this Privacy Policy. If you access other sites using the links provided, the operators of these sites may collect information from you that will be used by them in accordance with their privacy policy, which may differ from ours.
-
Changes to the privacy policy.
This privacy policy is regularly reviewed and will be updated when necessary. If we make any significant changes to the policy we will communicate these to you