B&W GROUP LIMITED

FAIR PROCESSING NOTICE: FORMATION PRODUCT RANGE AND ASSOCIATED APP

We ask that you read this fair processing notice carefully as it contains important information on who we are, how and why we collect, store, use and share personal information when you purchase and use a Formation product (including Formation Duo, Formation Audio, Formation Bar, Formation Wedge, Formation Bass and any other models we introduce to the range) (each, a Product), use the associated mobile application software (App), your rights in relation to your personal information and on how to contact us and supervisory authorities in the event you have a complaint.

WHO WE ARE

B&W Group Limited collects, uses and is responsible for certain personal information about you. When we do so we are regulated under the Data Protection Act 2018 and the General Data Protection Regulation. We are responsible as ‘controller’ of that personal information for the purposes of those laws.

THE PERSONAL INFORMATION WE COLLECT AND USE

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

Through the App and/or the Products, and other interactions with you, we may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:

  • Identity Dataincludes first name, last name, username or similar identifier, title, date of birth and gender.
  • Contact Dataincludes billing address, delivery address, email address and telephone numbers.
  • Technical Data comprising:
    • Essential Technical Data includes your login data, network interface data (which may also include performance data such as temperature, signal strength, duration of use of Product), time zone setting and location, other technology on the mobile / handheld device on which you have installed the App, Product type and serial number, operating system, software version, device UUID, and system events; and 
    •  Additional Technical / Usage Data includes mobile “out of box” events, and the flow through mobile screens.    
  • Profile Dataincludes your username and password, preferences, feedback and survey responses.  
  • Usage Dataincludes information about how you use the App, the Product and our services. 
  • Marketing and Communications Dataincludes your preferences in receiving marketing from us and our third parties and your communication preferences.

We also collect, use and share anonymous data such as statistical or demographic data for any purpose. Anonymous data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data (with the Usage Data of others) to calculate the percentage of users accessing a specific product function. However, if we combine or connect anonymous with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this fair processing notice.

We do not collect any Special Categories of Personal Dataabout you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

Although users of all ages may access and use the App and/or a Product, we do not knowingly collect data relating to children. If we find out that a child under 16 has registered with us through the App because, for example, a parent has told us about it, we will cancel the registration and delete any personal information that child has provided to us

HOW WE COLLECT YOUR PERSONAL INFORMATION

We use different methods to collect data from and about you including through:

  • Direct interactions. You may give us your Identity, Contact, Profile, and Marketing and Communications Data by filling in forms (within the App) or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
    • register your product;
    • create an account on our website or through the App;
    • subscribe to our service or publications; 
    • request marketing to be sent to you;
    • enter a competition, promotion or survey; or
    • give us some feedback. 
  • Automated technologies or interactions. As you interact with the App and/or the Product, we will automatically collect Technical and Usage Data about your device on which the App is installed and/or the Product, browsing actions and patterns. We collect this personal data by using server logs and other similar technologies.

HOWWE USE YOUR PERSONAL INFORMATION

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Where we need to perform the contract we are about to enter into or have entered into with you – for example, the product warranty.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.
  • Where we rely on your consent – for example, where you consent to us collecting Technical and Usage Data through the Formation App or third party marketing communications to you via email or text message. You have the right to withdraw consent at any time by contacting us.

THE PURPOSES FOR WHICH WE USE YOUR PERSONAL INFORMATION.

We have set out below, in a table format, a description of the ways we plan to use your personal information, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. If you need details about the specific legal ground we are relying on to process your personal data, please contact us. 

Purpose/Activity

Type of data

Lawful basis for processing including basis of legitimate interest

To register you as a customer and your warranty

(a) Identity 

(b) Contact

 

Performance of a contract with you

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or this fair processing notice

(b) Asking you to leave a review or take a survey

(a) Identity 

(b) Contact 

(c) Profile 

(d) Marketing and Communications

(a) Performance of a contract with you 

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To use data analytics to improve our products/services, marketing, customer relationships and experiences

(a) Technical 

(b) Usage 

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our products updated and relevant, to develop our business and to inform our marketing strategy)

To make suggestions and recommendations to you about goods or services that may be of interest to you

(a) Identity 

(b) Contact 

(c) Technical 

(d) Usage 

(e) Profile 

Necessary for our legitimate interests (to develop our products/services and grow our business)

To help ensure your Product is working properly, performs its basic functions, and to provide you with customer support 

(a) Identity 

(b) Contact 

(c) Essential Technical 

 

Performance of a contract with you.

To improve your Product experience and to offer better products and services that meet our customers’ expectations and needs.

(a) Identity 

(b) Contact 

(c) Additional Technical / Usage

(d) Usage 

(e) Profile

Necessary for our legitimate interests (to keep our products updated and relevant).  

Note, you can opt out of sharing Additional Technical / Usage Data through the App’s settings. 

WHETHER INFORMATION HAS TO BE PROVIDED BY YOU, AND IF SO WHY

The provision of Identity, Contact Data and Essential Technical Data is required from you to enable us to perform our contract with you. If you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with an update, warranty support and/or support services). This means that you may not be able to continue to use the Product. 

HOW LONG YOUR PERSONAL INFORMATION WILL BE KEPT

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. 

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

WHO WE SHARE YOUR PERSONAL INFORMATION WITH

We routinely share personal data about you (including your name, delivery address details and technical / usage data)with our group companies) where required in order to provide you with the Product and/or App and our connected servicesPlease contact us for up-to-date details of our group companies.This data sharing enables us to: improve our products and services; support the Products and/or App and ensure they are working properly, and, improve your Product and/or App experience. Some of the group company recipients may be based outside the European Economic Area — for further information including on how we safeguard your personal data when this occurs, see ‘Transfer of your information out of the EEA’, below.

We will share personal information with law enforcement or other authorities if required by applicable law.

We will not share your personal information with any other third party.

TRANSFER OF YOUR INFORMATION OUT OF THE EEA

We may transfer your personal information to the following which are located outside the European Economic Area (EEA) as follows: 

  • Amazon Web Services (AWS) servers based in the United States of America. We use AWS for “cloud” storage of data we collect from you (and other users). 
  • Other group companies in order to provide you with our Products and/or App and our connected services, as detailed above.
  • Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented: We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  • We will only transfer to companies within our group if they have agreed to our Binding Corporate Rules (based on EU Model Clauses)Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US.  At the date of this notice, AWS are a member of Privacy Shield.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA. If you would like further information please contact us, our Data Protection Officer(see ‘How to contact us’below). 

YOUR RIGHTS

The Data Protection Act 2018 (and the General Data Protection Regulation) provides you with a number of important rights free of charge. In summary, those include rights to:

  • fair processing of information and transparency over how we use your use personal information
  • access to your personal information and to certain other supplementary information that this fair processing notice is already designed to address
  • require us to correct any mistakes in your information which we hold
  • require the erasure of personal information concerning you in certain situations
  • receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
  • object at any time to processing of personal information concerning you for direct marketing
  • object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
  • object in certain other situations to our continued processing of your personal information
  • otherwise restrict our processing of your personal information in certain circumstances
  • claim compensation for damages caused by our breach of any data protection laws

If you would like to exercise any of those rights, please:

  • email, call or write to us
  • let us have enough information to identify you– for example, by providing your name and address, and your product serial  number
  • let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill), and
  • let us know the information to which your request relates 

If you would like to unsubscribe from any email newsletteryou can also click on the ‘unsubscribe’ button at the bottom of the email newsletter. It may take up to 14 days for this to take place.

KEEPING YOUR PERSONAL INFORMATION SECURE

We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

HOW TO COMPLAIN

We hope that wecan resolve any query or concern you raise about our use of your information.

The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns/or telephone: 0303 123 1113.

CHANGES TO THIS FAIR PROCESSING NOTICE

This fair processing notice was published on [insert date] [and last updated on [insert date]].

We may change this fair processing notice from time to time. Please regularly check the privacy notice accessible through the App for updates.

HOW TO CONTACT US

Please contact us, if you have any questions about this fair processing notice or the information we hold about you.

If you wish to contact us, please send an email to [insert email address], write to [insert address] or call [insert telephone number].

DO YOU NEED EXTRA HELP?

If you would like this notice in another format (for example: audio, large print, braille) please contact us (see ‘How to contact us’ above).

B&W GROUP LIMITED

20 August 2018