C. Bonner and Son Ltd trading as bonnerofireland.com is committed to protecting our customer privacy and takes its responsibility regarding the security of customer information very seriously. We will be clear and transparent about the information we are collecting and what we will do with that information.
This policy sets out the following:
- What personal data we collect and process about you in connection with your relationship with us as a customer and through your use of our website;
- Where we obtain the data from;
- What we do with that data;
- How we store the data;
- Who we transfer/disclose that data to;
- How we deal with your data protection rights;
- And how we comply with the data protection rules.
- All personal data is collected and processed in accordance with Irish and EU data protection laws.
“C. Bonner & Son Ltd” (referred to as “we”, “us”, “our” or “Bonnerofireland.com” in this policy) is the “data controller” of all personal information that is collected and used about our customers for the purposes of [the Irish Data Protection Act 2018]. C. Bonner & Son Ltd is registered in Ireland with registration number 61532 and registered offices at Glenties Road, Ardara, Co. Donegal, Ireland.
What Personal Data We Collect
Personal data means any information relating to you which allows us to identify you, such as your name, contact details and information about your access to our website.
We may collect personal data from you when you order from our online shop (https://bonnerofireland.com/shop/), or when you contact us.
Specifically, we may collect the following categories of information:
- Name, home address, billing address, e-mail address, telephone number. We do not collect or store credit/debit card details as they are handled by a third-party;
- The communications you exchange with us or direct to us via emails and the contact form (https://bonnerofireland.com/contact/).
- Your IP Address, which is used to detect and / or prevent any fraudulent activities, and also to figure out your country in order to show you the relevant currency in our online shop.
What Do We Use Your Personal Data For, Why and For How Long
Your data may be used for the following purposes:
- To allow us to deliver goods you ordered on our online shop to your address.
- Contacting you about the status of your order, such as when an order is shipped or if there is a problem.
- Administrative or legal purposes: we use your data for statistical and marketing analysis, systems testing, maintenance and development, or in order to deal with a dispute or claim.
- Marketing: from time to time we may contact you with information regarding our products via e-communications. You will have the choice to opt in or opt out of receiving such communications by indicating your choice during the order process. You will also be given the opportunity on every e-communication that we send you to indicate that you no longer wish to receive our direct marketing material.
We will only process your personal data where we have a legal basis to do so. The legal basis will depend on the reasons we have collected and need to use your personal data for.
We will not retain your data for longer than is necessary to fulfil the purpose it is being processed for. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the purposes for which we process it and whether we can achieve those purposes through other means.
We must also consider periods for which we might need to retain personal data in order to meet our legal obligations, or to deal with complaints, queries and to protect our legal rights in the event of a claim being made.
When we no longer need your personal data, we will securely delete or destroy it. We will also consider if and how we can minimise over time the personal data that we use, and if we can anonymise your personal data so that it can no longer be associated with you or identify you, in which case we may use that information without further notice to you.
Security of Your Personal Data
We follow strict security procedures in the storage of your personal data, and to protect it against accidental loss, destruction or damage. The data you provide to us is protected using SSL (Secure Socket Layer) technology. SSL is the industry standard method of encrypting personal information so that they can be securely transferred over the Internet.
All personal information such as name, phone, shipping address and billing address are transmitted over SSL across dedicated network infrastructure.
Your credit/debit card details are handled securely by a dedicated third-party payment processor (Stripe, Revolut or PayPal). C. Bonner & Son Ltd never processes or stores your credit/debit card details.
We may disclose your contact information such as name, shipping address, billing address and IP address to our trusted third-party payment processors for the purposes of carrying out an order in our online shop. We require all third parties to have appropriate technical and operational security measures in place to protect your personal data, in line with Irish and EU law on data protection rules.
Sharing Your Personal Data
We only ever share your personal data if you make a payment using PayPal, Stripe or Revolut. We may share your name, shipping and billing address to PayPal, Stripe or Revolut payment gateway solely for the purposes of processing your order.
Cookies and Site Tracking
This site, like many others, uses small files called cookies to help us customise your experience.
Cookies are small text files that are stored by the browser (for example, Chrome, Internet Explorer or Safari) on your computer or mobile phone.
DATA PROTECTION OFFICER
We have appointed a Data Protection Officer (“DPO”) to oversee compliance with this policy. You have the right to make a complaint at any time to a supervisory authority. The Irish Data Protection Commissioner is the lead data protection supervisory authority for C. Bonner & Son Ltd as an Irish data controller.
Your Data Protection Rights
Under certain circumstances, by law you have the right to:
Request information about whether we hold personal information about you, and, if so, what that information is and why we are holding/using it.
Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing.
Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
Request transfer of your personal information in an electronic and structured form to you or to another party (commonly known as a right to “data portability”). This enables you to take your data from us in an electronically usable format and to be able to transfer your data to another party in an electronically usable format.
Withdraw consent. In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
If you want to exercise any of these rights, then please submit a request via our Contact form, or contact our DPO by post at The Data Protection Officer, C. Bonner & Son Ltd, Glenties Road, Ardara, Co. Donegal, Ireland.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights).
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
The Data Protection Officer,
C. Bonner & Son Ltd.
Ardara, Co. Donegal