TREX PRIVACY NOTICE

This version is effective from: December 2, 2024

This Privacy Notice (“Privacy Notice”) sets out how Trex Company, Inc. processes your personal data in connection with our business, including the provision of our website at https://ie.trex.com/ (“Site”) and the products and services we offer (“Products and Services”).

We will update this Privacy Notice from time to time to reflect any changes or proposed changes to our use of your personal data, or to comply with changes in applicable law or regulatory requirements. We may notify you by email of any significant changes to this Privacy Notice, but we encourage you to review this Privacy Notice periodically to keep up to date on how we use your personal data. If we update this Privacy Notice, we will update the effective date at the top of the page.

Your access to and use of our Site, including your account page and any secure area, is subject at all times to our Website Terms of Use.

1.      PURPOSE OF THIS PRIVACY NOTICE

This Privacy Notice explains our approach to any personal data that we might collect from you or which we have obtained about you from a third party, and the purposes for which we process your personal data. This Privacy Notice also sets out your rights in respect of our processing of your personal data. 

When we talk about “personal data”, we mean any information which relates to an identified or identifiable living individual. Individuals might be identified by reference to a name, an identification number, location data, an online identifier (such as an IP address) or to other factors that are specific to them, such as their physical appearance.

This Privacy Notice is intended to assist you in making informed decisions when using our Site and our Products and Services. Please take a moment to read and understand it. It should be read in conjunction with our Website Terms of Use and our Cookie Notice.

This Privacy Notice only applies to the use of your personal data obtained by us, whether from you directly or from a third party. It does not apply to personal data collected by third parties during your communications with those third parties or your use of their products or services (for example, where you follow links to third party websites over which we have no control, or you purchase goods or services from those third parties).

 
2.     ABOUT US

The Site and our Products and Services are made available by Trex Company, Inc (“Trex”, “we”, “us", “our”). Trex is the data controller responsible for your personal data. 

 
3.     HOW TO CONTACT US

If you have any questions about this Privacy Notice or want to exercise your rights as a data subject set out in this Privacy Notice, you can contact us using the following methods:

On site

Contact us using our Enquiry Form

Email Address

privacy@trex.com


4.     WHAT PERSONAL DATA WE COLLECT

In providing our Site and our Products and Services, we may collect and process different types of personal data about you for different processing purposes. The types of personal data we collect depends on who you are and how you use our Site and our Products and Services and includes the following:

Identity DataFirst name; last name.
Contact DataDelivery address; home address; billing address; email address; telephone number; social media handle.
Deck Cost Calculator DateEmail address; postal code.
Deck Designer DataFirst name; last name; address; email address; email marketing opt-in/out.
Deck Plans DataEmail address; postal code; country; project timeline.
Profile DataFeedback and survey responses; the content of any messaging sent through an Enquiry Form on the Site.
Behavioural DataData relating to your browsing activity or interaction with our emails, obtained through the use of cookies, marketing tags and other similar technologies; information about when your current or previous sessions started; details about any products you viewed or purchased through the Site.
Technical DataIP address; browser type and operating system; geolocation, to ensure the correct notices and information are shown; any other unique numbers assigned to a device.
Marketing and Communications DataMarketing preferences; service communication preferences.
Warranty Submission DataFirst name; last name; homeowner or contractor; home address; primary phone number; secondary phone number; email address; preferred contact method; installation address; Trex installer; whether or not the product is already installed; date of purchase or installation; deck area; deck material; deck colour; deck railing; deck lighting; description of other products involved; description of concerns with product; photo uploads of entire deck and issues being experienced; certification of accuracy.
Warranty Registration DataWarranty type; first name; last name; installation address; mailing address; phone number; email address; project completion date; project built by; contracting company; contracting contact name; contracting contact phone number; Trex products used in project; unit lot code; project length; approximate project cost; how did you hear about Trex; customer priority rankings of: appearance, durability, low maintenance, environmentally friendly, splinter free, warranty; email marketing opt-in/out.


 
5.     HOW WE COLLECT AND RECEIVE PERSONAL DATA

We collect and receive personal data using different methods:

Personal data you provide to us You may give us your personal data directly, for example, when you purchase products, contact us with enquiries, complete forms on our Site, subscribe to receive our marketing communications or provide feedback to us.
Personal data we collect using cookies and other similar technologiesWhen you access and use our Site, we will collect certain Behavioural Data and Technical Data. We collect this personal data by using cookies and other similar technologies (see the “Insight, analysis and retargeting through Cookies")
Personal data received from third partiesWe may receive personal data about you from third parties. Such third parties may include analytics providers, data brokers, third party directories and third parties that provide technical services to us so that we can provide our Site and our Services.
Publicly available personal dataFrom time to time, we may collect personal data about you (Identity Data, Contact Data or Profile Data) that is contained in publicly available sources (including open source data sets or media reports) or that you or a third party may otherwise make publicly available (for example posts on social media platforms).
 

6.     WHO WE COLLECT PERSONAL DATA ABOUT

We collect and process personal data from the following people:

Site visitors If you browse our Site, we will collect and process your personal data in connection with your interaction with us and our Site.
CustomersIf you buy our Products and Services, we may collect and process your personal data in connection with the supply of goods or services to you.
People who contact us with enquiriesIf you contact us with an enquiry through our Site, submit a complaint through our Site or provide any feedback to us in our surveys and feedback forms, we will collect and process your personal data in connection with your interaction with us and our Site.
People who work for our customers and suppliersIf you work for one of our customers or suppliers and have responsibility for placing orders with us, administering your organisation’s account with us or handling our orders or our account with your organisation, we will process your personal data in connection with your organisation’s relationship with us.
Visitors to our physical locationsIf you attend one of our physical stores, offices or other locations, we may process personal data that you volunteer in connection with your visit and any enquiries you make. For example, you may volunteer personal data when signing in as a guest. CCTV footage may also be collected for security purposes.
Event attendeesIf you attend one of our events, we will process personal data about you in connection with your attendance at the event. For example, we may ask you to complete a registration or feedback form, or other document relating to the event.
Job applicantsIf you apply for a job with us, whether through the Site or otherwise, we will collect and process your personal data in connection with your application.
Authorised Trex dealers

You may also provide us with certain information when registering your Trex products which we use to assist us with the administration of warranties that may be applicable to your purchase.

When you register your products with us that you have purchased from an authorised Trex dealer, we may ask for the dealer’s information such as address. 

 

7.     HOW WE USE YOUR PERSONAL DATA

We use your personal data for the purposes set out in this section. If we wish to make any changes to these purposes, or if we wish to use your personal data for any purpose that is not listed in this section, we will notify you using the contact details we hold for you.

Use of our Site.

If you browse our Site

When you browse our Site, we collect and process Behavioural Data and Technical Data to help us understand how you are using and navigating our Site. We do this so that we can better understand which parts of our Site are more or less popular and improve the structure and navigation of our Site.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Products and Services, or it is in our legitimate interest to use personal data in such a way to ensure that we provide access to our Site in a secure and effective way and so that we can make improvements to our Site.

If you use the interactive features on our Site

We will collect and use personal data about you when you use certain features on our Site. For example, depending on the nature of your enquiry, we may process your Identity Data, Contact Data, Registration Data, Profile Data and certain Behavioural Data and Technical Data when you use the Enquiry Form to get in touch with us.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Services, or it is in our legitimate interest to use personal data in such a way to ensure that we can respond to your enquiries, provide access to our Site in a secure and effective way and make improvements to our Site.

If you contribute to our Site or post content on our Site.

If you write an article or blog for us or contribute in any other way to publications we send to our account holders and/or publish on our Site or in print, we may use your personal data (such as your Identity Data and/or Contact Details) to credit you for your contribution. If you provide photographs or other images in support of your article or blog, we may publish one or more of those images alongside your article or blog.

If you submit any other content to us, including via our Site, such as photographs, quotes or testimonials, we may process any personal data comprised within that content for the purposes of making available particular Products and Services via our Site and promoting our Site and our Products and Services.

We may also allow third parties to use the articles or blogs that you contribute, or the content that you provide. If the use of such content would involve the use of your personal data, we may use your Contact Details to ask your permission to use the relevant content, unless we are satisfied that we have a lawful right to use the content without your permission.

Our legal basis for processing

Where we permit a third party to use your personal data contained within content that you submit, we will do so without your permission if we are satisfied that it is within our or the third party’s legitimate interest to use your personal data, including to promote our Products and Services or products and/or services offered by the third party. If it is not within our legitimate interest, we will contact you to ask your permission, in which case our processing of such personal data will be based on your consent.

If you link to social media sites and interact with our social media pages

If you click on one of the social media links on our Site or otherwise interact with our social media pages such as on Facebook or Instagram (including interacting with any ‘like’ or similar embedded features on our Site or social media accounts), we and the relevant social media platform may receive information relating to such interaction and may share your personal data in connection with this purpose, such as certain Behavioural Data and Technical Data. For more information about how we use this personal data, please see the “Insight, analysis and retargeting through Cookies” section below.

The relevant social media platform may also be a controller in respect of the personal data that is collected via your use of our social media pages and may use that personal data for additional purposes. For details of how the relevant social media platform uses your personal data, please see the privacy policy of the relevant social media platform.

Our legal basis for processing

It is in our legitimate interest to use personal data in the ways described above to ensure that we provide the Site in an effective way and to promote our Site via social media.

Fulfilment of our Services.  

Fulfilment of our Services

We collect and maintain personal data that you submit to us for the purpose of supplying our decking and related Products and Services. We may collect and process your personal data whether you are interacting with us on your own behalf or on behalf of any organisation you represent.

The personal data we process may include your Contact Data, Registration Data, and Financial Data (where applicable). We process this information so that we can fulfil the supply of Services, maintain our user databases and to keep a record of how our Services are being used.

If you attend one of our offices or other locations, we will process personal data about you which you volunteer in connection with your visit and any enquiries you may have. This will usually include your Contact Data, and any other personal data you volunteer. Some Services we offer are also subject to separate terms and conditions which will also apply.

Our legal basis for processing 

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you, or it is in our legitimate interest or a third party’s legitimate interest to use personal data in such a way to ensure that we provide the Services in an effective, safe and efficient way.

If you wish to register your Trex products

When registering your Trex products you will need to provide certain data such as Identity Data, Contact Data and, if applicable, certain Registration Data, Profile Data, Financial Data and Transaction Data which we will process to assist us with the administration of warranties that may be applicable to your purchase.

When you register your products with us that you have purchased from an authorised Trex dealer, we may also ask you for the name and address of the dealer from whom you purchased the products, date of purchase, and identifying information about the products. We use this information to register your product and to provide you with important information such as warranty information.

This information may also be utilised to contact you in the event of a product recall. You may decide not to provide contact information. Trex may not be able to properly inform you of warranty information and recalls without certain information given when registering your Trex products.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Products and Services, or it is in our legitimate interest to use personal data in such a way to ensure that we are able to help you with administering your warranties.

 

Customer service, enquiries and product returns.

If you have a general question or need help with any issue concerning our Site or our Products and Services

There are various ways in which you are able to contact us (see the “How to contact us” section above). In particular, our Site features a “Contact Us” page, which invites you to submit general enquiries about our Site via our Enquiry Form. From time to time, you may also be able to submit specific enquiries on other pages of our Site, including in secure account areas.

When you make an enquiry, we will collect and process your Identity Data, Contact Data and, if applicable, certain Profile Data and Transaction Data, as well as any other personal data you volunteer that is relevant to your enquiry. If you have a technical issue concerning our Site, we may also collect and process Behavioural Data and Technical Data to help us diagnose the technical issues you are experiencing and to help us resolve them in an efficient way. We use this information to manage and respond to your enquiry.

We also record (including voice recordings of telephone conversations) and use the information referred to above to train our personnel so that they can effectively deal with enquiries.

Our legal basis for processing

It is in our legitimate interest to use your personal data in the ways described above to ensure that we are able to help you with your enquiry, provide a good standard of service and improve our customer services.

 

Insight, analysis and retargeting through Cookies. 

If we use cookies to help us understand more about you and your use of our Site and our Products and Services 

We and our third-party partners use cookies, web beacons, marketing tags and other similar technologies (which we generically refer to as “Cookies”) to collect data from the devices that you use to access our Site, our Products and Services and any emails that you receive from us. The data that is collected includes Behavioural Data and Technical Data, and certain Profile Data. Please see our Cookie Notice for further information, including details of our third-party partners.

We and our third-party partners use this data to analyse how you use our Site and our Products and Services and the effectiveness of our Site and our Products and Services, including:

  • for the purposes described in the “If we carry out any online personalised advertising” section below;
  • to analyse how you use, and the effectiveness of, our Site and our Products and Services;
  • to count users who have visited our Site or opened an email and collect other types of information, including insights about visitor browsing habits, which helps us to improve our Site, our Products and Services and the effectiveness of our emails;
  • to measure the effectiveness of our content;
  • to learn what parts of our Site are most attractive to our users, which parts of our Site are the most interesting and what kind of features and functionalities our visitors like to see; 
  • to help us understand the type of marketing content that is most likely to appeal to our visitors and customers; and
  • to help us with the selection of future product and service lines, website design and to remember your preferences.

In some of our email messages, we use a “click-through URL” linked to certain websites administered by us or on our behalf. We may track click-through data to assist in determining interest in particular topics and measure the effectiveness of these communications.

To see which individual cookies we use on our Site, and the purposes for which they are used, please visit our Preference Centre, where you can also review and manage your cookie consent preferences whenever you wish.

Our legal basis for processing

Where your data is collected through the use of non-essential cookies, we rely on consent to collect your personal data and for the onward processing purpose. Please see our Cookie Notice for further details.

In certain circumstances, we may rely on another lawful basis when we use your personal data collected via the use of cookies. For example, where we use personal data collected through the use of analytics cookies to analyse how you use our Site, it is in our legitimate interest to use your personal data in such a way to improve our Site and our Products and Services.

 


Advertising and marketing activities.

If we send you marketing communications by email

We use your Identity Data, Contact Data and Marketing and Communications Data to send you (or the organisation you represent) marketing communications by email. Our marketing will include press releases and information about us, our Site, our Products and Services, any events we may hold and the offers and promotions we offer from time to time.

Our marketing communications will include personalised and non-personalised marketing. Personalised marketing has been specifically tailored to you and will include content that we think is most relevant to you, based on what we know about you. Non-personalised marketing is marketing that is not tailored to you.

Where we are sending you personalised marketing, we may also use Profile Data, Transaction Data and Behavioural Data to help us decide what sort of personalised marketing to send you (please see the “Insight, analysis and retargeting through Cookies” section above for more details).

Our legal basis for processing

It is in our legitimate interest to use your personal data for marketing purposes, for example to decide what marketing content we think may appeal to you.

It is in our legitimate interest to use your personal data to send our marketing to you by post.

However, we will only send marketing communications to you by email where you have consented to receive such content by email, or where we have another lawful right to send marketing to you using email. For example, in certain circumstances we may rely on our legitimate interest to send marketing by email to customers who have purchased our Products and Services. We may also rely on our legitimate interest to send marketing by email to certain business users of our Site and our Products and Services.

If we carry out any online personalised advertising

We and our third party partners may use your Profile Data, Behavioural Data and Technical Data and other data that is collected through your interactions with third party websites and services to provide you with, and analyse the effectiveness of, personalised ads when you visit other websites and/or use other services.

By “personalised ads”, we mean advertisements for products and services that you have shown an interest in when you have used our Site or which you otherwise might be interested in based on your browsing habits, although our third-party partners may use the data that is collected to show personalised ads for products and services offered by third parties.

Our legal basis for processing

Please see the “Insight, analysis and retargeting through Cookies” section above to learn about the legal basis that we rely on to collect data via the use of Cookies.

Where we use your personal data to display online personal advertising to you, we rely on the consent that you have provided in respect of the collection of such data, or it is otherwise in our legitimate interests to promote our Site and our Products and Services to you.

Our third party partners may rely on a different lawful basis in respect of their use of your personal data. Please read theprivacy policy of the relevant third-party provider, as set out in our Cookie Notice and/or our Cookie Preference Centre.

 

Recruitment

If we use your personal data in connection with our recruitment activities

We use your personal data for recruitment purposes, in particular, to assess your suitability for any of our positions that you apply for, whether such application has been received by us online, by email or by hard copy and whether submitted directly by you or by a third-party recruitment agency on your behalf. We also use your Identity Data and Contact Data to communicate with you about the recruitment process, to keep records about our recruitment process and to comply with our legal and regulatory obligations in relation to recruitment.

We will process any personal data about you that you volunteer, including during any interview, when you apply for a position with us. We may also process your personal data obtained from any third parties we work with in relation to our recruitment activities, including without limitation, recruitment agencies, background check providers, credit reference agencies and your referees.

The personal data we process may include your Identity Data, Contact Data, Registration Data, details of your education, qualifications and employment history, any other personal data which appears in your curriculum vitae or application, any personal data that you volunteer during an interview or your interactions with us, or any personal data which is contained in any reference about you that we receive. Such information may also include special categories of personal data (such as information about your health, any medical conditions and your health and sickness records) and information relating to criminal convictions and offences if that information is relevant to the role you are applying for.

We also use your personal data for the purposes of reviewing our equal opportunity profile in accordance with applicable legislation. We do not discriminate on the grounds of gender, race, ethnic origin, age, religion, sexual orientation, disability or any other basis covered by local legislation. All employment-related decisions are made entirely on merit.

Our legal basis for processing

Where we use your personal data in connection with recruitment, it will be in connection with us taking steps at your request to enter into a contract we may have with you or it is in our legitimate interest to use personal data in such a way to ensure that we can make the best recruitment decisions.

We will not process any special (or sensitive) categories of personal data or personal data relating to criminal convictions or offences except where we are able to do so under applicable legislation or with your explicit consent.

 

Receipt of products and services from our suppliers.

If we have engaged you or the organisation you represent to provide us with products or services

If we have engaged you or the organisation you represent to provide us with products or services (for example, if you or the organisation you represent provide us with services such as IT support or financial advice), we will collect and process your personal data in order to manage our relationship with you or the organisation you represent, to receive products and services from you or the organisation you represent and, where relevant, to provide our Products and Services to others. The personal data we collect from you may include your Identity Data and Contact Data and any other personal data you volunteer which is relevant to our relationship with you or the organisation you represent.

Our legal basis for processing

It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you or the organisation you represent, or it is in our legitimate interest to use personal data in such a way to ensure that we have an effective working relationship with you or the organisation you represent and are able to receive the products and services that you or your organisation provides, and provide our Products and Services to others, in an effective way.

 

Business administration and legal compliance.

If we need to use your personal data to comply with our legal obligations or in connection with the administration of our business

We may use your personal data: (i) to comply with our legal obligations; (ii) to enforce our legal rights; (iii) to protect the rights of third parties; and (iv) in connection with a business transition such as a merger, reorganisation, acquisition by another company, or sale of any of our assets.

Our legal basis for processing

Where we use your personal data in connection with a business transition, to enforce our legal rights or to protect the rights of third parties, it is in our legitimate interest to do so. For all other purposes described in this section, we have a legal obligation to use your personal data to comply with any legal obligations imposed upon us, such as a court order.

We will not process any special (or sensitive) categories of personal data or personal data relating to criminal convictions or offences except where we are able to do so under applicable legislation or with your explicit consent.

 

Event management.

If we need to use your personal data in connection with the management of events 

We may run events which you may be interested in attending and we will share your personal data with third-party service providers that are assisting us with the operation and administration of that event. If we are running an event in partnership with other organisations, we will share your personal data with such organisations for use in relation to the event.

Our legal basis for processing

Where we use your personal data in connection with managing an event, it is in our legitimate interest to ensure the event is managed effectively and we can, for example, communicate with and record attendees.

 



8.      IF YOU FAIL TO PROVIDE YOUR PERSONAL DATA

Where we are required by law to collect your personal data, or we need to collect your personal data under the terms of a contract we have with you, and you fail to provide that personal data when we request it, we may not be able to perform the contract we have or are trying to enter into with you. This may apply where you do not provide the personal data we need in order to provide the Products and Services you have requested from us or to process an application to register an account. In these circumstances, we may have to cancel your application or the provision of the relevant Products and Services to you, in which case we will notify you.

9.      HOW WE OBTAIN YOUR CONSENT

Where our use of your personal data requires consent, you can provide such consent at the time we collect your personal data following the instructions provided, or by informing us using the contact details set out in the “How to Contact Us ” section above.

10.      THIRD-PARTY LINKS

This Privacy Notice only applies to personal data processed by us through your use of our Site and/or in connection with our business operations. However, from time to time, our Site may contain links to third-party websites and services. We have no control over these websites and services and this Privacy Notice does not apply to your interaction with the relevant third parties.

When you use a link to go from our Site to another website (even if you don’t leave our Site) or you request a service from a third party, your browsing and interactions on any other websites, or your dealings with any other third-party service provider, is subject to that website’s or third-party service provider’s own rules and policies. For example, our Site invites you to connect with us on social media platforms such as Facebook and Instagram. When you click on the links we provide to such third-party platforms, you will be transferred from our Site to the relevant third-party platform and the privacy notice (and other terms and conditions) of that platform will apply to you.


We do not monitor, control or endorse the privacy practices of any third parties. We encourage you to become familiar with the privacy practices of every website you visit or third-party service provider that you use in connection with your interaction with us and to contact them if you have any questions about their respective privacy notices and practices.

 

11.      SHARING PERSONAL DATA

We only share personal data with others when we are legally permitted to do so. When we share personal data with others, we put contractual arrangements and security mechanisms in place to protect the personal data shared and to comply with our data protection, confidentiality and security standards and obligations.

When processing your personal data, we may need to share it with third parties as set out in the table below. This list is non-exhaustive and there may be circumstances where we need to share personal data with other third parties.

Third-party suppliers who provide applications/ functionality, data processing or IT servicesWe share personal data with third parties who support us in providing our Site and help provide, run and manage our internal IT systems. Such third parties may also include, for example, providers of information technology, cloud-based software-as-a-service providers, identity management, website design, hosting and management, data analysis, data back-up, security and storage services. The servers powering and facilitating that cloud infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them. We also share your personal data with third-party service providers to assist us with insight analytics. These providers are described in our Cookie Notice.
Authorised Trex dealersWe share personal data with third parties who assist us with the administration of Product warranties.
Payment providers and banksWe share personal data with third parties who assist us with the processing of payments and refunds.
Delivery and courier companiesWe share personal data with suppliers who assist us in the delivery of our Products and Services to our customers.
Advertising partnersWe share personal data with third party advertising partners, including those set out in our Cookie Notice when you use our Site. This data is used to provide you with, and measure the effectiveness of, online advertising and for other advertising related activities.
Third-party post/email marketing and CRM specialistsWe share personal data with specialist suppliers who assist us in managing our marketing database and sending out our email marketing communications and account-related communications (including customer surveys and feedback requests).
Third-party suppliers who assist us in administering our promotionsWe share personal data with specialist suppliers who assist us in administering our prize draws, prize competitions and other promotions.
Event partners and suppliersWhen we run events, we will share your personal data with third-party service providers that are assisting us with the operation and administration of that event. If we are running an event in partnership with other organisations, we will share your personal data with such organisations for use in relation to the event.
Recruitment agencies and related organisationsWe share personal data with external recruiters, third-party providers that undertake background checks on our behalf, third parties who assist us with the recruitment process. 
Auditors, lawyers, accountants and other professional advisersWe share personal data with professional services firms who advise and assist us in relation to the lawful and effective management of our organisation and in relation to any disputes we may become involved in.
Law enforcement or other government and regulatory agencies and bodiesWe share personal data with law enforcement or other government and regulatory agencies or other third parties as required by, and in accordance with, applicable law or regulation.
Other third partiesOccasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, or to establish, exercise or defend legal rights. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.
 

12.      TRANSFERS OUTSIDE THE UK AND THE EUROPEAN ECONOMIC AREA ("EEA")

We are located in Virginia, USA. Therefore, when you submit personal data to us, whether through your interactions with our Site you acknowledge that your personal data will be transferred outside the UK and the EEA to the USA where it will be stored and processed by us and our suppliers for the purposes set out in this Privacy Notice.

Where necessary in order to provide our Site and our Products and Services, we will transfer personal data to countries outside the UK and the EEA.

Countries outside the UK and EEA do not have the same data protection laws as the UK and the EEA. In particular, countries outside the UK and EEA countries may not provide the same degree of protection for your personal data, may not give you the same rights in relation to your personal data and may not have a data protection supervisory authority to help you if you have any concerns about the processing of your personal data. However, when transferring your personal data outside the UK or the EEA, we will comply with our legal and regulatory obligations in relation to your personal data, including having a lawful basis for transferring personal data and putting appropriate safeguards in place to ensure an adequate level of protection for the personal data. We will take reasonable steps to ensure the security of your personal data in accordance with applicable data protection laws.

When transferring your personal data outside the UK or the EEA, we will, where required by applicable law, implement at least one of the safeguards set out below. Please contact us if you would like further information on the specific mechanisms used by us when transferring your personal data outside the UK or the EEA. 

Adequacy decisionsWe may transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission and/or the UK Government (as applicable).
Model clausesWhere we use certain service providers, we may use specific standard contractual clauses approved by the European Commission and/or the UK Government which give personal data the same protection it has in the EEA and/or the UK.
 
13.      HOW LONG WE KEEP YOUR PERSONAL DATA

In respect of personal data that we process in connection with the supply of our Products and Services, we may retain your personal data for up to six years from the date of supply of the relevant Products and Services and in compliance with our data protection obligations. We may then destroy such files without further notice or liability.

Where we process personal data in connection with the registration and use of an account on our Site, we may retain your personal data for up to six years from the date that the relevant account is terminated (and in compliance with our data protection obligations). We may then destroy such files without further notice or liability.

Where we process any other personal data, we will retain relevant personal data for up to three years from the date of our last interaction with you (and in compliance with our data protect obligations). We may then destroy such files without further notice or liability.

If any personal data is only useful for a short period (e.g. for a specific activity, promotion or marketing campaign), we will not retain it for longer than the period for which it is used by us.

If you have opted out of receiving marketing communications from us, we will need to retain certain personal data on a suppression list indefinitely so that we know not to send you further marketing communications in the future. However, we will not use this personal data to send you further marketing unless you subsequently opt back in to receive such marketing.

14.      CONFIDENTIALITY AND SECURITY OF YOUR PERSONAL DATA

We are committed to keeping the personal data you provide to us secure and we have implemented information security policies, rules and technical measures to protect the personal data under our control from unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss. In addition, all our employees and data processors (i.e. those who process your personal data on our behalf) are obliged to respect the confidentiality of the personal data of all users of our Site and those who purchase our Products and Services.

15.      PERSONAL DATA OF MINORS

Our Site is not intended for use by, or targeted at, minors (individuals under the age of 18) and we do not knowingly collect personal data of minors. However, this does not prevent minors from providing personal data to us. If we do collect personal data of minors, we will comply with all applicable laws and regulations relating to the processing of personal data of minors.

If you are under the age of 18, you must not use our Site or purchase Products and Services from us and you must not provide us with any personal information. If we discover that we are holding the personal data of a minor, we will delete that information as soon as possible. Please contact us if you have reason to believe that a minor may have submitted personal data to us (see the “How to contact us ” section above).

16.     YOUR RIGHTS AS A DATA SUBJECT

You have certain rights in relation to the personal data we hold about you. These rights include the right: (i) to obtain copies of your personal data; (ii) to have your personal data corrected or deleted; (iii) to limit the way in which your personal data is used; (iv) to object to our use of your personal data; (v) to transfer your personal data; (vi) not to be subject to decisions based on automated processing (including profiling); and (vii) to complain to a supervisory authority. If you would like to exercise any of these rights, please contact us using the details set out in the “How to Contact Us” section above.

Your right of access If you ask us, we will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data (along with certain other details). If you require additional copies, we may charge a reasonable fee for producing those additional copies.
Your right to rectification If the personal data we hold about you is inaccurate or incomplete, you are entitled to have it rectified. If we have shared your personal data with others, we’ll let them know about the rectification where possible. If you ask us, where possible and lawful to do so, we will also tell you who we’ve shared your personal data with so that you can contact them.
Your right to erasureYou can ask us to delete or remove your personal data in some circumstances, such as where we no longer need it or where you withdraw your consent (where applicable). If we have shared your personal data with others, we will let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we will also tell you who we have shared your personal data with so that you can contact them directly.
Your right to restrict processing You can ask us to “block” or suppress the processing of your personal data in certain circumstances such as where you contest the accuracy of that personal data or you object to us processing it for a particular purpose. This may not mean that we will stop storing your personal data but, where we do keep it, we will tell you if we remove any restriction that we have placed on your personal data to stop us processing it further. If we’ve shared your personal data with others, we’ll let them know about the restriction where it is possible for us to do so. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we’ve shared your personal data with so that you can contact them directly.
Your right to data portabilityYou have the right, in certain circumstances, to obtain personal data you have provided to us (in a structured, commonly used and machine-readable format) and to reuse it elsewhere or to ask us to transfer it to your chosen third party.
Your right to objectYou can ask us to stop processing your personal data, and we will do so, if we are: (i) relying on our own or someone else’s legitimate interest to process your personal data, except if we can demonstrate compelling legal grounds for the processing; or (ii) processing your personal data for direct marketing purposes.
Your rights in relation to automated decision-making and profilingYou have the right not to be subject to a decision when it is based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for the entering into, or the performance of, a contract between you and us.
Your right to withdraw consentIf we rely on your consent (or explicit consent) as our legal basis for processing your personal data, you have the right to withdraw that consent at any time. You can exercise your right of withdrawal by contacting us using our contact details in the “How to Contact Us” section above or by using any other opt-out mechanism we may provide, such as an unsubscribe link in an email.
Your right to lodge a complaint with the supervisory authority

If you have a concern about any aspect of our privacy practices, including the way we have handled your personal data, please contact us using the contact details provided in the “How to Contact Us” section above. You can also report any issues or concerns to a national supervisory authority in the Member State of your residence or the place of the alleged infringement. You can find a list of contact details for all EU supervisory authorities at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.

The regulatory authority for the United Kingdom is the Information Commissioner’s Office (“ICO”). Contact details for the ICO can be found on its website at https://ico.org.uk.

(NOT ALL PRODUCTS ARE AVAILABLE IN EVERY COUNTRY.)

Unable to Add to Cart

You may order up to 4 free samples. To adjust your selections, remove what you do not need and then add your new choices.