Last updated: 01/01/2023
Here at Soltan®, we take the privacy of our users very seriously. This policy outlines how we collect, use and protect any personal data collected when you interact with our website, purchase our products or contact our customer service team. Please read it carefully to understand our practices regarding your personal data and how we will treat it.
1. Who We Are
Soltan® Sun Protection is the controller and responsible for your personal data. Our head office address is:
Cloverfield House
Whistler Drive
Nottingham, NG8 6DF
We are registered in England and Wales under company number 012345678.
If you have any questions or concerns about our privacy practices, please contact us:
By Email: [email protected]
By Phone: 0800 413 498
By Post: FAO: Data Privacy Officer, Soltan Sun Protection, Cloverfield House, Whistler Drive, Nottingham, NG8 6DF
2. The Data We Collect About You
We collect certain personal data when you use our website, purchase our products or contact us which may include:
- Contact details – Such as your name, email address, postal address, phone number.
- Account login details – Such as usernames and securely hashed passwords if you create an account to purchase or access certain content.
- Purchase and order information – Details of the products you purchase or order from us.
- Marketing preferences – Details of your preferences in receiving marketing communications and newsletters from us.
- Correspondence – Records of any correspondence with our customer service team such as queries, complaints etc.
- Usage data – Details of how you use our website such as which pages you visit, products you view etc.
- Survey responses – Any information you provide when participating in user surveys, competitions or research activities.
We do not intentionally collect any sensitive personal data such as information relating to health, race, religious beliefs, political views, sex life or sexual orientation.
3. How We Use Your Personal Data
We only collect and use your personal data where we have lawful grounds and legitimate business reasons to do so. These may include:
To Provide Products or Information Requested
- To process orders and provide the products, services or information you request.
- To communicate with you regarding your order status, shipping and returns.
- To manage your account and provide customer support.
To Improve Our Products & Services
- To better understand how users interact with our website so we can improve navigation, performance, etc.
- To monitor and prevent technical issues such as problems, bugs, or unauthorized access.
- To conduct research and analysis of user behaviour, preferences and trends to improve the relevance of products, services and marketing communications we may send.
To Manage Our Relationship With You
- To provide important service and product updates, notifications or safety information.
- To respond to any comments, questions or complaints you direct to us.
- To send periodic customer satisfaction, market research or website usage surveys.
To Enable Legal Requirements
- To comply with applicable laws, regulations, court orders, government and law enforcement requests.
- To operate and maintain the security of our systems and infrastructure.
- To protect the rights, safety and property of Soltan®, our users or the public from fraud or illegal activity.
To Send Marketing Communications
- To keep you informed about new Soltan® products, special offers, news and educational sun safety content (where you have actively consented to receive these).
We do not share your personal data with any external parties for their own marketing purposes without your explicit consent.
4. The Legal Basis for Using Your Data
We will only collect and use your personal data when permitted under one of the following legal bases:
Consent – Where you have explicitly agreed for us to process your information for a specific purpose such as sending you marketing communications or participating in research activities.
Contract – When processing is necessary to deliver the products, services or information you have requested from us.
Legal Obligation – If required to process your data to comply with the law.
Vital Interests – To protect the vital interests of you or another person.
Legitimate Interests – Where processing enables us to properly manage our business, continue to improve our products/services and maintain an optimal user experience. This is done in a way that ensures a fair balance between your rights/interests and ours.
You have the right to object at any time to processing based on legitimate interest. We will always respect such requests by stopping this activity unless we have compelling reasons that outweigh your rights and interests.
5. How We Protect Your Data
Protecting your personal data is a top priority for us. We implement appropriate technical and organisational measures to ensure a level of data security appropriate to the risks represented by the processing and nature of the personal data.
Measures include:
- Secure network architecture, firewalls, intrusion detection/prevention systems (IDS/IPS) and regular penetration testing.
- Transport Layer Security (TLS) encryption of data in transit and encryption of sensitive data at rest.
- Access controls and role-based permission restrictions on a need to know basis.
- Secure disposal procedures for physical and electronic records.
- Regular staff privacy awareness training.
- Contractual data protection requirements when working with third-party processors.
While we work hard to protect your personal information, no system can provide absolute security. As a result, we cannot guarantee the complete elimination of risks associated with personal data use. However, we have robust processes in place to identify and respond to any potential privacy breaches rapidly.
6. Data Retention
We will only retain your personal data as long reasonably required for the purposes outlined in Section 3 of this policy unless a longer retention period is mandated by law. Specific retention times can vary based on the nature of the data concerned but some typical examples include:
- Account information like names and addresses will be kept as long as your account remains active.
- Order information is retained for 7 years to comply with tax and financial regulations.
- Usage data needed for analytics and improvements is anonymized after 26 months.
- Marketing consent records will be retained as long as your consent remains valid or you unsubscribe.
- Correspondence with customer service is kept for 3 years after the enquiry is closed.
We will securely delete or anonymize your personal data once the applicable retention period expires.
7. Cookies
Cookies are small text files placed on your device when you visit a website. We use cookies on our website for purposes like:
- Ensuring site functionality and providing a smooth user experience.
- Remembering your preferences and account settings.
- Monitoring aggregate site usage trends and patterns.
- Enabling social media features like sharing and liking.
- Facilitating personalised promotions and content.
You can control and limit cookie use through your browser settings. The ‘Help’ function in your browser should provide details on how to do this. Please note disabling cookies may negatively impact your user experience on our site.
8. Third-Party Links
Our website may contain links enabling you to visit external third-party websites. If you click these links, please be aware we do not control these sites or their privacy practices, which will differ from our policy. We do not accept any responsibility or liability for their policies whatsoever as we have no means of controlling them. Please check the privacy policy notices on those external sites before submitting any personal data to them.
9. Your Data Rights
Under certain circumstances, you have rights under data protection laws regarding personal data we hold about you:
- Access your data – You can request details of the personal data we hold about you including a copy of the information.
- Rectify inaccuracies – If you believe the data we hold is inaccurate or incomplete, you can ask us to correct or update it.
- Be forgotten – Ask for your personal data to be erased in certain situations such as where it is no longer needed or our use is unlawful.
- Restrict processing – You can request we halt using your data in certain ways, while not requiring full deletion.
- Data portability – Obtain a machine-readable copy of your information or request a transfer to another provider.
- Object to processing – You can ask us to stop processing data if our lawful basis is legitimate interest.
- Withdraw consent – Withdraw any consents you have previously given for us to handle your information. This will not affect prior activities but we will cease any further processing.
To exercise any of these rights, please contact us at [email protected] providing your name and relevant details needed to identify you. We will respond promptly and no later than one month from your request.
If you have any complaints about our privacy practices, you have the right to lodge a complaint with the UK data protection authority – the ICO (https://ico.org.uk). We appreciate the chance to address any concerns directly, so please contact us first if you have any issues.
10. International Data Transfers
In certain situations we may transfer the personal data we collect about you to recipients in countries outside of the European Economic Area (EEA). For example, to follow your instructions to deliver products to an international destination.
When making these international transfers, we will take steps to ensure your data remains adequately protected and transported securely. This may include imposing contractual obligations approved by European data protection authorities, or other legal means such as EU-US Privacy Shield certification when applicable.
11. Changes to This Policy
We may occasionally make changes to this Privacy Policy to reflect updates in our practices, technology, legal requirements and other factors. We encourage you to check this policy each time you submit personal data or order products to stay informed of how we handle and protect your information.
If we make significant changes, we may also take steps to notify you more directly – such as by emailing account holders or displaying a prominent notice on our website.
12. Contacting Us
If you have any questions, concerns or suggestions about our privacy practices, please get in touch using the contact details at the start of this policy and we will be happy to assist. Thank you for taking the time to understand how we approach privacy. Our goal is to ensure we earn and maintain your trust as a responsible steward of your personal data.