OUR POLICIES

ASTRA SIGNS
- Privacy & Cookie Policy

Astra Signs Arrow Graphic

The following document outlines the Privacy Policy for the Astra Signs e-shop website.

IINTRODUCTION

Choosing to shop with Astra Signs means you have placed a great deal of trust in us. With trust comes responsibility and we take this responsibility very seriously.

This Privacy Notice helps you to understand how we use your personal information, who we share it with and the rights that you have. For more information on your rights and how to exercise them, head straight to the Your Rights section later in this document.

This Privacy Notice applies if you shop on any Astra Signs websites, or if you otherwise share your personal information with us, for example if you contact us with a query or we send you marketing.

We change the terms of this Privacy Notice from time to time and you should check it regularly. If we make any material changes, we will take steps to bring it to your attention.

WHO WE ARE

We are Astra Signs Limited (“we”, “our”, “us”) and operate under the name of Astra Signs Limited are registered with the ICO under number ZA932535.

We are the data “controller”, which means we are responsible for deciding how and why your personal information is used. We are also responsible for making sure it is kept safe, secure and handled legally.

We operate to the highest standards when protecting your personal information and respecting your privacy. If you have any questions about your personal information, or how we use it, you can contact our Data Protection Team via email at GDPR@astragroup.co.uk or by writing to us at Astra Signs Limited, Unit 1 First Avenue, Europa Way, Trafford Park, Manchester, M17 1 JZ

YOUR RIGHTS

You have a number of ‘Data Subject Rights· below is some information on what they are and how you can exercise them. There is more information on the Information Commissioners website www.ico.org.uk

  1. Right of access – You have the right to request a free copy of the personal information that we hold about you.

  2. Right to rectification – If you think any of your personal information that we hold is inaccurate, you have the right to request it is updated. We may ask you for evidence to show it is inaccurate.

  3. Right to erasure (also known as the Right to be Forgotten} and the Right to restriction of processing

    -You have the right to request that we stop processing, or delete, all your personal information that we hold. If you exercise this right, we will keep a note of your name linked to your request and it will not prevent us from processing any new information you provide to us subsequently.

  4. Right to data portability-You have the right to ask us to electronically move, copy or transfer your personal information in a machine-readable format.

  5. Rights with regards to automated decision making. including profiling -We sometimes use your personal information to make decisions by automated means. This involves us analysing your account activity including applications, orders, payments etc. We do this to confirm your identity, prevent and detect crime, and lend responsibly. This automated decision making is necessary if you would like to continue to shop with us online. You have a right to reject automated decisions, but it may mean that you can only shop with us in our stores.

  6. Right to withdraw Consent-Where we are relying on your consent for processing you can withdraw or change your consent at any time.

The above rights may be limited in some circumstances, for example, if fulfilling your request would reveal personal information about another person, if you ask us to delete information which we are required to have by law, or if we have compelling legitimate interests to keep it. We will let you know if that is the case and will then only use your information for these purposes. You may also be unable to continue using our services if you want us to stop processing your personal information.

If you have any general questions or want to exercise any of your rights, please contact GDPR@astragroup.co.uk or call 0161 832 2429. Our security procedures mean that we may need to request proof of identity before we disclose personal information to you in response to any request.

We encourage you to get in touch if you have any concerns with how we collect or use your personal information. You do however also have the right to lodge a complaint directly with the Information Commissioners Office, the data protection regulator in the UK, their contact details can be found on their website www.ico.org.uk

THE LAWFUL BASES WE USE TO PROCESS DATA

We will only ever process your information if we have a lawful basis to do so. The lawful bases we rely on are;

  1. Contract – This is where we process your information to fulfil a contractual arrangement, we have made with you.

  2. Consent- This is where we have asked you to provide explicit permission to process your data for a particular purpose.

  3. Legitimate Interests – This is where we rely on our interests as a reason for processing, generally this is to provide you with the best products and service in the most secure and appropriate way.

  4. Legal Obligation – This is where we have a statutory or other legal obligation to process the information, such as for the investigation of crime or to meet responsible lending criteria.

THE INFORMATION WE COLLECT AND HOW WE USE IT

We collect and use the information that you provide to us directly, for example when you register for an account; we also use cookies and other similar technologies to collect information from your devices when you interact with our advertising or use our website (you can find out more information in our cookie policy); we keep records when you speak to our sales teams; and we take personal information from a number of third parties to help us manage your account and improve your shopping experience. For more detailed information you can read the below which outlines how we use your personal information:

To process any orders that you place with us and to facilitate any returns (Contract)

We take payment details to process payment for any credit or debit card orders you place with us. We share these details with our chosen payment processors (for example Worldpay or Paypal).

We use your account information plus your chosen delivery address details to; deliver your purchases and keep you informed of their status, and to process any returns including (where appropriate).

Our chosen payment processors store your payment card details at your request to speed up your checkout in the future (consent).

To provide you with access to an account (Contract)

To register an account with us we capture information such as your name, date of birth, contact and delivery information, and a password to protect your account (account information). We use the same information on an ongoing basis to manage and provide secure access to your account and provide you with the services you request.

To provide customer service to you (Legitimate interest)

We record calls and keep correspondence (customer service records) when you contact our sales teams or interact with us on social media. We use these customer service records to manage your queries or complaints effectively, for quality monitoring and to continually improve our services.

To offer and manage any credit we provide to you (Contract Legitimate Interest)

When you apply for and use credit with us, we will use your account information to make searches with third parties who will give us information about you, such as your financial history. We do this to assess your creditworthiness and product suitability.

We use purchase history and payment history, along with your account information, on a cyclical basis to manage your credit facility with us.

We use your account information, purchase history, payment history and third-party information to collect and recover money that is owed to us should your account fall into arrears.

To personalise and improve your experience when you shop (Legitimate Interest)

We keep a record of how you interact with our website and any marketing you are exposed to, we use this data, along with purchase history, demographics, account information and third-party information, to show you products and offers that we think you will be interested in.

We use your account information, information on the devices you use to access our sites and your interactions with us to operate personalised features across our websites, apps, and communications.

To inform you about products and services that may interest you (Legitimate Interest)

We use technologies such as cookies within digital marketing networks, ad exchanges and social media networks to get relevant marketing messages across to you and other customers.

We share limited information with selected suppliers to enable them to identify new prospective customers on our behalf and to prevent us repeatedly advertising products or services you have already bought.

We receive information on how you interact with our adverts and content on third-party websites and social media platforms (such as Google) which we use to tailor the information that is displayed to you.

To keep in touch with you (Legitimate Interest)

When you register for an account and shop with us, we start to keep you up to date with news of products and services, unless you tell us you do not want us to through your account or using the link in every email that we send to you.

When we send you communications, we use records of how you interact with our website and any other marketing we have sent to you, along with purchase history, to tailor the messages to include information you are most likely to be interested in.

We use your account information to notify you about important service messages, such as material changes to this policy, product recalls or information about your account.

To ensure the Website and the services we offer you operate properly (Legitimate Interest)

We use cookies and other similar technologies to keep track of your preferences when using our site.

We use other cookies and similar technologies to help us understand how you use the site; this allows us to optimise your experience and continually improve our site.

We gather information about the devices you use to access our sites (desktop and mobile) for example your IP address and device type, to ensure the site is secure and works across multiple platforms.

We use information for Logistics planning, demand forecasting, management information, dealing with errors on our site, and general research and development.

To develop and improve our products. range. and services (Legitimate Interest)

We share insights about our customers (in an anonymised and aggregated format) with the companies whose products we sell. This helps them better understand the different profiles of our customers, focusing on those who buy their products or are interested in them.

We may contact you to take part in customer satisfaction surveys, if you respond we collect your feedback and contributions (customer feedback). We use this information to develop the services we offer.

We use all information, including third party data in the development of new products, services, and systems to ensure they work as expected and will be useful to our customers.

To prevent and detect crime (Legitimate interest/Legal obligation)

We use your account information, order history and payment history to assist in monitoring for fraudulent transactions or suspected money laundering.

When you register an account. apply for credit, or contact our call centres we use your account. application and purchase history information to confirm your identity.

We use device identifiers and IP addresses in fraud prevention and investigation, and to maintain network and data security.

To fulfil our legal obligations (Legal obligation)

We use your data to ensure we comply with any requirements imposed on us by law or court order, including disclosure to law or tax enforcement agencies and authorities or pursuant to legal proceedings.

We will share data with regulatory and other official bodies if they make formal requests. We will maintain records to meet regulatory and tax requirements.

HOW LONG WE KEEP IT FOR

  1. We keep your personal information as long as you are a customer of ours and generally for seven years afterwards to comply with legal requirements. During that time, we take steps to remove any personal data as soon as we no longer need it.

  2. We consider you a customer as long as you hold an open credit account.

  3. for 2 years from the point. you last made a purchase from our website using a non-credit account. or during any time we are managing a service request from you.

Third Parties we share data with and receive data from Sending information outside the European Economic Area

Our main operations are based in the UK and your personal information is generally processed, stored, and used

within the UK. In some instances, your personal information may be processed outside the European Economic Area.

If this is the case, we take steps to ensure there is an appropriate level of security, so your personal information is protected in the same way as if it were being used within the EEA.

Where we need to transfer your data outside the UK or EEA, we will use one of the following safeguards:

The use of European Commission approved standard contractual clauses in contracts for the transfer of personal data to third countries.

Transfers to a non-EEA country with privacy laws that give the same protection as the EEA.

You can find out more about the above data protection safeguards on the European Commission Justice website.

Third-party apps. websites. and services

If you use any third-party apps, websites, or services to access our services, your usage is subject to the relevant third party’s terms and conditions, cookies policy, and privacy notice. For example, if you interact with us on social media, your use is subject to the terms and conditions and privacy notices of the relevant social media platform (Linkedln, Twitter etc.). The same stands if you use third-party services, as your use of the service is subject to their applicable terms and conditions. We may be required to share customer information relating to transactions and use of such third-party services with that third party.

HOW YOU CAN GET IN TOUCH

Should you need to contact us please write to:

Data Protection Officer Astra Signs Limited Unit 1
First Avenue Europa Way Trafford Park Manchester M17 1JZ

or via GDPR@astragroup.co.uk