Privacy and Cookie Policy
Background
This privacy policy sets out how we use your personal data and what your rights are in respect of it. We may change this privacy policy from time to time. If we make significant changes in the way we treat your personal information, or to the privacy policy, we will make that clear on this website, or by some other means such as email, so that you are able to review the changes before you continue to use our website.
This page was last updated on 06/12/2023.
Details
We are your data controller for the purposes of the personal data we will collect. Our details are as follows: WorldGift.com Limited, a limited company registered in England with the company registration number 11397739 and our registered address at Ashford Commercial Quarter, 1 Dover Place, Ashford, Kent, TN23 1FB. If you wish to contact us in relation to this policy, or data protection policy and procedures generally, please contact us, whose details are provided below.
Other controllers
Please note that when you place an order on WorldGift.com, you are placing an order directly with a third-party seller. We are therefore a co-controller of your personal data, and if you seek information about how the seller uses your personal data, you should contact them using the details provided to you at the time you have placed your order. Worldgift.com is not responsible for how sellers use your personal data, although we do require them in their contract with us to only use your personal data for the purposes of fulfilling your order.
Processing
Processing
This privacy policy applies to visitors and users of to this website (worldgift.com). The details below set out the personal data that we will collect, why we collect it, the legal basis on which we rely and how long we will keep it.
Your first name, surname, postal address, email address and telephone number. Note that we may obtain some of these details from Facebook account where you authorise us to sign you up using your Facebook account.
Purpose
- To administer your user account, which is required if you wish to place orders on our website, and to fulfil and administer the orders you place on our website
- To save your details for future orders, to make things easier for you on your next visit.
- To confirm your identity next time, you visit.
- To deal with any queries or returns.
- To bring or defend legal claims.
- To effect product recalls, in the unlikely event that they are required.
- To prevent fraud.
Legal basis for the processing
- It is necessary for the performance of our contract with you for the product or service that you order. Failure to provide this data may mean we are unable to fulfil your order
- Our legitimate interest in increasing sales.
- Our legitimate interest in keeping our website secure.
- Necessary for the performance of our contract with you for the product or service that you order, and/or necessary for us to comply with our legal obligations under consumer law. Failure to provide this data may mean we are unable to fulfil your order.
- Our legitimate interest in establishing, exercising, or defending legal claims.
- Our legitimate interest in preventing loss through fraud.
How long we keep it
- Seven years from the date on which you placed your order.
Where a WorldGift user has ordered you a gift, your first name, surname, postal address, email address and telephone number.
Purpose
- To deliver your gift to you.
Legal basis for the processing
- Our legitimate interest of fulfilling our contract between us and the WorldGift user.
How long we keep it
- Seven years from the date on which the gift was ordered.
The details of any query or complaint you raise with a customer services team.
Purpose
- To deal with your queries and/or complaints.
- To bring or defend legal claims.
Legal basis for the processing
- Necessary for the performance of our contract with you for the product or service that you order, and/or necessary for us to comply with our legal obligations under consumer law. Failure to provide this data may mean we are unable to deal with your query or complaint.
- Our legitimate interest in establishing, exercising or defending legal claims.
How long we keep it
- Seven years from the date on which you placed your order
The contents of your virtual shopping basket.
Purpose
- To allow you to purchase items on our website.
Legal basis for the processing
- Necessary preparatory steps for the performance of our contract with you for the products or services that you would like to order. Failure to provide this data may mean we are unable to take your order.
How long we keep it
- Seven years from the date on which you placed your order.
Data relating to your visit to our website, for instance which pages you visited, how long you spent on them, the dates and times you visited and the searches you have made on our website.
Purpose
- To understand how you use our website, and optimise it and its contents according to your apparent interests.
Legal basis for the processing
- Our legitimate interest in increasing user satisfaction and sales and improving our website.
How long we keep it
- Two years from the date on which you gave consent to us sending marketing to you.
Data which you volunteer to us when creating your account on our website, including data received from a social media network where you register an account with us using that social media network.
Purpose
- To market products that we think you may be interested in whilst on other websites (known as "re-targeting").
Legal basis for the processing
- Consent
How long we keep it
- Two years from the date on which you gave consent to us sending marketing to you.
Data relating to the links or banners that you have clicked on in our emails or on our website, for instance the fact that you clicked, when you clicked, which page that link took you to, and the page or email from which you clicked the link
Purpose
- To understand what links and banners are of interest to you in order to tailor any emails we send you or any adverts we display you while on our website.
Legal basis for the processing
- Our legitimate interest in increasing user satisfaction and sales.
How long we keep it
- Two years from the date on which you gave consent to us sending marketing to you.
Your name and contact details.
Purpose
- To send marketing material to you, including newsletters and reminders of your friends' birthdays.
Legal basis for the processing
- Consent
How long we keep it
- Two years from the date on which you gave consent to us sending marketing to you.
Where a WorldGift account holder has added you as a "top ten friend": your first name, surname, postal address, and your date of birth.
Purpose
- To remind the relevant account holder when their friends' birthdays are approaching and where they are based.
Legal basis for the processing
- Our legitimate interest of increasing sales.
How long we keep it
- Two years from the date on which you gave consent to us sending marketing to you.
Data collected by our web servers, including your IP address, the type of device you are using and its operating system, the name of your ISP and the website from which you came.
Purpose
- To main access logs for the purposes of technical troubleshooting and detecting potential security threats.
Legal basis for the processing
- Our legitimate interest in maintaining and securing our website and systems.
How long we keep it
- Where multiple retention periods apply to one category of data, the retention period will be the longest one (although we will stop using that category of data when the retention period for that longest lasting purpose expires). Where our legal basis for processing is:
- Consent, you have the right to withdraw consent at any time (see the section titled "Withdrawing consent" below); or
- Legitimate interests, you may have the right to object to our processing (see the section titled "Objecting to legitimate interests processing" below).
Where we obtain your personal data from
We obtain your personal data in the following ways:
- Directly from you, for instance where you sign up to our website, purchase something from us, communicate with us, or otherwise voluntarily providing personal data to us;
- From your accounts on other website, where you give us permission to do so. For instance, if you use Facebook to log into our website, we may obtain some information from Facebook;
- Automatically when you use our website. For instance: when you use our website. For instance:
- like most websites, we use cookies (which are smaller text files sent between your web browser and our services) to provide or improve certain functionality and to track which of our pages you visit (see our cookie policy for more information);
- our web server automatically collects certain information about your use of our website, for instance some key settings on your device, what type of device you are using, the operating system on your device, the website from which you came and your IP address; and
- From commercial organisations for the purposes of fraud prevention, and in some cases for the purposes of assessing whether we can provide you credit.
Persons with whom we may share your data:
In general, access to your personal data will be restricted to those who have a need to access it in order to carry out their duties (for example our customer services team). However, we will also share your personal data with the following external third parties in some circumstances:
- The person or organisation that you have placed your order with, for the purposes of fulfilling your order. We contractually restrict such persons from using your data in any other way;
- Fraud prevention agencies or other third parties that assist us in preventing fraud or other forms of risk;
- Regulators such as the ICO, and government authorities such as HMRC or the police, if we are required to do so by law or if the regulator or authority requests it and we regard that request as reasonable;
- Our insurers, legal advisers or other third parties who need access to it in the context of managing, investigating or defending claims or complaints;
- In connection with re-organisations, mergers and acquisitions of all or part of our business;
- Organisations that process your data on our behalf who are not allowed to use your data for any other purpose, for instance our web hosts and the companies we use to pick, pack and deliver your orders;
- Other companies within our group, for instance where they provide us services; and
- Where you have consented to do us doing so.
- Where we share your personal data with our service providers, we have contracts with those service providers setting out how they must handle your personal data, including a requirement not to use your personal data other than in accordance with our instructions.
Where we share your personal data with our service providers, we have contracts with those service providers setting out how they must handle your personal data, including a requirement not to use your personal data other than in accordance with our instructions.
Where we have been able to full anonymise personal data, we may share that anonymised data with third parties, for instance to report to some of the brands about interest in their products.
Transfers outside of the EEA
In certain limited circumstances, we may export personal data outside of the European Economic Area for processing, and we may use third party service providers who do the same. We only do that if there is a good reason to do it and where either:
- There are adequate safeguards in place (such as the appropriate contractual arrangements with suppliers, or adequacy decisions, depending on the destination country); or
- We are otherwise permitted by data protection law (for instance, where you consent or such transfer is necessary to provide our service to you).
For example, where a WorldGift.com user places an order for delivery outside of the EEA, we will transfer personal data out of the EEA as it is necessary for the performance of a contract concluded for the benefit of you, the gift recipient.
Withdrawing consent
Where we process your personal data on the basis of consent for marketing purposes, you can withdraw your consent in one of the following ways:
- By visiting www.worldgift.com/myaccount (note, you may need to login to verify your identity);
- By following the unsubscribe link which we include in all electronic marketing; or
- By contacting our customer services team using the details on our "contact us" page.
Objecting to our legitimate interests processing
Where we process your personal data on the basis of our legitimate interests for direct marketing purposes, you always have the right to object to that processing. To object to direct marketing either follow the instructions for withdrawing marketing consent in the section above or contact us using the details at the top of this notice. You have the right to object to other processing on the basis of our legitimate interests, but we might not have to cease processing where you do so if either:
- We are able to demonstrate compelling legitimate grounds for the processing which override your interests; or
- Where that legitimate interest is the establishment, exercise or defence of legal claims.
To object to legitimate interests processing, please contact us using the details at the top of this notice.
Your rights (with effect from 25 May 2018)
The law gives you certain rights in respect of the personal data that we hold, which you should be aware of:
- You have the right to obtain your personal data from us except in limited circumstances. Where we provide it, the first copy will be free of charge, but we reserve the right to charge a small fee for additional requests;
- You have the right to require us to rectify any inaccurate personal data we hold concerning you;
- Taking into account the purposes of the processing, you may also have the right to have incomplete personal data completed, by means of providing a supplementary statement or otherwise;
- You have the right to require us to erase your personal data on certain limited grounds (including where they are no longer necessary for the purpose for which they were collected or where we rely on consent, which you withdraw, and there is no other legal ground for the processing);
- Where we process personal data either on the basis of consent or contractual necessity, you provided the personal data to us, and we process that personal data by automated means, you have the right to require us to give you your data in a commonly used electronic format;
- You have the right to object to our processing of personal data which we process on the grounds of our legitimate interests, as detailed in the paragraph titled "objecting to our legitimate interest processing" above;
- You have the right to require us to restrict the processing of your personal data on certain grounds, including where
- You contest the accuracy of the personal data and want us to restrict processing of your personal data while we verify its accuracy;
- The processing is unlawful, but you request a restriction of the processing rather than erasure;
- We (as controller) no longer need the data for the purposes of the processing, but you have told us you require us to retain that personal data for you to establish, exercise or defend legal claims; or
- You have objected to us processing your personal data on grounds of legitimate interests and want us to restrict processing of your personal data while we consider your objection.
- If you would like to exercise any of these rights, please contact us using the details set out at the top of this notice.
If we can't remedy an issue you have
Should you have any complaints or issue with our treatment of your personal data, you may lodge a complaint with the Information Commissioner's Office (ico.org.uk).
Cookies
Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and allows us to improve our site. By continuing to browse the site, you are agreeing to our use of cookies.
A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer's hard drive. We use the following cookies:
- Strictly necessary cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website, use a shopping cart or make use of e-billing services.
- Analytical/performance cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
- Functionality cookies. These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
- Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.
Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical/performance cookies or targeting cookies.
You block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our site.
You can find out more about cookies by visiting the ICO's website: https://ico.org.uk/for-organisations/guide-to-pecr/cookies-and-similar-technologies.