Beverly Hills Bakery is committed to protecting our customer privacy and takes its responsibility regarding the security of customer information very seriously. We will be clear and transparent about the information we are collecting and what we will do with that information.
This Policy sets out the following:
- What personal data we collect and process about you in connection with your relationship with us as a customer and through your use of our website, and online services;
- Where we obtain the data from;
- What we do with that data;
- How we store the data;
- Who we transfer/disclose that data to;
- How we deal with your data protection rights;
- And how we comply with the data protection rules.
- All personal data is collected and processed in accordance with UK and EU data protection laws.
“Beverly Hills Bakery” (referred to as “we”, “us”, “our”, “Beverly Hills Bakery”, “BHB” or “BHB Club” in this policy). Beverly Hills Bakery is the main operating company of Beverly Hills Bakery Ltd, and, where appropriate, to other companies in the Beverly Hills Bakery Group or other entities over which Beverly Hills Bakery exercises management control. Beverly Hills Bakery is the “data controller” of all personal information that is collected and used about Beverly Hills Bakery customers for the purpose of carrying out our business. Beverly Hills Bakery Ltd is registered in the UK with registration number 04913500 and registered offices at Laxmi House, 2B Draycott Avenue, Harrow HA3 0BU
What personal data we collect
Personal data means any information relating to you which allows us to identify you, such as your name, contact details, web reference (order) reference number, payment details and information about your access to our website.
We may collect personal data from you when you place and order with us (either directly or indirectly through our trusted third party partners), create a BHB Club account, use our website and other websites accessible through our website, participate in a survey or competition, or when you contact us.
Specifically, we may collect the following categories of information:
- Name, home address, e-mail address, telephone number, credit/debit card or other payment details;
- Information about your use of our website;
- The communications you exchange with us or direct to us via letters, emails, chat service, calls, and social media.
- Approximate location, including real-time geographic location of your computer or device through your IP Address.
What do we use your personal data for, why and for how long
Your data may be used for the following purposes:
- Providing products and services you request: we use the information you give us to perform the services you have asked for in relation to your order, including requested changes;
- Contacting you in the event of a change to your order: we send you communications about the services you have asked for and any changes to such services. These communications are not made for marketing purposes and cannot be opted-out of;
- Credit or other payment card verification/screening: we use your payment information for accounting, billing and audit purposes and to detect and / or prevent any fraudulent activities;
- we may pass your information to government authorities or enforcement bodies for compliance with legal requirements;
- Customer Services communications: we use your data to manage our relationship with you as our customer and to improve our services and enhance your experience with us;
- Marketing: from time to time we will contact you with information regarding promotions and ancillary products via e-communications. You will have the choice to opt in or opt out of receiving such communications by indicating your choice when you place an order or register with the BHB Club. You will also be given the opportunity on every e-communication that we send you to indicate that you no longer wish to receive our direct marketing material.
We will only process your personal data where we have a legal basis to do so. The legal basis will depend on the reasons we have collected and need to use your personal data for.
In most cases we will need to process your personal data so we can enter into our contract of sale with you.
We may also process your personal data for one or more of the following:
- To comply with a legal obligation
- You have consented to us using your personal data (e.g. for marketing related uses);
- To protect your vital interests or those of another person
- It is in our legitimate interests in operating our business (e.g. for administrative purposes).
Only persons aged 18 or over can provide their own consent. For persons under this age, the consent of the person’s parent or legal guardian is required.
We will not retain your data for longer than is necessary to fulfil the purpose it is being processed for. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the purposes for which we process it and whether we can achieve those purposes through other means.
We must also consider periods for which we might need to retain personal data in order to meet our fiduciary and legal obligations or to deal with complaints, queries and to protect our legal rights in the event of a claim being made. For retention of information on your Beverly Hills Bakery Club account, please see the below section about BHB Club.
When we no longer need your personal data, we will securely delete or destroy it. We will also consider if and how we can minimise over time the personal data that we use, and if we can anonymise your personal data so that it can no longer be associated with you or identify you, in which case we may use that information without further notice to you.
Security of your personal data
We follow strict security procedures in the storage and disclosure of your personal data, and to protect it against accidental loss, destruction or damage. The data you provide to us is protected in transit using TLS (Transport Layer Security) technology. TLS is the industry standard method of encrypting personal information and credit card details so that they can be securely transferred over the Internet.
All online payment details are transmitted over TLS to our payment processing service provider and stored in compliance with Payment Card Industry Data Security Standards (PCI DSS).
International Data Transfer
Beverly Hills Bakery operates in multiple jurisdictions, some of which are not located in the European Economic Area (EEA). While countries outside the EEA do not always have strong data protection laws, we require all service providers to process your information in a secure manner and in accordance with UK and EU law on data protection. We utilise standard means under EU law to legitimise data transfers outside the EEA.
Sharing your personal data
Your personal data may be shared with other companies within the Beverly Hills Bakery Group
- Government authorities, law enforcement bodies, and regulators
- Trusted GDS (Global Distribution System) agents through which you book your parcel
- Partners required to deliver the services you have asked for, such as Fedex;
- Trusted service providers we are using to run our business such as handling agents. Call centres providing assistance to our customers, cloud service and email marketing service providers assisting our marketing team with running customer surveys and providing targeted marketing campaigns;
- Credit and debit card companies which facilitate your payments to us, and anti-fraud screening, which may need information about your method of payment and order to process payment or ensure the security of your payment transaction;
- Legal and other professional advisers, law courts and law enforcement bodies in all countries we operate in in order to enforce our legal rights in relation to our contract with you;
- Our trusted third party ancillary partners (identified on our website) who offer related products and services on our website: If you choose to purchase products or services offered on our websites by third parties, you may be a customer of both Beverly Hills Bakery and these third parties, and we and our partners may collect and share information about you, such as your contact details and your billing information. We are not responsible for third parties’ use of your personal data where such use is permitted for their own purposes. Please consult their privacy policies for further information.
We understand the importance of taking extra precautions to protect the privacy and safety of children. Accordingly, persons under the age of 18 will not be permitted to open a BHB Club account. We will delete any Club account created by a person under the age of 18, as soon as are made aware of it.
Upon registering or logging in to our website, you will remain signed-in into your BHB Club account. This will only apply to the computer / device and the browser that you’re using. If you do not wish to stay signed on a particular browser, simply sign out of BHB on that browser. To protect your personal data, we recommend that you actively sign out of our website when using a shared computer or a computer that you do not own.
When our use of your personal data is based on your consent, you have the option to withdraw your consent to our processing and request that we delete your personal data at any time. You may do this by contacting us by email or phone.
We keep your personal information contained in your BHB Club account for as long as you hold the account. You may request that we delete your BHB Club account by contacting us by email or phone. Please note that general retention periods apply to any personal data we collected to enter into a contract with you or to perform that contract or because we have a legal obligation to process it.
Cookies and site tracking
Cookies are small text files that are transferred to and stored in your browser or mobile device to enable us to recognise you and help us to track visitors to our site; thus enabling us to understand better the products and services that will be most suitable to you. A cookie contains information to allow us to identify your computer when you travel around our site for the purpose of helping you accomplish your order. Most Web browsers automatically accept cookies, but, if you wish, you can change these browser settings by accepting, rejecting and deleting cookies. The "help" portion of the toolbar on most browsers will tell you how to prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether. If you choose to change these settings, you may find that certain functions and features will not work as intended. The cookies we use do not detect any information stored on your computers.
For more information about cookies and how to stop cookies being installed visit www.allaboutcookies.org.
We use tracking software to monitor customer traffic patterns and site usage to help us develop the design and layout of the websites. This software does not enable us to capture any personal customer information.
Data Protection Officer
We have appointed a Data Protection Officer (“DPO”) to oversee compliance with this policy. You have the right to make a complaint at any time to a supervisory authority. The Information Commissioner’s Office (ICO) is the lead data protection supervisory authority for Beverly Hills Bakery as a UK data controller.
Your Data Protection Rights
Under certain circumstances, by law you have the right to:
- Request information about whether we hold personal information about you, and, if so, what that information is and why we are holding/using it.
- Request access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Object to automated decision-making including profiling, that is not to be subject of any automated decision-making by us using your personal information or profiling of you.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request transfer of your personal information in an electronic and structured form to you or to another party (commonly known as a right to “data portability”). This enables you to take your data from us in an electronically useable format and to be able to transfer your data to another party in an electronically useable format.
- Withdraw consent. In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
If you want to exercise any of these rights, then please email us at firstname.lastname@example.org or contact our DPO by post at Beverly Hills Bakery, Data Protection Officer, 2 Bridges road, Stanmore, Middlesex HA7 3LZ
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.