Privacy Notice




Watch Shop is part of The Watch Shop Holdings Limited, who is the data controller for your personal data.

To help us provide the best possible service, we collect personal information about you but we respect and protect your privacy and do all we can to honour the trust you place in us by being transparent about what personal information we collect and how we use it, vowing to handle your data fairly and lawfully at all times.

We are The Watch Shop Holdings Limited, Edinburgh House, Hollins Brook Way, Bury, BL9 8RR, United Kingdom and we are a Data Controller registered with the UK Information Commissioner’s Office with registration number ZA537589.

Our Data Protection Officer is contactable via watchshopdpo@datacompliant.co.uk.

This notice is to inform you about how we collect and protect any personal information you provide to us and how you can control what personal information we collect from you. It sets out how we intend to use your information, who we will share it with, and what rights you have about our use of your information.

This notice applies to all our activities, however you provide personal information to us, whether you visit us online at any of our websites or visit our stores or contact us via social media or whether you telephone, email, write to or text us.

Here we provide you with details about:



WHAT PERSONAL DATA DO WE COLLECT?


We may collect the following information about you:

  • Your name, age/date of birth and gender;
  • Your contact details: postal address including billing and delivery addresses, telephone numbers (including mobile numbers) and e-mail address;
  • Purchases and orders made by you;
  • Your social media handles;
  • Your online browsing activities on any of our websites including what items you store in your shopping bag;
  • Your password(s);
  • Information about the device you use to browse our websites including the IP address and the device type;
  • When you make a purchase or place an order with us, your payment card details;
  • Your communication and marketing preferences;
  • Your interests, preferences, feedback and competition and survey responses;
  • Your location;
  • Your correspondence and communications with us; and
  • Other publicly available personal data, including any which you have shared via a public platform (such as Instagram, YouTube, Twitter or public Facebook page.

This list is not exhaustive and, in specific instances, we may need to collect additional data for the purposes set out in this Notice. Some personal data are collected directly, for example when you set up an online account on our websites, or send an email to our Customer Services team. Other personal data are collected indirectly, for example, when you browse our websites or undertake online shopping activity. We may also collect personal data from third parties who have your consent to pass your details to us, or from publicly available sources.

We may anonymise and aggregate personal data for insight and research but this will not identify anyone.

Our websites are not intended for children and we do not knowingly collect data relating to children.


HOW WE USE YOUR DATA


1. General


The Watch Shop Holdings Limited (and trusted partners acting on our behalf) use your personal data:


  • To provide goods and services to you;
  • To make a tailored website available to you;
  • To manage any account(s) you hold with us;
  • To verify your identity;
  • For crime and fraud prevention, detection and related purposes;
  • For analysis, insight and market research purposes to better understand your needs and ensure we are giving you what you like;
  • To administer competitions and identify and contact competition winners;
  • To enable us to manage customer service interactions with you; and
  • Where we have a legal right or duty to use or disclose your information (for example in relation to an investigation by a public authority or in a legal dispute).

2. Marketing


The Watch Shop Holdings Limited use your personal data for marketing purposes and may send you postal mail, texts and/or emails:


  • about promotional offers and events which we think may interest you;
  • about relevant products and services of interest to you.

You have the right to opt out of receiving promotional communications at any time, by:


  • 1: Clicking on the simple “unsubscribe” link which is included in all our marketing emails
  • 2: Contacting our Data Protection Officer on watchshopdpo@datacompliant.co.uk, or by post to Finance, Director, Watch Shop, PO Box 8174, Reading, Berkshire, RG6 9PE, United Kingdom
  • 3: Contacting our Customer Services on 0800 024 8794, extension 2


This will not stop service messages such as order updates.


3. Personalisation and Automated Decision Making


In order to improve your shopping experience with us, when you visit any of our websites, you may receive personalised banner advertisements whilst browsing websites of other companies. Any banner advertisements you see will relate to your browsing activity on our websites from your computer or other devices.

These advertisements are provided by us via external market leading specialist providers using ‘cookies’ placed on your computer or other devices. See further information on the use of cookies in our Cookie Policy. You can remove or disable cookies at any time, see here for further information.

We may collect data directly from you, as well as analysing your browsing and purchasing activity, both online and in store, and your responses to marketing communications. The results of this analysis, together with other demographic data, allow us to ensure that we contact you with information on products, services, events and offers that are relevant to you. To do so, we use software and other technology (automated decision-making including profiling).

We may do this to decide what marketing communications are suitable for you and this activity is based on our legitimate interests to develop and improve our products and services for you.

You have the right to opt out of any automated decision-making processes including profiling at any time by:


  • 1: Contacting our Data Protection Officer on watchshopdpo@datacompliant.co.uk, or by post to Finance Director, Watch Shop, PO Box 8174, Reading, Berkshire, RG6 9PE, United Kingdom.

  • 2: Contacting our Customer Services on 0800 024 8794, extension 2.

In order to provide more personalised services and experiences, we may also ask your permission to review third party data about you, for example, your Twitter or Facebook feeds, to get to know you better and to provide more effective personalisation. Some of our services enable you to sign-in via a third party service, such as Facebook. If you choose to sign-in via a third party app, you will be presented with a dialog box which will ask your permission to allow us to access your personal information (e.g. your full name, date of birth, email address and any other information you have made publicly accessible). You are not obliged to give your permission.


SHARING DATA WITH THIRD PARTIES


We will never sell or rent your personal information to other organisations for marketing purposes.

We will not disclose your personal information to any third party, except for those referred to below.

We may share your data with:


  • Other companies within our group;
  • Purchasers, investors, funders and advisers if we sell our business or assets or restructure whether by merger, re-organisation or otherwise;
  • Our legal and other professional advisers, including our auditors;
  • Credit reference agencies where necessary for card payments;
  • Governmental bodies, regulators, law enforcement agencies, courts/tribunals and insurers where we are required to do so:
    • To comply with our legal obligations and/or the administration of justice;
    • To exercise our legal rights (for example in court cases);
    • For the prevention, detection, investigation of crime or prosecution of offenders; and
    • For the protection of our employees and customers.
  • Our service providers and suppliers.

Type of External Service Provider
Reason for Sharing Your Information
Database Administrators
Administration of our marketing databases
Mailing Houses
Postal administration
Electronic Mail Administrators
Delivery of email campaigns including electronic newsletters and administration of on-line competitions
Couriers and Logistics Service Providers
Goods delivery
Software Providers
Administration of sales and returns
Marketing Consultancies and Advertising Services Providers
Analysis of marketing data and customer insight for the development and administration of marketing campaigns. Delivery of offers, promotions and other marketing campaigns. Website tracking to assist with personalising your on-line buying experience. Facilitate customer product and service reviews
Insurers
Provision of insurance cover on products purchased from us
Finance Companies
Provision of interest free and interest bearing credit for our customers
Watch Manufacturers
Administration of guarantees and repairs
Call Recording Providers
Call recording to facilitate customer care and customer training, administration of enquiries and complaints, to facilitate telephone orders and order fulfilment for the Watch Shop website
Insurance Claims and Repair Handlers
Facilitate certain types of insurance claim administration
Electronic Platform Providers
To create on-line accounts, to fulfil website orders and electronic newsletter distribution
Operational Email Administrators
Provision of operational email system
Live Engagement Platform Providers
Delivery of live chat environment
App Developer
Delivery of customer chat app called Akin
Payment Service Providers
Website payment services
Website Hosting Service Providers
Administration of our websites, fulfilment of on-line orders and electronic marketing campaigns
Order Fulfilment Providers
Facilitate fulfilment of orders on websites and customer care
Electronic Repair Administrators
Repair processing and workshop administration: facilitating watch repairs by post, facilitating communications with our repair services
Document Disposal Managers
Document disposal

In order to make certain services available to you, we use certain trusted third parties including IT, mailing, payment services, delivery and marketing service providers. We may need to share your personal information with some of our service providers, who will act under our instructions to provide services with confidentiality. security and integrity, and in compliance with relevant data protection laws such as the Data Protection Act 2018, the GDPR and the Privacy and Electronic Communications Regulations. We have put in place strong contracts to ensure they only use your personal information to provide services to us and to you, and for no other purpose.


LEGAL BASIS FOR USING DATA


We are required to set out the legal basis for our ‘processing’ of your personal data.

We collect and use customers’ personal data:


  • 1: As necessary to perform our contract with you
    • For the purposes of complying with our duties and exercising our rights under contracts for the sale of goods or services to customers; or
    • Selling and supplying goods and services to our customers;
    • Handling customer contacts, queries, complaints or disputes;
    • Managing insurance claims by customers;

  • 2: As necessary for the pursuit of our legitimate interests including:
    • Promoting, marketing and advertising our products and services to our current and past customers, and those who have asked for information,
    • Sending promotional communications which are relevant and tailored to individual customers (including administering loyalty schemes);
    • To administer competitions and promotions and identify and contact competition winners;
    • Understanding our customers’ behaviour, activities, preferences, and needs;
    • Improving existing products and services and developing new products and services;
    • Protecting customers, employees and other individuals and maintaining their safety, health and welfare;
    • Good governance, accounting and managing and our operations and complying with our legal obligations;
    • Protecting our company, its employees and customers, by taking appropriate legal action against third parties who have committed criminal acts or are in breach of legal obligations to us;
    • Handling any legal claims or regulatory enforcement actions taken against us; and
    • Fulfilling our duties to our customers, colleagues, shareholders and other stakeholders or

  • 3: As necessary for complying with our legal obligations including:
    • Where you exercise your rights under data protection laws;
    • For compliance with legal and regulatory requirements; or
    • To establish or defend our legal rights; or
    • Preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies;

  • 4: Based on your consent

  • Analysing website visitor data, to gain understanding that enables us to improve our website to meet visitor and customer needs and preferences
  • Serving relevant ads to WatchShop customers on Facebook and Google based on information we hold about you

  • You have the right to withdraw consent at any time. Where consent is the only legal basis for processing your personal data, we will cease to process your personal data for that purpose after consent is withdrawn.


    HOW WE PROTECT YOUR DATA


    Our Controls


    The Watch Shop Holdings Limited is committed to keeping your personal data safe and secure.

    Our security measures include:


    • Encryption of data;
    • Regular cyber security assessments of all service providers who may handle your personal data;
    • Regular planning to ensure we are ready to respond to cyber security attacks and data security incidents;
    • Daily penetration testing of systems;
    • Security controls which protect the our IT systems infrastructure and our premises from external attack and unauthorised access; and
    • Internal policies setting out our data security rules for our personnel.
    • Regular training for our employees.

    WHAT YOU CAN DO TO HELP PROTECT YOUR DATA


    You should always be cautious when sharing your personal data. No one from our company will ever ask you to confirm any bank account or credit card details via email. If you receive an email claiming to be from The Watch Shop Holdings Limited asking you to do so, please ignore it and do not respond.

    If you are using a computing device in a public location, we recommend that you always log out and close the website browser when you complete an online session.

    In addition, we recommend that you take the following security measures to enhance your online safety


    • Keep your account passwords private because anyone who knows your password may access your account or be compromised if your account is accessed without authority.

    • When creating a password, use a difficult word/number combination of at least 8 characters and something that is not easily guessed by hackers such as dictionary words, your name, email address, or other personal data that can be easily obtained. Also, frequently change your password. You can do this accessing your account, clicking ‘your account’, clicking ‘your data’ and selecting ‘change password’.

    • Avoid using the same password for different online accounts.

    HOW LONG WE KEEP YOUR DATA


    We will not retain your data for longer than necessary for the purposes set out in this Notice. Different retention periods apply for different types of information, and our Data Retention Policy sets out the length of time we will usually retain personal data and where these default periods might be changed.

    In summary, various laws, accounting and regulatory requirements applicable to us require us to retain certain records for specific amounts of time. In relation to your personal data, we will hold this only for so long as we require that personal data for legal or regulatory reasons or for legitimate organisational purposes and we will not keep your data for longer than is necessary for the purposes for which we collect them.


    Record Retention Periods


    Record
    Type of Personal Data
    Retention Period
    Contracts with Suppliers
    Names
    10 years after expiry
    Supplier details
    Names, addresses, email addresses, telephone numbers
    Permanently
    Rental and hire purchase agreements
    Names
    10 years after expiry
    Payment services agreements
    Names
    10 years after expiry
    Cookies
    Webtracking information including IP addresses
    5 years
    Customer deposits
    Names
    Permanently
    Contracts with Customers
    Names, addresses, telephone numbers, transactional details
    10 years from date of transaction
    Contracts with Customers – bank transfers
    Names, addresses, telephone numbers, Bank and Branch
    14 days
    Contracts with Customers – waiting lists
    Names and products
    Until purchase or as long as customer requires
    Contracts with Customers – pre-owned watches
    Names, addresses, age and product
    3 years
    Contracts with Customers
    Email addresses
    website emails: 7 years, customer care emails: 7 years, store support emails: 2 years
    Customer complaints
    Names, addresses, telephone numbers, email addresses
    7 years
    Interest Free Credit applications
    Customer emails, names, addresses, dates of birth, marital status, employment details, financial details such as income and major outgoings, bank account details
    14 days
    Interest Bearing Credit applications
    Customer emails, names, addresses, dates of birth, marital status, employment details, financial details such as income and major outgoings, bank account details
    14 days
    Promotional materials
    Names and customer images
    3 years
    Customer listings for promotional communications
    Names and addresses, email addresses
    30 days
    Marketing databases
    Names and dddresses, email addresses
    15 years
    Social Media communications
    Names, addresses, email addresses, transactional data, hobbies, interests, payment references
    Permanently
    Product and service reviews by customers
    Names, emails and products services purchased
    Personal data: 12 months, review content: permanently
    Records of administration of watch and jewellery insurance claims for Insurance Companies
    Names, addresses, telephone numbers, email addresses, insurance policy number, item claimed for, call recordings, bank sort code details
    Permanently
    Call recordings
    Telephone numbers, call recordings
    28 days
    Customer live chat forum
    Voice recordings images and messaging
    28 days
    Mobile app - Akin
    Names, mobile phone numbers
    28 days
    CCTV
    Images of attendees at our premises
    As long as required for security purposes
    Visitor records
    Names and images of attendees at our premises
    As long as required for security purposes
    Automatic Number Plate Recognition System
    Vehicle registration plates of visitors, suppliers and other attendees at our HQ
    As long as required for security purposes

    INTERNATIONAL TRANSFERS


    To deliver products and services to you, it is sometimes necessary to share your personal information outside the UK and European Economic Area (the EEA). This will typically occur when service providers are located outside the UK or EEA or if you are based outside the UK or EEA. These transfers are subject to special rules under data protection laws. If we transfer your personal information outside the UK or EEA, we will ensure that the transfer will be compliant with data protection law and all personal data will be secure. Our standard practice is to assess the laws and practises of the destination country and relevant service provider and the security measures that are to be taken as regards the data in the overseas location. Alternatively, we use standard data protection contract clauses.


    LINKS TO OTHER WEBSITES


    Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.


    COOKIES


    Our websites use cookies to collect information. This includes information about browsing and purchasing behaviour by people who access our websites including pages viewed, products purchased and the customer journey around our websites.


    Detailed information is set out in our Cookie Policy and is provided to ensure you are fully aware of the cookies we use, allowing you to make an informed choice about your continued acceptance of cookies.


    A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.


    We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.


    Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not.


    For information on the cookies we use, please see our Cookie Policy.

    YOUR RIGHTS


    You have the following rights:


    • The right to be informed about our processing of your personal data which is the aim of this Notice;
    • The right to request access to personal data that we hold about you at any time;
    • The right to ask us to update and correct any out-of-date or incorrect personal data that we hold about you;
    • The right to object to processing of your personal data and/or to withdraw any consent you have given us and to opt out of any marketing communications that we may send you.
    • The right to prevent processing that is likely to cause damage or distress to you or anyone else;
    • The certain rights in relation to automated decision-making processes including the right to object to profiling;
    • The right to request that we erase or destroy your personal data in certain circumstances (the right to be forgotten) for example when the data are no longer necessary for the purpose for which we collected them;
    • The right to have your personal data provided to you by us in a structured, commonly used and machine-readable format and the right to have that data transmitted to another data controller. This is known as the right to data portability.

    If you wish to exercise any of these rights, or to request details of personal information which we hold about you, please write to The Finance Director, Watch Shop, PO Box 89174, Reading, Berkshire, RG6 9PE or email the Watch Shop Data Protection Officer at watchshopdpo@datacompliant.co.uk


    You have the right to lodge a complaint with the Information Commissioner’s Office at Wycliffe House, Water Lane, Wilmslow SK9 5AF, United Kingdom if you believe we have not handled your personal data in accordance with the law. Further information, including contact details, is available at https://ico.org.uk.


    The Watch Shop Holdings Limited

    Units 55-58

    Suttons Business Park

    Sutton Park Avenue, Earley

    Reading

    RG6 1AZ

    United Kingdom


    Last Updated: July 2021