In this policy, “processes” means collects, stores, shares and otherwise uses for lawful purposes. “We” and “our” means Panzer (Delicatessen) Ltd and it covers all instances where we might process personal information of customers, clients, supporters, event attendees, beneficiaries and other relevant parties when using the www.panzers.co.uk site (‘Website’) or purchasing goods in store or by telephone.
When we collect your personal information
We collect personal information when you provide it to us by:
- registering on our Website for an online account;
- placing orders via our Website, in store or by telephone;
- updating the ‘My Account’, ‘Dashboard’, ‘Orders’, ‘Address’ or ‘Account Details’ section of our Website;
- communicating with us by phone or e-mail;
- subscribing to our e-newsletter;
- engaging with us on social media.
Kinds of personal information we collect
While using our Website and providing products and/or services to you, we may collect, use, store and transfer the following types of information about you:
- Personal Details: including your first name, last name and title.
- Contact Details: including your billing and shipping addresses, e-mail address and telephone numbers.
- Image Data: including CCTV footage and stills.
- Financial Data: including bank details and credit/ debit card information.
- Transactional Data: information on goods purchased either in-store or online, including payment and card information, billing and deliveries.
- Instore Transaction Data: products purchased, amount spent, payment information.
- Account Data: including your username and password.
- Communications: including any correspondence with us.
- Marketing Data: your preferences in receiving marketing and communications.
- Technical Data: including your IP address, login data, browser type, time zones and location, operating system, and other information on the devices you use to access our website.
Information from third parties
We may receive personal information about you from third parties who assist us with providing products and/or services to you, including:
- delivery and address information from couriers who deliver products to you;
- data analytics information from companies that provide us with data analytics services; and
- information on your account, payment and credit history, including information from credit bureaus and service providers we use to process payments.
How we use your information
We are a community business: keen to stay in touch with our valued customers and hear what love you most while also keeping you informed about what is new and excites us. We learn and improve from your data, including how you prefer to use our website and which products you engage with most. Data privacy laws allow us to do this as part of our legitimate interest to understand our customers and provide the highest quality service.
We may use your personal information for the following purposes:
- to register you as a new customer and establish a relationship;
- to respond to your enquiries and complaints;
- to handle your orders, send you order confirmations, deliver purchased items and process payments;
- to send you email notifications when you place a product in your basket and you abandon your browsing before completing your checkout;
- to communicate with you about store updates, orders, products, services, promotional offers and/or events;
- to update our records and maintain any online account you may have with us;
- to prevent or detect fraud or abuses of our Website, and safeguard your personal and financial data;
- to inform our business decisions and help us understand what you want to see from us as a customer in terms of products and services;
- to improve and maintain our technical systems using data analytics; including enabling third parties to carry out technical, logistical or other functions on our behalf;
- for market research to improve the products and services we provide and improve customer experiences;
- to comply with our financial obligations;
- to comply with legal obligations to share data with law enforcement and/or government bodies when requested;
- to protect our customers, premises, assets and partners from crime we use CCTV and other security measures in-store.
If you wish to question or change how we use your data, please get in touch with us via the contact details at the end of this notice.
Legal basis for processing personal information
When processing your personal information, a company is required to have a ‘legal basis’ for doing so. Our legal basis to process your personal information will fall into one or more of the following categories:
- Express and informed consent has been given by the person whose data is being processed; and/or
- Panzer Delicatessen Ltd has a legitimate interest in processing the data; and/or
- It is necessary in relation to a contract or agreement which the person has entered into or because the person has asked for something to be done so they can enter into a contract or agreement; and/or
- There is a legal obligation on Panzer Delicatessen Ltd to process data.
- Where Panzer Delicatessen Ltd is relying solely on consent as the basis for processing data, we are required to obtain your expressed consent and you can modify or withdraw this consent at any time by notifying us in writing, although this may affect the extent to which Panzer Delicatessen Ltd is able to provide services to or interact with you in future.
If you do not provide information that we have requested, we may be unable to provide some products and services to you. For example, without your full address, we will not able to deliver products to you. For more information on the specific legal basis we refer to in relation to any of the above, please get in touch with via the contact details at the end of this notice.
Where consent is our legal basis for processing your personal information, you can withdraw at any time. Please contact us using the details at the end of this privacy notice to amend any of your personal information with us.
Personal information for marketing purposes & opting out
If you are an existing customer or you have consented to receiving marketing communications by phone, post or email, we may send you information about our products and/or services that we believe may be of interest to you. If you have opted into Panzer’s marketing we may use Google and Facebook services to identify users for personalised advertising on these platforms. You can unsubscribe from marketing emails using the ‘unsubscribe’ link in any marketing email we send you.
Sharing of your personal information
On occasion, we share your personal information with trusted third parties so that they can assist us in providing products and/or services to you. These trusted third parties will only process your information at our request, and we remain responsible for ensuring that your personal information is protected and processed lawfully.
Some examples of such trusted third parties are:
- Couriers and delivery partners;
- Ecommerce marketing companies who help us send customer communications;
- Technology partners involved in the operation and support of our website and business systems.
We do not sell or share personal details to third parties for the purposes of marketing. In some specific circumstances, we may share your personal information with third parties who process it for their own purposes. Those third parties will have their own legal obligations to protect your information, and you will have legal rights that you can enforce directly against them. For example:
- In order to process payments, prevent fraud and reduce credit risk, we may share your personal information with other companies and organisations;
- When required, we may share your personal information with government bodies, regulatory bodies or law enforcement organisations so that they can carry out their legal functions.
- If we share your data with colleagues or programme partners, including in or outside of the European Union, we will only do so if we are confident that they adhere to the same high standards that we do when processing data and protecting its privacy and security.
If you would like further information about the third parties with whom we share your personal information, please contact us via the contact details at the end of this notice.
Collection of Information by Third-Party Sites
Our Website contains links to other websites whose information practices may be different to ours. Please consult the privacy notices of those third-party sites as we have no control over information that is submitted to, collected, or processed by them.
Cookies and similar technologies
A cookie is a short string of text that a website stores in your browser’s cookie file on your computer’s disk.
- remember what is in your shopping basket when you shop online;
- remember your logins to a website;
- analyse web traffic; and
- track your browsing behaviour.
Storing your information securely
We use many safeguards to keep your personal information secure, including but not restricted to the following:
- Encrypted data systems for personal information and payment card data;
- if any information is written down on paper, it is immediately destroyed after being processed appropriately into our systems;
- credit card data is never kept on file;
- access to systems and data is password protected, and restricted on a need-to-know basis, so employees can only access the data they need in order to perform their job; and
- we work with partners who monitor our systems for vulnerabilities and signs of cyberattacks, also regularly conducting penetration tests to assess the strength of our systems. Firewalls protect connections between our internal systems and the internet.
We kindly request you do not send any sensitive information such as credit card details or passwords via email to us as we cannot guarantee email correspondence to be secure.
Whenever we collect or process your personal information, we will only keep your data as long as necessary to process. At the end of this period, your data will either be deleted (i.e. we will never keep credit card details once processed), stored securely (i.e. contact details so you can receive our newsletters) or anonymised (i.e. for analytical purposes).
You have legal rights in relation to the personal information that we hold about you:
- You can request access to your personal information, known as a “data subject access request”, which allows you to check which data we hold on you and that we are processing it lawfully. This will give you a copy of the personal information we hold on you in a structured, commonly used, machine-readable format.
- You can request a correction of the personal information we hold about you.
- You can request that we restrict the usage of or delete your personal information when there is no reason for us to process it or if you would like to opt-out of our using your information for our legitimate business concerns as listed above or for marketing purposes on one or all channels.
- Where you have given us your consent for any processing activity, you may withdraw that consent at any time, and we will stop any use of your data which relied on that consent.
For more information on your legal rights or to get in touch with us about any of these rights, please contact us using the details at the end of this notice.
How to Contact us
You have the right to raise any issues of concern regarding data protection and our processing of your information to the data protection regulator, The Information Commissioner’s Office (ICO). Here is a helpful link to their website: https://ico.org.uk/concerns/