1. GENERAL INFORMATION
This privacy notice sets out the ways in which Nc’Nean Distillery Limited, company number SC445789, (Nc’Nean) collects, processes and shares your personal data.
2. WHAT INFORMATION IS COLLECTED THROUGH OUR WEBSITE
Nc’nean may collect, process and use the following information you provide when you are on our website, during the online order process and when you sign up for our newsletter online:
• email address;
• telephone number;
• IP address;
• your payment card information;
• browsing data, including pages you look at on our website, your URL and your IP address;
• your date of birth; and
• your purchase and website viewing history.
3. WHAT IS YOUR DATA USED FOR
Nc’nean processes your personal data in the following ways, and on the following legal bases:
• Your name and email address for the purposes of sending you our newsletter and marketing materials. Nc’nean will only do this if you have given your consent, or if you have purchased similar goods or services and have not chosen to opt-out. You may opt-out of the newsletter or marketing materials at any time by contacting email@example.com or by changing your preferences.
• To carry out Nc’nean’s obligations arising from any contracts entered into between Nc’nean and you, for example to create and operate your Nc’nean account, to process and deliver any orders you place (including payment), and to confirm and keep you up to date with such orders. It does this on the basis that it is necessary in order to perform its contract with you.
• To keep a full record of owners of casks and to contact you about your cask. It does this on the basis that it is necessary in order to perform its contract with you.
• To enhance your experience of the Nc’nean website. It does this as it is in its legitimate interest to ensure that you receive the best experience possible when you shop with Nc’nean.
• To respond to your queries, including any queries about Nc’nean’s products and its cask offer.
• Any other purposes where Nc’nean has obtained your consent to do so.
Nc’nean may use your information in an anonymised and/or aggregated manner in order to analyse the data so that it can enhance its IT systems or website and carry out research. Nc’nean may share this anonymised and/or aggregated data with third parties, but you will not be identifiable from any such data.
4. DISCLOSING INFORMATION TO 3RD PARTIES
Nc’nean does not sell, trade, or otherwise transfer your personal identifiable information to outside parties other than as set out in this privacy notice.
Nc’nean provides your personal data:
• to selected third party providers in order to process and deliver your orders, for example delivery companies and payment providers;
• to selected marketing agencies, web-mailing companies and hosting companies who assist with the development and running of the website;
• to a third party bookkeeping company for the purpose of creating an invoice after you have ordered a cask or product;
• credit reference agencies or fraud prevention agencies.
Nc’nean occasionally may transfer your personal data outside of the European Economic Area (EEA) where is uses external third parties who are based outside the EEA. Whenever Nc’nean transfers your personal data out of the EEA, it ensures a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
• it is only transferred to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;
• the third party enters into a specific contract which has been approved by the European Commission which gives personal data the same protection it has in Europe; or
• where the personal data is transferred to the US, the US third party is certified under the Privacy Shield, which requires the third party to provide similar protection to personal data shared between Europe and the US.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Nc’nean will disclose your personal data to third parties:
• if Nc’nean sells or buys any business or assets, in which case Nc’nean will disclose your personal data to the prospective seller or buyer of such business or asset;
• if Nc’nean or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets; or
• if Nc’nean is under a duty to disclose or share your personal data in order to comply with any legal obligation, or to protect the rights, property, or safety of Nc’nean, you or any third party, and to investigate illegal activities and breaches of any agreement Nc’nean has with you. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Nc’nean may pass your personal data to third parties in a statistical and/or aggregated manner in order to analyse the data, Nc’nean will always ensure that you are not identifiable in any such data.
5. PROTECTING YOUR PERSONAL DATANc'nean has put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, it limits access to your personal data to those employees, agents, contractors and other third parties who have a business need to know and in accordance with this privacy notice. They will only process your personal data in accordance with Nc’nean’s instructions. Nc’nean has put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where it is legally required to do so.
6. HOLDING YOUR PERSONAL DATA
Nc’nean will retain your data in accordance with its data retention policy. It may also retain your data for further periods where it needs to do so in order comply with any legal or regulatory requirements (including keeping certain records for seven years for VAT purposes), to carry out audits, to detect and prevent fraud, to enforce contracts or to resolve any disputes.
To determine the appropriate retention periods set out in its data retention policy, Nc’nean considers the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which Nc’nean processes your personal data and whether those purposes can be achieved through other means, and the applicable legal requirements.
7. YOUR RIGHTS
Where Nc’nean relies on consent as the condition for processing your personal data, for example for sending you electronic direct marketing, you have the right to withdraw that consent at any time.
You have various statutory rights in relation to your personal data. In particular, you have the right to:
• object to direct marketing communications at any time;
• request and obtain access to your personal data;
• rectification or erasure of your personal data, in certain circumstances;
• object to or restrict the processing of your personal data in certain circumstances;
• have your personal data stored in a manner in which it is portable from the environment in which it is stored by Nc’nean to another environment; and
• file a complaint with the Information Commissioner’s Office.
9. CHANGES TO PRIVACY NOTICE
If Nc’nean decides to change this privacy notice, any changes will be posted on this page.
This privacy notice was last modified on 3 September 2018.
If you wish to contact Nc’nean in relation to this privacy notice, including in relation to any of the rights set out in section 8 above, please contact us at firstname.lastname@example.org.