- What personal data must you provide to us as part of a statutory/regulatory or contractual requirement?
In certain circumstances you may be obliged to provide us with personal data and if you fail to provide the personal data, when requested, we may not be able to fulfil your purchase order or assist with your enquiry. Where this is the case we have identified these instances in the table above with an “*.”
- Credit card and debit card information
All payment details are sent to and managed securely by our third party payment service provider. Jigsaw will only retain the card type and last four digits as a reference of the purchase.
- What special category or criminal data does Jigsaw process about you?
We do not collect or process any special category or criminal data relating to our customers.
- CCTV in our stores
It is not standard practice for our retail stores to use CCTV. Currently CCTV is only installed in Jigsaw Bellevue Road and Jigsaw Dulwich.
Jigsaw does not access CCTV recordings unless required for security purposes. This data is erased after two weeks unless it needs to be referred to due to a suspected incident or for some other legal reason.
- Promotional communications and direct marketing
When we are permitted to do so we may use your personal data to send you updates (by email , or post) about our products and services, including exclusive offers, promotions new products and products you may have shown an interest in buying.
- What are cookies and how are these used?
You can see an up to date list of the cookies that we use on our website in the Cookie Declaration and manage your preferences. You can also click on this link to view a current up to date list and manage your preferences.
- Who we share your personal information with?
We will share your personal data with other companies in order for them to fulfil services for us.
We share your personal data with the below companies:
- our delivery providers;
- our online payment providers;
- our customer issue tracking tool provider, this includes our call recordings;
- our customer reviews provider
- our customer database system providers;
- our digital marketing tool providers, such as email service provider;
- our website platform provider;
- our website app providers, for services such as wish list and reserve in store;
- our order fulfilment providers, such as ship-from-store providers;
- marketing service providers, for example those used to help us generate online advertisements or send catalogues.
We only allow our service providers to handle your personal data on our behalf if we are satisfied they will take appropriate measures to protect your personal data. We also impose contractual obligations on service providers to ensure they only use your personal information to provide the requested service. They are not able to use your personal data for their own purposes unless you have a separate agreement with them directly to provide a service in their own right. These might include payment service providers with whom you have signed up for an account, such as Amazon Pay, PayPal, Klarna or others.
In certain circumstances we may disclose and exchange information with law enforcement agencies to comply with our legal and regulatory obligations.
We may also need to share some personal information with other parties, such as potential buyers of some or all of our business or during a re-structuring. Usually, information will be anonymised but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.
10. Sharing your personal data Epsilon Abacus (registered as Epsilon International UK Ltd)
Please note, that we only share personal data that is strictly necessary to support postal communications. Your email address and phone number will not be shared with the members of the Abacus Alliance and you will not receive any electronic marketing as a result. If you do not wish to be contacted by post by other companies, you can let us know by
a) opting out using the option on the payment page; or
b) emailing DataProtection@InsideJigsaw.com
11. Sharing your data with Meta Platforms
We place adverts on Meta platforms (Facebook and Instagram) (Meta). To make sure our adverts are seen by people who are most likely to be interested in them, we share your ‘hashed’ email address with Meta. Emails are hashed so that they are secure. Meta uses hashed email addresses to match our customers with Meta accounts so that we can serve our adverts to you via Facebook and Instagram.
Meta also uses hashed email addresses to analyse our customers so that we can target adverts to individuals who share similar interests or characteristics.
If you do not want your information to be used in this way you can opt out at any time by emailing DataProtection@InsideJigsaw.com.
Jigsaw also shares personal data with Meta to help us measure how successful the adverts that we place on Meta platforms are. To do this we share information such as name and email address of customers who have been active on our website. Meta uses this information to identify if any of those customers have interacted with an advert on one of the Meta platforms. This enables us to understand how successful our Meta adverts are.
Meta does not share any identifiable personal data with us.
How long will your personal data be kept?
We will only keep your personal data for as long as is necessary for the purposes for which it was collected. In order to determine the appropriate retention period for your personal data, we consider the amount, nature, and sensitivity of your personal data. We will also consider legal and regulatory requirements, for example where the law says we must keep your personal data for a certain period.
12. Transferring your personal data out of the UK
To deliver services to you, it is sometimes necessary for us to share your personal information outside the UK.
Whenever we transfer your personal data outside of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK;
- Where we use third parties outside of the UK, we may use specific contracts approved under UK law, these are sometimes known as standard contractual clauses which give personal data the same protection it has in the UK.
If you would like more information about the methods used to transfer your personal data outside of the UK, please contact us at DataProtection@InsideJigsaw.com.
13. Keeping your personal data secure
We have appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed unlawfully. We limit access to your personal information to those who have a genuine business need to access it. Those processing your personal data will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
14. Your rights relating to your personal data
You have a number of rights in relation to how we use your personal data. These are as follows:
- your right to request access to your personal data – you have the right to know how we are using your personal data, a right to see a copy of the personal data we hold for you and a right to be provided with additional information, for example, about how and why we are using your personal data and who it is being shared with.
- You have the right to request that any inaccurate personal data is amended – if you think that any of the personal data that we hold about you is wrong or incomplete then you have the right to tell us and we have to ensure that the personal data we have is reviewed and if necessary, amended to ensure it is correct.
You have the right to ask for your personal data to be deleted – in certain circumstances, you can ask us to delete your personal data where there is no good reason for us to hold or use this anymore, where:
- we are using your personal data because you provided us with your consent to use it in this way and you withdraw your consent; or
- where you have challenged our use of your personal data and there are no good reasons for us to process your personal data.
- This does not apply to all of your personal data, as we may need to still keep your personal data, for example, to comply with laws.
You have the right to request restriction of processing your personal data – this right allows you to ask us to put processing on hold so:
- we can establish if the personal data that we have about you is correct;
- we can investigate any objection you have made about the use of your personal data; or
- if we have no justification for keeping it any longer you may ask us to put the processing on hold but retain the personal data in case you need this, for example, for legal reasons.
- You have the right to have your personal data sent to another organisation – in certain circumstances, you have the right to get your personal data from us in a way that is accessible and machine-readable, and you also have the right to ask us to transfer your personal data to another organisation. This only applies to personal data that you have provided to us and which is held electronically. We only have to comply with this right if it is technically feasible to provide this personal data in a commonly used format, for example, a csv file.
- You have the right to object to the processing of your personal data – you have the right to tell us about any concerns regarding the processing of your personal data and to ask us to stop using your personal data. This includes objection to marketing.
If you would like to exercise any of those rights please contact us by email to DataProtection@InsideJigsaw.com