1.2 If you are an employee or worker of Red Button, the information about how we handle your personal data as an employee or worker will be provided to you separately.
1.3 If you have any questions about this Policy, please contact us in writing at the above address or by email to firstname.lastname@example.org.
1.4 HOW WE COLLECT PERSONAL DATA
1.5 We will collect and store your personal data when you interact with our website, when you complete a ‘contact us’ form on our website https://redbutton.com/contact/ and when you request our products or services. We also collect personal data in writing, by telephone and by e-mail. This includes your name, email address, address, phone number, company and any other additional information that you choose to provide to us.
1.6 Red Button collects personal data directly from the individual to whom it relates, except where that individual has consented to Red Button collecting the personal data from a third party or the law otherwise permits Red Button to do so.
2 WHAT PERSONAL DATA DO WE HOLD ABOUT YOU
2.1 Personal data means any information relating to a person that enables them to be identified either directly or indirectly. Personal data that we hold about you includes different kinds of personal data which we have grouped together as follows:
2.1.1 Identity data – includes first name, last name, title, date of birth and gender.
2.1.2 Contact data – includes address, email address and telephone numbers.
2.1.3 Technical data – includes information about your internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
2.2 If you are a customer, personal data that we hold about you may include the same information listed in Section 2.1 above, along with:
2.2.1 Business data – your function/job title within the company and your work email address, company’s name, postal address, VAT and/or company number.
2.2.2 Financial and transaction data – including bank account and payment card details as well as details about payments to and from you and other details of services you have purchased from us.
3 how we use your information
3.1 We will use your personal data, and may share your personal data with other parties acting on our behalf, for one or more of the following purposes:
3.1.1 creating and maintaining your customer account, if you are a registered customer;
3.1.2 handling and fulfilling your orders, if you request goods or services from us. This may also include processing of information that we receive from third parties, for example, address data to verify your correct address;
3.1.3 obtaining payment from you, if you purchase any of our goods and/or services;
3.1.4 enabling our suppliers and service providers to carry out certain functions on our behalf, including payment processing, verification, technical, logistical or other functions, as may be required, in order to fulfil your orders;
3.1.5 resolving any returns, refunds or disputes, if you lawfully exercise your rights or if you wish to dispute any part of our offering;
3.1.6 ensuring the security of your account and our business, preventing or detecting fraud or abuses of our website, for example, by requesting verification information in order to reset your account password;
3.1.7 developing and improving our products and services, for example, by reviewing visits to our website and its various subpages, demand for specific goods and services and User comments;
3.1.8 to comply with Red Button’s regulatory and legal obligations, for example, in response to a request from a court or regulatory body, where such request is made in accordance with the law; and
3.1.9 to administer and protect this website.
3.2 We do not sell your personal data to others and if we wish to use your personal data for a purpose beyond that for which it was originally provided, we will ask for your consent or seek to rely on another valid legal ground to process your personal data in accordance with the applicable law.
4 Grounds for processing
4.1 To process your personal data lawfully we need to rely on one or more valid legal grounds. The grounds we may rely upon include:
4.1.1 legitimate interests pursued by Red Button as a business, except where such interests are overridden by your interests and fundamental rights; or
4.1.2 compliance with a legal obligation to which Red Button is subject. For example, we have a duty to investigate and respond to complaints made against us and may need to process your personal information as part of such investigation; or
4.1.3 if you are a party to a contract, because processing your personal data is necessary for the performance of a contract; or
4.1.4 your consent to particular processing activities.
5 DISCLOSURE OF your personal data
5.1 There are circumstances where we wish to disclose or are compelled to disclose your personal data to third parties. This will only take place in accordance with the applicable law and for the purposes listed above. These scenarios include disclosure:
5.1.1 to our subsidiaries, branches or associated offices;
5.1.2 to our outsourced service providers or suppliers to facilitate the provision of our services or goods to our Users, for example, the disclosure to our data centre provider for the safe keeping of your personal data, webhosting provider through which your personal data may be collected, identity verification partners in order to verify your identity against public databases;
5.1.3 to our advertising partners who enable us to deliver personalised ads to your devices or similar advertising;
5.1.4 subject to your consent, to our marketing partners, who may contact you by post, email, telephone, SMS or by other means. If you wish to withdraw your consent, you can do so by contacting us at the contact details set out above or emailing us at email@example.com;
5.1.5 to third party service providers and consultants in order to protect the security or integrity of our business, including our databases and systems and for business continuity reasons;
5.1.6 to another legal entity, on a temporary or permanent basis, for the purposes of a joint venture, collaboration, financing, sale, merger, reorganisation, change of legal form, dissolution or similar event. In the case of a merger or sale, your personal data will be permanently transferred to a successor company;
5.1.7 to public authorities where we are required by law to do so; and
5.1.8 to any other third party where you have provided your consent.
6 INTERNATIONAL TRANSFER OF PERSONAL DATA
6.1 We may transfer your personal data to a third party in countries outside the country in which it was originally collected but within the EU for further processing in accordance with the purposes set out in paragraph 3 above. In particular, your personal data may be transferred to our outsourced service providers located abroad. In these circumstances we will, as required by applicable law, ensure that your privacy rights are adequately protected by appropriate technical, organisation, contractual or other lawful means. Please contact us at the contact details set out above for a copy of the safeguards which we have put in your place to protect privacy rights in these circumstances.
6.2 We may also transfer your personal data to a third party in countries outside the EU for further processing in accordance with the purposes set out in paragraph 3 above. In particular, your personal data may be transferred to our outsourced service providers located abroad. In these circumstances we will, as required by applicable law, ensure that your privacy rights are adequately protected by appropriate technical, organisation, contractual or other lawful means. Please contact us for a copy of the safeguards which we have put in place to protect your personal data and privacy rights in these circumstances.
7 RETENTION OF PERSONAL DATA
Your personal data will be retained for as long as it is necessary to carry out the purposes set out in this Policy (unless longer retention is required by applicable law). However, we will not retain any of your personal data beyond this period and the retention of your personal information will be subject to periodic review. We may keep an anonymised form of your personal data, which will no longer refer to you, for statistical purposes without time limits, to the extent that we have a legitimate and lawful interest in doing so.
8 Confidentiality and Security
8.1 Red Button is committed to seeking to safeguard all personal information that you provide to us; seeking to ensure that it remains confidential and secure; and taking all reasonable steps to ensure that personal privacy is respected.
8.2 All our data is stored in written or electronic form on our servers and computers and in various physical locations. We maintain physical, electronic and procedural safeguards to protect your personal information from misuse, unauthorised access or disclosure and loss or corruption by computer viruses and other sources of harm. We restrict access to personal information to those staff members, group companies and third parties who need to know that information for the purposes set out in this Policy.
9 your rights with regard to your personal data
9.1 Data protection law provides data subjects with numerous rights, including the right to: access, rectify, erase, restrict, transport, and object to the processing of, their personal data. Data subjects also have the right to lodge a complaint with the relevant data protection authority if they believe that their personal data is not being processed in accordance with applicable data protection law.
9.2 Right to obtain a copy of your personal data – you have the right to obtain a copy of the personal information we hold about you. If you would like to make a SAR, i.e. a request for copies of the personal data we hold about you, you may do so by contacting us at the contact details above or emailing us at firstname.lastname@example.org. The request should make clear that a SAR is being made. You may also be required to submit a proof of your identity.
9.3 Right to rectification – you may request that we rectify any inaccurate and/or complete any incomplete personal data.
9.4 Right to withdraw consent – you may, as permitted by applicable law, withdraw your consent to the processing of your personal data at any time. Such withdrawal will not affect the lawfulness of processing based on your previous consent. Please note that if you withdraw your consent, you may not be able to benefit certain service features for which the processing of your personal data is essential.
9.5 Right to object to processing – including automated processing and profiling. You may, as permitted by applicable law, request that we stop processing your personal data. In relation to automated processing and profiling, you may object to the processing and you will have the right to obtain human intervention.
9.6 Right to erasure – you may request that we erase your personal data and we will comply, unless there is a lawful reason for not doing so. For example, there may be an overriding legitimate ground for keeping your personal data, such as, a legal obligation that we have to comply with, or if retention is necessary for us to comply with our legal obligations.
9.7 Right to data portability – in certain circumstances, you may request that we provide your personal data to you in a structured, commonly used and machine readable format and have it transferred to another provider of the same or similar services. This is only relevant to our delivery services. We will comply with such transfer as far as it is technically feasible. Please note that a transfer to another provider does not imply erasure of your personal data which may still be required for legitimate and lawful purposes.
9.8 Your right to lodge a complaint with the supervisory authority – please contact us first about any questions or if you have a complaint in relation to how we process your personal data. However, you do have the right to contact the relevant supervisory authority directly.
Please note that this website is not intended for children under the age of 16.
11 LINKED WEBSITES
Our website provides hyperlinks to websites owned and controlled by others. Red Button is not responsible for the privacy practices of any website that it does not own or otherwise control and you should read the privacy policies of websites owned and controlled by others before deciding whether to proceed.
12 CHANGES TO THIS POLICY
As we strive to improve our practices, we may review this Policy from time to time. We reserve the right to change this Policy at any time and to notify you of those changes by posting an updated version of this Policy on our website. It is your responsibility to check our Policy each time before you access our website for any changes.