Customer Privacy Notice
What this Notice covers
H2O Spa Limited are committed to protecting the privacy and security of your personal information. This Privacy Notice describes how we collect and use personal information about you. This notice does not form part of any agreement or contract and may be updated at any time.
Identity of the data controller
H2O Spa Limited are the data controller. We are a data controller for any personal information that you provide to us. This means that we are responsible for determining how information relating to you is used, stored and shared.
Categories of personal data we process
We will collect, store, and use the following categories of personal information about you:
- Your full name
- Your address
- Your contact details such as phone numbers and email addresses
- Your employment status, salary and homeowner status
Sources of personal data
We collect personal information relating to you directly from you, either via telephone, email or contact form via our website.
Our lawful bases for processing your data
We will use your personal information in the following circumstances:
- Where we need to perform the contract we have entered into with you
- Where it is necessary for our legitimate interests or those of a third party and your interests and fundamental rights do not override those interests
- To comply with relevant legislation and regulations
Our purposes for processing your data
- Performing the contract that we have entered in to with you by providing you with the products and services that you have ordered
- To provide you with a quote and the details of all available payment methods when you have shown an interest in our products and services
- To issue marketing material to you about the products and services we offer
- To process a finance application for you
Sensitive Personal Data
There may be instances where it is necessary for you to share information with us containing special categories of personal information or ‘sensitive personal data’. This relates to things such as details of medical conditions which you may need to share with us so we are able to meet your specific requirements when providing our goods and services.
Due to the sensitive nature of this information, we will only take it from you if you have given us your explicit consent and it is necessary for us to do so. We will also inform you of what we will do with this information and who we will share it with.
Cookies are stored on your computer’s hard drive and cannot be used to identify you personally as they contain no personal information.
Who has access to your data
We may share your personal information with third parties where required by law, where it is necessary to administer the contract we have entered in to you with you, or where we have another legitimate interest in doing so.
Recipients of your data may include third-party service providers, other related business entities, a regulator, or to otherwise comply with the law.
If you choose to fund your purchase with us using one of the finance products we offer to our customers as a credit broker on behalf of lenders, we will share your data with the relevant lender so they are able to process your finance application.
Where we do so, we will require third parties to respect the security of your data and to treat it in accordance with the law.
Security of your data
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
How we decide how long to retain your data
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal or contractual requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and any applicable legal or contractual requirements.
You have the right to:
- Request access to, and a copy of, your personal information that we hold.
- Request correction of the personal information that we hold about you if you believe it is incomplete or inaccurate
- Request erasure of your personal information in specific circumstances, such as; if our processing of your personal information is based upon legitimate interests and you believe it is no longer necessary; or if you believe we have processed your personal data unlawfully or not for the purposes which it was intended.
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
- Request to restrict the processing of your personal information in specific circumstances, such as; you have requested that your personal information is corrected and want to restrict processing whilst we correct it; where you believe our processing is unlawful but do not want us to erase your personal information; where we no longer need to store your personal information but you require us to do so to enable you to exercise or defend a legal claim.
- Data Portability in particular circumstances meaning that you can request for your personal information to be securely moved, copied or transferred from our IT environment to another. This only applies if our lawful basis for processing your data is consent or performance of a contract, and we are processing your data by automated means.
If you believe we have not complied with your rights, you can complain to the Information Commissioner by visiting their website https://ico.org.uk/.
Automated decision-making & Profiling
We do not conduct any automated decision-making or profiling activities whilst processing your personal information.
Changes to this Privacy Notice
The Company reserves the right to update this privacy notice at any time. You can request the most up to date version from us at any time by contacting us on the contact details below.
Please do not hesitate to contact us regarding any matter relating to this Privacy notice via email to [email protected] or in writing to H2O Spa Limited, Unit 4G Blenheim Court, Blenheim Industrial Park, Nottingham, NG6 8YP
Data Protection & Privacy
H2O Hot Tubs collect data from customers when they register and make a purchase online. We also gather data about our customers from their use of the website. We use this data to corroborate our customers' identity, process payments, manage orders including delivery, and communicate with customers about orders, products, services and promotions. We also use this data to further develop this website to be of use to customers and to manage security.
When you view this website by linking from another web page H2O Hot Tubs may store the name of that web page for the purposes of internal administration and analysis. In order to process your registration and enable management of this website, your personal information may be passed to third party service providers who may process your information on our behalf and under our control. We may share non-personal, anonymous, aggregate statistics (group) data about visitors to this website, use and other traffic patterns with connected, or third parties.
By using this website you agree that any successor operator of the H2O Hot Tubs business may use your personal information on the same basis as we do. We will not disclose your personal information to third parties except as outlined above or in the unlikely event that we are required to do so by court order or other legal requirement.
Your rights over your information
By law, you can ask us what information we hold about you, and you can ask us to correct it if it is inaccurate.
You can also ask us to give you a copy of the information and to stop using your information for a period of time if you believe we are not doing so lawfully.
To submit a request by email, post or telephone, please use the following contact information.
Strictly Necessary Cookies
There are certain first party cookies on this site that are necessary for the site to function. These are cookies that allow you to log into the site and access any protected content.
These cookies cannot be disabled.
Third Party and Nonessential Cookies
We also use third party cookies and other nonessential first party cookies to enhance the functionality and/or accessibility of the site's content. You can indicate if you'd like to Allow or Block the these cookies.
If you deny these cookies certain areas of the site may stop functioning as expected.
Revoking Cookie Access
If at any point you change your mind about allowing Cookies on this site you can amend your choice with these Cookie Consent Settings.
Links to other Websites
You may provide a link (but not a framed link) to the home page of this site but not (save with our prior written agreement) in any way, which gives the impression that we are associated with or have approved such other site. Apart from this you may not link from another Internet site or equivalent entity to materials or information on this website or reproduce or store any part of this site on any other website without our prior written consent.
Data Protection Act
In addition to these policies your personal data is protected in the UK by the Data Protection Act 1998. Under this Act we will only process any data we hold about you in a lawful and fair manner. We will keep your data securely to prevent unauthorised access by third parties.
Your personal data may have to be disclosed if we are required to disclose it by law or as a result of a lawful request by a governmental or law enforcement authority.
List of cookies we collect
The table below lists the cookies we collect and what information they store.
The association with your shopping cart.
Stores the category info on the page, that allows to display pages more quickly.
The items that you have in the Compare Products list.
Your preferred currency
An encrypted version of your customer id with the store.
An indicator if you are currently logged into the store.
An encrypted version of the customer group you belong to.
Stores the Customer Segment ID
A flag, which indicates whether caching is disabled or not.
You session ID on the server.
Allows guests to edit their orders.
The last category you visited.
The most recent product you have viewed.
Indicates whether a new message has been received.
Indicates whether it is allowed to use cache.
A link to information about your cart and viewing history if you have asked the site.
The ID of any polls you have recently voted in.
Information on what polls you have voted on.
The items that you have recently compared.
Information on products you have emailed to friends.
The store view or language you have selected.
The products that you have recently viewed.
An encrypted list of products added to your Wishlist.
The number of items in your Wishlist.
Google Analytics: We use Google Analytics to monitor traffic levels, search queries and visits to this website.
Google Analytics stores IP address anonymously on its servers in the US, and neither CIVIC or Google associate your IP address with any personally identifiable information.
These cookies enable Google to determine whether you are a return visitor to the site, and to track the pages that you visit during your session.
YOUR RIGHT TO COMPLAIN
If you have a complaint about our use of your information, you can contact the Information Commissioner’s Office via their website at www.ico.org.uk/concerns or write to them at:
Information Commissioner's Office