Tozer Seeds respects your privacy when you use our services and is committed to complying with privacy legislation. This privacy notice has been updated to comply with The European Union’s General Data Protection Regulation (GDPR) regulation which changes how companies use and process the personal data of European users.
The information below is what is referred to as a ‘Privacy Notice’ which explains how we use and protect your personal data.
What is Personal data
Personal data means any information which can identify and relate to a living person. This can also include information which, when put together with other information, can then identify a person
Where it came from and what we hold:
Customer data has come from contact about our products. We collect personal data when customers place an order or enter into correspondence with our sales, finance or customer services staff. This may include name, email address, postal address and telephone number and payment details. We continue to liaise with customers in the context of our products. The customer was originally able to cease contact and is always able to decline further contact.
Supplier data has come from contact by the supplier or research into suppliers. They have also approached us, through our website, by phone or email. We liaise with them in the context of providing services to our employees.
This constitutes implied consent or ‘soft opt-in’ but future communications will require new customers to opt in.
Tozer Seeds is not required to refresh existing consent* for the reasons above but please see the end of document for full advice to companies on consent.
Why we use your Personal data:
We collect this information to;
- Supply and deliver seed orders to you
- Take payment for your order
- Provide information regarding your order
- Provide information about our products
- Provide feedback from any questions you may have
- Keep you informed of new products
- Keep you informed about Open Days and our attendance at Trade Shows
Who we share your personal data with
Tozer Seeds does not pass on or sell information about our customers to any other business or organisation. The only exception to this is where we are legally obliged to do so to comply with a current judicial proceeding, a court order or legal process served on our website.
How do we protect your personal data
We maintain reasonable administrative, technical and physical safeguards in an effort to protect against the loss, theft, unauthorised access, use, modification and disclosure of personal information in our custody and control. We will do what we can to make sure we hold personal records (on paper and electronically) in a secure way, and we will only make them available to those who have a right to see them.
How long do we keep your personal data
We only keep your personal information as long as necessary for the purposes we collected it, or as otherwise required by law.
Customers who no longer wish to receive promotional communications may opt-out of receiving these communications by clicking the link at the bottom of the correspondence or by emailing email@example.com with unsubscribe in the subject line of the email.
When buying seed through our website you will be re-directed to the website of E.W. King & Co Ltd (Kings Seeds). They are an authorised partner of Tozer Seeds Ltd. We do not share your details with E.W.King & Co Ltd. Any details you enter on the E.W.King & Co Ltd website for the purposes of purchasing seed are used by E.W.King & Co Ltd to fulfil your order.
Feel free to contact us with any questions about our Privacy Notice, how we treat your personal information or to unsubscribe from an email or other marketing list. You may also access or update the personal information we have about you. Please email us at firstname.lastname@example.org or write to us at the address below. To protect your privacy, we will take reasonable steps to help verify your identity before granting access or making corrections.
Tozer Seeds, Pyports, Downside Bridge Road, Cobham KT11 3EH
Your Privacy Rights
The law provides you with a number of rights to control the processing of your personal data:
- the right to be informed
- the right of access
- the right to rectification
- the right to erasure
- the right to restrict processing
- the right to data portability
- the right to object
- the right not to be subject to automated decision-making including profiling
If you would like to request information held about you, or makes changes to the data we have you can contact us at email@example.com. Once a written request has been received, Tozer Seeds will act or respond within one month. If action is required, it will be taken by a company director.
Tozer Seeds can refuse or charge for requests that are manifestly unfounded or excessive. If we refuse a request, we will tell you why and explain that you have the right to complain to the supervisory authority for a judicial remedy. This will take place without undue delay and, at the latest, within one month.
Tozer Seeds is able to detect, report and investigate a personal data breach as it employs an IT company to oversee its technology. Alerts are in place.
Tozer Seeds is only required to notify the ICO (Information Commissioner’s Office) of a breach where it is likely to result in a risk to the rights and freedoms of individuals – if, for example, it could result in discrimination, damage to reputation, financial loss, loss of confidentiality or any other significant economic or social disadvantage.
Where a breach is likely to result in a high risk to the rights and freedoms of individuals, Tozer Seeds will notify those concerned directly.
Data Protection by Design Protection Impact Assessments
A DPIA is required in situations where data processing is likely to result in a high risk to individuals, for example:
- where a new technology is being deployed
- where a profiling operation is likely to significantly affect individuals
- where there is processing on a large scale of the special categories of data
Consequently, Tozer Seeds has no current requirement to undertake a DPIA
Data Protection Officer
Tozer Seeds does not require a Data Protection Officer (DPO) because we are not:
- a public authority
- an organisation that carries out regular and systematic monitoring of individuals on a large scale
- an organisation that carries out the large scale processing of special categories of data, such as health records, or information about criminal convictions
* Consent Advice
Consent must be freely given, specific, informed and unambiguous. There must be a positive opt-in. Consent cannot be inferred from silence, pre-ticked boxes or inactivity. It must also be separate from other terms and conditions, and you will need to have simple ways for people to withdraw consent. Consent has to be verifiable and individuals generally have more rights where you rely on consent to process their data.
You are not required to automatically ‘repaper’ or refresh all existing DPA consents in preparation for the GDPR. But if you rely on individuals’ consent to process their data, make sure it will meet the GDPR standard on being specific, granular, clear, prominent, opt-in, properly documented and easily withdrawn. If not, alter your consent mechanisms and seek fresh GDPR-compliant consent, or find an alternative to consent.
Cookies & how you use this website
You can visit our site (www.tozerseeds.com) without telling us who you are or providing us with any personal information. However, we collect the I.P. (Internet protocol) addresses of all our website visitors and other related information such as page requests, browser type, operating system and average time spent on our website through an analytics programme (Google Analytics) which we use to monitor and improve our website.
To make this website easier to use, we sometimes place small text files on your device (for example your iPad or laptop). These are known as ‘cookies’. Our cookies aren’t used to identify you personally. They’re just here to make the site work better for you.
By using our website, you agree that we can place these types of cookies on your device.
For more information about cookies (including how to turn them off) please visit www.allaboutcookies.org
|Cookie Name||Expires||Typical Content||Management||Domain|
|__utma||Persistent:2 Years||Used to collect anonymised data on how visitors use our webpages. The information generated is used to create Google Analytics reports which are used to inform future improvements in our website usability and performance. Further details can be found here: www.cookielaw.org||Google Analytics Third Party||Tozerseeds.com|
|__utmb||Session; Expires after 30 minutes|
|__utmc||Session; erased when the Web browser is closed|
|__utmz||Persistent; 6 months|
For further details on Google Analytics cookies, including those not used by tozerseeds.com visit cookies set by Google Analytics