PRIVACY NOTICE AND STATEMENT
Personal data collected by Build-A-Cupcake Ltd are processed in accordance with the Law on Legal Protection of Personal Data of UK Courts and other legal acts. All employees, agents and employees of the agents of Build-A-Cupcake Ltd who know the secret of personal data must keep it safe even after termination of the employment or contractual relationship.
For the purpose of the processing personal data, Build-A-Cupcake Ltd may engage data processors and/or, at its sole discretion, hire other persons to perform certain functions on behalf of Build-A-Cupcake Ltd. In such cases, Build-A-Cupcake Ltd shall take necessary measures to ensure that such data is processed by the personal data processors in accordance with instructions of Build-A-Cupcake Ltd and applicable legislation. Build-A-Cupcake Ltd shall also require the personal data processors to implement appropriate measures for the security of personal data. In such cases, Build-A-Cupcake Ltd shall ensure that such persons will be subject to the non-disclosure obligation and will not be able to use this information for any other purpose, except to the extent necessary to perform the functions assigned to them.
EUROPEAN UNION GDPR COMPLIANCE (DATA PROCESSING NOTICE)
We are committed to ensuring your privacy is protected. This Data Protection Notice (“DPN”) sets out details of the personal information that we may collect from you and how we may use that information. Please take your time to read this DPN carefully
We as an entity set out in more detail in this DPN, personal data is shared between companies within the Build-A-Cupcake Ltd in order to provide you with your policy.
You can find permanently updated information about the Build-A-Cupcake Ltd on the following website: www.buildacupcake.co.uk
By providing your personal information to us, you acknowledge that we may use it in the ways set out in this DPN. We may provide you with further notices highlighting certain uses we wish to make of your personal information. We may also give you the ability to opt-in or opt-out of selected uses, such as marketing, when we collect your personal information.
In addition to this DPN, some of our products and services may have their own notices (for example, the Online and Mobile Privacy Notice), which describe in more detail how your personal information is used in a particular context).
From time to time we may need to make changes to this DPN, for example, as a result of government regulation, new technologies, or other developments in data protection laws or privacy generally. If we change this DPN, we will notify you of the changes. Where changes to the DPN will have a fundamental impact on the nature of our processing of your personal information, or otherwise have a substantial impact on you, we will give you sufficient advance notice so that you have the opportunity to exercise your rights in relation to your personal information.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
This is the privacy notice of Build-A-Cupcake Ltd or https://www.buildacupcake.co.uk and Build-A-Cupcake Ltd. In this document, “we”, “our”, or “us” refer to Build-A-Cupcake Ltd.
Similar to other websites, our website utilizes a standard technology called ‘cookies’ (see explanation below and our cookies policy page for more information) and server logs to collect information about how our site is used. Information gathered through cookies and server logs may include the date and time of visits, the pages viewed, time spent at our site, and the websites visited just before and just after our own, as well as your IP address.
DATA PROTECTION POLICY
This Policy intends to provide the visitors of firstname.lastname@example.org (hereinafter: Website) with clear and detailed information on the manner their personal data are processed and, in particular, on the types of processed data, the legal basis of data processing and their rights and legal remedies related to data processing.
LEGAL BASIS OF DATA PROCESSING UNDER GDPR
The processing of certain personal data belonging to you (hereinafter: User) will be carried out on the basis of the User’s freely given and informed consent.
By using www.buildacupcake.co.uk the User expressly agrees and consents to the collection and processing of his/her personal data, as specified herein, in accordance with this Policy.
Build-A-Cupcake Ltd will process User data both on the basis of the User’s consent and within the framework of statutory data processing.
As far as statutory data processing is concerned, the legislation allows Build-A-Cupcake Ltd to process certain data of the User for the purpose of providing various services.
Furthermore, Build-A-Cupcake Ltd will also have the right to request the User to give consent for processing such User data that may be processed within the framework of statutory data processing under the relevant legislation. Therefore this is considered primarily as the consent-based processing of such User data. However, the provision of statutory data will be a precondition for using the relevant service.
Furthermore, the User may opt to provide certain data in addition to his/her data subject to statutory data processing so that such additional data may be used by Build-A-Cupcake Ltd for market research and efficiency enhancement. However, the provision of such additional data will not be a precondition for using the relevant service.
The following sections of this Policy contain the breakdown of data as per above as well as the rights and legal remedies available for the consumer.
WHO ARE WE?
We are Build-A-Cupcake Ltd. Our address is ********************************. You can contact us by post at the above address, by email at email@example.com or by telephone on +44 798 305 5960.
We are not required to have a data protection officer, so any enquiries about our use of your personal data should be addressed to the contact details above.
HOW WE USE YOUR INFORMATION
- When you use our website
- When you submit an enquiry via our website
- When you purchase a cake from our website
- Your rights as a data subject
- Your right to complain
Your personal information captured when placing an order will include name, e’mail address and your relevant personal details to complete the booking and payment of a cake to be delivered by a baker of Build-A-Cupcake Ltd. The Baker will be issued with the recipient details in order to fulfil the order name, address and contact telephone number to fulfil the orders. We have agreement with all bakers restricting disclosure of data supplied by us.
Your personal information will be used to notify you of the status of your order, and may use this information to contact you for your views on the service. By submitting a review you consent to us using this information in any marketing or advertising material- we will only identify you for this purpose by your first name and the town associated with you.
Personal information will not be shared with any 3rd parties or affiliates without your permission, unless compelled by applicable law.
Any changes required which affect the fulfilment of an order should be communicated to us
DATA PROCESSING BASED ON USER CONSENT:
Data processing based on User consent qualifies as data processing under the EU GDPA Regulation. I.e. where personal data is recorded under the consumer’s consent, the Controller will, unless otherwise provided for by law, be able to process the data recorded where this is necessary:
- For compliance with a legal obligation pertaining to the Controller, or
- For the purposes of legitimate interests pursued by the Controller or by a third party, if enforcing these interests is considered proportionate to the limitation of the right for the protection of personal data, without the consumer’s further consent, or after the consumer’s consent has been withdrawn.
In certain circumstances, we need your personal data to comply with our contractual obligations.
For example, if you order an item from us for delivery, we’ll collect your address details to deliver your purchase, and pass them to our courier.
Third party advertisements may appear on our site and they may have cookies associated with these, to enable the advertiser to track the effectiveness of their campaign. We do not control or have access to any third party cookies.
We take all reasonable precautions to protect data, and as such use secure transmission, encryption software, utilising SSL (Secure Sockets Layer) and will continue to use the most up to date security levels available. However, due to the openness of the internet we cannot guarantee that all data transmitted will be secure, and your use of this website assumes this risk.
Our Controller will implement appropriate technical and organizational measures and establish adequate procedural rules to ensure, for the entire duration of data processing, the safety of personal data given or made available by the User.
Right to request the amendment, erasure or blocking of data, right to object, and right to request information or legal remedy
By sending a message to Enquiries@buildacupcake.co.uk, the User may request the Controller to erase, amend or block the User’s personal data. Within 30 days after the receipt of such request, the Controller will take the necessary measures and inform the User about data processing.
By sending a message to Enquiries@buildacupcake.co.uk, the User may object to data processing and request information from the Controller regarding the User’s personal data managed by the Controller.
PERSONAL DATA WE MAY COLLECT FROM YOU
We may collect and process the following personal data about you:
Personal Data you give us
- to enable you to access our Web portal and to correspond with us by phone, email or otherwise
- to allow you, as part of the Build-A-Cupcake Ltd, to receive information, Products and services that you request from us
- to provide you with information about other cake recipes and items we offer that are similar to those that you have already purchased or enquired about
The personal data you give us may include items such as your name, address, e-mail address and phone number. We rely on ‘contractual necessity’ as the lawful ground for the processing of your personal data in such cases.
PERSONAL DATA WE COLLECT ABOUT YOU
- to improve our Products and to ensure that Web portal content is presented in the most effective manner for you and for your computer or device
- to allow you to participate in interactive features of our Web portal and services, when you choose to do so
- to make suggestions and recommendations to you for our goods or services that may interest you
This includes automatically collecting and using the following personal data: technical information, including your account registered information, and information about your session, including the information (such as scrolling, clicks), and other personal data supplied as part of the registration to the Build-A-Cupcake Ltd and using the Web portal to purchase products.
When you place an order on our website, we will likely collect information that will enable us process your order and deliver your order at a particular day and time. We collects information such as
- General information such as your name, address, contact details, date of birth, gender, relationship to the customer (where you are not the customer)
- Financial information such as your bank details, payment details and information obtained as a result of our credit checks
- Any correspondence via email or telephone with our Customer Contact Centers
- Your marketing preferences and information about the types of Build-A-Cupcake Ltd products and cakes in which you may be interested
IF YOU FAIL TO PROVIDE PERSONAL DATA
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with our products or services or open up a customer account). In this case, we may have to suspend or cancel a product or service you have with us but we will notify you if this is the case at the time.
WHAT ARE THE PURPOSES FOR WHICH YOUR PERSONAL INFORMATION IS USED?
We may process your personal information for a number of different purposes. For each purpose we must have a legal ground for such processing. When the information that we process is classed as sensitive personal information, we must have an additional legal ground for such processing.
Build-A-Cupcake Ltd. may share Information with third party service providers it employs to perform functions and provide services for Build-A-Cupcake Ltd. and the Website, subject to the terms of this policy, and only to the extent necessary:
- to process payments,
- to prevent, detect, and investigate fraud or other prohibited activities,
- to facilitate dispute resolution, such as chargebacks or refunds, and
- for other purposes associated with the acceptance of credit or debit cards.
- to fascilitate shipping of items purchased via website
- if when required by law
CREDIT AND DEBIT CARD INFORMATION
Build-A-Cupcake Ltd. may share User credit or debit card numbers with third party payment services providers or card networks, only to the extent necessary to monitor card transactions at participating buyer and track redemption activity for the purposes of providing card-linked services.
The Website uses Google Maps (“Google Maps API”), a Google service, to provide more information for the User. When in use, this service may transmit certain data to Google but this transmission concerns only anonymized data.
- » enable, facilitate and streamline the functioning of and your access to our website;
- » track traffic flow and patterns of travel in connection with our website;
- » understand the total number of visitors to our Website on an ongoing basis and the types of internet browsers (e.g. Firefox, Chrome or Internet Explorer) and operating systems (e.g. Windows or Mac OS) used by our visitors;
- » monitor the performance of our website and continually improve it;
- » customize and enhance your online experience.
YOU’RE RIGHT TO DELETE OR BLOCK COOKIES
You have the right to accept or stop cookies from being stored on your device at any time by modifying the settings in your web browser to reflect your cookie preferences.
Please be aware that you may not be able to use all the interactive features of the website and/or online courses and content once cookies are disabled.
Most browsers offer instructions on how to change your cookie settings. These settings will typically be found in the “options” or “preferences” menu of your browser. If you only want to limit third party advertising cookies, you can turn such cookies off by visiting the following links:
- Your Online Choices (http://www.youronlinechoices.com/uk/)
- Network Advertising Initiative (http://www.networkadvertising.org/)
- Digital Advertising Alliance (http://www.aboutads.info/consumers)
Please bear in mind that there are many more companies listed on these sites than those that drop cookies via our website.
Build-A-Cupcake Ltd is not responsible for the protection of the Client’s privacy on websites of third parties, even if such websites are accessed by the client through links provided on this website. Build-A-Cupcake Ltd recommends to learn privacy policies of each website which does not belong to Build-A-Cupcake Ltd.
We will get your express opt-in consent before we share your personal data with any company outside Build-A-Cupcake Ltd for marketing purposes. We have made it clear to our clients that they must do the same. If you think any of our clients are not operating in accordance with this policy, please let us know.
OPTING OUT / UNSUBSCRIBING
You can ask us or our clients to stop sending you marketing messages at any time by logging into your account (if you are a customer account user using our software on our clients’ websites) and checking or unchecking relevant boxes to adjust your marketing preferences or by following the opt-out / unsubscribe links on any marketing message sent to you or by contacting us at any time.
Where you opt out of receiving these marketing messages, you may still receive messages for other purposes (such as providing the services to you).
LEGAL BASIS FOR DATA PROCESSING UNDER THE GDPR REGULATION
If you reside within the European Economic Area (EEA), our processing of your personal information will be legitimized as follows:
- Whenever we require your consent for the processing of your personal information such processing will be justified pursuant to Article 6(1) lit. (a) Of the General Data Protection Regulation (EU) 2016/679 (“GDPR”). This article in the GDPR describes when processing can be done lawfully.
- If the processing of your personal data is necessary for the performance of a contract between you and Build-A-Cupcake Ltd or for taking any pre-contractual steps upon your request, such processing will be based on GDPR Article 6(1) lit. (b).”). If this data is not processed, Build-A-Cupcake Ltd will not be able to execute the contract with you.
- Where the processing is necessary for us to comply with a legal obligation, we will process your information on basis of GDPR Article 6(1) lit. (c), for example complying in the fields of employment law.
- And where the processing is necessary for the purposes of Build-A-Cupcake Ltd’s’ legitimate interests, such processing will be made in accordance with GDPR Article 6(1) lit. (f), for example to detect fraud.
YOUR RIGHTS AS A DATA SUBJECT
By law, you can ask us what information we hold about you, and you can ask us to correct it if it is inaccurate. If we have asked for your consent to process your personal data, you may withdraw that consent at any time.
If we are processing your personal data for reasons of consent or to fulfil a contract, you can ask us to give you a copy of the information in a machine-readable format so that you can transfer it to another provider.
If we are processing your personal data for reasons of consent or legitimate interest, you can request that your data be erased.
You have the right to ask us to stop using your information for a period of time if you believe we are not doing so lawfully.
Finally, in some circumstances you can ask us not to reach decisions affecting you using automated processing or profiling.
To submit a request regarding your personal data by email, post or telephone, please use the contact information provided above in the Who Are We section of this policy.
YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These rights are detailed below: The European Union’s General Data Protection Regulation and other countries’ privacy laws provide certain rights for data subjects. If you wish to confirm that Build-A-Cupcake Ltd is processing your personal data, or to have access to the personal data Build-A-Cupcake Ltd may have about you, or have other questions, please contact us via Enquiries@buildacupcake.co.uk
- Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
- Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
- If you wish to exercise any of the rights set out above, please contact us directly (please see the ‘CONTACT’ section).
- No fee usually required. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
- What we may need from you. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
- Time limit to respond. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you update
ACCESS TO INFORMATION
In accordance with the General Data Protection Regulation 2018 and Data Protection Act 1998 you have certain rights relating to what and how we hold your personal data.
You have the right to request:
- Access to any personal data we hold about you, free of charge.
- The amendment or correction of your personal data.
- Withdraw your consent or object to any data we hold about you.
- We delete or make anonymous data held about you where we have no legitimate overriding interest.
- That we stop using your data for direct-marketing.
PROTECTING YOUR DATA
We take every reasonable step to protect our customers and visitors. We secure access to all transaction areas of our website and apps by https security.
Access to your personal data is password-protected and sensitive data is secured by SSL encryption.
All members of our staff receive data protection training to ensure your data is protected.
CHANGES TO THE PRIVACY STATEMENT
From time to time, we may need to update or modify this Privacy Statement, to reflect changes in our business practices, data collection practices or organization. We reserve the right to amend this Privacy Statement at any time, for any reason, without notice to you, other than the posting of the amended Privacy Statement on our website, or, if you have provided your email address to us, sending you an email notifying you of the amended Privacy Statement. It is strongly recommended to check the Website often, referring to the date of the last modification listed at the top.
We will in any case not reduce your rights under this Privacy Statement without your explicit and informed consent. If you do not agree to the changes, you should discontinue your use of the Website, and cease providing personal information to us, prior to the time the modified Privacy Statement takes effect. If you continue using the Website or provide personal information after the modified Privacy Statement takes effect, you will be bound by the modified Privacy Statement.
(Last Updated May 17th, 2019)
Courts of England: Rev. 243D589