Finisterre UK Limited ("We") respects your privacy and is committed to protecting your personal data.
This site is not intended for use by children. If you are under the age of 18 and wish to order products from our site, your parent or guardian must submit your order, and provide your personal data, on your behalf.
You may provide personal data whilst you are in contact with us. Personal data is information that can be used to identify or contact you. You do not have to provide the personal data that we request, however, if you choose not to, we may not be able to provide you with the products and services that you have requested.
If we combine personal data with non-personal data, the combined information will be treated as personal data for as long as it remains combined. Personal data does not include data where the identity has been removed (anonymous data).
SPECIAL CATEGORIES OF PERSONAL DATA
We do not knowingly collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
You may provide information about your health (e.g. any restrictions you have to access wetsuits) when you order, or enquire about, our products and the legal basis for this processing is performance of a contract and/or taking steps, at your request, to enter into such a contract. Health data is a Special Category of Personal Data and we need to have further justification for collecting, storing and using this type of data. We may process special categories of personal information with your explicit written consent.
We will only use your health data:
to respond to your enquiry;
to process your order;
for internal training purposes; and
for monitoring and evaluating the products and services we provide.
For the purpose of the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) and the Data Protection Act 2018 (“Data Protection Legislation”) the data controller is Finisterre UK Limited a company registered in England and Wales with company registration number 04444480 whose registered office is at Unit 6 Wheal Kitty Workshops, St. Agnes, Cornwall, TR5 0RD. Our Data Protection Registration Number is ZA128860.
INFORMATION WE MAY COLLECT FROM YOU AND HOW WE USE IT
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Financial Data includes payment card details (type, number, name (appearing on card), expiry date and CCV code). The financial data may be processed for the purposes of processing and delivering your order (namely managing payments and collecting monies). The legal basis for this processing is the performance of a contract and our legitimate interests (namely to recover debts due).
Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us. The transaction data may be processed for the purpose of processing and delivering your order. The legal basis for this processing is the performance of a contract and our legitimate interests (namely our interest in the proper administration of our site and business).
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this site. The technical data may be processed for the purpose of administering and protecting our business and site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) and to deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you. The legal basis for this processing is our legitimate interests (namely to grow our business and to inform our marketing strategy).
Usage Data includes information about how you use our site, products and services. This usage data may be processed for the purposes of enabling you to enter a competition or complete a survey, delivering relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you, to use data analytics to improve our website, marketing, customer relationships and experiences and to make suggestions and recommendations to you about goods or services that may be of interest to you. The legal basis for this processing is the performance of a contract and our legitimate interests (namely to study how our site is used and to grow our business and to keep our site updated and relevant).
Marketing and Communications Data includes your preferences in receiving marketing from us, third parties and your communication preferences. The marketing and communications data may be processed for the purposes of sending you the relevant notifications, newsletters and brochures by email, text or post. The legal basis for this processing is consent and our legitimate interests.
In addition to the specific purposes for which we may process your personal data set above, we may also process any of your personal data where such processing is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
We may also provide you with information about offers and products that are similar to those that you have already received or we feel may interest you. If you:
have already concluded a contract with us (e.g. where you have purchased products from us), we will only contact you by electronic means (email or text) with information about offers and products similar to those which were the subject of a previous contract. If you do not want to be on our mailing list, you can opt out at any time by unsubscribing by using the links provided in our electronic communications or by ticking the opt-out box situated on the website page on which we collect your details.
are a potential new customer (e.g. enquiring about products), we will contact you by electronic means (email or text) only if you have provided your consent to this. If you are happy for us to use your personal data in this way, please tick the relevant box situated on the website page on which we collect your details. Again, if you do not want us to use your data in this way, you can opt out at any time by contacting us or unsubscribing by using the links provided in our electronic communications.
HOW IS YOUR PERSONAL DATA COLLECTED
We use different methods to collect data from and about you including through:
Direct interactions. You may give us your Identity, Contact and Financial Data when you order products, when you fill in forms on our site or when you corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
order products from our site;
create an account on our site;
subscribe to our newsletters;
request marketing materials to be sent to you;
enter a competition, promotion or survey; or
give us some feedback or contact us.
Automated technologies or interactions. As you interact with our site, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies.
Third parties or publicly available sources. We may receive personal data about you from various third parties which include:
Technical Data from analytics providers and search engine providers (such as Google and Bing) based outside the UK;
Contact, Financial and Transaction Data from providers of technical, payment and delivery services;
Identity and Contact Data from social media platforms (such as Facebook, Instagram, Pinterest) based outside the UK;
Identity and Contact Data from publicly available sources such as Companies House and the Electoral Register based inside the UK.
Some of the third parties which we work closely with are based outside of the UK so their processing of your personal data will involve a transfer of data outside of the UK.
Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
we will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data;
or we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.
CHANGE OF PURPOSE
DISCLOSURE OF YOUR INFORMATION
You agree that we may disclose your information (including personal data) to the following categories of third parties:
suppliers and subcontractors for the performance of any contract we enter into with them or you;
third party service providers who provide services to us;
analytics and search engine providers that assist us in the improvement and optimisation of our site;
data storage providers, in connection with cloud storage and file hosting services;
third party software providers (such as CACI Ltd the provider of Acorn), which assists us to analysis consumer behaviours and improve our site;
third party advertising providers (such as Google AdSense, Facebook Custom Audiences tool and Rakuten Advertising) in order to deliver effective advertising to you;
social media platforms (such as Facebook, Instagram, Pinterest) in order to deliver effective advertising to you;
operators of data cooperatives (such as Epsilon International UK Ltd and Experian) and third parties who are members of the data cooperative. We may disclose your Identity Data, Contact Data and Transaction Data with Epsilon and Experian who will analyse this information to determine consumer habits. Epsilon and Experian may share your Identity Data, Contact Data and Transaction Data with third party members of the data cooperative who may use this information to send you marketing materials by post. The legal basis for this processing is consent (an opt-in which appears on the page on which we collect your details).
We may disclose your personal data to third parties:
where we have your consent to do so;
where we are pursuing a legitimate interest;
to provide and/or improve our services;
in the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets;
if Finisterre UK Limited or substantially all of its assets are acquired by a third party, in which case personal data held by us about you will be one of the transferred assets; and
if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or to protect the rights of Finisterre UK Limited, our customers, suppliers, contractors or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
Under Data Protection Legislation, in certain circumstances you have the following rights in relation to your personal data:
Right to access. You have the right to request access to information held about you. We will provide you with a copy of your personal data held by us free of charge (providing your request is not excessive or for multiple copies, in which case we may charge a reasonable fee to cover our costs) and certain information about the processing of your personal data and the source of such data (if not directly collected from you by us). You also have the right to request that your personal data is transferred to a third party.
Right to object to data processing. You may withdraw your consent to the processing of your personal data at any time by contacting us or ticking a box to opt out of receiving marketing materials. Upon receipt of your notification, we shall promptly stop any processing of your personal data and (if requested by you) erase such information if we are not required to retain it for legitimate business or legal purposes.
Right to restrict processing. You may ask us to suspend the processing of your personal data in the following circumstances: if you do not think your personal data is accurate; where we are found to be processing unlawfully but you do not want us to erase your personal data; where you need us to continue holding your personal data to establish, exercise or defend legal claims; or where you have objected to our use of your personal data but we need to verify whether we have overriding legitimate grounds to use it.
Right of rectification and right of erasure. You have the right to request that we correct or erase any inaccuracies in your personal data if such information would be incomplete, inaccurate or processed unlawfully.
Where we are relying on consent to process your personal data, you may withdraw consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you withdraw your consent.
You can also exercise these rights at any time by contacting us by email at firstname.lastname@example.org, by telephone on 01872 554 881 or by post at Data Protection Officer, Finisterre, Unit 6, Wheal Kitty Workshops, St Agnes, Cornwall TR5 0RD. We may reject requests that are unreasonable or require disproportionate effort (for example, such a request would result in a fundamental change to our existing practice) or risk the privacy of others. Our site may, from time to time, contain links to and from third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
PERSONAL DATA RETENTION
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. When personal data is no longer needed, we will securely delete or destroy it. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
If you have any cause for complaint about our use of your personal data, please contact us using the details provided above and we will do our best to solve the problem for you. If we are unable to help, you also have the right to lodge a complaint with the Information Commissioner’s Office (www.ico.org.uk).
Last updated: April 2022