Camskill is committed to protecting our customer privacy and takes its responsibility regarding the use and security of customer information very seriously.
We will be clear and transparent about the information we are collecting and what we will do with that information. It is our aim to build a strong relationship based on trust.
We have tried to write this policy in plain terms and be open and transparent. There is a lot of information but we have tried to break this down into easily navigable sections.
When reading this policy the following terms apply.
We, us, our, the company, Camskill - we mean Camskill (UK) Ltd.
You, your, user, visitor, the customer, an individual - we mean a Customer acting on their own behalf or for a business.
Individuals have greater rights than companies therefore we treat every customer as if they are an individual, as sole traders and partnerships are classed as individuals under GDPR.
Camskill (UK) Ltd
Registered Office: Unit 1, Pottery Road, Whitehaven, Cumbria. CA28 9BZ. United Kingdom.
Registered Limited Company in England & Wales: 05111619
Registered as a Data Controller with the Information Commissioners Office (ICO): Z2420455
Complying to:
UK Data Protection Act (1998) (DPA)
European General Data Protection Regulations (GDPR)
Privacy Electronic Communications Regulations (2013) (PECR)
We will comply with the UK Data Protection Bill, which will replace the DPA, when it comes into law and will incorporate the GDPR and the PECR.
Version 1.0 - 25/05/2018
- What information of yours do we collect and where and when do we collect it
- This section sets out what personal data we collect from you and where and when we collect it.
During your interaction with our website we will highlight when we are collecting data from you to make you aware that it is happening.
Children/Minors:
This website is not intended to be used by minors; which under UK law are those persons under 18 years old. We do not knowingly collect personal information from minors. As such we do not take special account of their needs. It is our intention that minors do not interact with the website, other than to view it, and hence we collect no personal information from them. If we are made aware that use has taken place by someone under 18 years old we will remove their data from our systems at the earliest opportunity.
We collect information from you in these places
- When you place an order on the website
- When you make a card payment on the website.
- When you apply for finance on the website.
- When you opt-in to receive Marketing Communications at Checkout.
- When you fill out a Stock Alert Request
- Website contact form
- When you email us directly
- Monitoring
We do not currently collect information from you in any other way. However we will update this policy if we alter this.
- How we use your information
- If you are ordering from us:
- We will use your information to process your order, carry out fraud screening and deliver goods to you.
- Some of your details may be shared with trusted third parties, for example a payment processor and a delivery agent.
- If you are using our contact form or any other form of enquiry form on the website or if you email us directly., eg Product Enquiry on product pages, or similar:
- Your information will only be used to answer your enquiry
Third-Party processing of your information
Monek (Secure Hosting) are our trusted payment services provider. https://www.securehosting.com/company/. We transfer you to Monek to make payment when you order from us and select our secure checkout. We do not have access to your full payment card information. Payment card information is at no point stored or transferred to/from this website.
- If you are ordering from us:
- How we store and how long we retain your information
Our website has automated features which ensure that no personally identifiable information is retained for any longer than is necessary.
All personally identifiable information stored on our web servers is stored in an encrypted format.
Completed Orders : 366 weeks
If you have placed a successful order with us then after the retention period the personal information element of the order data is automatically deleted.
Your order data is also stored in our internal financial system within VAT invoices to comply with financial record legal requirements. This is retained for the same retention period after which it is completely destroyed.Incomplete Finance Orders : 8 weeks
If you apply for finance through our website, but the transaction does not complete for whatever reason, your personal information is automatically removed from the order record after the retention period.
Incomplete Non Finance Orders : 4 weeks
If you commence but do not fully complete an order, some of your information may have been captured, however your personal information is automatically removed from the abandoned order record after the retention period.
Stock Alert Requests - Confirmed : 52 weeks UnConfirmed : 48 hours
If you have requested a stock alert from our website, your information (email address only stored) is retained until the item comes back into stock, or the retention period, whichever is the soonest. You are required to confirm all stock alert requests, with unconfirmed requests automatically removed after the retention period.
If you wish for us to remove your Stock Alert Request (email address only stored) before is auto expires then please request us to remove it - see Contact section.Customer Rewards Account :Until requested to remove
If you have a customer rewards account, it will remain active unless you request us to remove it - see Contact section. If you decide to have your account removed, any points balance will be lost.
Customer Product Review :Until requested to remove
If you leave a product review, it will remain active unless you request us to remove it - see Contact section.
Emails submitted directly or via website contact form: Varies
When you send us an email either directly or via the website contact form this is sent via our web servers to our Gmail based email system where it is stored. We only look to retain customer emails as long as is necessary but due to the varying nature of these emails the retention period will vary. Google's Gmail system stores the email data securely and although can be stored around the world it is stored in compliance with EU GDPR standards.
3rd Party Providers: Varies
These include, but not limited to our parcel delivery companies (name, delivery address information, telephone number and/or email address only), our suppliers who ship direct to our customers (name, delivery address information, telephone number and/or email address only), our payment services and finance product partners and our technology partners eg. but not limited to: email systems, web hosting, security/anti-fraud systems, data storage. The retention period of the data varies due to the varying requirements but retention periods are set to only retain for as long as is required to complete the necessary task/processing.
Web Access Logs: Up to Indefinitely
Web logs are purged after a retention period of between 8-16 weeks depending upon site traffic levels. Data is analysed to create the website stats which are retained indefinitely.
The server does not correlate IP addresses against any other form of personally identifiable information. Logs can be used to detect patterns in visitor behaviour and investigate malicious activity- International Transfers i.e. Outside the EEA
Third parties with whom we share your personal information, for example our service providers, may be located in the UK, other countries in the European Economic Area or elsewhere in the world. Different privacy laws may apply in these countries and you understand and unambiguously agree to the transfer of personal information to these countries and parties.
Whenever we or our service providers transfer your personal information outside of the European Economic Area, we or they impose the standard contractual obligations approved by the European Commission on the recipients of that information to protect your personal information to the standard required in the European Economic Area or require the recipient to subscribe to 'international frameworks'. More details on the standard contractual obligations and the international frameworks are available on the ICO's website (https://www.ico.org.uk).- Crime and Fraud Prevention
We use your information to screen for fraudulent activity in order to protect ourselves against crime and loss to the company.
We may be asked to provide the information you provided to us to a government crime prevention/law enforcement agency or to the financial companies directly related to your payment transaction.
Fraud prevention agencies hold your personal information for up to two years, and if you are considered to pose a fraud or money laundering risk, your information is held for up to six years.- Security
Your connection to this website utilises Secure Socket Layer (SSL) (https) technology which encrypts all communications between your browser/device and the site. We use Comodo to provide SSL encryption to the highest standard (https://ssl.comodo.com/)
Once any personally identifiable information you share with us is received, any data we store within the website is stored in an encrypted format which can only be accessed by Camskill (UK) Limited.
Whilst we cannot 100% guarantee the security of data, we take all reasonable and practical precautions to keep your information safe.
Our website is hosted on servers located in the UK. Our payment service provider and finance provider are UK based companies.- Cookies
We use Cookies (and other technology) on our website to collect information about visitor habits in order to improve our website and the services we offer. For full information please view our Cookie Policy
We use tracking software to monitor customer traffic patterns and site usage to help us develop the design and layout of the website. This software does not enable us to capture any personal visitor information.- Links to Other Websites
This website may contain links to third party websites. We are not responsible, nor have control of the privacy policies or practices of third party websites. No information provided through this website will be passed to a third party website except where specifically stated above.
- Your Data Protection Rights
- Under certain circumstances, by law you have the right to:
- Request information about whether we hold personal information about you, and, if so, what that information is and why we are holding/using it.
- Request access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Object to automated decision-making including profiling, that is not to be subject of any automated decision-making by us using your personal information or profiling of you.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request transfer of your personal information in an electronic and structured form to you or to another party (commonly known as a right to "data portability"). This enables you to take your data from us in an electronically usable format and to be able to transfer your data to another party in an electronically usable format.
- Withdraw consent. In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights).
However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
We have 1 month to reply in full to your request from the time we receive adequate proof of identification (if requested) but we hope to reply sooner. In complex or numerous cases we make take longer but we will inform you if this is the case. - Changes to Privacy Policy
Periodically, and as circumstances change, we will review our Privacy Policy. If this results in any material changes to our policy we will update our policy and show what changes have occurred in the change log below. In addition we will communicate the changes to you by a notice on our website and/or by email prior to the change becoming effective.
Version 1.0 - Issued 25/05/2018 - New GDPR Privacy Policy- Contact Details & Complaints
If you are unhappy about how your personal information has been used, please contact our Data Protection Office using the details set out below.
You also have a right to complain to the Information Commissioner's Office (https://www.ico.org.uk), which is the lead data protection supervisory authority for the UK.
Our Data Protection Office can be contacted in writing, by email or by telephone.
Data Protection Office
Camskill (UK) Ltd.
Pottery Road
Whitehaven
Cumbria
CA28 9BZ
United Kingdom
Email: privacy@camskill.co.uk
Tel. 01946-518200 (+44-1946-518200) - Ask for Data Protection Office
Office Hours: 09:30 to 17:00 Monday to Friday excluding Public/Bank Holidays