The Data Controller connected with this Privacy Notice is UK Building Products Ltd trading as Gripit.

1.1. Purpose

In this instance your data is being processed for the specific purpose of responding to an enquiry for further information.

1.2. Lawful Basis

The collection of your data for this purpose is under the Lawful Basis of Consent.

1.3. Information Collected

The personal data we may process about you in connection with this purpose is:

1.3.1. Name

1.3.2. Address

1.3.3. Telephone number(s)

1.3.4. Email Address

1.4. Retention

Under the Lawful Basis referenced in paragraph 1.2, your data will be retained until you ask us to delete it. You may do this by either selecting an “unsubscribe” option on any electronic communication we send to you, or by sending us a request using the contact details provided to you in paragraph 5.2.

1.5. Data Sharing

Whilst we control your personal data, we will need to share this data with the following parties, for the following purposes:

1.5.1. Blue Horizons Ltd for the sole purpose of supporting our website and its associated activities

1.5.2. Cifer Data Systems Ltd and Microsoft Corporation for the sole purpose of supporting our IT systems.

1.5.3. Wise Software (UK) Ltd for the sole purpose of managing our customer database.

All of these data sharing activities are governed by commercial terms, which include data sharing clauses. These various data processors act under Gripit’s control and are only permitted to use the personal data for the sole purpose for which it is shared with them.

2.1. Purpose

In this instance your data is being processed for the specific purpose fulfilling an order you have placed with Gripit.

2.2. Lawful Basis

The collection of your data for this purpose is under the Lawful Basis of Contract. In that we need to process your personal data in order to fulfil our obligations under the Terms & Conditions which cover your purchase.

2.3. Information Collected

The personal data we may collect and process about you in connection with this purpose is:

2.3.1. Name

2.3.2. Delivery Address

2.3.3. Billing Address (if different from the Delivery Address)

2.3.4. Telephone number(s)

2.3.5. Email Address

2.3.6. Payment information

2.4. Retention

Under the Lawful Basis referenced in paragraph 2.2, your data will be retained until the end of the financial year in which your order is completed and for a further 6 years thereafter. This is in order to meet the requirements of HMRC in connection with accounting rules and financial record keeping.

2.5. Data Sharing

Whilst we control your personal data, we will need to share this data with the following parties, for the following purposes:

2.5.1. Blue Horizons Ltd for the sole purpose of supporting our website and its associated activities

2.5.2. Cifer Data Systems Ltd and Microsoft Corporation for the sole purpose of supporting our IT systems.

2.5.3. Wise Software (UK) Ltd for the sole purpose of managing our customer database.

2.5.4. Company Check Ltd for the sole purpose of credit referencing customers as necessary.

2.5.5. DPD Group, Palletways (UK) Ltd and the Royal Mail for the sole purpose of delivering our product to customers.

2.5.6. Gripit’s Accountants and Legal Advisers for the sole purpose of financial management and legal advice connected with any claim made against the Company.

All of these data sharing activities are governed by commercial terms, which include data sharing clauses. These various data processors act under Gripit’s control and are only permitted to use the personal data for the sole purpose for which it is shared with them

3.1. When you visit the website, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically-collected information as “Device Information”. We use this information to optimize your visit to the website and to improve its functionality for the future.

3.2. If you make a purchase through the website, we collect additional data as described in paragraph 2.3 in order to fulfil your order.

3.3. The Gripit website uses Google Analytics to analyse the traffic on the website as well as Cookies to help us both understand the use of our site and to personalise the service you receive from the website, both so we can improve the service you receive from the site. You will be given the option to allow Cookies to be used in connection with your use of our website and you do not need to accept their use. However, you should be aware that this may prevent you from taking full advantage of all of the site’s features. For more information about cookies, please visit: http://www.allaboutcookies.org. If you do not wish Google Analytics to capture data

regarding your visit to this or any other website, you can opt out. Please visit https://tools.google.com/dlpage/gaoptout for more information.

At the end of the relevant retention period (paragraphs 1.4 and 2.4) your data will be destroyed using an approved method unless prevented by Court order.

5.1. Under the General Data Protection Regulation, you, the Data Subject have certain rights regarding the control and processing of your personal data. Details regarding your rights can be found on the Information Commissioner’s Office (ICO) website.

5.2. Should you wish to contact Gripit in order to exercise any of these rights, please email the Data Controller’s representative using the following email address data.protection@gripitfixings.co.ukAlternatively, please call 0845 6800 215 (select option 2) and ask to speak with the Company’s representative with responsibility for Data Protection matters.

6.1. Recognising the importance of personal data to our consumers, we endeavour to put in place appropriate organisational and technical measures to protect that data.

6.2. Personal data we hold on electronic media is encrypted and stored in a secure data centre located in the UK.

6.3. Personal data we hold on non-electronic media is held in files, which are secured in lockable cabinets and we have access controls to our premises.

6.4. Data Subjects should be aware that not all electronic communications are secure. We use Transport Layer Security (TLS) to encrypt and protect email traffic in line with government advice. However, if your email service does not support TLS, you should be aware that any emails we send or receive may not be protected in transit.

6.5. We will also monitor any emails sent to us, including file attachments, for viruses or malicious software. Please be aware that you have a responsibility to ensure that any email you send is within the bounds of the law.

As a consumer of our services we may occasionally contact you to make you aware of offers or new products we’re developing, which we feel could be of interest to you. Such communications will be sent to you under the Privacy and Electronic Communications Regulations and you will be given the option to opt out of similar communications on each occasion.

Should you have any concerns regarding the way an organisation is processing your personal data, the ICO recommends that in the first instance you contact the organisation concerned. If the organisation does not address those concerns in an appropriate manner, you then have the option to escalate the issue to the ICO. If you wish to contact usbecause you have concerns about our use of your personal data, please contact us using the details provided in paragraph 5.2.

This Privacy Notice is kept under review and it is update as appropriate. It was last updated on 29th May 2018.