Privacy Notice

Contents

1. About us and how to contact us

This website at www.mastrum.com (our “Website”) is operated by Global Design & Innovation Limited, a company incorporated in England and Wales with company number 07523409 and whose registered office is at Unit 9, Hemmells Park, Laindon, Essex SS15 6GF, United Kingdom (“we”, “us” or “our”). 

As a controller of your personal data (i.e. any information about an individual from which that individual can be identified), we are committed to protecting and respecting your privacy. 

Any questions or requests regarding this Privacy Notice, including any requests in respect to your personal data that we process, can be sent by post to the above-stated address or emailed to [email protected].

This Privacy Notice (together with our Terms of Use and any other documents referred to on it, and our Cookie Notice) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. 

Our Website and the products sold on it are not intended for children and we do not knowingly collect data relating to children.

Our Website includes links to third-party websites and applications. We do not control these third-party websites and are not responsible for their privacy statements, notices, or policies. When you leave our Website, we encourage you to read the privacy notice of every website you visit. We do not accept any responsibility or liability for the privacy policies or notices on third-party websites. Please check these policies before you submit any personal data to such third-party websites. 

2. Information we collect about you

Depending on the services we provide to you and how you interact with us, we collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

  • Contact Data, which includes email address, billing address, delivery address, and telephone number (including any phone number used to contact our customer services number).
  • Employment Data, which includes all data listed below as ‘Recruitment Data’, as well as your date of birth, gender, marital status and dependants, next of kin and emergency contact information, National Insurance number, bank account details, payroll records and tax status information, and details of your salary, annual leave, pension and benefits, sickness, absences, parental leave, start date and leaving dates of your employment or engagement, location of your workplace, performance information, disciplinary and grievance information, photographs, and employment records;  
  • Financial Data, which includes payment card details and other financial and billing information.
  • Identity Data, which includes date of birth, first name, last name, and title.
  • Recruitment Data, which includes details of your qualifications, experience, academic and/or job or employment history (including job titles), interests, and references obtained about you from previous employers and/or education providers, and diversity and equal opportunities monitoring information (this may include ‘special category’ data, such as your racial or ethnic origin, religious beliefs, and/or sexual orientation), your nationality and immigration status, previous criminal offences and convictions, and information from related documents (such as your passport, driving licence, and/or other identification and immigration information). 
  • Technical Data, which includes your internet protocol (IP) address, cookie identifiers, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Website.
  • Transaction Data, which includes information such as details of your purchases and the fulfilment of your orders (such as basket number, order number, subtotal, title, currency, discounts, shipping, number of items, product number), payments to and from you and details of other products you have obtained from us, correspondence or communications with you in respect of your orders, and details of any rewards and bonuses awarded.
  • Usage Data, which includes information about how you use our Website and products, such as clickstream to, through, and from our Website (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
  • Profile Data, which includes information about purchases or orders made by you, product and style interests, preferences, feedback, and survey responses.
  • Marketing and Communications Data, which includes your preferences in receiving marketing from us and our third parties and your communication preferences.

3. How we collect and use your information

We will only collect and process your personal data where we have a lawful basis to do so, i.e. where:

  • we need your personal data to perform a contract with you (for example, to process a payment from you, fulfil your order or provide customer support connected with an order);
  • the processing is in our legitimate interests (as described below) and not overridden by your interests, rights, or freedoms;
  • we have a legal obligation to collect or disclose personal data from you; 
  • we need your personal data where you work for our organisation in connection with our obligations and rights in connection with employment, social security, or social protection law; and/or 
  • we have your consent to process your personal data.

The following table sets out what personal data we collect about you, what we use that personal data for, and our lawful basis for doing so. Please be aware that we sometimes process your personal data using more than one lawful basis, depending on the specific purpose or activity.

Purpose/Activity

Type of data

Lawful basis for processing 

To register you as a customer 

(a) Identity

(b) Contact

Performance of a contract with you

To process and deliver your order, including: recording your order details; keeping you informed about the order status; process payments and refunds; and collect money owed to us

(a) Identity

(b) Contact

(c) Financial

(d) Transaction

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (for collecting money owed to us)

To inform or remind you by email of any task carried out via our Website which remains uncompleted, such as incomplete orders or abandoned baskets

(a) Identity

(b) Contact

(c) Profile

(d) Technical

(e) Usage

Necessary for our legitimate interests (to improve your shopping experience)

To manage our relationship with you, including handling any complaints or queries and notifying you about changes to our Terms of Use, Terms of Sale, and/or this Privacy Notice

(a) Identity

(b) Contact

(c) Transaction

(d) Profile

(a) Performance of a contract with you

(b) Necessary to comply with our legal obligations

To administer and protect our business and our Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

(a) Identity

(b) Contact

(c) Technical

(d) Transaction

(e) Profile

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud, and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with our legal obligations

To use data analytics to improve our Website, products/services, marketing, customer relationships and experiences

(a) Technical

(b) Usage

(c) Profile

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Website updated and relevant and ensure that its content is presented in the most effective manner for you and for your device, to develop our business and to inform our marketing strategy)

To make suggestions and recommendations to you about goods or services that may be of interest to you, including by way of email and text message

(a) Identity

(b) Contact

(c) Technical

(d) Usage

(e) Profile

(f) Marketing and Communications

Your consent (you can withdraw this at any time by clicking the link to unsubscribe in our marketing emails and/or the relevant ‘STOP’ number in text messages, or by contacting us using the details above)

To protect us, our customers, and our Website from fraud and theft

(a) Identity

(b) Contact

(c) Financial

(d) Transaction

Necessary for our legitimate interests (for detecting and preventing fraud)

To make a decision about your recruitment or appointment and to move your application forward before signing a contract of work (including undertaking pre-employment checks) and to identify and keep under review the equality of opportunity or treatment between different groups of people

(a) Identity

(b) Contact

(c) Recruitment

(a) Performance of a contract with you

(b) Necessary to comply with our legal obligations

(c) Necessary for the purposes of carrying out our obligations or rights imposed or conferred by law on us in connection with employment,  social security, or social protection law

(d) Necessary for our legitimate interests of undertaking, managing, and administering our business and workforce

(e) Necessary for our establishment, exercise, or defence of legal claims

To undertake, manage, and administer our business and support and manage our staff, including (but not limited to) administering payroll, conduct performance reviews, managing our working relationship with you, and identifying or keeping under review the equality of opportunity or treatment between different groups of people

(a) Identity

(b) Contact

(c) Employment

(a) Performance of a contract with you

(b) Necessary to comply with our legal obligations

(c) Necessary for the purposes of carrying out our obligations or rights imposed or conferred by law on us in connection with employment,  social security, or social protection law

(d) Necessary for our legitimate interests of undertaking, managing, and administering our business and workforce

(e) Necessary for our establishment, exercise, or defence of legal claims

 

Where the lawful basis stated above is your consent, you have the right to withdraw this consent at any time. You can also object to our processing in certain circumstances where our lawful basis for processing is our legitimate interests. Please see section 7 of this Privacy Notice for further information on how to exercise these rights. 

Please note that, where we rely on your consent or our legitimate interests to process your personal data and you withdraw that consent or object to our processing, we will no longer be able to provide certain services to you that are dependent on this processing.

If any of your personal data (such as your Contact Data) changes, please ensure that you let us know by editing this in your account settings, so that the information we have about you is kept up to date.

4. How we store your information, who we share it with, and how long we keep it for

We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it, such as our staff, professional advisors, and business partners, suppliers, and subcontractors that we use in connection with the running of our business for the purposes set out in the table in section 3 of this Privacy Notice. If you make a purchase on our Website, your Financial Data is sent to the payment processing service that you select. Please refer to the privacy information provided by the relevant payment processor for further details.   

Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality. We may be required to share your personal information for prevention of crime or where otherwise required to do so by other regulators or by law.

Our Website uses Secure Sockets Layer (SSL) certificates to verify our identity to your browser and to encrypt any data you give us via the Website. Whenever information is transferred between us in this way, you can check the relevant SSL certificate by looking for a closed padlock system or other trust mark in your browser’s URL bar or toolbar.

We have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

If you have registered an account on our Website,  we will retain your information for as long as you have an account on our Website. If you delete your account or request us to do so, we will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we will be able to use this information indefinitely without further notice to you.

If you have sent us information in connection with a job application, we will keep your Recruitment Data (including interview notes) for no longer than is reasonable, taking into account the limitation periods for potential claims such as race or sex discrimination (as extended to take account of early conciliation), after which they will be destroyed. If there is a clear business reason for keeping Recruitment Data for longer than the recruitment period, we will do so, but we will first consider whether the records can be pseudonymised, and the longer period for which they will be kept. If you make a job application to us that is successful, we will only keep the Recruitment Data that is necessary in relation to your employment or engagement. Once this employment or engagement ends, we will retain and securely destroy your personal information in accordance with applicable laws and regulations.

5. Cookies

Our Website uses cookies to distinguish you from other users of our Website. This helps us to provide you with a good experience when you browse our Website and also allows us to improve our Website. 

For further information on cookies (including about how we use them and when we will request your consent before placing them and how to disable them), please see our Cookie Notice.

6. International transfers of your information

We do not transfer your personal data to processors outside of the United Kingdom. If this changes and we are still processing your personal information, we will notify you by email and we will take steps to ensure that your personal information and rights are protected through methods approved under applicable data protection laws.  

7. Your rights

Under applicable data protection laws, you have a number of important rights free of charge. In summary, those include rights to:

  • access to your personal information and to certain other supplementary information that this Privacy Notice is already designed to address;
  • require us to correct any mistakes in your information which we hold;
  • require the erasure of personal information concerning you in certain situations (please note this that this right will not apply where it is necessary for us to continue to use the relevant personal information for a lawful reason);
  • receive the personal information concerning you which you have provided to us (and where the relevant lawful basis stated in section 3 of this Privacy Notice is your consent or our performance of a contract with you), in a structured, commonly used, and machine-readable format and have the right to transmit those data to a third party in certain situations (please note that this right does not apply to personal data contained only in hard-copy records);
  • withdraw your consent (if you have given this to us previously) for us to contact you for direct marketing purposes;
  • object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you;
  • object in certain other situations to our continued processing of your personal information; and
  • otherwise restrict our processing of your personal information in certain circumstances.

If you would like to exercise any of those rights, please contact us using the details provided section 1 of this Privacy Notice, letting us know the information to which your request relates. 

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests (in which case we will notify you and keep you updated).

There are some exceptions to the rights listed above and, although we will always try to respond to any instructions you may give us about our handling of your personal information, there may be situations where we are unable to meet your requirements in full.

We hope that we can resolve any query or concern you raise about our use of your information. You have the right to make a complaint at any time to the supervisory authority in the United Kingdom for data protection issues, the Information Commissioner’s Office (ICO), whose website is at www.ico.org.uk. If your usual place of residence is in the European Economic Area (EEA), you additionally have a right to a lodge a complaint with your local supervisory authority. Click here for the contact details of each EEA country’s supervisory authority.  

We would, however, appreciate the opportunity to deal directly with your concerns before you approach the ICO or any other supervisory authority, and would be pleased to respond to any such complaints as your first-priority contact. 

8. Updates to this Privacy Notice

This Privacy Notice was last updated on 7 May 2021.

We may amend this Privacy Notice from time to time as necessary to comply with law or for legitimate business purposes. Any changes we make to this Privacy Notice in the future will be posted on this page and, where appropriate, notified to you by email. Please check back frequently to see any updates or changes to this Privacy Notice.