PRIVACY
Overview
Maintaining the security of your data is of paramount importance to us and we are committed to respecting your privacy rights.
This notice, which including without limitation applies when using our sites, provides you with information about:
-
How we use your data
-
What personal data we collect
-
Who we share your data with
-
How we ensure your privacy is maintained; and
-
Your rights relating to your personal data
Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of the General Data Protection Regulation (EU Regulation 2016/679, when applicable, the “GDPR”), and the EU Data Protection Directive (Directive 95/46/EC), the data controller is Allmakes PR2 4x4 Ltd of Unit 188, Park Drive, Milton Park, Abingdon, Oxon. OX14 4SR.
Information we may collect from you and other sources
Although the precise details of the personal information collected will vary according to the specific purpose for which we are collecting the information, we may collect and process the following data about you:
-
Information that you provide by filling in forms on our social media pages or on our sites. This includes information provided at the time of registering to use our sites, subscribing to our service, purchasing goods, posting material or requesting further services. Examples of such data are Name, Company, Address, Email Address, Telephone Number. We may also ask you for information when you report a problem with our sites.
-
If you contact us by phone, email or otherwise and is provided voluntarily, we may keep a record of that correspondence.
-
We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
-
Details of transactions you carry out through our sites and of the fulfilment of your orders.
-
Details of your visits to our sites including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise and the resources that you access.
-
We also collect behavioural and browsing data from you for the purposes of offering you a tailored or personalised online shopping experience.
-
We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users' browsing actions and patterns, and does not identify any individual. We collect some of this information using Cookies, see below and our cookies policy at here. We may also collect any personal information which you allow to be shared that is part of your public profile on a third party social network.
-
We obtain certain personal information about you from sources outside our business which may include our group of companies (further defined below). We may receive your personal information from other sources, such as: public databases, our retail and supplier partners, referrals from insurance and accident management companies, joint marketing partners; social media platforms; from people with whom you are friends or otherwise connected on social media platforms, as well as from other third parties. For example, this other personal data helps us to:
-
Provide the relevant services in an accurate manner;
-
Review and improve the accuracy of the data we hold; and
-
improve and measure the effectiveness of our marketing communications, including online advertising.
-
Uses made of the Information
We use information held about you in the following ways:
-
To ensure that content from our sites is presented in the most effective manner for you and for your computer.
-
To provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes.
-
To carry out our obligations arising from any contracts entered into between you and us. For example, we pass your contact details to our courier company who may contact you via SMS to confirm delivery of your order. We may notify our suppliers of your details for any warranty purposes.
-
To allow you to participate in interactive features of our service, when you choose to do so.
-
To enhance your experience whilst using our sites.
-
To notify you about changes to our service.
-
If you are an existing customer, we will only contact you by electronic means with information about goods and services that we offer.
-
If you are a new customer, we will contact you by electronic means if you have consented to this.
-
We may use your personal information to contact you in the event of any urgent safety or product recall notices to communicate to you where we otherwise reasonably believe that the processing of your personal information will prevent or reduce any personal harm to you. It is in your vital interests for us to use your personal information in this way.
Third-party links
Our sites may include links to third-party sites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party sites and are not responsible for their privacy statements. When you leave our sites, we encourage you to read the privacy notice of every site you visit.
Cookies
For the same reason, we may obtain information about your general internet usage by using a cookie file which is stored on the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive. They help us to improve our sites and to deliver a better and more personalised service. They enable us:
-
To estimate our audience size and usage pattern.
-
To store information about your preferences, and so allow us to customise our sites according to your individual interests.
-
To speed up your searches.
-
To recognise you when you return to our sites.
You may refuse to accept cookies by activating the setting on your browser which allows you to refuse the setting of cookies. However, if you select this setting you may be unable to access certain parts of our sites. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our sites.
Please note that any advertisers we include on the site may also use cookies, over which we have no control.
Many of our sites save the contents of your basket when you haven’t completed a transaction. If you quit our sites without placing an order the system will remember the items you added to your basket and send you an email with a reminder. We do this to make sure your shopping experience is as hassle free as possible. If you do not want to receive these emails in the future, please click on the unsubscribe link at the bottom of the email you have received.
Our cookie policy can be found here
.
Disclosure of your information
In order to make certain services available to you, we may need to share your personal data with third parties.
-
We may disclose your personal information to:
-
any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006;
-
our trusted service providers acting on our behalf who provide services such as: web hosting, web analytics and integration, customer service web chat and ticketing, order fulfilment, data analysis including data personalisation, infrastructure provision, email marketing data, review sites of our services, auditing services and other services to enable them to provide services;
-
our courier company who delivers your orders;
-
selected third parties if you are a new customer and you have consented to this;
-
third party suppliers who manage our secure payment platform and credit card processing.
-
-
In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
-
If Allmakes PR2 4x4 Ltd substantially sell all of its assets or are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
-
If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use or terms and conditions of supply and other agreements; or to protect the rights, property, or safety of Allmakes PR2 4x4 Ltd, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
International Transfers
It is sometimes necessary for us to share your data outside of the European Economic Area (EEA). This generally occurs when our service providers are located outside of the EEA or you are based outside of the EEA.
If this happens, we will ensure that the transfer will be compliant with the relevant data protections laws including the GDPR.
Our standard practice is to use standard contractual clauses which have been approved by the European Commission for such transfers. Those clauses can be accessed here. Where standard contractual clauses are not used and your data is transferred to the United States, we will ensure that the service providers have signed up to the EU-US Privacy Shield which is a framework designed to protect the fundamental rights of anyone in the EU whose personal data is transferred to the United States for commercial purposes.
How do we protect your data
We are committed to keeping your personal data safe and secure and employ a number of security measures such as:
-
We ensure our sites and data is supported with TLS1.2 technology using RSA 2048 bit security standard;
-
Monitoring and auditing our service providers to ensure they have an adequate level of protection as required under the PCI DSS;
-
All credit and debit card payment transactions are initiated on our sites via our online shopping basket;
-
All information you provide to us is stored on our secure servers. For registered users, where we have given you (or where you have chosen) a password which enables you to access certain parts of our sites, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
We use reasonable, organisational, technical and administrative measures to protect personal information under our control. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our sites; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Legal basis for processing your personal data
The personal data that you provide to us in order to purchase goods and other personal data generated for transactional agreements is processed as it is necessary for the performance of a contract with you.
All other personal data is processed for our legitimate interests (as set out below) and to comply with our legal obligations.
In general, we only rely on consent:
-
to send direct marketing communications to customers via email or text message
-
to contact (and allow for selected third parties to contact) new customers by electronic means.
You have the right to withdraw your consent at any time.
Our legitimate interests
The normal legal basis for processing customer data, is that it is necessary for our legitimate interests including:-
-
selling and supplying goods and services to our customers;
-
protecting customers, employees and other individuals and maintaining their safety, health and welfare;
-
promoting, marketing and advertising our products and services;
-
sending promotional communications which are relevant and tailored to individual customers;
-
understanding our customers’ behaviour, activities, preferences, and needs;
-
complying with our legal and regulatory obligations;
-
preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies;
-
handling customer contacts, queries, complaints or disputes;
-
managing insurance claims by customers;
-
protecting us and our employees and customers, by taking appropriate legal action against third parties who have committed criminal acts or are in breach of legal obligations to us;
-
effectively handling any legal claims or regulatory enforcement actions taken against us; and
-
fulfilling our duties to our customers, colleagues, shareholders and other stakeholders.
Your Rights
At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
-
Right of access – you have the right to request a copy of the information that we hold about you.
-
Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
-
Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records.
-
Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
-
Right of portability – you have the right to have the data we hold about you transferred to another organisation.
-
Right to object – you have the right to object to certain types of processing such as direct marketing.
-
Right to object to automated processing, including profiling – you also have the right not to be subject to the legal effects of automated processing or profiling.
-
Right to judicial review: in the event that we refuse your request under rights of access, we will provide you with a reason as to why. You have the right to complain as outlined below in the "Contact" section.
All of the above requests will be forwarded on should there be a third party involved in the processing of your personal data.
You can also exercise the right at any time by contacting us by any of the means outlined below.
Our sites may, from time to time, contain links to and from the sites of our partner networks, advertisers and affiliates. If you follow a link to any of these sites, please note that these sites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these sites.
Our Obligations as a Data Processor
Where you declare the personal details of another individual, such as setting someone other than yourself as a recipient of an order, we agree not to use this 3rd party data for any other purpose than for carrying out the service for which you have requested. 3rd party details will not be shared across databases but may be retained on any sales related documentation for as long as is required for legal or accounting purposes.
We will redact or remove all 3rd party information from our commercial databases after the companies maximum warranty period (30 months) unless otherwise instructed by yourself.
How long do we keep your data?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
We retain customer/subscriber data within our database for 30 months (2.5 years) from the date of last sale / date of consent to cover warranty periods and average service intervals but will present opportunities to amend your data and contact preferences on an annual basis either by way of the sites or through electronic mail. However this option is available upon request at any time to all individuals for whom we process personal data.
The email marketing unsubscribe function will remove your details from marketing lists and confirmation of your removal will be sent to your email address. We have introduced means to throttle the communication you receive if you would just rather reduce the frequency of communication.
Data back-ups can take up to 60 days to remove specific data from the system.
We will take reasonable steps under Article 17 of the GDPR to meet subject access requests.
Changes to our Privacy Policy
Any changes we may make to our privacy notice in the future will be posted to this section and, where appropriate, notified to you by e-mail. Previous versions of our Privacy Policy will be retained and available upon request.
Contact
If you have any questions about how we use your personal data that are not answered here, or if you want to exercise your rights regarding your personal data, please contact us by any of the following means:
-
Write to use at: info@overlanding.at
You have the right to make a complaint at any time to the local data protection supervisory authority which, for the EU, is the Information Commissioner's Office however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Issue Date: 01 feb 2020
Herewith is the proposed consumer facing privacy policy to satisfy our obligations in GDPR. A separate Employee Privacy Policy should be drafted to ensure that matters of employment are addressed in accordance with GDPR rules.
Privacy Notice
Allmakes PR2 4x4 Ltd is a company registered in England and Wales.
Overview
Maintaining the security of your data is of paramount importance to us and we are committed to respecting your privacy rights.
This notice, which including without limitation applies when using our sites, provides you with information about:
-
How we use your data
-
What personal data we collect
-
Who we share your data with
-
How we ensure your privacy is maintained; and
-
Your rights relating to your personal data
Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of the General Data Protection Regulation (EU Regulation 2016/679, when applicable, the “GDPR”), and the EU Data Protection Directive (Directive 95/46/EC), the data controller is Allmakes PR2 4x4 Ltd of Unit 188, Park Drive, Milton Park, Abingdon, Oxon. OX14 4SR.
Information we may collect from you and other sources
Although the precise details of the personal information collected will vary according to the specific purpose for which we are collecting the information, we may collect and process the following data about you:
-
Information that you provide by filling in forms on our social media pages or on our sites. This includes information provided at the time of registering to use our sites, subscribing to our service, purchasing goods, posting material or requesting further services. Examples of such data are Name, Company, Address, Email Address, Telephone Number. We may also ask you for information when you report a problem with our sites.
-
If you contact us by phone, email or otherwise and is provided voluntarily, we may keep a record of that correspondence.
-
We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
-
Details of transactions you carry out through our sites and of the fulfilment of your orders.
-
Details of your visits to our sites including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise and the resources that you access.
-
We also collect behavioural and browsing data from you for the purposes of offering you a tailored or personalised online shopping experience.
-
We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users' browsing actions and patterns, and does not identify any individual. We collect some of this information using Cookies, see below and our cookies policy at here. We may also collect any personal information which you allow to be shared that is part of your public profile on a third party social network.
-
We obtain certain personal information about you from sources outside our business which may include our group of companies (further defined below). We may receive your personal information from other sources, such as: public databases, our retail and supplier partners, referrals from insurance and accident management companies, joint marketing partners; social media platforms; from people with whom you are friends or otherwise connected on social media platforms, as well as from other third parties. For example, this other personal data helps us to:
-
Provide the relevant services in an accurate manner;
-
Review and improve the accuracy of the data we hold; and
-
improve and measure the effectiveness of our marketing communications, including online advertising.
-
Uses made of the Information
We use information held about you in the following ways:
-
To ensure that content from our sites is presented in the most effective manner for you and for your computer.
-
To provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes.
-
To carry out our obligations arising from any contracts entered into between you and us. For example, we pass your contact details to our courier company who may contact you via SMS to confirm delivery of your order. We may notify our suppliers of your details for any warranty purposes.
-
To allow you to participate in interactive features of our service, when you choose to do so.
-
To enhance your experience whilst using our sites.
-
To notify you about changes to our service.
-
If you are an existing customer, we will only contact you by electronic means with information about goods and services that we offer.
-
If you are a new customer, we will contact you by electronic means if you have consented to this.
-
We may use your personal information to contact you in the event of any urgent safety or product recall notices to communicate to you where we otherwise reasonably believe that the processing of your personal information will prevent or reduce any personal harm to you. It is in your vital interests for us to use your personal information in this way.
Third-party links
Our sites may include links to third-party sites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party sites and are not responsible for their privacy statements. When you leave our sites, we encourage you to read the privacy notice of every site you visit.
Cookies
For the same reason, we may obtain information about your general internet usage by using a cookie file which is stored on the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive. They help us to improve our sites and to deliver a better and more personalised service. They enable us:
-
To estimate our audience size and usage pattern.
-
To store information about your preferences, and so allow us to customise our sites according to your individual interests.
-
To speed up your searches.
-
To recognise you when you return to our sites.
You may refuse to accept cookies by activating the setting on your browser which allows you to refuse the setting of cookies. However, if you select this setting you may be unable to access certain parts of our sites. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our sites.
Please note that any advertisers we include on the site may also use cookies, over which we have no control.
Many of our sites save the contents of your basket when you haven’t completed a transaction. If you quit our sites without placing an order the system will remember the items you added to your basket and send you an email with a reminder. We do this to make sure your shopping experience is as hassle free as possible. If you do not want to receive these emails in the future, please click on the unsubscribe link at the bottom of the email you have received.
Our cookie policy can be found here
.
Disclosure of your information
In order to make certain services available to you, we may need to share your personal data with third parties.
-
We may disclose your personal information to:
-
any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006;
-
our trusted service providers acting on our behalf who provide services such as: web hosting, web analytics and integration, customer service web chat and ticketing, order fulfilment, data analysis including data personalisation, infrastructure provision, email marketing data, review sites of our services, auditing services and other services to enable them to provide services;
-
our courier company who delivers your orders;
-
selected third parties if you are a new customer and you have consented to this;
-
third party suppliers who manage our secure payment platform and credit card processing.
-
-
In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
-
If Allmakes PR2 4x4 Ltd substantially sell all of its assets or are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
-
If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use or terms and conditions of supply and other agreements; or to protect the rights, property, or safety of Allmakes PR2 4x4 Ltd, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
International Transfers
It is sometimes necessary for us to share your data outside of the European Economic Area (EEA). This generally occurs when our service providers are located outside of the EEA or you are based outside of the EEA.
If this happens, we will ensure that the transfer will be compliant with the relevant data protections laws including the GDPR.
Our standard practice is to use standard contractual clauses which have been approved by the European Commission for such transfers. Those clauses can be accessed here. Where standard contractual clauses are not used and your data is transferred to the United States, we will ensure that the service providers have signed up to the EU-US Privacy Shield which is a framework designed to protect the fundamental rights of anyone in the EU whose personal data is transferred to the United States for commercial purposes.
How do we protect your data
We are committed to keeping your personal data safe and secure and employ a number of security measures such as:
-
We ensure our sites and data is supported with TLS1.2 technology using RSA 2048 bit security standard;
-
Monitoring and auditing our service providers to ensure they have an adequate level of protection as required under the PCI DSS;
-
All credit and debit card payment transactions are initiated on our sites via our online shopping basket;
-
All information you provide to us is stored on our secure servers. For registered users, where we have given you (or where you have chosen) a password which enables you to access certain parts of our sites, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
We use reasonable, organisational, technical and administrative measures to protect personal information under our control. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our sites; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Legal basis for processing your personal data
The personal data that you provide to us in order to purchase goods and other personal data generated for transactional agreements is processed as it is necessary for the performance of a contract with you.
All other personal data is processed for our legitimate interests (as set out below) and to comply with our legal obligations.
In general, we only rely on consent:
-
to send direct marketing communications to customers via email or text message
-
to contact (and allow for selected third parties to contact) new customers by electronic means.
You have the right to withdraw your consent at any time.
Our legitimate interests
The normal legal basis for processing customer data, is that it is necessary for our legitimate interests including:-
-
selling and supplying goods and services to our customers;
-
protecting customers, employees and other individuals and maintaining their safety, health and welfare;
-
promoting, marketing and advertising our products and services;
-
sending promotional communications which are relevant and tailored to individual customers;
-
understanding our customers’ behaviour, activities, preferences, and needs;
-
complying with our legal and regulatory obligations;
-
preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies;
-
handling customer contacts, queries, complaints or disputes;
-
managing insurance claims by customers;
-
protecting us and our employees and customers, by taking appropriate legal action against third parties who have committed criminal acts or are in breach of legal obligations to us;
-
effectively handling any legal claims or regulatory enforcement actions taken against us; and
-
fulfilling our duties to our customers, colleagues, shareholders and other stakeholders.
Your Rights
At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
-
Right of access – you have the right to request a copy of the information that we hold about you.
-
Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
-
Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records.
-
Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
-
Right of portability – you have the right to have the data we hold about you transferred to another organisation.
-
Right to object – you have the right to object to certain types of processing such as direct marketing.
-
Right to object to automated processing, including profiling – you also have the right not to be subject to the legal effects of automated processing or profiling.
-
Right to judicial review: in the event that we refuse your request under rights of access, we will provide you with a reason as to why. You have the right to complain as outlined below in the "Contact" section.
All of the above requests will be forwarded on should there be a third party involved in the processing of your personal data.
You can also exercise the right at any time by contacting us by any of the means outlined below.
Our sites may, from time to time, contain links to and from the sites of our partner networks, advertisers and affiliates. If you follow a link to any of these sites, please note that these sites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these sites.
Our Obligations as a Data Processor
Where you declare the personal details of another individual, such as setting someone other than yourself as a recipient of an order, we agree not to use this 3rd party data for any other purpose than for carrying out the service for which you have requested. 3rd party details will not be shared across databases but may be retained on any sales related documentation for as long as is required for legal or accounting purposes.
We will redact or remove all 3rd party information from our commercial databases after the companies maximum warranty period (30 months) unless otherwise instructed by yourself.
How long do we keep your data?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
We retain customer/subscriber data within our database for 30 months (2.5 years) from the date of last sale / date of consent to cover warranty periods and average service intervals but will present opportunities to amend your data and contact preferences on an annual basis either by way of the sites or through electronic mail. However this option is available upon request at any time to all individuals for whom we process personal data.
The email marketing unsubscribe function will remove your details from marketing lists and confirmation of your removal will be sent to your email address. We have introduced means to throttle the communication you receive if you would just rather reduce the frequency of communication.
Data back-ups can take up to 60 days to remove specific data from the system.
We will take reasonable steps under Article 17 of the GDPR to meet subject access requests.
Changes to our Privacy Policy
Any changes we may make to our privacy notice in the future will be posted to this section and, where appropriate, notified to you by e-mail. Previous versions of our Privacy Policy will be retained and available upon request.
Contact
If you have any questions about how we use your personal data that are not answered here, or if you want to exercise your rights regarding your personal data, please contact us by any of the following means:
-
Email us on: privacymatters@allmakes.co.uk
-
Write to use at: Allmakes PR2 4x4 Ltd of Unit 188, Park Drive, Milton Park, Abingdon, Oxon. OX14 4SR
You have the right to make a complaint at any time to the local data protection supervisory authority which, for the UK, is the Information Commissioner's Office (ICO (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Issue Date: 01 November 2019