Who we are

Our website address is: https://sittingbourneballoons.co.uk.

What personal data we collect and why we collect it

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Contact forms

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.

Analytics

Who we share your data with

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where we send your data

Visitor comments may be checked through an automated spam detection service.

Your contact information

Additional information

How we protect your data

What data breach procedures we have in place

What third parties we receive data from

What automated decision making and/or profiling we do with user data

Industry regulatory disclosure requirements

Sittingbourne Balloons Privacy Policy

Here at the Sittingbourne Balloons we know how important it is to keep your personal data safe. We are committed to making sure that you receive the service you’d expect and that your privacy is protected.

Here, we explain the ins and outs of the data we collect from you and how we use it. It might not be something you’re interested in, but it is important you have a read and, of course, let us know if you have any questions.

Who are we?

Sittingbourne Balloons (‘we’ and ‘us’) is the wholesale trading name SuzanneAUstin, Julian Austin, Jane Large and Jonathan Austin trading as Sittingbourne Balloons

Explaining the legal bases we rely on

The law on data protection sets out a number of different reasons for which a company may collect and process your personal data, including:

Consent

Sometimes we collect and process your data with your consent. An example is when you sign up to receive our emails from the home page of our website.

Contractual obligations

If you buy from us, in legal terms, there is a contract. We would then need your personal data in order to comply with our contractual obligations, for example, we would need your address in order to deliver your order and these details would be passed on to our couriers.

Legal compliance

If the law requires us to, we may need to collect and process your data for example in the case of fraudulent activity on your credit card (if it was stolen) we may be required by law to pass your information on to the authorities if requested.

Legitimate interest

We may require your data to pursue our legitimate interests in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interests. An example might be when we combine data to identify trends, purchase history of a product or send you marketing emails if you have applied for an account or placed any orders with us.

When do we collect your data?

In most cases you will know when we are collecting data as you will be freely giving it to us, for example, when placing an order online or signing up for an account.

We collect your data:

  • When you apply for a account
  • When you contact us by live chat
  • When you call us
  • When you complete one of our enquiry forms on our website
  • When you make an online purchase
  • When you make a purchase in person
  • When you email us directly
  • When you place a telephone order
  • When you follow / like / subscribe to one of our social media platforms
  • When you interact with us on one of our social media platforms
  • When you complete any of our surveys
  • When you review us or our products online on our website or on other platforms
  • Any individual may access personal data related to them, including opinions. So, if your comment or review includes information about the Partner who provided that service, it may be passed on to them.
  • When our partners, such as BOC, share information with us about any transaction you may have made through us or something that may affect a transaction we are involved in.
  • We may collect data from publicly-available sources (192, Facebook etc) when researching your eligibility for a trade account or if we are suspicious of a particular transaction.
  • When you visit Sittingbourne Balloons in person we have CCTV outside and inside. This is for security purposes. There are multiple signs posted bringing this to your attention. Footage is usually kept for 7-10 weeks depending on the amount of activity recorded after which time it is automatically deleted. These systems may record your image, the images of those you are with and details of your vehicle during your visit.

 

What do we collect and why?

When you apply for an account or buy a product or service through us either by phone or online, we’ll collect some of your personal details, to make sure we have everything we need to ensure you receive your products as efficiently and safely as possible. We’ll only use this data for processing and delivery of your orders, and for keeping in touch. We don’t ask for anything we don’t need (Marital status, employment status, etc). You are allowing us to use this data for this and for the purposes listed below.

Most of the information listed below is usually collected whenever you apply for a trade account with Sittingbourne Balloons. Some is collected during other communication with us. Much of the information is collected for contractual obligations. Some is on the basis of the legitimate interests of our business. Some is used for both.

What we collect Why do we collect it? How do we use it?
First and last name So that your order goes to the right person. So that we can address you nicely in any communication.
Address(es) So that your order can be delivered to where you want it delivered to.
Telephone number (Landline and or mobile) So that we, or the delivery partners we work with, are able to get in touch with you regarding your order. We also may need to call you regarding something on your account or to take payment or follow up on an enquiry. Mobile numbers are also used for the delivery tracking by our delivery partners if you choose to receive notifications by text. We may also call you to let you know of new products or to sort out any operation problems (eg: courier delay).
Email address Your email is used as your login to the site. We use your email so that we can contact you. This may be to confirm your account has been approved, to send you confirmation of your order or send you delivery status updates though our delivery partners. We also use your emails for the “Email me when available” facility on our website if items are out of stock and to send you communications required by law or which are necessary to inform you about our changes to the services we provide you. For example, updates to this Privacy Notice, product recall notices, and required information relating to your orders. These service messages will not include any promotional content. We also use your email to keep in touch and inform you of new products, offers etc. This is done on the basis of legitimate business interests. If you have requested to receive our emails on our home page your email address will be used for this also. You can unsubscribe from our marketing emails at any time – you just need to click on the unsubscribe link in the email. You may still receive emails for other things such as product recalls. We will also still send you order confirmation emails. It may be used to show you products through third party platforms such as Facebook and Instagram – this will only be possible if you have agreed on the specific platform to receive marketing from advertisers. If you have not agreed, you should not see anything from us. You can stop who you see ads from in the settings on whatever platform you are using.
Payment card details These may be taken to take payment for your orders. If ordering online it is done through our secure payment provider, Stripe by you if using a debit or credit card and not using Paypal.  We are unable to see the full card details at any time. We do have the facility to charge your card on the Worldpay or Stripe portal manually if you give us permission to do so, usually over the phone. If payment is taken over the phone, your card details are entered into our Stripe or Worldpay payment portal without being written down. Your details are also used to issue refunds.
Trading name Sittingbourne Balloons is a Public & Trade website and Trade Counter
VAT Number This is only required if you are a European customer outside of the UK. If you are in the UK, you do not need to provide this information. The reason we ask for it is because you do not need to pay VAT as a European customer due to the cross-border VAT rules. Once we have checked this on the VAT database, VAT will automatically not be included on your order.
Password This is so that only you can access your account from the login screen. We do not know your password and if you forget your password you will need to click on the link saying you forgot your password (happens to us all!). We are able to log in to your basket through our website back-end and help you with your basket or take your order through the checkout stage however we do not have access to your password at any point. We do have the facility to change your password for you but always suggest you change it again as soon as you have logged in.  We do not have the facility to enter your payment as ‘you’. We take your card details separately and process the payment manually and securely as outlined above.
Where you heard about us This information helps us to know where people find out about us and what marketing efforts are working, and which ones aren’t.
Notes on any interactions If you call or email and we have an interaction with you, some or all of the details of the conversation may be saved to help deliver the service to you.
Documentation you may send us to prove you are in the trade We may need this to prove you are in the trade. Some examples might be a certificate of balloon training or a certificate of incorporation. Possibly personal documents to prove where you live. We only use the data required on these documents to help demonstrate the case.
Order details and order history Details of your order and your order history is automatically stored on our database for you to access at any time. This allows you to use the re-order facility. It also allows us access combined data on customer order total value, number of orders placed etc.
Cookies Information gathered by the use of cookies in your web browser. These are an important part of an online business and help us offer a better service.
Reviews of products or Sittingbourne Balloons If you leave a review on our site for a product you have purchased or about your experience with Sittingbourne Balloons on social media platforms, it is visible to the public and is carried out with your consent as you are the only one that would be able to do this. We do not review ourselves.
Technical information To deliver the best possible web experience, we collect technical information about your internet connection, browser, hardware, country, ip address, session ID, the web pages viewed during your visit, and any search terms you entered. This helps us track, develop, test and improve the systems, services and products we provide to you. We do this on the basis of our legitimate business interests.
CCTV We use CCTV to protect our premises, team, customers, and assets from crime. We operate CCTV systems inside and outside our premises.  We do this on the basis of our legitimate business interests. This data in only accessible by the most senior people in the company and is not used for ‘observation’ of team members or customers on a day to day basis unless any suspicion is raised. Footage is kept for 7-10 weeks after which time it is automatically deleted. This time period varies dependent on the amount of activity that is recorded on the camera as activity is only recorded when there is movement. If we discover any criminal activity or alleged criminal activity through our use of CCTV, fraud monitoring and suspicious transaction monitoring, we will process this data for the purposes of preventing or detecting unlawful acts and share it with the relevant parties involved. We aim is to protect the individuals we interact with from criminal activities.

 

Using information provided by third parties

We use very limited data from any third parties and it is information that is already in the public domain (For instance, a 192 listing or a Facebook profile used to confirm you are a genuine trade customer). We don’t buy any email lists or business listings. We only collect data from our customers, people applying for a trade account and people that are enquiring about our services.

Keeping and storing your data

If you’re a current or past customer or someone that has been approved for an account but never purchased, we’ll keep a copy of your personal details for no longer than 7 years, from the time your active relationship with us ends. By ends, we mean you have told us explicitly you no longer wish to buy from us or no longer want to log in access to our website (and therefore, prices). As a wholesaler we recognise you may use us occasionally, sometimes purchasing from us years apart. We therefore need you to tell us if you want your account closed. If we do not receive this, we will keep data up to a maximum of 10 years to be able to build a statistical picture of customer buying patterns and gain a better understanding of what lines we should continue to offer and what areas we should grow our range.  Holding on to data allows us to keep accurate records for tax purposes and to handle any future complaints. All other personal data used for enquiring and quotation requests is kept for a maximum of 3 years should it not result in a relationship (purchase). Enquiry data that is written down is destroyed in a timely manner.

Some of the data that we collect may be transferred to and stored at a destination outside the European Economic Area (‘EEA’), for example some of our IT systems are run on servers hosted in the USA and Australia. We take all steps reasonably necessary to ensure that your data is treated in accordance with this privacy notice and applicable privacy laws

Sharing your data with third parties:

Occasionally we may need to share your data for fraud management. This would be information about fraudulent or potentially fraudulent activity on our website. This may include sharing data about individuals with law enforcement or government bodies in the UK or worldwide should a valid request be received. This would be assessed on a case by case basis and your privacy would always be taken into consideration first.

We may pass your details onto a limited number of third parties we use for the processing of your order, communication with you and to provide information to us that allows us to improve the customer experience. The reasons we pass your information to the third parties is outlined in the table below.

We respect your privacy and that’s why we don’t give your data to any third parties for their own marketing purposes.

To ensure your privacy and the security of your data:

  • We only provide information needed to carry out their specific services.
  • They may only use your data for the exact purposes we specify in our contract with them.
  • We work closely with them to ensure that your privacy is respected and protected at all times.
  • If we stop using their services, any of your data held by them will either be deleted or rendered anonymous.

We currently use the following types of companies/organisations who will process your personal data as part of their contracts with us.

Who Why
Shipping / Delivery partners Our delivery partners need to have your information to make sure they know where to go to deliver your parcel. They also use your email / mobile number to communicate the status of your delivery (Delivery timeslot, delivered time etc). Our partners sometimes use contracted delivery companies to fulfil their delivery commitments. If you are based outside the UK and place an order with us, your data will be shared with delivery companies employed by our delivery partners in your country or countries that your order is transported through.
Postcode lookup companies To automatically find your address when your postcode is entered. This uses Royal Mail Databases.
Social media platforms We use social platforms to communicate with customers and the wider world. By following us or interacting with us on a particular platform you are giving that platform the knowledge that you have done so. You will already have a contract with the platform if you have an account with them. We use the power of social platforms to help communicate with you. This may be done by using your email address or facts you have posted on your accounts’ profile that allow targeting. This means, you may see ads from us. You can change your settings in each platform you use regarding seeing ads from any advertiser.
Gas companies The gas companies we work with for helium supply will need your details in order to be able to deliver your helium / compressed air / nitrogen cylinders. They also need details if you collect from their depots to ensure you are the right person.
Communication software (email, live chat etc) We use various software companies in order to be able to communicate with you. This software sometimes includes other business functions such as documentation creation software. Most of the software we use is stored securely in a cloud-based environment. We send out bulk communication and marketing emails. This is mainly for emails about holiday opening times, issues with our front-line services, offers etc. You can unsubscribe from these emails at any time just by clicking the link in the received email. This is an automatic process once you click unsubscribe.
Security company Our security and CCTV company maintain our on-site security systems. They have access to our CCTV feed but only access this if instructed by us.
Web intelligence software We use various technology that allows us to observe website visitors on the page as well as collect data on that usage. It allows us to build a more user-focussed web experience. Data is anonymous so we do not know which session relates to which user.
Payment platform

 

We use a secure online payment platform to process your payments securely on the website. This also allows us to securely re-charge your card without seeing your card details. This is essential to make payment online. It is also used to help us investigate suspected fraudulent transactions.
Paypal This is another platform you may choose to use to process your payments securely on the website. This is essential to make payment online if you want to pay using your Paypal account. We are unable to process payments on your behalf through Paypal.
Accounting software companies We use various accounting software companies to help prepare and manage out accounts. Our accountants have access to our accounts software in order to carry out their legal duties on our account as well as aid us with our accounts where necessary. If you have received a manually prepared invoice from us, your details are stored on this software. If you have only placed orders on the website, your data is not stored on our account software but is stored on the website platform as above. The exception to this is if you are a European customer or outside of EU customer when an invoice has to be created on our accounting software.
Suppliers / Manufacturers We may, on occasion, send your order direct from one of our suppliers or manufacturers. If this is the case, your data is given to them in order to be able to send the order through their delivery partners. Only the information that is essential to send the orders is provided to them. They would share this with their delivery partners in order to deliver to you.
Stock management / order management / scanning technology. We use various integrated systems in order to be able to process your orders, order from suppliers and book in your delivery with our delivery partners. These allow us provide an efficient and accurate service.

 

 

 

Protecting your data outside the EEA

The EEA includes all EU Member countries as well as Iceland, Liechtenstein and Norway. We may transfer personal data that we collect from you to third-party data processors in countries that are outside the EEA. This is usually for delivery purposes only.

What are my rights?

The personal data we hold on you is only ever data you have provided to us or that is in the public domain (192 entry, facebook page etc). If you’d like to see the personal information that we hold about you, you can request it. If this information is incorrect you can ask for it to be updated (or you can do this in your own account when logged in). Or you can request that it’s deleted from our systems.

If we choose not to action your request, we will explain to you the reasons for our refusal.

You also have other rights:

  • Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent.
  • You have the right to tell us to stop using your personal data for direct marketing. This is usually by email and so you can stop receiving marketing emails at any time by unsubscribing in the email.
  • You have the right to a review by a human of any decision made based solely on automatic processing of your data (i.e. where no human has yet reviewed the outcome and criteria for the decision).

To action these, simply email us at https://sittingbourneballoons.co.uk/contact-us/ or you can post a request to us at:

Sittingbourne Balloons

A7 Smeed Dean Centre

Castle Road, Sittingbourne Kent ME10 3EW

To protect the confidentiality of your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Notice. If you have authorised a third party to submit a request on your behalf, we will ask them to prove they have your permission to act. Once we’ve seen and are happy with this proof being genuine, we’ll send you a copy of the personal data we hold / confirm action has been taken within 28 days.  We reserve the right to charge a reasonable fee to supply this information of up to £25

Where we rely on our legitimate interest

In cases where we are processing your personal data on the basis of our legitimate business interest, you can ask us to stop for reasons connected to your individual situation. We must then do so unless we believe we have a legitimate overriding reason to continue processing your personal data.

 

How we protect your data

We know how much data security matters to all our customers. With this in mind we treat your data with care and take all appropriate steps to protect it.

We secure our website and all online apps with ‘https’ technology.

We employ the services of a professional IT provider to advise and action any security recommendations.

We use automatically updating IT security software.

All computers are turned off at night or are locked and password protected.

Access to your personal data is password-protected on our network.

Payment card information is secured on the payment provider’s secure server. It is never stored locally by us.

Any sensitive information written down is shredded immediately if it is no longer required.

All paper with any personal data that is no longer required is stored in a locked cupboard to then be collected in a sealed bag for commercial shredding. The bag is not opened for shredding.

We regularly monitor our system for possible vulnerabilities and attacks, and we carry out regular penetration testing to identify ways to further strengthen security.

Contact the regulator

If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office.

You can contact them by calling 0303 123 1113. Or go online to www.ico.org.uk/concerns (opens in a new window; please note we can’t be responsible for the content of external websites)

If you are based outside the UK, you have the right to lodge your complaint with the relevant data protection regulator in your country of residence.

Got any worries?

If, at any time, you feel that we haven’t processed your data fairly or you’re not satisfied with how we’ve handled your personal information, you can contact the Information Commissioners Office, who will look into this for you. For full details about how to share any concerns you may have, visit www.ico.org.uk/concerns/

Links to other Websites

Any links to other websites that we provide on our websites or emails or other forms of communication are provided to help further understand the product or topic you are looking at.  Please remember that when you use a link to go from our website to another website, this privacy notice no longer applies. Your browsing and interaction on any other website, including those which have a link on our website, are subject to that site’s own rules and policies so please make sure you are happy with that before using the site before giving any personal information.

Updates

This notice will be updated from time to time and we recommend that you check back regularly but we will notify you of any changes through our website where this policy is posted. The version number and date released will always be listed below:

Version: 2.1