This Privacy Notice explains in detail the types of personal data we may collect about you and your company when you interact with us. It also explains how we’ll store and handle that data and keep it safe.
This Privacy notice contains much detail, but we want to ensure that you and your company are fully informed about your rights and how BBL Batteries uses your data, for example we will explain account application credit checking and how we combine data from across BBL Batteries to build a picture of you or your company.
We hope all the information here will answer all your questions but if not, please do not hesitate to contact us.
It’s likely that we’ll need to update this Privacy Notice from time to time, you’re welcome to come back and check it whenever you wish.
When you are using BBL Batteries websites, Bristol Batteries Limited is the data controller.
2. What is BBL Batteries?
BBL Batteries is the trading name for Bristol Batteries Limited. It consists of six branches in six locations in the southwest of England; Bristol, Evesham, Exeter, Plymouth, Swindon and Truro. The companies Head Office is based in Bristol.
BBL Batteries is a specialist distributor of Batteries and associated products.
Our companies house number: 01066031
Our VAT Number: GB 138 6316 60
Our Information Commissioner’s registration reference: ZA308124
For simplicity throughout this notice, ‘we’ and ‘us’ refers to BBL Batteries.
The law on data protection has changed, it now sets out a number of different reasons for which a company may collect and process your personal data, including:
Consent – in specific situations we collect and process your data with your consent. For example, when you have ticked a box to receive marketing information.
Contractual Obligations – in certain circumstances, we need your information to comply with our contractual obligations to you. For example, if you order items for delivery, we will collect your address to deliver your purchase and potentially pass them onto a courier.
Legal Compliance – If the law requires us to, we may need to collect and process your data. For example, we can pass on details of people involved in criminal activity affecting us to law enforcement.
Legitimate interest – In specific situations, we require your data to pursue our legitimate interests in a way which might reasonably be expected as part of running a business which does not materially impact on your rights, freedom or interests. For example, we will use your purchase history to send you, or make available, offers. We also combine your purchase history of all of our customers to identify trends and ensure we keep up with demand or develop new products or services.
4. When do we collect your personal data?
- When you visit any of our websites and make a purchase or enquiry about any product.
- When you visit any of our websites but do not make a purchase we monitor your activity while on our website so we can improve the customer experience (this information is purely monitor based but not held specifically to the customer – for example, how much time did it take for the viewer to find what they were looking for on our website).
- When you apply for a Credit or * account.
- When you engage with us on social media.
- When you sign up to receive our newsletters or marketing information.
- When you request a quote on a product over the phone or within a branch.
- When you visit any of our branches (both in car parks & Stores/Warehouses) through the use of CCTV systems operated for the security of customers and staff.
- When you contact us to make an enquiry or a complaint.
- When you choose to complete a survey we may send to you.
- When you complete forms when on site, for example, if an accident happens while on one of our premises, a staff member may collect your personal data.
- When you purchase certain products from us we may ask you to prove your age, identity and license (where applicable). For example, an EPP (Explosive Precursor and Poisons) license is required when purchasing sulphuric acid over the specified percentage.
- When you apply for employment or work for BBL Batteries.
- When you agree to be a supplier, either on a regular of ad-hoc basis.
5. What sort of personal data do we collect?
- As a cash customer buying over the phone or at one of our branches: your name, address, the product you buy and their associated documents (invoices).
- If you have an account with us: Company name, invoicing address, delivery address, email address, contact telephone number and, if applicable, a specific contact person for accounts or purchasing enquires as well as a record or your purchase, supply and payment history.
- Details of your interactions with us. For example, emails sent to any person within our company, we collect notes from conversations or interactions that may be held between us detailing any specific comments made by you or your company or details of specific product requirements.
- Details of how you found us, whether you visited our website and which branch you visited.
- We’ll only ask you for, and use, your personal data collected for recommending items of interest and to tailor your experience with us. We will only ever use your personal information for the purposes of marketing if you have given us expressed permission.
- It is your choice to share – payment card details, your comments and reviews, your image on our CCTV when you visit a branch or car park, your car number plate may be recorded in our branch car park and your social media username if you interact with us through social media channels.
6. How and why do we use your personal data?
- We use the information you give us to ensure we can provide you with the best service. For example, we can review what products you previously bought from us, if you are an account customer, so assist you with re-purchasing or finding a more suitable product. This data enables us to be able to help you resolve any purchase or payment queries. This data enables us to be able to contact you if there has been any form of product notification that might mean the item needs to be recalled or replaced. This data enables us to be have a quoted product ready and waiting for you when you come into branch to collect it.
- Your data will be combined with all our customer data to give us information of how our company is being used, what current and future trends are and how we can meet the needs of our customers. We will compare current data with data from previous years.
- Without collecting your data – we would be unable to honour our commitment to process your order and comply with our legal obligations of a sale.
- Without your data – we would be unable to respond to your queries, refund requests and complaints. Storing your data enables us to respond to your requests. We may also keep a record of these and any future communication with us and to demonstrate how we communicated with you throughout. We do this on the basis of our contractual obligations to you, our legal obligations and our legitimate interests in providing you with the best service and understand how we can improve our service based on your experience.
- To protect our customers, premises, assets and staff from crime, we operate CCTV systems in our branches, offices and car parks which record images for security. We do this on the basis of legitimate business interests.
- To process payments and to prevent fraudulent transactions. We do this on the basis of our legitimate business interests. This also helps protect customers against fraud.
- If we discover any criminal activity or alleged criminal activity through our use of CCTV, fraud monitoring and suspicious activity monitoring, we process this data for the purpose of preventing or detecting unlawful acts. We aim to protect individuals we interact with from criminal activities.
- With your consent, we will use your personal data, preferences and details of your transactions to keep you informed by email or post about relevant products and services including special offers, discounts, promotions, events and competitions. Of course, you are free to opt out of hearing from us by your chosen method at any time.
- If we do not have your permission, either by you ticking a box on an email or letter or by signing up to our marketing lists on the touch screens in the branch shops, we will never use your data for the purpose of marketing.
- To develop, test and improve the systems, services and products we provide. We’ll do this on the basis of legitimate business interests.
- To comply with our contractual or legal obligations to share data with law enforcement.
- To send you survey and feedback requests to help us improve our services and or product ranges. These communications will not include any promotional content and do not require prior consent when sent by email or post.
- To send you communications required by law, or which are necessary, to inform you about our changes to the services we provide you. For example, updates to this Privacy notice, product recall notices and legally required information relating to youor your order. These services will not include any promotional content and do not require prior consent when sent. If we do not use your personal data for these purposes, we would be unable to comply with our legal obligations.
7. How we protect your personal data
We, at BBL Batteries, understand how much security of data matters to our customers, suppliers and staff. With this in mind we will treat your data with the utmost care and take appropriate steps to protect it.
Access to customer/supplier information is held on password protected Accounts system to which access is limited to authorised users as defined by their specific roles. These systems are backed up both at our Head Office site as well as using cloud technology. The ‘cloud’ servers are based in Germany at a secure, GDPR compliant site.
We do not store any bank or card details on our accounts systems. These are processed by Worldpay and Natwest, both of whom are fully GDPR compliant, taking data security to the highest levels. All bank details provided in writing are filed in secured rooms within secured filing systems.
BBL Batteries is Cyber Essential Plus certified which is assessed annually. Part of this certification requires us to regularly monitor our systems for possible vulnerabilities ad attacks, and we carry out penetration testing to identify ways to further strengthen security.
Any job application forms or staff related forms completed are all kept in paper format and filed in a secure filing system within a locked office. Access to these rooms/files are strictly limited to only those immediately involved with each individual scenario.
BBL Batteries is ISO 9001:2015 Quality Management System accredited. The processes in place for this accreditation supports our data protection efforts.
8. How long will we keep your personal data?
Whenever we collect or process your personal data, we’ll only keep it for as long as is necessary for the purpose for which it was collected.
At the end of that retention period, your data will either be deleted completely or anonymised for example, by combining it with other data so that it can be used in a non-identifiable way for statistical analysis and business planning.
Some examples of retention periods are:
9. Who do we share your personal data with?
- Invoices, delivery notes and purchase orders are kept for a period of 7 years in either paper or digital format for the purposes of HMRC auditing and review. After this time, they are archived within our digital records and paper record are destroyed.
We share your data with trusted, GDPR compliant companies who help us provide the level of service we strive for at BBL Batteries.
These third party companies include couriers, IT support companies (both general and system specific), human resource consultants, accountants, solicitors, financial institutions and government agencies.
Here is the policy we apply to those organisations to keep your data safe and protect your privacy:
We may, from time to time, expand, reduce or sell the company and this may involve the transfer of branches or the whole business to new owners. If this happens, your personal data will, where relevant, be transferred to the new owner or controlling party, under the terms of this Privacy Notice.
- We provide only the information they need to perform their specific services. For example, we would only provide your delivery address to a courier company.
- They may only use your data for the exact purposes we specify in our contract with them.
- We work closely with them to ensure that your privacy is respected and protected.
- If we stop using their services, any data provided by our company to them will be rendered anonymous or deleted.
BBL Batteries has never and will never share your data with any third party companies not involved in your individual case. BBL Batteries has never and will never sell your data for the purposes of extended marketing and profits. When we ask for your consent, this is purely for the purposes of BBL Batteries marketing of its products and services.
To support BBL Batteries services online through our websites and social media, we currently use companies who will process your personal data as part of their contracts with us. Details of these specific companies are available on request. We apply the same principles of engagement with these companies as set out above.
Our social media facilitators store data on customers and those who interact with us online but only if you choose to interact with us online. These companies are:
10. Where your personal data may be processed
Sometimes we use suppliers outside the European Economic Area (EEA), such as Asia or the USA. Please be reassured that BBL Batteries data only (our companies accounts, addresses and specified personnel) is shared with these companies and no access is granted to customer information. In the case of a specific, more bespoke order we will manage the order directly, protecting our customers details.
With regard to our support companies, we do use third party organisations outside the EEA. For example, we use Microsoft Office 365 subscriptions and phone system software which are supported from the USA with servers and first line support based in the EEA. We have contracts with these companies that stipulate they will comply to the standards set out by GDPR.
The EEA includes all EU Member countries as well as Iceland, Liechtenstein and Norway. We may transfer personal data that we collect from you to third-party data processors in countries that are inside the EEA.
If we have to transfer data outside the EEA, we have procedures in place to ensure your data receives the same protection as if it were being processed inside the EEA. For example, our contracts with third parties stipulate the standards they must follow at all times.
Any transfer of your personal data will follow applicable laws and we will treat the information under the guiding principles of this Privacy Notice.
11. What are your rights over your personal data?
An overview of your different rights
You have the right to request:
• Access to the personal data we hold about you, free of charge in most cases.
• The correction of your personal data when incorrect, out of date or incomplete.
• For example, when you withdraw consent, or object and we have no legitimate overriding interest, or once the purpose for which we hold the data has come to an end (such as the end of a warranty).
• That we stop using your personal data for direct marketing (either through specific channels, or all channels).
• That we stop any consent-based processing of your personal data after you withdraw that consent.
If we choose not to action your request we will explain to you the reasons for our refusal.
Your right to withdraw consent
Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent.
Where we rely on our legitimate interest
In cases where we are processing your personal data on the basis of our legitimate interest, you can ask us to stop for reasons connected to your individual situation. We must then do so unless we believe we have a legitimate overriding reason to continue processing your personal data.
You have the right to stop the use of your personal data for direct marketing activity through all channels, or selected channels. We must always comply with your request.
Checking your identity
To protect the confidentiality of your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Notice. If you have authorised a third party to submit a request on your behalf, we will ask them to prove they have your permission to act.
12. How can you stop the use of your personal data for direct marketing?
There are several ways you can stop direct marketing communications from us:
Please note that you may continue to receive communications for a short period after changing your preferences while our systems are fully updated.
• Click the ‘unsubscribe’ link in any email communication that we send you. We will then stop any further emails from that particular division.
• Write to Data Protection Lead, BBL Batteries, 3 ST Philips Trade Centre, Albert Road, St Phillips, Bristol, BS2 0YB.
13. BBL Batteries Accounts
BBL Batteries has two types of accounts that we offer regular customers.
*Accounts: Allows the customer/company to order products for local delivery by BBL Batteries staff. Payment of these goods must be made on or before delivery.
Credit Accounts: Allows customers/companies to apply for a specific credit allowance, with specified terms of payment based on the size and credit history of the company applying..Credit account customers will be offered local delivery from BBL Batteries staff, from the accounts key branch.
13.1 How we use your personal data
On applying for an account with BBL Batteries, you will be asked to provide informationabout your company. If you are applying for a Credit account you will be asked for considerably more information than if opening a * Account. This information is then reviewed by our accounts team.
For * Accounts – this information is added to our accounts management system and stored for the purposes of honouring our legal obligations to you. To prepare and deliver the products you have ordered at the price and time framed agreed
If you agree to receive marketing communications from us, we will use your data to personalise what we send you. You are free to opt out of receiving marketing communications from us at any time.
If you agree to receive marketing communications from us, we will use your data to personalise what we send you. You are free to opt out of receiving marketing communications from us at any time.
Find out more about the use of your data for marketing in section 7.
This information is reviewed before approving an application. On approval, your information is entered into our accounts management system and maintained to ensure your information is accurate and fulfils our legal and regulatory obligations The paper applications formscompleted are then filed in locked offices. These applications are kept for the duration thatthe account is held with BBL Batteries as the form acts as a legal agreement to our terms and conditions.
Our protocols for application are applied to every company applying but these are reviewed on a case by case basis to ensure every opportunity has been given to each individual company’s circumstances.
If your application is not successful, we will hold the application form and any related documentation as evidence of the processing of that information that lead to a final decision. We reserve the right to potentially retain this information for up to 10 years to facilitate future application assessments after we have informed you of the result of application, after which point it will be shredded.
14. Contacting the Regulator
If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office.
If you are based outside the UK, you have the right to lodge your complaint with the relevant data protection regulator in your country of residence.
15. If you are based outside the UK
For all non-UK customers
By using our services or providing your personal data to us, you expressly consent to the processing of your personal data by us or on our behalf. Of course, you still have the right to ask us not to process your data in certain ways, and if you do so, we will respect your wishes.
Sometimes we’ll need to transfer your personal data between countries to enable us to supply the goods or services you’ve requested. In the ordinary course of business, we may transfer your personal data from your country of residence to ourselves and to third parties located in the EEA.
By dealing with us, you are giving your consent to this overseas use, transfer and disclosure of your personal data outside your country of residence for our ordinary business purposes.
This may occur because our information technology storage facilities and servers are located outside your country of residence, and could include storage of your personal data on servers in the EEA.
We’ll ensure that reasonable steps are taken to prevent third parties outside your country of residence using your personal data in any way that’s not set out in this Privacy Notice. We’ll also make sure we adequately protect the confidentiality and privacy of your personal data.
16. Any questions?
We hope this Privacy Notice has been helpful in setting out the way we handle your personal data and your rights to control it.
If you have any questions that haven’t been covered, please contact our Data Protection Leadwho will be pleased to help you:
This notice was last updated on 24/05/2018
• Or write to us at Data Protection Lead, BBL Batteries, 3 ST Philips Trade Centre, Albert Road, St Phillips, Bristol, BS2 0YB.