HILLIER CASH & CARRY, a division of Hillier Nurseries Ltd
Hillier Nurseries Ltd have been growing and selling quality plants since 1864 and we continue to strive to supply plants, trees, gardening accessories and services of the highest calibre to all our customers. Our mission is to inspire the creation of green living spaces for now and the future. We believe it is important for you to know what information we collect and how we treat the information you share with us.
2. Where and how we collect your information
Information you give us
We will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you.
- Where it is necessary for our legitimate business interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we have your express consent.
For example, when you request us to register you as a new Trade customer, or to quote or place an order with us, or arrange delivery for an order, we will ask you for your personal information in order for us to process quotes, orders, invoices, and to be able to deliver an item. This information is likely to include contact information, payment information, or marketing preferences.
Information collected automatically through our website.
- technical information, including your operating system, the browser you use, time zone setting, browser plug in types and versions, your log in information and the internet protocol address used to connect your computer to the internet (Device Information);
- details of your use of our website including traffic data, the resources you use, where you have clicked through to our website from that of a third party, the domain name of the connecting website, page response times, download errors, length of your visit, page interaction information and browsing behaviour (Log Information);
Some online identifiers (such as static IP addresses) are personal information. We collect Device Information so that we can ensure adequate technical support for our website and ensure it is functioning properly on all operating systems/browsers. We want to ensure the content of our website is being presented to you in the most appropriate way to ensure it is easy to use/navigate. We also need this information in order to allow you to participate in interactive features on the website where you choose to do so. We collect Log Information so that we can better understand how our website is used and improve its functionality/content. We want to provide you with a customised service. Your Device Information and Log Information will be combined with that of our other users and reported in statistical form. It will not be possible to identify you from this aggregated information.
To enhance your experience on our website and social media platforms we use ‘cookies’. This means that the Hillier website will remember you for a particular length of time. When you access our website, your device may provide us with data about the device you’re using, including the type of device, operating system, and it may report details of a website or app crash. Device manufacturers or operating system providers will be able to provide you with more details about the data your device makes available to us. The list of cookies used by Hillier Cash & Carry on digital platforms are listed below.
3. What data do we collect and how is it used?
The type of personal data we collect depends on the purpose of collecting the information.
Registered Trade Customer Accounts
If you register with us as a Trade Customer (either pay as you go or pro-forma), we collect the following personal data: name, email address, business name, address, postcode, company registration number, date of incorporation, website address, telephone number, signature. We will use this data for the following reasons:
- Provide you with the services you have requested
- Process your Trade customer account to enable you to order from us at Trade discounted amenity prices
- Keep a record of your marketing and communication preferences with us
- To enable us to deliver more relevant content to you, through communications
We process this data in order to perform our contract with you and offer you information about our products and services as part of our legitimate business interests.
If you arrange a delivery for an order from Hillier Cash & Carry, we will collect the following personal data: name, phone number, email address delivery address, delivery postcode We will use this data for the following reasons:
- To arrange delivery of purchased goods
- To pass delivery details to the specified haulier to arrange delivery
We process this data in order to perform our contract with you.
Enquiries and Complaints
When you send us an enquiry or complaint we will share this information and details with relevant parties to be able to resolve your enquiry. We will only keep this information for 6 months after resolution. It is in our legitimate business interests to collect this information.
Data collection for other reasons
Sometimes there is a need to collect data for other specific reasons, these include, but are not limited to: accident forms, photography and CCTV imagery / videos and phone call logging. If you would like more information about these specific reasons, please contact firstname.lastname@example.org It is in our legitimate business interests to collect this information. Details for how long we keep the personal information that is collected and processed by Hillier Cash and Carry can be found in our retention policy. If you would like a copy of our retention policy please email email@example.com
3.7 Direct marketing
We will only contact you by email and/or phone if you have consented to this, unless there is a legitimate reason to contact you. Consenting to Hillier Cash & Carry emails or opting in to email communications, means you have granted us permission to use your email address to send you email marketing communication. You may choose to opt out of such communications at any time – more information about opting out is in section 3.9
If you have provided us with your postal address we may contact you by post if you have consented for us to do so. We may also contact you by post if we have a legitimate reason to contact you. Consenting to Hillier Cash & Carry postal marketing means you have granted us permission to use your address to send you marketing communications.
3.8 Third parties
Hillier Cash & Carry will not sell your data and we will not share your data for third party marketing purposes. In some circumstances, we may need to share your details with a third party for processing. This could be to process your personal details if we need to send your data to a mailing house in order to fulfil a postal mailing to you, this could include sending you a letter about your membership. Or it could be to send you emails or text messages via a marketing communications platform such as Salesforce or Mailchimp. We also store data on the system we use for sales at Hillier Nurseries to store account details for Registered Trade Customers and purchase information. If we would like to use any information that you have provided to us for marketing purposes, we will always ask for your consent to do so. For example, if we display testimonials of satisfied customers on our website or advertising materials. With your consent, we may post your first name alongside the quote.
3.9 Your choice:
You always have a choice as to whether you want to receive communications about our products and services, and how you receive them. You can opt out of this when we collect your details or at a later time. If you want to change your preferences, or opt out of communications, you can do so by contacting firstname.lastname@example.org at any time. You can also opt out of the email marketing by clicking the unsubscribe link at the bottom of any email from us. If you choose not to be contacted by us we will never send you personalised marketing communications. We will only keep any necessary details on a ‘suppression list’ to ensure you aren’t contacted.
3.10 Lawful basis for processing your personal data
In some situations we will collect and process your personal data using the legitimate interest legal processing basis. This means we’ll process your data as it is part of a contract which you have entered into. For example:
- All data shared with external hauliers and Third Party contractors is necessary for the Third Party's legitimate interests in relation to performing their role in our contract with the Data Subject. All external contractors are GDPR compliant and will never store any customer data after performing their role.
In most circumstances however, we will rely on your consent when we use your personal data. An example of this would be when we request your consent to receive marketing emails from Hillier Cash & Carry.
We hold your personal data and information for only as long as necessary for the purpose needed. Details for how long we keep the personal information that is collected and processed by Hillier Cash and Carry can be found in our retention policy. If you would like a copy of our retention policy please email email@example.com
3.12 Job application data
4. How do we keep your personal data secure?
To protect the personal data you provide us with we always ensure that we have the necessary controls in place, implementing suitable physical or electronic security alongside organisational training. Regular audits are carried out to identify who has access to data so that we can ensure that your information is only accessed by trained staff who have a legitimate reason to access it.
Information storage and security
The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (EEA). It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff maybe engaged in, among other things, the provision of support services. By submitting your personal data, you agree to this transfer, storing or processing. When we use external companies to process your personal data on behalf of Hillier Garden Centres thorough checks are carried out on any companies we work with. Contracts are in place with each of these companies to ensure that they process your information in line with our expectations and the General Data Protection Regulation. Transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our channels; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. We may disclose your Personal Information to any member of our group, which means our ultimate holding company and its subsidiaries (if applicable), as defined in section 1159 of the UK Companies Act 2006. We will only share your Personal Information outside of our group with (a) your consent; (b) as required by law; (c) in the event that we sell or buy any business or assets; (d) if all or substantially all of our assets are acquired by a third party; or (e) to protect customers or the public, with companies that help Hillier fulfil its obligations with you, and then only with partners who share Hillier’s commitment to protecting your online privacy. Sometimes we use external companies to process your personal data on behalf of Hillier Garden Centres. We carry out thorough checks on any companies we work with and have a contract in place with each of these companies to ensure that they process your information in line with our expectations and the General Data Protection Regulation.
4.1 Your credit and debit card information
When making payments every effort is made to maintain customer confidentiality. This means ensuring the security of your credit or debit card details and other personal information. We also ensure our systems and processes comply with PCI DSS, the worldwide Payment Card Industry Data Security Standard. The PCI DSS was set up to help businesses process card payments securely and reduce card fraud. This is achieved through tight controls of storage, transmission and processing of data, it is intended to safeguard sensitive cardholder data.
5. Your right to your personal information
We recognise that the personal information we hold about you belongs to you and it is right that you have control over that personal information. We have detailed below a summary of your legal rights. You can:
- ask us to have access to, and for a copy of, the personal information we hold about you;
- request that we amend or delete your personal information;
- ask us to stop processing your personal information altogether or in a certain way;
- change your mind about how you have agreed we can use your personal information. If you have given us
consentto use your personal information in a specific way you can withdraw it. This means that we will stop processing your personal information in the way you have objected to from the date that your permission is withdrawn;
- issue a complaint to the appropriate authority – see ico.org.uk for more information;
- request that we transfer your personal information to another provider (this is known as data portability);
- object to any automatic processing we conduct.
If you would like to exercise any of these rights, or discuss them in more detail, please contact us at Data Protection Team, Hillier Nurseries, Ampfield House, Ampfield, Romsey SO51 9PA or email firstname.lastname@example.org. We will then send you a form to complete and send back to us by post. We will also require you to provide two forms of identification. Once we have received your information request and your identification we will respond within 30 days.
7. Raising Queries or Concerns
Hillier Nurseries Ltd are on the ICO Data Protection Register Registration Number: ZA162542