Privacy Policy CREASEY’S GROUP CUSTOMER PRIVACY POLICY Creasey’s Group (‘Creasey’s’) includes: Creasey & Son ltd Creasey’s Ltd Creasey’s (Franchise) ltd – trading as Marks and Spencer Guernsey Overview Maintaining the security of your data is a priority at Creasey’s and we are committed to respecting your privacy rights. We pledge to handle your data fairly and legally at all times. Creasey’s is also dedicated to being transparent about what data we collect about you and how we use it. This policy, which applies whether you visit our stores or use our web site, provides you with information about: How we use your data What personal data we collect How we protect your data Your legal rights relating to your personal data Our legitimate interests HOW WE USE YOUR DATA General: Creasey’s (and trusted partners acting on our behalf) uses your data: To provide goods and services to you To manage any registered accounts you hold with us To verify your identity To contact you about promotional offers and products and services which we think may interest you For market research purposes – to better understand your needs For crime and fraud prevention, detection and related purposes Where we have a legal right or duty to use or disclose your information (for example in relation to an investigation by a public authority or in a legal dispute). Marketing: Creasey’s uses your personal data for marketing purposes to update you on our latest offers. Creasey’s aims to update you about products and services which are of interest and relevant to you. You have the right to opt out of receiving promotional communications at any time by: Making use of the “unsubscribe” link in emails. Contacting us through the channels set out in this policy. We may analyse your purchasing activity and your responses to marketing communications. The result of this analysis allows us to ensure that we contact you with information on products and offers that are relevant to you. To do this we may use software and other technology (automated processing). Sharing data with third parties: In order to make certain services available to you, we may need to share your personal data with some of our trusted service providers. These include IT, delivery and marketing service providers. Creasey’s only allows its service providers to handle your personal data when we have confirmed that they apply appropriate data protection and security controls. We also impose contractual obligations on service providers relating to data protection and security, which mean they can only use your data to provide services to us and to you and for no other purposes. Other third parties: Aside from our service providers Creasey’s will not disclose your personal data to any third party, except as set out below. We will never sell or rent our customer data to other organisations for marketing purposes. We may share your data with: Credit reference agencies where necessary for card payments States bodies, regulators, law enforcement agencies, courts, tribunals and insurers where we are required to do so to comply with our legal obligations To exercise our legal right (for example in court cases) For the prevention, detection and investigation of crime or the prosecution of offenders For the protection of our employees and customers. How long we keep data: We will not retain data for longer than necessary for the purposes set out in this Policy. Different retention periods apply for different types of data, however we would not normally keep data for more than 10 years. WHAT PERSONAL DATA WE COLLECT Creasey’s may collect the following information about you: your name, age/date of birth and gender your contact details, including postal address, telephone and email address when you make a purchase or place an order with us, your payment card details items you have purchased from us if a One Card or Creaseys Account card was used at the time of the purchase copies of any correspondence between us. HOW WE PROTECT YOUR DATA Creasey’s is committed to keeping your personal data safe and secure. We do this by: encrypting data where appropriate establishing service contracts with third party service providers regularly reviewing security of our IT systems ensuring data is stored securely and is accessible only to those whose job requires it YOUR LEGAL RIGHTS RELATING TO YOUR PERSONAL DATA You have the following legal rights: the right to ask what personal data we hold about you the right to ask us to update and correct any out-of-date or incorrect data the right to opt out of any marketing communication we may send you the right to ask us to delete your personal data. OUR LEGITIMATE INTERESTS The normal legal basis for processing customer data is that it is necessary for the legitimate business interests of Creasey’s, including: Selling and supplying goods and services to our customers Promoting, marketing and advertising our products and services Sending promotional communications which are relevant to individual customers (including administering our One Card loyalty scheme) Understanding our customers behaviour, activities, preferences and needs Improving existing products and services and developing new products and services Complying with our legal and regulatory obligations Preventing, detecting and investigating all forms of crime and prosecuting offenders Protecting customers, employees and other individuals and maintaining their safety, health and welfare Handling customer contacts, queries, complaints or disputes Managing insurance claims Fulfilling our duties to our customers, employees, shareholders and other stakeholders Contact us If you have any concerns about how Creasey’s uses your personal data, or you wish to exercise any of your rights, then please contact us at: mail@creaseys.com or write to us at: Creasey’s Ltd, High St, St Peter Port, Guernsey, GY1 2JZ Updates This policy was last updated in May 2018