Joules Limited Privacy Statement
Whilst we like to focus on the fun stuff here at Joules there are times when we have to take things a little more seriously so here are some details for you to read and digest about how we use and look after your data.
Our use of your data: We typically use your personal information in order to fulfil an order you place with us, to monitor website activity, to personalise your experience and for marketing purposes.
Marketing: We rely on a legitimate commercial interest to use your personal data for our marketing purposes which we consider does not unduly impact your rights except when we ask you for an express opt-in consent (this can sometimes be relevant to email or SMS marketing, for example). You may ask us to stop sending you marketing information at any time.
Sharing: We may share your data with third parties, including third-party service providers and other entities in the group. We will not share your data with third parties with the purpose of allowing them to market their goods or services to you unless we expressly ask for your permission to do so.
Security: We respect the security of your data and treat it in accordance with the law.
International: We may transfer your personal information outside the UK and EU and, if we do, you can expect a similar degree of protection in respect of your personal information, with transfer mechanisms where those are needed under data protection laws. You can request details of mechanisms from us.
Your Rights: You have rights in respect of your data, for more information please see section 19 of this statement.
What is the purpose of this privacy statement?
- Under data protection legislation, Joules is required to explain to you why we collect information about you, how we intend to use that information and whether we will share your information with anyone else.
- This statement applies to our customers, users of our website, those who wish to receive marketing information from us and anyone who otherwise provides their data to us. Please read this statement carefully to understand our views and practices regarding your personal data and how we will treat it.
- This statement relates to information collected from you through your use of our website www.joules.com, through emails we send to you, our social media channels and any other website on which this policy is posted or expressly referenced (collectively the “Joules Sites”). It also relates to information which we collect from you in our stores, over the telephone, by you entering our competitions & promotions, by you signing up to receive SMS alerts or the Joules mobile wallet pass (“Mobile Services”), or if you contact us in writing.
- Please do not use the Joules Sites, or purchase any products over the telephone with our customer services team, or sign up to receive our Mobile Services or enter our competitions or promotions unless you agree with this policy.
- This statement does not form part of any contract to provide services. We may update this statement at any time and you should check it regularly. If we make any material changes we will take steps to bring it to your attention.
- It is important that you inform us of any changes to your personal information which we hold so that the information which we hold is accurate and current.
Who are we?
- We are The Harborough Hare Limited, a company registered in England and Wales under company number 14504304 and with our registered office at Desford Road, Enderby, Leicester, United Kingdom, LE19 4AT England.
- Joules is a "data controller". This means that we are responsible for deciding how we hold and use personal information about you. We are registered in the UK with the ICO under number ZB489860.
- Our Compliance team are responsible for overseeing what we do with your information and monitoring our compliance with data protection laws. If you wish to contact our compliance team you can do so by writing to email@example.com.
- For EEA Residents: Please contact our EU Representative at firstname.lastname@example.org. Alternatively, they can be reached by post (The DPO Centre, Alexandra House, 3 Ballsbridge Park, Dublin, D04C 7H2) or +353 1 631 9460. www.dpocentre.com.
Why are we collecting your information?
- The information that we collect is required in order for us to:
- fulfil your orders for products with us, deal with your returns (refunds and exchanges), and provide you with access to an account;
- provide you with offers and marketing information about products and services in which you may be interested;
- for our monitoring of the use of the Joules Sites by users;
- increase the relevance of the Joules Sites' content and our marketing activities based upon users' demographics and browsing and purchasing behaviour, and to improve our products and services;
- to administer our competitions and promotions;
- for the purpose of keeping our stores secure and to prevent fraud and money laundering;
- to conduct customer surveys, focus groups and user testing in relation to our products and services;
- to allow you to subscribe for regulatory alerts;
- to fulfil our legal obligations;
- to process and respond to any queries that you might have.
- The information that we collect is required in order for us to:
Types of personal information we collect
- We are collecting information about you in order to achieve the purposes set out above (see 'Why are we collecting your information?'). This may include:
Personal details and payment
- personal details and demographics (such as name, gender and date of birth);
- contact details (such as your address, phone number and email address);
- purchasing history and payment information (such as payment methods, billing address details and other information related to payment). Please note Joules does not retain or store credit card, debit card or other confidential payment information. Instead we store a unique security “token” assigned to your card details by your payment provider and the last 4 digits of your card;
Website use, interaction and communications
- details of any contact with our support or customer services teams such as a record of your correspondence with us or any calls that you make to us (such as location data, timing, weblogs, other communication data and resources that you access);
- information about your use of our information and communications systems;
- browser information and online identifiers (such as your browser types, browser version host operating system, browser language and your IP address);
- information about your visit to any Joules Site (such as full Uniform Resource Locators (URL) clickstream to, through and from our site, whether your visit was directly from a marketing email we have sent, products viewed or searched for, page response times, download errors, lengths of visits to certain pages, page interaction information (such as scrolling, clicks and mouse overs) and methods used to browse away from the page);
- information from third parties such as digital marketing networks and social media networks such as Facebook, Instagram, Pinterest and Google to help manage your account, improve your shopping experience and get relevant marketing message across to you;
- aggregated information (such aggregate traffic information collected from your visit to any Joules Site);
Competitions and survey information
- competition entries;
- your responses to our surveys, polls, focus groups, interviews, ethnography studies and user testing;
- details of any agreement or objection to receiving marketing information from us;
In store security
- images of you captured through the use of in store CCTV cameras.
- We are collecting information about you in order to achieve the purposes set out above (see 'Why are we collecting your information?'). This may include:
Privacy of children and special categories of personal data
- We do not knowingly collect personal data from anyone under the age of 18.
- We do not knowingly obtain or store any Special Categories of Personal Data, such as information about health or medical conditions, race or religious beliefs (except where this is indicated on CCTV footage of customers in our stores and this will be incidental processing i.e. it is not our intended purpose to capture that more sensitive type of data nor we do we use it for any purpose other than security and safety of our staff and customers).
- If we are made aware that we have received information from anyone under the age of 18 or Special Categories of Personal Data, we will use reasonable efforts to locate and remove that information from our records (except in the case of CCTV footage which will be retained for a short period or for as long as relevant to a police or other investigation e.g. if a crime happens in our stores).
Source of your personal information
- The information which we collect about you will be obtained through a variety of sources which include:
- if you register to use the Joules Sites;
- if you are placing an order online at a Joules Site, in store or over the telephone with our customer service team. We will never ask you to confirm or supply any account or credit card details via email or text message. If you receive such an email or text message, please do not respond and notify us immediately at: email@example.com;
- if you enter a competition or promotion sponsored by us;
- when you report a problem with our site and/or your order;
- when you contact our support or customer service teams;
- if you sign up to our Mobile Services;
- when you complete our surveys or join in with polls, focus groups, interviews, ethnography studies and user testing;
- information automatically collected about you and your visit to any of the Joules Sites;
- information automatically collected about you when you open a marketing email or engage with our content or adverts on social media and third party sites;
- recording of your telephone calls with our customer service team;
- CCTV footage when you visit one of our stores.
- we may collect information about you from third parties where we carry out identity verification credit or anti-fraud checks against your name using third party databases.
- we may collect information about you from third parties for marketing where you have provided your express consent to the third party for your information to be shared for such purpose;
- we may work with third party information providers such as Merkle, LiveRamp and Experian, who specialise in consumer profiling and provide demographic or other data to help better understand our customers lifestyles, shopping behaviour and preferences;
- online advertising and marketing companies to help us display the advertising content most relevant to you and to analyse the effectiveness of our campaigns;
- we may collect information about you from third parties who we have partnered with to run competitions.
Information provided by you
Information collected automatically about you
Information collected from third parties
What we do with your information
- We may use your personal data for the following purposes:
- We may use your personal data, and permit third parties (e.g. social media networks such as Facebook and search engines such as Google) on our behalf to use your personal data, to provide you with information that you have requested from us and to inform you of offers or other goods or services that may be of interest to you (but only where you have not objected to be contacted for such purposes or where you have consented to this).
- Sometimes we will contact you by electronic means (email as one example) or post with information about goods and services similar to those which were the subject of a previous sale to you. We will do this where you have made an order with us or you have otherwise confirmed that you agree to us sending you such information. Sometimes we will contact you about other goods and services (including those from friends of Joules) using appropriate lawful reasons for that. (See 'What is our lawful basis for using your information' below).
- We will only contact you by SMS if you have expressly agreed to receive mobile marketing alerts.
- Where we permit selected third parties to use your data, we (or they) will contact you by electronic means or post. Details of those third parties can be found at 'Sharing your information'.
- Please note that you have the right to ask us not to process your personal data for marketing purposes. We will usually inform you before collecting your data if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by:
- checking certain boxes on the forms we use to collect your data; or
- you can also request us not to use your personal data for this purpose when setting up your Joules account; or
- by logging into your Joules account and changing your marketing preferences; or
- by emailing us at firstname.lastname@example.org.
- for Mobile Services, by texting STOP to shortcode 80353
- We use your personal data to process and fulfil your orders effectively and to carry out any further obligations arising from any contracts entered into between you and us. This will include using your email address and/or mobile phone number so that we can send you information confirming your order.
- If you report a problem with your order, we may use your personal data to investigate that problem.
- When you use the Joules sites we may use your personal data to:
- register you to use the Joules Sites (if you choose to do so);
- administer the Joules Sites and for internal operations such as to help diagnose problems with our server, trouble shoot, analyse data and other administrative purposes;
- improve the Joules Sites and to ensure that content is presented in the most effective manner for you and your computer, tablet or mobile phone (this may include providing you with content and services in your country's local language and currency);
- allow you to participate in interactive features of our service when you choose to do so;
- keep the Joules Sites safe and secure;
- improve the services we offer, make recommendations about goods or services that may be of interest to you and to develop marketing programs (we may use personal data for these reasons as a result of you opening Joules’ emails too); and
- if you report a problem with the Joules Sites, use your personal data to investigate and resolve the reported problem.
- Profiling is defined in law as “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person…”.
- We use information collected from the Joules Sites, in-store, from third party consumer information providers such as Merkle, LiveRamp and Experian from your interaction with Joules’ marketing communications and from competition & promotion entries, in order to categorise users into specific profiles, or to aggregate data into larger datasets, which are then used to improve the relevance of your shopping experience and the marketing you receive from us. That information is then used to prioritise certain products and promotions on the Joules Sites in order to personalise the Joules’ Sites for you and to ensure that our marketing is tailored to your preferences.
- We will use your personal data in relation to your entry into competitions run by Joules or our competition partners and promotions sponsored by us or our partners.
- We will use your personal data to provide the Mobile Services where you have provided your details for these purposes.
- We may use your personal data in order to handle any issue which you raise with our support or customer service team.
- We, or our appointed third party research companies, may contact you to take part in customer surveys or polls. If you complete a survey for us, such as a customer satisfaction survey, we or the research company, will review and analyse your answers to the survey questions so we can better understand how we can improve our products and services.
- If you have consented to take part in customer focus groups, interviews, ethnography studies or user testing, we or our appointed third party research company, may make contact with you to arrange these activities and we, or our research company, will review and analyse your answers so we can better understand how we can improve our products and services.
- We may also use your personal data in order to train our members of staff or for monitoring purposes.
- If you sign up to regulatory new alerts on our corporate site, we will provide you with the requested information.
- We may also use your personal data to notify you about changes to our service.
- We may use your personal data to help to protect you from fraud. For instance, we may carry out identity verification, credit or anti-fraud checks against your name using third party databases which may involve disclosure of your personal details to registered credit reference or fraud prevention agencies who may retain and use your personal information.
- Where you enter one of our stores, your image may be recorded by our CCTV cameras. CCTV footage may be used in order to ensure the security and safety of our staff and customers and could potentially be used as evidence in an investigation or civil or criminal legal proceedings.
- If we are required to conduct a product recall in respect of a product you have purchased, then we will contact you to notify you about this.
- We will use your data to comply with any requirements imposed on us by law or as part of any legal proceedings, will share data with regulatory bodies if required to do so and will maintain records to comply with tax and regulatory requirements.
Placing an order
Operate the Joules Sites and Joules’ emails
Profiling - To personalise your shopping experience and improve your interactions with us
Administering competitions or promotions
Customer service, surveys and training
Prevention of fraud and security
To fulfil our legal obligations
What may happen if you do not provide your personal information?
Placing an order or a request for information
- Many of the services that we offer are only made available if we have certain information about you. To access these services, you will, from time to time, be asked to submit personal data about yourself. If you do not provide that personal data, we will not be able to offer those services to you. For example, if you do not provide information about your method of payment or delivery address, we will not be able to complete your order with us.
Complying with data protection law
- We will comply with data protection law. At the heart of data protection laws are the 'data protection principles' which say that the personal information we hold about you must be:
- used lawfully, fairly and in a transparent way;
- collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes;
- relevant to the purposes we have told you about and limited only to those purposes;
- accurate and kept up to date;
- kept only as long as necessary for the purposes we have told you about; and
- kept securely.
What is our lawful basis for using your information?
- In accordance with the data protection laws, we need a 'lawful basis' for collecting and using information about you. There are a variety of different legal bases for using personal data which are set out in the data protection laws.
- The lawful bases on which we rely in order to use the information which we collect about you for the purposes set out in this statement will be:
- Contract: Using your information will be necessary for us to either perform the contract between us or in order to take steps at your request prior to entering into the contract;
- Legal compliance: Using your information will be necessary for us to comply with a legal or regulatory obligation which is placed on Joules;
- Legitimate interest:Using your information will be necessary for our legitimate commercial interest and our interest is not outweighed by the potential impact on your privacy. For example, except when we ask you for an express opt-in consent, we rely on legitimate interest as our lawful basis to send you marketing information by email or by post if you have placed an order with us and you have not objected to receiving such marketing information. If you would prefer not to receive marketing information from us, please email us at email@example.com;. In addition, we rely on legitimate interests as our reason under data protection laws for processing your personal information for customer profiling, customer surveys or polls, prevention of fraud and security, each as described in section 8 “what we do with your information”;
- Consent: It is possible that you may give us your consent to use your information for a particular purpose. If you have expressly consented to receive communications from us e.g. you have signed up on our website or competition entry form to receive our newsletter, and if you agree to take part in customer focus groups, then we are operating under consent instead of legitimate interest when keeping in touch with you. You can withdraw your consent at any time (see below for information about your data protection law rights).
Sharing your information
- We may share some of your personal data with third parties as described below.
- We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
- We will share your personal information with other entities in our group as part of our regular reporting activities on company performance, in the context of a business reorganisation or group restructuring exercise, for system maintenance support and hosting of data and with Next Retail Limited to allow them to provide their “Total Platform” services of behalf of Joules.
Sharing your information with third parties
- We may also share your personal information with third parties, such as:
- our nominated third party carriers, warehousing and logistics providers to enable them to deliver your order and to contact you if there is a problem with delivery (i.e. telephone, email, name and address only);
- our nominated marketing agencies who provide marketing services on our behalf;
- social media sites such as Facebook and search engines such as Google to allow them to serve personalised product recommendations alongside specific messaging in advertising;
- our payment service providers and IT providers (see 12.5 below in respect of payment via Klarna);
- research and analytics companies;
- sellers of our “Friends of Joules” Marketplace products or some of our licence partners where the licensee operates a drop-ship delivery model. When you place an order for a Friends of Joules product or for a product fulfilled by one of our licensees on joules.com we will share your information with the relevant seller/licensee so that they can process and deliver your order and deal with any returns;
- service companies such as printers and mailing houses who assist us in providing our services;
- registered credit reference or fraud prevention agencies who may retain and use your personal information, the police and other regulatory bodies if we are requested to do so; or
- third party companies who are co-hosting a competition and you have consented to that transfer; or
- with our professional advisors (such as administrators and insolvency practitioners, auditors, law firms and accountants) and other third parties in connection with our legitimate business activities. These organisations may use your personal data as a “controller” – they will have their own privacy notices which you should read, and they have their own responsibilities to comply with applicable data protection laws; or
- With purchasers of our business or assets – they too will have their own privacy notices and obligations as “controllers” under applicable data protection laws.
Sharing your information within the Joules group
Security of your data
- We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.
- We will never ask you to confirm or supply any account or credit card details via email or text message. If you receive such an email or text message, please do not respond and notify us immediately at: firstname.lastname@example.org.
- All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology. When you proceed to make your purchase and your browser connects to the secure section of a Joules Site your browser window frame will show a padlock icon to indicate that you are entering a secure area.
- If you are using a computer or other device to access the Joules Sites in a public location we recommend that you always log out and close the website browser down when you complete an online session for your security.
- Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
- Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
- Third parties will only process your personal information on our instructions and where they have agreed to treat the information confidentially and to keep it secure.
- All our third-party service providers and other entities in the group are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow our third-party service providers to use your personal data for their own purposes. We only permit them to process your personal data for specified purposes and in accordance with our instructions.
Third parties security measures
TRANSFERRING INFORMATION OUTSIDE THE UK, EU AND EEA
- The data that we collect from you may be transferred to, and stored at, a destination outside the UK (or the EU, if you are a customer in the EU) and European Economic Area ("EEA"). It may also be processed by staff operating outside the UK, EU or EEA who work for us or for one of our suppliers. Such staff may be engaged in, amongst other things, the fulfilment of your order, the processing of your payment details and the provision of support services. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy statement.
- We will transfer the personal information we collect about you to the following countries outside the UK, EU and EEA in order to perform our contract with you:
There is an adequacy decision by the UK government for transfers from the UK to countries in the EU and EEA. There is an adequacy decision from the European Commission regarding transfers from the EU to the UK and to the EEA. This means that those countries are deemed to provide an adequate level of protection for your personal information.
For the remaining countries which do not have an adequacy decision from the UK or European Commission, we have put in place appropriate measures to ensure that your personal information is treated by those third parties in a way that is consistent with and which respects the EU and UK laws on data protection:
Standard data protection clauses in the form of template transfer clauses adopted by the European Commission or UK government (as relevant). For some transfers the UK government allows the historic European Commission transfer clauses to remain valid until 2024. For some other transfers the UK’s international data transfer agreement or international addendum to the 2021 European Commission transfer clauses are relevant. For transfers from the EU the 2021 European Commission transfer clauses are usually relevant. All these transfer mechanisms are to ensure that your personal information is treated by the third party recipients (such as our service providers) in a way that is consistent with and which respects applicable data protection laws.
- If you require further information about these protective measures, you can request it from our compliance team. Contact details are in this privacy statement.
Can we use your information for any other purpose?
- We typically will only use your personal information for the purposes for which we collect it. In limited circumstances we may use your information for a purpose other than those set out in this policy. If we intend to do so, we will provide you with information relating to that other purpose before using it for the new purpose.
- We may use your personal information without your knowledge or consent where such use is required or permitted by law.
Links to other websites
Cookies and similar technology
- We use technology such as cookies and pixels on the Joules Sites including in our emails to distinguish you from other users, to provide you with a good experience when you browse the Joules Sites, to allow us to improve the Joules Sites and to provide relevant marketing messages to you. For detailed information on the cookies and other technology we use and the purposes for which we use them see our Cookies Policy.
Storing your information and deleting it
- We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Details of retention periods for different aspects of your personal information are available in our retention policy which is available from our compliance team.
- To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
- In some circumstances we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.
- If you have any questions about our use of your personal data, you are welcome to contact us. You will find our contact details at the top of this page. If you notice any errors in your personal data, you have the right to have them corrected.
- Under certain circumstances, by law you have the right to:
- Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
- Object to processing of your personal information (including automated decision making and profiling) where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal information to another party.
- If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact email@example.com in writing.
You are not always entitled to exercise each of these rights (except for the right of access). The rights which you are entitled to exercise depend on a number of factors including the lawful basis on which we rely to use your personal data. Therefore, if you make a request to exercise a right which is not available to you, we have the right to decline the request. You can request access to your personal data at any time and this does not depend on the lawful basis of our processing – we will explain to you if exemptions apply or if the right of access is not engaged. In some circumstances, you may be able to exercise your rights, but this will impair your ability to use the services we offer.
Right to withdraw consent
- In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact firstname.lastname@example.org, or, in respect of Mobile Services, please text STOP to 80353. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
Right to complain to the ico
- You also have the right to complain to the Information Commissioner's Office (the "ICO") if you are not satisfied with the way we use your information. You can contact the ICO by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
- If you are a customer located in the EU you can if you wish complain to your local data protection supervisory authority. Our EU representative can also be contacted (contact details as above).
Changes to this privacy statement