VISIT OUR NEW SHOP! naafishop.co.uk

The Royal NAAFI/NAAFI UK Ltd Privacy Policy

Terms

“We” - refers to NAAFI UK Ltd registered number 10930168 and it’s parent company The Royal NAAFI registered number 00171912.

“GDPR” – refers to the EU General Data Protection Regulation.

“Data Protection Laws”  - refers to the UK Data Protection Act 2018.

“The Law” – refers to the law of England and Wales.

“Third Party” – any company that is not either NAAFI UK Ltd or The Royal NAAFI.

Overview

The Royal NAAFI/NAAFI UK Ltd is committed to protecting your privacy online and ensuring that your personal data is handled securely.

The Royal NAAFI and NAAFI UK Ltd share administrative personnel for their joint businesses, therefore all data held by NAAFI UK Ltd may be accessed by The Royal NAAFI Ltd.

Our policies are fully compliant with the UK General Data Protection Regulations (GDPR).

We do not retain personal data for longer than it is required for the purposes that we collect it and we do not sell personal data to third parties.

Our full cookie policy can be found here  

Our policies may be amended from time to time to ensure that they remain current and reflect best practice.

Third Parties

We do share contact information with a third party service provider for the purpose of providing you with information on products and offers. We do not share this information unless you have asked us to by signing up to our mailing list.

Our online service is hosted by Dynamic Web and Advania. These companies do not handle customer data directly, but may access our platform at our request to carry out maintenance tasks. We have contracts with both companies ensuring the highest standard of data security.

Legal Basis for Processing Data

The EU GDPR and UK data protection laws require a legal basis for our use of personal information. Our basis varies depending on the specific purpose for which we use personal information. We use:

Performance of a contract when we provide you with products or services, or communicate with you about them. This includes when we use your personal information to take and handle orders, deliver products and services, and process payments.

Our legitimate business interests and the interests of our customers when we improve our services, when we detect and prevent fraud and abuse in order to protect the security of our customers, ourselves, or others.

Your consent when we ask for your consent to process your personal information for a specific purpose that we communicate to you. When you consent to our processing your personal information for a specified purpose, you may withdraw your consent at any time and we will stop processing of your data for that purpose.

Compliance with a legal obligation when we use your personal information to comply with laws. For instance, we collect seller place of establishment and bank account information for identity verification purposes.

 

Your Rights

The GDPR provides the following rights for individuals:

The right to be informed – you have the right to be informed about the collection and use of your personal data.

The right to access – you have the right to obtain a copy of your personal data that we hold. This is known as a “subject access request”

The right to rectification – if we hold incorrect data about you, you have the right to request that it is corrected.

The right to erasure – you have the right to request that data we hold about you is erased. This right may be limited by our legal obligations, in which case we will provide you with a clear statement as to why we cannot erase your data.

The right to restrict processing – you have the right to request that we stop processing your personal data.

The right to data portability – you have the right to request that, where you request copies of your data, that it is provide in an electronic, portable form.

The right to object – you have the right to object to our processing your personal data in certain circumstances. You have an absolute right to stop your data being used for direct marketing.

Rights in relation to automated decision making and profiling – you have the right to insist that any automated decision or profiling of you is reviewed by a human being.

More information on your rights in respect of your personal data can be found at the Information Commissioner’s Office at https://ico.org.uk

 

Contact Details

You can contact our Data Protection Manager about your personal data either by email at:

enquiries@naafi.co.uk

Or by post at our registered office at:

The Royal NAAFI Ltd
Forum 5, Solent Business Park, 
Fareham, 
United Kingdom, PO15 7PA