Here at Lilly Dilly’s, we take your privacy seriously. We promise to respect any personal data you share with us, and keep it safe.
This policy explains who we are, what information we collect, how and why we use it, how it is stored and your rights with regard to any information you share with us.
Please read this information carefully, as by providing your data to us you acknowledge you have read this policy and understand we will process your data in accordance with its terms.
Who are we?
Lilly Dilly’s is a small independant business based in Bewdley, Worcestershire.
The address is 5 Welch Gate, Bewdley, DY12 2AT
We promise to use the information we collect about you in accordance with the General Data Protection Regulation (2018) (GDPR), the Data Protection Act (2018) and the Privacy and Electronic Communications Regulations (PECR, 2003). We aim to be clear when we handle your data, and not do anything you wouldn’t reasonably expect.
What information do we collect?
You may be required to give us personal information when complete an enquiry form, attend an event, register for a mailing list for updates or alerts, update your preferences, sign up for an event, visit the boutique, buy something on our website or ETSY store, apply for a job, place an order via email, social media, phone or in person. Making a purchase from the boutique.
We may collect the following information from or about you:
- Postal address
- Telephone number(s)
- Email address
- Event Information
- Billing/payment information
- Communications preferences
- Qualitative opinions or attitudes about our services and programme through surveys
- Any other information you provide to us by email, letter, telephone, social media, via our websites or apps, or in person
- CCTV security recordings, and possible photography or video at events
- Information that is publicly available
Online Information: Through our websites and apps, we receive and store certain details through “cookies” which record how the sites are being used to help us provide improved services, analyse usage and enable transactions. Cookies are small text documents, stored by your web browser on your device when you visit our websites, which enable an enhanced experience by storing information such as your user details or preferences. You can decide whether or not to allow cookies on your device.
We keep a record of the emails we send you, and we may track whether you receive or open them so we can make sure we are sending you the most relevant information.
We use social media to provide updates on our activities and to promote new products and projects. We may tailor adverts on social media and elsewhere online relevant to your interests. Depending on your own privacy settings, you may control Lilly Dilly’s permission to access information via social media platforms.
We use some online tracking and analysis services such as Google Analytics to find out how our websites are being used, which campaigning activities are working best, and how we can improve customer experience.
Why do we collect this information, and how do we use it?
We will use your information for the purposes listed below either on the basis of: performance of your contract; your consent (where we require it); where we need to comply with a legal obligation; or our legitimate interest or those of a third party.
Developing a good understanding of customers and supporters through personal data allows us to make better business decisions enabling us to operate, market our services, and provide services more efficiently.
We use the information we collect about you:
- to contact you to dicuss your requirements or order
- to fulfil our contract with you
- to keep a record of the relationship we have with you
- to process a transaction and carry out completion of a purchase (your personal information and card details may be passed to third party service providers; card details will only be used in this way for the purpose of handling an individual transaction)
- to inform you about relevant events, services or activities we believe will be of interest
- to provide a personalised service and ensure the best possible experience when you visit us
- to ensure that the information we already hold is accurate and up to date
- to improve our products, services and information in the future
- to ensure we know how you prefer to be contacted
- to protect against fraud or unlawful activity
- to ensure compliance with policies, procedures and laws
- to process any recruitment information, whether directly or via an agent, including sharing this with our third party recruitment software supplier
- to share with approved suppliers (for instance for research and direct mail)
- from time to time, to undertake customer research to help us understand how we can improve our services or information
- to promote the boutique & atelier and its activities (e.g. imagery, quotes from social media etc)
- to inform you of special offers and sales, new product launches.
Sharing your data with third parties: We will only share data with third party providers on the legal bases as listed below:
- For fulfilment of contract: services such as sourcing materials and services from suppliers,email service and mailing houses. We have agreements in place with each provider to ensure your data is secure and cannot be accessed or used for any other purpose. Your personal data is never sold to any agencies or companies.
- Legitimate business interests: we may make data available to approved suppliers for analysis and research purposes only, for example identifying sales trends, assessing campaign effectiveness, or postcode mapping etc This assists us with reporting and with our strategic planning, helping us apply our resources more intelligently. All such agencies will be carefully checked and have a separate data sharing agreement with us including non-disclosure agreements, and their Privacy Policies will have to be at least as secure as our own.
Sharing data outside the EU: We are located in the UK. Some our suppliers run operations outside the European Economic Area (EEA). Although they may not be subject to the same data protection laws as in the UK, we take steps to make sure they provide an adequate level of protection in accordance with UK law. By submitting your personal information to us you acknowledge that you understand that your personal information may be transferred, and processed, outside the EEA. Where we use providers based in the US, we may transfer data to them if they are part of the EU-US Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US.
How can you update you preferences?
You can set and update your personal contact and interest preferences at any time, by visiting the website and using the contact form.
How we keep your data safe
We are located in the UK. Your data is held in the UK and processed on secure systems owned by Lilly Dilly’s and details are only accessed by authorised and trained staff. Only employees and approved contractors/developers are granted access to personally identifiable information. This will be from time to time, and only when they need to perform a specific job. If required by law (e.g. by police, regulatory bodies or legal advisers) we may need to disclose your details. We will ensure information is held securely, and only those who need access to it can see it. We will delete this information when we no longer need it.
Data retention: We will retain your information for as long as is necessary to provide you with the services you have requested or require from us unless (a) we must keep it to comply with applicable laws or evidence compliance with such applicable laws; (b) there is an outstanding issue, claim or, dispute requiring us to keep such information until the issue, claim, or dispute is resolved; or (c) the information must be kept for our legitimate business interests, such as fraud prevention and enhancing users’ safety and security. We regularly review email and paper correspondence and minimise our storage through archiving and destruction of out of date materials. We will store data in our ticketing system for a maximum of 10 years after your last transaction or communication with us. We have considered the nature, relevance and volume of this data, the potential risks, and the purposes for which we process your data.
Changes to this policy
You have rights including the following:
- to be informed of the ways in which we use your information, as we seek to do in this policy
- to request us to stop processing your personal data for marketing purposes
- you can request a copy of the personal information we hold about you
- you can request that inaccuracies are corrected
- you can withdraw any consent to direct marketing (please see the section “Why do we collect this information, and how do we use it?” above to see when we are relying on your consent)
- the right to object to our using your information on the basis of our legitimate interests (refer to the section headed “Why do we collect this information, and how do we use it?” above to see when we are relying on our legitimate interests) (or those of a third party) and there is something about your particular situation which makes you want to
object to processing on this ground
- in certain circumstances you can request that we limit or cease processing or erase your personal data
Please note that we may need to retain certain information for our own record-keeping and research purposes. We may also need to send you service-related communications.
Do you have any questions or concerns?
Email us: firstname.lastname@example.org
Write to us:
Lilly Dilly’s, 5 Welch Gate, Bewdley, DY12 2AT
Call us: 07508004975