Effective: June 2019
Revised: July 2021
IF YOU ARE A CLIENT AND PROVIDE PERSONAL INFORMATION ON THE WEBSITE, OR IF YOU ENTERED INTO AN AGREEMENT, OR INTERACTED WITH US IN SUCH A WAY THAT YOU HAVE PROVIDED YOUR PERSONAL INFORMATION TO US, YOU HEREBY AGREE THAT YOUR PERSONAL INFORMATION BE HOSTED, TRANSFERRED, STORED AND FURTHER PROCESSED IN CANADA, AND/OR IN THE USA AND/OR VIA CLOUD COMPUTING.
· Use of our Website, including the mobile interface;
· Entering into any agreement with BF Group;
· Visits to our stores or attendance at one of our events;
· Any type of communication;
· Social media interactions with us on our Website and other third-party websites, such as, but not limited to Facebook, YouTube, Pinterest, Google+, Instagram and Twitter;
· Viewing our online advertisements or emails; and
· Any interactions with or through our authorized Service Providers (as defined herein).
3. Information We Collect
We collect the names, cell or home phone numbers, email and/or postal address of customers and/or potential clients, who placed an order with us, entered into any agreement with us, completed our online form for a free in-home consultation, or contacted us for any reason. Additionally, we may collect your purchase history, billing addresses and other digital contact information. We may also collect information that you provide to us about others.
When you make a purchase, we may collect your payment information, including information from your credit or debit card, check, PayPal account or gift card. If you apply for a BF Group-administered loan or financing, we might collect any other information related to your application.
We may collect information about reviews you submit and other data like your age and gender.
If you use our mobile website (including the Website), mobile applications, or other smart device applications, we may collect location data obtained from your device. If you use our Website, we may collect location data obtained from your IP address.
We collect and process usage data that includes information about how you use our Website, products and services.
Social Media Information, and Information Provided Electronically
If you interact with us on social media, such as, but not limited to Facebook, YouTube, Pinterest, Google+, Instagram and Twitter, we may collect your user name, other identifiable personal information, and any of the information or content that you provide through our Website, device applications, or online forums.
We collect technical data that includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform (collectively, the “Technical Data”), and other technology on the devices you use to access this Website.
If you apply for an employment opportunity, we may collect certain personal information that you provide to us (whether it be in a resume, cover letter or similar employment-related materials, or any applicable pre-screening questions). With respect to our current respective employees, we collect their personal information for employment-related purposes, as permitted by applicable law. We may also collect personal information of our respective employees when it is necessary for rendering services by BF Group.
Information Collected Through the Free In-Home Consultation Form
The Free In-Home Consultation is an optional form to fill out if you are interested in a BF Group product. You do not have to fill out the form to browse our Website online. When filling out the form, you are asked for personal information such as your name, address, phone number and email address that you select. This information may be used to help our sales representatives contact you to answer any questions or provide you with a free in-home consultation appointment.
4. How Information is Collected
We collect information directly from you or from others if they provide your information to us.
To illustrate the manner we collect personal information, below we list just some examples of how and when we may collect information from you:
· During your Website visit or through a completed form;
· If you upload or share a photo, submit a request, submit any information, or post other digital content through Website, applications or via social media interactions on third-party websites like Facebook or Twitter;
· If you register for a referral program or apply for a BF Group managed loan or financing;
· If you participate in a survey, provide feedback regarding BF Group services, or decide to post a review;
· If you participate in a sweepstakes, contest, promotion, program, clinic or workshop;
· If you request a quote, warranty or other information;
· If you use a rebate;
· If you apply, inquire about employment, or when you accept our employment offer; or
· In connection with your interactions with us as a registered user of our Website.
We may get information about you from other sources, such as third-party business partners, such as Google Analytics. We may collect information about you from a friend or other relative. For example, if your friend provides your personal information through one of our refer-a-friend type features. If you use one of these features, please ensure that you only submit email addresses and other personal information of individuals, with whom you have a close personal or family relationship, who would be interested in receiving the communication, and who have authorized you to share their email address and other personal information.
5. How We Use Information
We use the information we collect for our business purposes, including:
To respond to your questions and requests.
· Fulfilling orders, ensuring proper delivery/installation or providing services (e.g. delivering an electronic copy of your receipt)
· Administering your participation in a contest, sweepstakes or other promotion, including shipping any prizes you might have won
· Registering you for a particular website, referral program, or extended warranty service or providing you with information regarding programs or services
· Processing a service request
· Responding to a product or service review
To enter into an agreement with you.
We may use your information to negotiate an agreement with you, enter into an agreement with you, and store the agreement for our records.
To improve our products and services.
We may use your information to make Website, device application, or product and service improvements.
To look at Website and device application trends and customer interests.
We might use your information to customize your experience with us. We may collect information about your activities and interactions with various devices and link that information. Through cross-device linking, we provide customers with a consistent experience across devices used. We may also combine information we get from you with information about you we have received from third parties or publicly available sources to assess trends and interests.
For security and loss prevention purposes.
We may collect/use your information to protect our business, our facilities, customers, our respective employees or our Website. For example, we might use cameras in our stores to track store traffic and stock.
For our marketing.
To communicate with you about your account, our programs, your feedback, and any rebates.
For employment purposes.
We may use the personal information you provide in connection with a job application or related inquiry for the purpose of processing and responding to your application or inquiry. We may further use your personal information when you accept our employment offer to comply with obligations imposed on BF Group by applicable law, or when it is necessary for rendering services by BF Group.
For social media.
For other uses we may disclose to you.
We may also use your personal information, as permitted or required by applicable law, including but not limited to, upon receiving your consent.
6. Information Sharing
We may share your information for our business purposes and as legally required or permitted, including, but not limited to:
With third parties, who perform services on our behalf (the “Service Providers”).
We share information with our Service Providers, such as Horizon Next, Google, Quanticmind, Bing, and Hotjar. We might also authorize our Service Providers to collect information on our behalf. Some Service Providers may be located outside of the United States and/or Canada. These Service Providers also have their own privacy statements that stipulate the manner, in which they will collect, use and disclose (process) personal information. We encourage you to review each Service Provider’s privacy statement. We might also share information with the vendors and manufacturers of our products and services to respond to your reviews and questions.
To offer financial products.
We use Service Providers to offer financial products, such as Wells Fargo, Snap, Greensky, Aqua Finance, Fortiva & Genesis Creditloans/financings. We may share personal information about you with these Service Providers in order to provide you with tailored information about products and services and special offers. These Service Providers also have their own privacy statements that stipulate the manner in which they will collect, use and disclose (process) personal information. We encourage you to review each Service Provider’s privacy statement at the time you submit your application for financial products.
With any successor to all or part of our business.
We may share, sell or disclose your information in case all or part of our respective business is sold, or in the course of preparation for or as part of that transaction.
In order to comply with applicable law.
We will disclose information to respond to a court order or subpoena. We may also disclose information if a government agency or investigatory body files a request.
With our business partners.
We might share information with one of our franchisees or a business partner, who is running a joint promotion with us, who provides a product or service in partnership with us, who is collecting from clients and prospective clients reviews of our services or feedback thereon, or with whom we share personal information of clients and prospective clients due to the overlap between the location of business partners, and residency of such clients and prospective clients (so-called “lead sharing”). These franchisees and business partners should also have their own privacy statements that set out the manner, in which they will collect and disclose personal information. We encourage you to review each such franchisee or business partner’s privacy statement before signing on with them.
To protect us, or a third party.
We will disclose information if we suspect fraud, or in any other case to protect us, or any third party. We will also share information as part of an investigation. We may also disclose personal information to assist us in collecting a debt owed by you.
By your request.
For example, if you ask us to provide your information to a third-party to facilitate the resolution of a dispute.
7. Your Privacy Preferences
You can register or change your preferences to receive or not receive marketing communications from us by emailing us. Please allow sufficient time for your preferences to be processed. Even if you opt out of receiving marketing messages, we may still contact you for transactional purposes like confirming or following up on an order or service request, responding to customer service inquiries, asking you to review a product or service you have ordered, or notifying you of product or service rebates. If, in the future, you do indeed want to receive marketing communications from us we will remove your information from our opt-out database.
8. Our Sites and Children
Our Website and device applications are not created for children. No one under age of 16 may provide any information to us or on Website. We do not knowingly collect personal information from children under 16. If you are under 16, do not use or provide any information on this Website or through any of its features, register on the Website, make any purchases through the Website, use any of the interactive or public comment features of this Website, or provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or user name you may use. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us at firstname.lastname@example.org.
California residents under 16 years of age may have additional rights regarding the collection and sale of their personal information. Please see “Your California Privacy Rights” below for more information.
9. Your California Privacy Rights
Privacy Notice for California Residents According to the CCPA
Information We Collect
We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“Personal Information”). Personal Information does not include:
· Publicly available information from government records.
· Deidentified or aggregated consumer information.
· Information excluded from the CCPA’s scope, like:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
- Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.
In particular, we have collected the following categories of Personal Information from consumers within the last twelve (12) months:
Use of Personal Information
Sharing Personal Information
We may disclose your Personal Information to a third party for a business purpose, which may include sharing information about our customers or our visitors with third parties, including, but not limited to Facebook. When we disclose Personal Information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract.
Disclosures of Personal Information for a Business Purpose
In the preceding twelve (12) months, BF Group has disclosed Personal Information for a business purpose. In particular, the following categories of Personal Information collected by BF Group’ have been disclosed for a business purpose:
Sales of Personal Information
In the preceding twelve (12) months, BF Group has not sold any Personal Information.
Your Rights and Choices
The CCPA provides consumers (California residents) with specific rights regarding their Personal Information. This section describes your CCPA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
· The categories of Personal Information we collected about you;
· The categories of sources for Personal Information we collected about you;
· Our business or commercial purpose for collecting or selling that Personal Information;
· The categories of third parties with whom we share that Personal Information;
· The specific pieces of Personal Information we collected about you (also called a “data portability request”);
· If we sold or disclosed your Personal Information for a business purpose, two separate lists disclosing:
sales, identifying the Personal Information categories that each category of recipient purchased; and disclosures for a business purpose, identifying the Personal Information categories that each category of recipient obtained.
Deletion Request Rights
You have the right to request that we delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our Service Providers to delete) your Personal Information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our Service Provider(s) to:
· Complete the transaction for which we collected the Personal Information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you;
· Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
· Debug products to identify and repair errors that impair existing intended functionality;
· Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law;
· Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.);
· Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent;
· Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us;
· Comply with a legal obligation;
· Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described in the sections “Access to Specific Information and Data Portability Rights” and “Deletion Request Rights” above, please submit a verifiable consumer request to us at email@example.com, or mail us at 225 Roy Street, Saint-Eustache, QC, J7R 5R5, Canada.
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a twelve (12) month period. The verifiable consumer request must:
· Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative;
· Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you.
Making a verifiable consumer request does not require you to create an account with us.
We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
For instructions on exercising sale opt-out rights.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to ninety (90) days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
· Deny you goods or services.
· Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
· Provide you a different level or quality of goods or services.
· Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your Personal Information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
While we use industry standard means to protect our Website and your information, the Internet is not 100% secure. The measures we use are appropriate for the type of information we collect. We cannot guarantee use of our Website or mobile applications are 100% secure. We encourage you to use caution when using the Internet.
11. Our Tracking Techniques, Cookies, and Way to Control Our Tracking Tools
Tracking Tools We Use, Cookies
We collect personal and other information about users over time and across different websites, including cookies, browser and flash cookies, web beacons, and server logs and other similar technologies to collect your information passively and other devices when you use this Website or service.
• Distinguish you from other users of the Website. This helps us provide you with a good experience when you browse the Website and also allows us to improve it;
• Track new visitors to our Website;
• Recognize returning customers;
• Learn what site referred you to our Website or device application;
• Personalize your experience on our Website, device application and on third-party social networking websites, plug-ins and applications;
• Collect and store geographic data determined by the IP address of your computer;
• Optimize and tailor our Website and device applications;
• Make product recommendations and provide you with advertising content we believe may be of interest to you. As part of this customization, we may observe your behaviors on our device applications, our Website or on other websites. We may also get information about your browsing history from our trusted business partners and vendors so we can better understand our audience, our customers, our Website visitors and device application users, and their respective interests, which includes learning about your online activities across devices.
We or third parties may also collect or receive information from our device applications and others’ device applications and use that information to provide measurement services and targeted ads.
We only place cookies where you have given us consent to do so. You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies, you may not be able to access all or parts of the Website.
A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer. Cookies contain information that is transferred to your computer’s hard drive. All cookies will expire after a two-year period.
We use the following cookies:
· Analytical or performance cookies. These allow us to recognize and count the number of visitors and to see how visitors move around the Website when they are using it. This helps us to improve the way the Website works, for example, by ensuring that users are finding what they are looking for easily;
· Functionality cookies. These are used to recognize you when you return to the Website. This enables us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region);
· Targeting cookies. These cookies record your visit to the Website, the pages you have visited and the links you have followed. We will use this information to make the Website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.
You can find more information about the individual cookies we use and the purposes for which we use them in the table below:
We may also receive Technical Data about you if you visit other websites employing our cookies. We also have third parties that collect personal information this way, or our vendors, use several common online tracking tools to collect this information.
Controlling Our Tracking Tools
Your browser may give you the ability to control cookies, and browser add-ons like Ghostery allow you to decide which cookies to activate/deactivate. How you do so depends on the type of cookie. Certain browsers can be set to reject browser cookies. To control flash cookies, click: http://www.macromedia.com/support/documentation/en/flashplayer/
Our “Do Not Track” policy: Some browsers have a “Do Not Track” feature that lets you inform Website that you do not want to have your online activities tracked. These browser features are not uniform, so we are not currently set up to respond to those signals.
Controlling Online Interest-Based Ads
We sometimes work with online advertising vendors to provide you with relevant and useful ads. This may include ads served on our Website or device applications. This may also include ads served on other websites. These ads may be based on information collected by us or third parties. For example, information a third party collects when you register on a website: e.g. your zip code. This might be used to target an ad for people in your area. These ads may also be based on your activities on our Website or on third-party websites.
To learn more about interest-based ads and to opt out of certain types of interest-based advertising and certain other uses of information collected over time and across different online services and devices, please contact us at firstname.lastname@example.org. To opt out of certain interest-based advertising associated with your use of device applications, you may be able to adjust your device settings via the applicable settings configuration of your iOS or Android mobile device. Please see the support materials for your operating systems or devices for more information.
Some of the social media platforms we work with may serve you with interest-based advertising on their platforms. In addition to or instead of the opt-out mechanism described above, you may be able to opt out of their interest-based advertising by changing your advertising preferences in the platforms after you log in.
12. Contact Us
If you have additional questions you may call us at 1-800-764-5539 or reach us by email at email@example.com. You can write to us at 225 Roy Street, Saint-Eustache, QC, J7R 5R5, Canada.
13. Notice to Nevada Residents
Nevada residents, who use or visit the Website or online service and desire to review and request changes to any of their Personal Information that is collected through the Website or online service, shall submit their request thereon to firstname.lastname@example.org;
Nevada residents, who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address: email@example.com. However, please know we do not currently sell data triggering that statute's opt-out requirements;
If processing of your personal information falls within the scope of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (as defined by the GDPR) and on the free movement of such data, known as the General Data Protection Regulation (the “GDPR”), then Bath Fitter Limited, an Irish entity that, with respect of personal information governed by the GDPR serves as a controller. (for the purposes of this GDPR section, “Bath Fitter Ltd.”) shall perform such processing in accordance with GDPR requirements. Therefore, in such case, in addition to the above terms, Bath Fitter Ltd. provides you with the following information:
1. IMPORTANT INFORMATION AND WHO WE ARE
2. THE DATA WE COLLECT ABOUT YOU
3. HOW IS YOUR PERSONAL DATA COLLECTED?
4. HOW WE USE YOUR PERSONAL DATA
5. DISCLOSURES OF YOUR PERSONAL DATA
6. INTERNATIONAL TRANSFERS
7. DATA SECURITY
8. DATA RETENTION
9. YOUR LEGAL RIGHTS
1. IMPORTANT INFORMATION AND WHO WE ARE
The Website is not intended for children and we do not knowingly collect data relating to children.
Bath Fitter Limited, Units 25 & 41 Eastlink Business Park, Ballysimon, Limerick, Ireland
Email address: firstname.lastname@example.org
Postal address: Units 25 & 41 Eastlink Business Park, Ballysimon, Limerick, Ireland
Telephone: +1 450 472 0027 x6789
You have the right to make a complaint at any time to the appropriate Data Protection Commission. Bath Fitter Ltd. would, however, appreciate the chance to deal with your concerns before you approach the Data Protection Commission so please contact Bath Fitter Ltd. directly in the first instance.
It is important that the personal data Bath Fitter Ltd. holds about you is accurate and current. Please keep Bath Fitter Ltd. informed if your personal data changes during your relationship with us.
2. DATA WE COLLECT ABOUT YOU
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
Bath Fitter Ltd. may collect, use, store and transfer different kinds of personal data about you which it has grouped together as follows:
· Identity Data includes name, username or similar identifier, title.
· Contact Data includes location address, email address and telephone numbers.
· Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Website.
· Profile Data includes your interests, preferences, feedback and any survey responses.
· Usage Data includes information about how you use our Website, products and services.
· Marketing and Communications Data includes your preferences in receiving marketing from Bath Fitter Ltd. and your communication preferences.
Except for employment-related information, and subject to applicable law, Bath Fitter Ltd. does not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Except for employment-related information, and subject to applicable law, Bath Fitter Ltd. does not collect information about criminal convictions and offences.
IF YOU FAIL TO PROVIDE PERSONAL DATA
Where Bath Fitter Ltd. needs to collect personal data by law, or under the terms of a contract it has with you, and you fail to provide that data when requested, Bath Fitter Ltd. may not be able to perform the contract it has or is trying to enter into with you (for example, to provide you with goods or services). In this case, Bath Fitter Ltd. may have to cancel a product or service you have therewith, but Bath Fitter Ltd. will notify you if this is the case at the time.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
Bath Fitter Ltd. uses different methods to collect data from and about you including through:
· Direct interactions. You may give Bath Fitter Ltd. your personal data by filling in forms or by corresponding with Bath Fitter Ltd. by post, phone, email or otherwise. This includes personal data you provide when you:
o contact Bath Fitter Ltd. with an enquiry;
o request marketing to be sent to you or subscribe to any newsletters or other information we make available from time to time;
o enter a promotion or survey; or
o give Bath Fitter Ltd. feedback.
Third parties. Bath Fitter Ltd. will receive Technical Data relating to you from Google Analytics.
4. HOW BATH FITTER LTD. USES YOUR PERSONAL DATA
Bath Fitter Ltd. will only use your personal data when the law allows it to. Most commonly, Bath Fitter Ltd. will use your personal data in the following circumstances:
Where Bath Fitter Ltd. needs to perform the contract it is about to enter into or has entered into with you.
Where it is necessary for its legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Where Bath Fitter Ltd. needs to comply with a legal obligation.
Generally, Bath Fitter Ltd. does not rely on consent as a legal basis for processing your personal data although it will get your consent before sending direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting Bath Fitter Ltd.
PURPOSES FOR WHICH BATH FITTER LTD. WILL USE YOUR PERSONAL DATA
Bath Fitter Ltd. has set out below, in a table format, a description of all the ways Bath Fitter Ltd. plans to use your personal data, and which of the legal bases it relies on to do so. Bath Fitter Ltd. has also identified what its legitimate interests are where appropriate.
Note that Bath Fitter Ltd. may process your personal data for more than one lawful ground depending on the specific purpose for which it is using your data. Please contact Bath Fitter Ltd. if you need details about the specific legal basis it is relying on to process your personal data where more than one ground has been set out in the table below.
Bath Fitter Ltd. strives to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. Where you no longer wish to receive marketing information from us, please contact Bath Fitter Ltd. at email@example.com at any time to let it know and it will cease all marketing communications to you.
PROMOTIONAL OFFERS FROM US
Bath Fitter Ltd. may use your identity, contact, technical, usage and profile data to form a view on what it thinks you may want or need, or what may be of interest to you. This is how Bath Fitter Ltd. decides which products, services and offers may be relevant for you (Bath Fitter Ltd. calls this marketing).
You will receive marketing communications from Bath Fitter Ltd. if you have requested information from Bath Fitter Ltd. or purchased goods or services therefrom and you have not opted out of receiving that marketing, or where you give Bath Fitter Ltd. consent to market to you.
You can ask Bath Fitter Ltd. to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting Bath Fitter Ltd. at any time at firstname.lastname@example.org.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to Bath Fitter Ltd. as a result of a product/service purchase, warranty registration, product/service experience or other transactions.
CHANGE OF PURPOSE
Bath Fitter Ltd. will only use your personal data for the purposes for which it has collected it, unless Bath Fitter Ltd. reasonably considers that it needs to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact Bath Fitter Ltd.
If Bath Fitter Ltd. needs to use your personal data for an unrelated purpose, it will notify you and explain the legal basis which allows Bath Fitter Ltd. to do so.
Please note that Bath Fitter Ltd. may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
5. DISCLOSURES OF YOUR PERSONAL DATA
Bath Fitter Ltd. may share your personal data with the parties set out below for the purposes set out in the table “Purposes for which we will use your personal data” above.
Internal Third Parties as set out in the Glossary.
External Third Parties as set out in the Glossary.
Bath Fitter Ltd. requires all third parties to respect the security of your personal data and to treat it in accordance with the law. Bath Fitter Ltd. does not allow its third-party Service Providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with its instructions.
6. INTERNATIONAL TRANSFERS
Bath Fitter Ltd. shares your personal data with BF Affiliates, including Bath Fitter Distributing Inc., incorporated in Canada and located at 225, rue Roy, Saint-Eustache (Québec) Canada J7R 5R5. In case of a data transfer outside the European Economic Area (EEA), such transfer will, where required, take place pursuant to written agreements, which contain provisions to safeguard your data.
7. DATA SECURITY
Bath Fitter Ltd. has put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, Bath Fitter Ltd. limits access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on Bath Fitter Ltd.’s instructions, and they are subject to a duty of confidentiality.
Bath Fitter Ltd. has put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where Bath Fitter Ltd. is legally required to do so.
8. DATA RETENTION
HOW LONG WILL YOU USE MY PERSONAL DATA FOR?
Bath Fitter Ltd. will only retain your personal data for as long as reasonably necessary to fulfil the purposes it collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. Bath Fitter Ltd. may retain your personal data for a longer period in the event of a complaint or if it reasonably believes there is a prospect of litigation in respect to Bath Fitter Ltd.’s relationship with you.
To determine the appropriate retention period for personal data, Bath Fitter Ltd. considers the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which Bath Fitter Ltd. processes your personal data and whether Bath Fitter Ltd. can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
By law Bath Fitter Ltd. has to keep basic information about its customers for six years after they cease being customers for certain regulatory purposes.
In some circumstances you can ask Bath Fitter Ltd. to delete your data: see Section 9 “Your Legal Rights” below for further information.
In some circumstances Bath Fitter Ltd. will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case Bath Fitter Ltd. may use this information indefinitely without further notice to you.
9. YOUR LEGAL RIGHTS
· Request access to your personal data
· Request correction of your personal data
· Request erasure of your personal data
· Object to processing of your personal data
· Request restriction of processing your personal data
· Request transfer of your personal data
· Right to withdraw consent
If you wish to exercise any of the rights set out above, please contact Bath Fitter Ltd.’s data privacy manager.
NO FEE USUALLY REQUIRED
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, Bath Fitter Ltd. may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, Bath Fitter Ltd. could refuse to comply with your request in these circumstances.
WHAT WE MAY NEED FROM YOU
Bath Fitter Ltd. may need to request specific information from you to help Bath Fitter Ltd. confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person, who has no right to receive it. Bath Fitter Ltd. may also contact you to ask you for further information in relation to your request to speed up its response.
TIME LIMIT TO RESPOND
Bath Fitter Ltd. tries to respond to all legitimate requests within one month. Occasionally it could take Bath Fitter Ltd. longer than a month if your request is particularly complex or you have made a number of requests. In this case, Bath Fitter Ltd. will notify you and keep you updated.
Legitimate Interest means the interest of Bath Fitter Ltd.’s business in conducting and managing its business to enable it to give you the best service/product and the best and most secure experience. Bath Fitter Ltd. makes sure it considers and balances any potential impact on you (both positive and negative) and your rights before Bath Fitter Ltd. processes your personal data for its legitimate interests. Bath Fitter Ltd. does not use your personal data for activities where its interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how Bath Fitter Ltd. assesses its legitimate interests against any potential impact on you in respect of specific activities by contacting Bath Fitter Ltd.’s data privacy manager.
Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request (or in response to an enquiry from you) before entering into such a contract.
Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that Bath Fitter Ltd. is subject to.
INTERNAL THIRD PARTIES
Other companies in the BF Group including Bath Fitter Distributing Inc. and who are based in Canada and other countries acting as controllers and processors and who provide IT, system administration, support and maintenance, management, hosting of data, financial and business support services.
EXTERNAL THIRD PARTIES
Service providers acting as processors based in the EEA and outside of the EEA who provide business support services, IT, HR, marketing, customer experience and system administration services.
Service providers acting as processors based in the EEA and outside of the EEA who provide surveying, measurements, photographic, design, fabrication, repair and installation services.
Professional advisers acting as processors and controllers including lawyers, marketing agencies, bankers, auditors and insurers based in the EEA and outside of the EEA who provide consultancy, banking, legal, insurance and accounting services.
The Revenue Commissioners, regulators and other authorities acting as controllers based in Ireland who require reporting of processing activities in certain circumstances.
Contractors for after sale/installation services
YOUR LEGAL RIGHTS
You have the right to:
Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data Bath Fitter Ltd. holds about you and to check that Bath Fitter Ltd. is lawfully processing it.
Request correction of the personal data that Bath Fitter Ltd. holds about you. This enables you to have any incomplete or inaccurate data Bath Fitter Ltd. holds about you corrected, though Bath Fitter Ltd. may need to verify the accuracy of the new data you provide thereto.
Object to processing of your personal data where Bath Fitter Ltd. is relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts your fundamental rights and freedoms. You also have the right to object where Bath Fitter Ltd. is processing your personal data for direct marketing purposes. In some cases, Bath Fitter Ltd. may demonstrate that it has a compelling legitimate ground to process your information which override your rights and freedoms.
Request restriction of processing of your personal data. This enables you to ask Bath Fitter Ltd. to suspend the processing of your personal data in the following scenarios:
o If you want Bath Fitter Ltd. to establish the data’s accuracy.
o Where you need Bath Fitter Ltd. to hold the data even if it no longer requires it as you need it to establish, exercise or defend legal claims.
o You have objected to Bath Fitter Ltd.’s use of your data but Bath Fitter Ltd. needs to verify whether it has an overriding legitimate ground to use it.
Request the transfer of your personal data to you or to a third party. Bath Fitter Ltd. will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for Bath Fitter Ltd. to use or where Bath Fitter Ltd. used the information to perform a contract with you.
Withdraw consent at any time where Bath Fitter Ltd. is relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, Bath Fitter Ltd. may not be able to provide certain products or services to you. Bath Fitter Ltd. will advise you if this is the case at the time you withdraw your consent.
Effective Date: 6/14/2019
Last Revision Date: 07/20/2021
Effective Date: 6/14/2019
Last Revision Date: 07/20/2021