Privacy Policy

 

Overview

Magnolia Tree Wools (MTW) needs to gather and use certain information about individuals. These can include customers, suppliers, business contacts, employees and any other people that MTW has a relationship with, or may need to contact.This policy describes how this personal data must be collected, handled, stored to meet the company’s data protection standards and to comply with the law.

Why this policy exists

I process personal information to enable me to sell my goods and services to customers; to promote and advertise my services; maintain my own accounts and records and to support and manage my employees. This Data Protection Policy ensures that MTW:

  • Complies with data protection law and follows good practice
  • Protect the rights of staff, customers, and partners
  • Is open about how it stores and processes individuals’ data
  • Protects itself from the risks of data breach

Data protection law

This Privacy Policy adheres to the EU/UK General Data Protection Regulation (GDPR). MTW is registered with The Information Commissioner’s Office. More information can be found on the ICO website. The regulations apply to all personal information stored whether electronically stored, or on paper. The rights and principles of GDPR are outlined below.

The Individuals’ Rights:

  • The right to be informed
  • The right of access
  • The right of rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • The right not to be subject to automated decision making, including profiling

The Organisation’s Principles:

Data is collected, used, and stored:

  • In a fair and transparent manner
  • Is collected for specific reasons, and only used for those specified reasons
  • Is adequate, relevant, and limited to what is necessary
  • Is accurate, and kept up-to-date
  • Kept in an identifiable form for no longer than necessary
  • Held securely to prevent inappropriate access, loss, or disclosure

Policy scope

This policy applies to MTW’s customers, contractors, suppliers, and other people MTW has a relationship with. It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the GDPR. This can include:

  • Names of individuals
  • Postal addresses
  • Email addresses
  • Telephone numbers
  • Plus any other information relating to individuals

Responsibilities

I, Lucy Davies of MTW am ultimately responsible for ensuring that MTW meets its legal obligations. I am responsible for:

  • Reviewing all data protection procedures and related policies, in line with the GDPR.
  • Handling data protection questions from clients and anyone else covered by this policy.
  • Dealing with requests from individuals to see the data that MTW holds about them.
  • Ensuring all systems services and equipment used for storing data meet acceptable security standards.
  • Performing regular checks or scans to ensure security hardware and software is functioning properly.
  • Evaluating any third-party services the company uses/plans to use to store data.

Types of data collected

**WEBSITE COOKIES

What are cookies?

Like most websites MTW uses cookies to collect information. Cookies are small data files which are placed on your computer or other devices (such as smart ‘phones or ‘tablets’) as you browse this website. They are used to ‘remember’ when your computer or device accesses the MTW website. They are also used to tailor the products and services offered and advertised to you, both on my website and elsewhere.

Information collected & what it is used for

Some cookies collect information about browsing and purchasing behaviour when you access this website via the same computer or device. This includes information about pages viewed, products purchased and your journey around a website. I do not use cookies to collect or record information like your name, address or other contact details.

I may collect information about your computer, including where available your IP address, operating system and browser type, this is for system administration and to report aggregate information to my advertisers. This is statistical data about MTW’s users’ browsing actions and patterns and does not identify any individual. Cookies help me to improve the site and to deliver a better and more personalised service. They enable me:

  • To estimate my audience size and usage pattern.
  • To store information about your preferences, and so allow me to customise the site according to your individual interests.
  • To speed up your searches.
  • To recognise you when you return to my site.

You may refuse to accept cookies by activating the setting on your browser which allows you to refuse the setting of cookies. However, if you select this setting you may be unable to access certain parts of my site. Unless you have adjusted your browser setting so that it will refuse cookies, my system will issue cookies when you log on to MTW’s website.

**GOOGLE ANALYTICS

When someone visits MTW website, I use a third-party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. I do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way which does not identify anyone. I do not make, and do not allow Google to make, any attempt to find out the identities of those visiting my website.

**MAILING LISTS

You have the option to subscribe to my regular newsletter. The purpose of this communication is to share news about MTW, promote products, events, and services, and share advice and tips about knitting and crochet. As part of the registration process for my newsletter, I collect personal information (Your first name and email address). I use that information for a couple of reasons: your first name is to deliver a more personal experience, and your email address is to deliver emails about information you’ve signed up to receive; I may also contact you if I need to obtain or provide additional information; to check my records are right and to check every now and then that you’re happy and satisfied. I do not rent or trade email lists with other organisations and businesses.

I use a third-party provider, MailChimp, to deliver my newsletter. I gather statistics around email opening and clicks using industry standard technologies to help me monitor and improve my e-newsletter. For more information, please see MailChimp’s Privacy Policy. You can unsubscribe to general mailings at any time of the day or night by clicking the unsubscribe link at the bottom of any of my emails or by emailing me: lucy@magnoliatreewools.com

**INFORMATION ABOUT CUSTOMERS

If you are a past/current customer of MTW and have been bought any product or event ticket via my website then you will have a client profile on my ecommerce system. This will include your name, email address, and may include your physical address and phone number. Absolutely none of this information is ever shared. I use an online tool called Woocommerce to manage online sales. Read the Woocommerce privacy policy here.

All payments for purchases made via the MTW website are managed through a third party called Paypal. MTW has no access to your card or bank account details at any time. Read the Paypal privacy policy here.

**CONTACT FORMS & EMAILS

MTW uses contact forms on the website. This feature asks for your name and email address so that I can respond to your message. The information you give within the contact form goes directly to my email account and is not stored on my website. Absolutely none of this information is ever shared.

I use a third-party provider, G Suite, as my email software. For more information, please see G Suite’s Privacy Policy.

**FACEBOOK ADVERTISING AND REMARKETING

I use Facebook advertising to deliver information to website visitors on Facebook based on email addresses of newsletter subscribers. You can learn more about Facebook customer audiences here. If you would like to opt out of this service please contact lucy@magnoliatreewools.com

** BLOG

Commenting on any posts that I have published on my blog will save the following information to the website’s database:

  • the name and email address you enter with your comment
  • your computer’s IP address and the time and date that you submitted the comment

This information is only used to identify you as a contributor to the comment section of the respective blog post and is not passed on to anyone. Only your name will be shown on the public-facing website, although if the supplied email address is linked to a Gravatar account, your Gravatar photo will also be displayed. You can read Gravatar’s Privacy Policy here.

Your comment and it’s associated personal data will remain on this site until I see fit to either:

  1. Remove the comment
  2. Remove the blog post

Should you wish to have the comment and it’s associated personal data deleted, please email me here using the email address that you used at the time of commenting.

If you are under 16 years of age you MUST obtain parental consent before posting a comment on my blog.

NOTE: You should avoid entering personally identifiable information to the actual comment field of any blog post comments that you submit on this website.

**THIS WEBSITE’S SERVER

This website is hosted by Siteground within a UK data centre. Some of the data centre’s more notable security features are as follows: All facilities are well protected by 24x7 human security, biometrics, access control man traps, bulletproof lobbies, and video surveillance. All traffic (transferral of files) between this website and your browser is encrypted and delivered over HTTPS. You can read Siteground’s Privacy Policy here.

What you can do about the information I hold about you

**ACCESSING/AMENDING/DELETING INFORMATION HELD ABOUT YOU

You are entitled to view, amend, or delete the personal information that MTW holds about you. Email your request to lucy@magnoliatreewools.com. Provision of such information will be subject to:

  • the payment of a fee (currently fixed at £10.00); and
  • the supply of appropriate evidence of your identity

I may withhold such personal information to the extent permitted by law. You may instruct me not to process your personal information for marketing purposes by sending an email to me. In practice, you will usually either expressly agree in advance to my use of your personal information for marketing purposes, or I will provide you with an opportunity to opt-out of the use of your personal information for marketing purposes.

My principles

**SECURITY OF YOUR PERSONAL INFORMATION

I will take all reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. I will store all the personal information you provide on secure (password- and firewall- protected) servers. All electronic transactions you make to, or receive from me, will be encrypted using SSL technology.

Any data stored about you is currently stored in an identifiable fashion; a limitation of the content management system that this website is built on (WordPress). In the near future, I aim to change the storage of this data to a pseudonymous fashion meaning that the data would require additional processing using a separately stored ‘key’ before it could be used to identify an individual.

Pseudonymisation is a recent requirement of the GDPR which many web application developers are currently working to fully implement. I am committed to keeping it as a high priority and will implement it on this website as soon as I am able to.

Of course, data transmission over the internet is inherently insecure, and I cannot guarantee the security of data sent over the internet. You are responsible for keeping your password and user details confidential.

**DISCLOSURE

I may disclose information about you to any of my employees, officers, agents, suppliers or subcontractors insofar as reasonably necessary for the purposes as set out in this privacy policy. In addition, I may disclose your personal information:

  • to the extent that I am required to do so by law
  • in connection with any legal proceedings or prospective legal proceedings
  • in order to establish, exercise or defend my legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk)
  • to the purchaser (or prospective purchaser) of any business or asset that I am (or am contemplating) selling
  • to any person who I reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in my reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information

Except as provided in this privacy policy, I will not provide your information to third parties.

** DISCLOSURE

I may disclose information about you to any of my employees, officers, agents, suppliers or subcontractors insofar as reasonably necessary for the purposes as set out in this privacy policy. In addition, I may disclose your personal information:

  • to the extent that I am required to do so by law
  • in connection with any legal proceedings or prospective legal proceedings
  • in order to establish, exercise or defend my legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk)
  • to the purchaser (or prospective purchaser) of any business or asset that I am (or am contemplating) selling
  • to any person who I reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in my reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information

Except as provided in this privacy policy, I will not provide your information to third parties.

** DATA BREACHES

I will report any unlawful data breach of this website’s database or the database(s) of any of my third party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.

**THIRD PARTY WEBSITES

The MTW website contains links to other websites. I am not responsible for the privacy policies or practices of third party websites.

**INTERNATIONAL DATA TRANSFERS

Information that I collect may be stored and processed in, and transferred between, any of the countries in which I operate in order to enable me to use the information in accordance with this privacy policy. Information which you provide may be transferred to countries which do not have data protection laws equivalent to those in force in the European Economic Area.

**MY PROMISE TO YOU

MTW stands by the principles outlined in the GDPR, and as such, ensures that any information held by the organisation is collected, used, and stored securely, and for specific reasons. No information I hold about you is shared, sold, or rented and is accessible by you upon request. If you would like access to your information, please contact me here. For current customers: In order to keep your information accurate and up-to-date, I may send you an email requesting that you check and update any information that I hold.

**POLICY DOCUMENTATION UPDATE

This document was updated on 16 March 2018. If you discover any errors in this document, please contact lucy@magnoliatreewools.com and I will rectify them immediately. Otherwise, this policy will be reviewed next on 16 March 2019 unless any circumstances/laws are changed. You should check this page occasionally to ensure you are happy with any changes.

Orders placed Monday-Friday before 2pm will be dispatched the same day. After 2pm and at weekends, parcels will be sent on the next working day. Dismiss

We'd love to stay in touch with you.

 

Our regular newsletter is a hub of product information, special offers, and great ideas for your next crafty adventure.

 

Enter your email address to join our mailing list now, and also get 10% off your next purchase.

You have Successfully Subscribed!

X