The privacy notice describes to you:
For the purposes of data protection law, the “controller” is Mundos Limited, a company incorporated and registered in England and Wales under company number 6284637 and having its registered office address 47 St Mary St, Cardigan, Ceredigion SA43 1HA, United Kingdom (from now on referred to as “Mundos”, "Cardigan Bay Company" or as “we” and related words such as “us” and “our”). Our registered VAT number is GB740722159.
As controller we are responsible for, and control the processing of, your personal data. We are registered as a data controller with the Information Commissioner’s Office, which is the UK’s supervisory authority for data protection matters.
If you would like to contact us about this notice, including if you wish to receive further information about any aspect of it, our details are as follows:
Data Privacy, Mundos, 12 Pendre, Cardigan, SA43 1JL
In the course of our business, which is the sale of clothing, accessories and homewares in our shops and online, we collect the following personal data when you provide it to us:
We do not knowingly collect “special category” personal data. This is a special type of sensitive data to which more stringent processing conditions apply, and comprises data concerning your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, and genetic data and/or biometric data.
We also do not collect information about criminal convictions or offences.
We obtain personal data from sources as follows:
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
In order to process personal data, we must have a lawful reason (sometimes called a lawful basis). We always ensure that this is the case, and we set out our lawful bases below – but please note that more than one may apply at any given time: for example, if we inform you of changes to our privacy notice, we may process your personal data on the ground of complying with law and on the ground of legitimate interests.
We will use your personal data only for the purposes for which we collected it, unless we fairly consider that we need it for another reason that is compatible with the original purpose.
Please contact us if you would like more information on this, and on situations in which more than one lawful basis applies.
If you are our customer or applying for a job, we will process your personal data for the following purposes, on the legal basis that it is necessary for us to provide our products and services to you:
Of course, you are not obliged to provide us with any of this information, but if you chose not to, we may be unable to provide the product or service that you have requested.
We process your personal information for our legitimate business purposes, which include the following:
Whenever we process your personal data for these purposes, we ensure that your interests, rights and freedoms are carefully considered.
We may process your personal data in order to comply with applicable laws (for example, if we are required to co-operate with an investigation pursuant to a court order).
If you have never purchased from us or have not purchased from us for a long time, but have given us your explicit consent to hear from us about our products, services, promotions or events that we consider may be of interest to you, we will contact you by post or email (according to the contact preference you have provided). You have the right to withdraw consent to marketing at any time.
We may provide your personal data to the following recipients for the purposes set out in this notice:
To form a contract with you, we will need some or all of the personal data described above so that we can perform that contract or the steps that lead up to it: this is set out above in this notice. If we do not receive the data, the contract could not be performed.
If you sign up to our mailing list, you will have to provide certain personal data. Of course, you may decide to stop receiving our mailings at any time.
We carefully consider the personal data that we store, and we will not keep your information in a form that identifies you for longer than is necessary for the purposes set out in this notice or as required by applicable law. In some instances, we are required to hold data for minimum periods: for example, UK tax law currently specifies a six-year period for retention of some of your personal data.
Although we are based in England, we may transfer your personal information to a location (for example, to a secure server) outside the European Economic Area, if we consider it necessary or desirable for the purposes set out in this notice.
In such cases, to safeguard your privacy rights, transfers will be made to recipients to which a European Commission “adequacy decision” applies (this is a decision from the European Commission confirming that adequate safeguards are in place in that location for the protection of personal data), or will be carried out under standard contractual clauses that have been approved by the European Commission as providing appropriate safeguards for international personal data transfers, or by the adoption of EU-US Privacy Shield.
Mundos has security measures in place designed to prevent data loss, to preserve data integrity, and to regulate access to the data. Only authorised Mundos employees and third parties processing data on our behalf have access to your personal data.
All Mundos employees who have access to your personal data are required to adhere to the Mundos Privacy Notice and we have in place contractual safeguards with our third-party data processors to ensure that your personal data is processed only as instructed by Mundos.
The security measures we have in place include:
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our website, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
We take all reasonable steps to keep your data safe and secure and to ensure the data is accessed only by those who have a legitimate interest to do so. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to us. Any transmission is at your own risk. Once we have received your personal data, we will use strict procedures and security features to try to prevent unauthorised access.
Please contact us using the details in section 1 of this notice if you would like more information about this.
We draw your attention to your following rights under data protection law:
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
Please contact us using the details in section 1 of this notice if you would like to exercise any of these rights or know more about them.
These rights are subject to certain limitations that exist in law. Further information about your information rights is available on the ICO’s website: https://ico.org.uk/.
We may change this notice from time to time. You should check this notice on our website occasionally, in order to ensure you are aware of the most recent version.
We hope that you will be satisfied with the way in which we approach and use your personal data.
Should you find it necessary, you have a right to raise a concern with the information regulator, the Information Commissioner’s Office: https://ico.org.uk/.
However, we do hope that if you have a complaint about the way we handle your personal data, you will contact us in the first instance using the contact details in section 1 above, so that we have an opportunity to resolve it.