1 x £78.80
Gardening Express and its associated companies are totally committed to protecting the privacy of our site visitors, suppliers and customers with how we use personal information collected on our website.
This policy may change from time to time, so please check this page as required to check for changes. By using the Gardening Express website you are agreeing to this policy.
Gardening Express, 1386 London Road, Leigh On Sea, SS9 2UJ
Email: gdprteam@gardeningexpress.co.uk (this email address is NOT to be used for customer support queries. All customer support queries need to be done using our quick messaging service.)
We process your data when you place any orders with us. This is so that:
This legal basis is contractual obligation. The information that you supply us with when ordering is kept for a maximum of 7 years for HMRC reporting and audit purposes.
You may have also subscribed to one of our mailing lists which you can unsubscribe from at any time you wish to which will remove you from the mailing list concerned.
We do use cookies and you can read more about the cookies we use and how we use them below.
The marketing and cookie data processing are for our legitimate interest to help us grow the business.
Your data is collected by us and in some cases shared with third-parties usually in the following order:
Our eCommerce website is on a framework called Magento which is stored on Amazon Web Services (AWS) servers: https://aws.amazon.com/ . The servers and processing are located in Ireland and we use a 24 hour a day dedicated hosting provider 'Akoova' who manage and monitor the site performance and security: https://akoova.com/
Our payment provider https://stripe.com/en-gb process payment and store data within the EU (Dublin, Ireland).
Our shipping solutions provider https://despatchcloud.com/ who process and store data in UK based data centres.
The data processing and storage of customer support queries handled by https://www.freshworks.com/ is currently (Dec 2020) in the process of being moved from USA to EU servers.
We take data security very seriously which is why we use a 24 hour dedicated server / hosting support solution. Our website and database are regularly backed up throughout each day.
Our eCommerce website uses a permissions based system which means that any administrators only have the exact permissions needed to fulfil their role.
We use a secure password control system www.lastpass.com which means staff are unable to share or know system passwords.
Our data processing systems and processes are regularly reviewed throughout every year.
The closest we come to profiling is analytics of the website.
We collect additional to Google Analytics data which is then used to present targeted online advertising.
These solutions are supplied at times by third-parties such as www.criteo.com and www.quantcast.com.
The newsletters which you receive (if you've opted-in) can be opted-out of receiving at anytime. This is done by clicking the 'unsubscribe' link at the bottom of any newsletter received. Please note this will permanently remove your email address and it cannot be re-added again.
We never pass on your details to any other third-parties separate to who we directly use for processing your order(s), and sending you information (if you have opted-in to receive). This also includes sending you newsletters for any mailing lists you may have opted-in to. Anonymised / Non-specific to you data is gathered using cookies (as mentioned above).
Gardening Express does fulfil orders sent to them by various voucher sites. Customers of these voucher sites are covered by the Gardening Express Terms & Conditions.
You can access the personal information which we hold for you at any time by logging into your Gardening Express account. Where you can edit the information held by us.
Personal data are only held for as long as they need to be held for the original purpose for which they were collected. We have to keep financial records for 7 years to comply with legal obligations. Other customer data is deleted when requested by customers or when customers close their accounts. Data may be held longer than 7 years if a customer's account is still active.
Some of the third parties we work with are based in the EU which we are no longer part of. When we transfer data to the EU, we do so as they have an adequacy decision. This means that their data protection status is essentially equivalent to our own.
We also work with third parties who are based in the US. Our partners there keep your data secure, but US law gives US security services rights to access data which does not give essentially equivalent protection to UK or EEA. We have risk assessed this and there isn't a significant risk to our data subjects. We process these international transfers using Standard Contractual Clauses (SCCs).
Under the GDPR we respect the right of our data subjects to access and control their personal data as follows:
You can exercise the above rights by sending an email FOR LEGAL ENQUIRIES ONLY to gdprteam@gardeningexpress.co.uk. Please refer to the 'Checking your details' section below.
Please be aware that your rights may be limited if either:
Note regarding fees: In most cases we cannot charge a fee to comply with a subject access request. However we may charge a 'reasonable fee' for the administration costs of complying with a request if it is manifestly unfounded or excessive, or if an individual requests further copies of data.
If you wish to verify the details you have submitted to Gardening Express you may do so by contacting us via the e-mail address, telephone number or address given below. Our security procedures mean that we will request proof of identity before we reveal information.
This proof of identity will take the form of:
We would strongly recommend that you do not use the browser's password memory function as that would permit other people using your terminal to access your personal information - write it down and keep it somewhere safe.
We are an internet only based company and are contactable by email FOR LEGAL ENQUIRIES ONLY at gdprteam@gardeningexpress.co.uk.
If you need to contact our DPO, they can be reached at dpo@gardeningexpress.co.uk
Our registered office is located at: Gardening Express, 1386 London Road, Leigh On Sea, SS9 2UJ
If you have a data protection issue that we have been unable to resolve with you, you have the right to contact the Information Commissioners' Office (ICO) and lodge a complaint with them.
Their address is:
Information Commissioner's Office