Data Protection Overview FAQ’s

Data Protection Overview FAQ’s 2018-05-24T08:03:52+00:00

Your information, our duty and your rights

To be our customer, you share information with us. We respect that information.

On this page you will find out how we do that and what your rights are. We think it’s important that you read this page. It will tell you everything you need to know.

You can read our Data Protection Notice, effective from May 25th 2018 here.

Our Data Protection Notice is changing under the General Data Protection Regulation (GDPR).

Overview of Data Protection

What is GDPR?

GDPR is the General Data Protection Regulation. It comes into effect from 25 May 2018. It sets out a series of new EU laws concerning how data is processed and used. The objective of the regulation is to strengthen and standardize data protection laws for all EU citizens. These regulations will apply to any organisation that controls and/or processes data on behalf of an individual or group of individuals. Those responsible for adhering to these regulations include employees of the organisation, including contractors, consultants, agents and third parties who have access to data either directly or indirectly.

What does this mean for Best menswear?

We have always appreciated your trust in us to collect, process and protect your information. As a data controller and processor of your personal data, we will continue to:

Develop on our strong risk culture by acting responsibly and putting your security at the top of our priorities;

Manage our controls, processes and systems to improve our level of customer service while providing you with the assurance that your information is safe and secure;

Conduct our business in a fair and transparent way and ensure we minimise the risk of unfair outcomes for our customers or impact on their data rights and freedoms.

Our Data Protection Notice and website explains how we collect personal information about you, how we use it and how you can interact with us about it.

Who we are?

When we talk about “Best Menswear” or “tailors of confidence” or “us” or “we” on our Data Protection Notice and this website, we are talking about “Best Menswear”

When we talk about our “websites” we are talking about www.bestmenswear.ie.

We share your information within Best Menswear to help us provide our services, comply with regulatory and legal requirements, and improve our products.

Our Data Protection team oversees how we collect, use, share and protect your information. We may consult a professional independent third party to ensure your rights are fulfilled. You can contact our Data Protection team at GDPR@BESTSMENSWEAR.COM or by writing to: GDPR Team, Best Menswear Suite 26 Northwood House/Northwood Business Park/Santry/Dublin 9/Ireland or by calling 0035318800888

How we collect information about you

We collect personal information from you, for example when you:

  • Make an enquiry through our sign up to our database/mailing list in the store or on our website;
  • Email us;
  • Call us;
  • Make a booking for Made to Measure;
  • Use your credit or debit card for banking purposes
  • Alterations of clothing;
  • Request us to contact you;

 
We also collect information through our website, social media, discussion forum, market research and our CCTV footage. Further information on how we collect information online is detailed on our websites, Privacy Policy and our Social Media Policy Statement.

We never record phone conversations.

Depending on your product or service, we may collect information to identify you through asking for your full name, email address, date of birth.

Our websites use ‘cookie’ technology. A cookie is a little piece of text that our server places on your device when you visit any of our websites or apps. They help us make the sites work better for you. Further information is available on our Cookie Policy.

What information do we collect about you?

This is some of the information we may collect and hold about you when applying for and using our products and services:

  • Full name
  • Email address
  • Phone number
  • Age
  • Gender
  • Date of birth
  • CCTV images
  • Location
  • Origin/source of hearing about us
  • Account history

 
Special categories of data

Under GDPR, there are special categories that require additional safeguards for processing.

Special categories of data; Does Best Menswear process this information?

  • Driving licence | No – We do not request details of your driving licence.
  • Health data | No – We do not collect health data from you when providing our products and services.
  • Racial or ethnic origin | No – We do not request you to provide details of racial or ethnic origin to provide our products and services.
  • Political opinions | No – We do not request you to provide political opinions to provide our products and services.
  • Religious or philosophical beliefs | No – We do not request you to provide religious or philosophical beliefs to provide our products and services.
  • Trade union membership | No – We do not request you to provide trade union membership to provide our products and services.
  • Genetic data | No – We do not request you to provide genetic data to provide our products and services.
  • Sexual orientation | No – We do not request you to provide sexual orientation to provide our products and services.

 

How we use your information

  • We use information about you to:
  • Provide relevant products and services;
  • Identify ways we can improve our products and services;
  • Maintain and monitor your products and services;
  • Protect your interests; and
  • Decide and recommend how our products and services might be suitable for you

 
To provide our products and services under the terms and conditions we agree between us, we need to collect and use personal information about you. If you do not provide this personal information, we may not be able to provide you with our products and services.

We analyse the information that we collect on you through your use of our products and services and on our social media, apps and websites. This helps us understand your behaviour, how we interact with you and our position in a market place. Examples of how we use this information include offering you products and services and personalising your experience.

Lawful basis for processing

To use your information lawfully, we rely on one or more of the following legal bases:

  • Performance of a contract;
  • Legal obligation;
  • Our legitimate interests;
  • Your consent;
  • Protecting the vital interests of you or others; and
  • Public interest.

 
To help you better understand where these lawful bases may apply, these are some examples for each lawful basis. In some cases, the same information is processed under more than one lawful basis:

  • Performance of a contract – Processing your information is necessary for us to provide your products and services providing relevant products and services
  • We provide our customers with products such as; Menswear Clothing
  • We process your information to identify and authenticate you to use our products and services.
  • Maintaining and monitoring our products and services
  • We must continually monitor and update information to ensure your data is safe, accurate and up to date. This ensures we keep your personal details and financial products secure, and give you the best customer service.

 
Our legitimate interests –Legitimate interest means the interests of Best Menswear in conducting and managing our business when providing products and services. The core legitimate interests of Best Menswear are to provide the best customer service, introduce new products, and to protect our customers and employees.

We will always assess whether the legitimate interest of Best menswear will adversely impact the rights and freedoms of the data subject prior to processing. We implement safeguards to ensure that the processing remains fair and balanced.

Our risk assessments help us understand what information we need, our business requirements, the impact on our customers and employees, alternative options for processing and how long we hold the information for.

Manage and understand risk

We must manage and understand our risk exposure to ensure our customers are protected.

We produce internal management information and models to understand risks across the business, ensure necessary safeguards are in place and assess the design and effectiveness of these safeguards.

Manage our relationship with you

We keep our records up to date and contact you when required and provide the best customer service.

Analyse information and research your experiences dealing with us

We want to continually improve and better understand our customers. By collecting and analysing data from multiple sources, we can better understand the requirements of our customers and how we can improve products and service offerings.

This analysis also helps us run our business more efficiently and effectively.

We may create report trends with third parties. These trend reports may include information about activity on devices, for example locations of mobile phones, laptops, and computers. When we prepare these reports, we group customers’ information and cannot access any names. We cannot share information in these reports that can identify you as a customer, such as your name, or account details.

Identify ways we can improve our products and services

We are always working to develop new products and innovative ways of bringing these to you.

We analyse the market and our customer base to better understand what people like and what people want. We do this by collecting data on your purchases, data from our newsletters, interactions with our website, and using occasional customer surveys. We use this information to provide a more personalised service to our customers and improve their experience using our products.

Directly contact you about new products and services

With your consent, we will let you know what products or services you might like.

Consent

Sometimes we need your consent to use your personal information such as emails.

We have controls to ensure that you are informed when making your decision and that you are aware that you can remove your consent at any time by contacting us. Our consent requests are built on the following principles:

  • Positive Action– Clear affirmative action is required.
  • Free will– Your consent must be freely given and not influenced by external factors.
  • Specific– We will be clear on what exactly we are asking your consent for (newsletter etc.)
  • Recorded– We will keep a record of your consent and how it was obtained.
  • Can be withdrawn at anytime – We will stop data processing requiring your consent at any time you make valid request.

 

Direct Marketing

For direct marketing, we need your consent to make you aware of products and services which may be of interest to you. We may do this by newsletter, post, email, text or through other digital media.

If we ever contact you to get your feedback on ways to improve our products and services, you have the choice to opt out.

How we keep your information safe

We protect your information with security measures under the laws that apply and we meet international standards. We keep our computers, files and buildings secure.

In addition to our technical controls, Our Data Protection team oversees how we collect, use, share and protect your information. We may consult a professional independent third party to ensure your rights are fulfilled. Our Data Protection team advises on how we can best understand risks to your data rights and freedoms, implemented processes to protect these and has responsibility to report to the Data Protection Authorities if we are not meetings our obligation.

When you contact us to ask about your information, we may ask you to identify yourself. This is to help us protect your information.

Your personal information rights

You can exercise your rights by email at GDPR@BESTSMENSWEAR.COM or by writing to: GDPR Team, Best Menswear Suite 26 Northwood House/Northwood Business Park/Santry/Dublin 9/Ireland or by calling 0035318800888

Whenever you contact us to ask about your information, we may ask you to identify yourself. This is to help protect your information.

Your right to obtain information cannot adversely affect the rights and freedoms of others. Therefore, we cannot provide information on other people without consent.

The following section details your information rights and how we can help ensure that you are aware of these rights, how you can exercise these rights and how we intend to deliver on your requests.

Accessing your personal information

You can ask us for a copy of the personal information we hold and further details about how we collect, share and use your personal information. You can request the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • where the personal data are not collected from the data subject, any available information as to their source.

 

Updating and correcting your personal details

If you want to update or correct any of your personal details, by email GDPR@BESTSMENSWEAR.COM or by writing to: GDPR Team, Best Menswear Suite 26 Northwood House/Northwood Business Park/Santry/Dublin 9/Ireland or by calling 0035318800888

Removing consent

You can change your mind wherever you have given us your consent, such as for direct marketing or processing your sensitive information, by email GDPR@BESTSMENSWEAR.COM or by writing to: GDPR Team, Best menswear Suite 26 Northwood House/Northwood Business Park/Santry/Dublin 9/Ireland or by calling 0035318800888

Restriction and objection

You may have the right to restrict or object to us processing your personal information. We will require your consent to further process this information once restricted. You can request restriction of processing where;

The personal data is inaccurate and you request restriction while we verify the accuracy;

The processing of your personal data is unlawful;

You oppose the erasure of the data, requesting restriction of processing instead;

You require the data for the establishment, exercise or defence of legal claims but we no longer require the data for processing;

You disagree with the legitimate interest legal basis and processing is restricted until the legitimate basis is verified.

Deleting your information (Right to be forgotten) – New GDPR right introduced from May 25th 2018

You may ask us to delete your personal information or we may delete your personal information under the following conditions:

  • the personal data is no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • you withdraw your consent where there is no other legal ground for the processing;
  • you withdraw your consent for direct marketing purposes;
  • the personal data has been unlawfully processed;
  • the personal data has to be erased for compliance with a legal obligation.
  • Moving your information (your right to portability) – New GDPR right introduced from May 25th 2018

 
Where possible we can share a digital copy of your information directly with you. We will provide this information in a structured, commonly used and easily read format. Note, we can only share this information where it has been processed manually (hard copy documents are excluded for portability) and was processed under your consent or performance of a contract (further details on this are available in our lawful basis section below).

We do not share information processed under legal obligation or our legitimate interest for portability, in line with GDPR guidance.

The right to lodge a complaint with a supervisory authority

If you have a complaint about the use of your personal information, please contact our GDPR team as soon as possible by email GDPR@BESTSMENSWEAR.COM. If you wish to make a complaint you may do so in person, by phone, in writing and/or by email. We will fully investigate all the complaints we receive. You may complain through our website, by phone, by email or in person. We ask that you supply as much information as possible to help us resolve your complaint quickly.

You can also contact the Office of the Data Protection Commissioner in Ireland on the below details:

Visit their website dataprotection.ie.

Email info@dataprotection.ie

Phone on +353 (0)57 8684800 or +353 (0)761 104 800

Write to Data Protection Office, Canal House, Station Road, Portarlington, Co. Laois, R32 AP23. Or 21 Fitzwilliam Square, Dublin 2, D02 RD28, Ireland.

Updates to this notice

We will make changes to this notice from time to time, particularly when we change how we use your information, and change our technology and products. You can always find an up-to-date version of this notice on this website at https://www.bestmenswear.ie/data-protection-notice/.

Key Definitions:

Please see explanations below of some of the data protection terms used on this website.

Consent – of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Data Controller – is a natural or legal person, public authority, agency or other body who determine the purpose and means of the processing – of personal data, where the purposes and means of such processing are determined by Union or Member State law. Best menswear are considered a data controller, as they process personal data on behalf of both their customers and their employees.

Data Processor – in relation to personal data, means any natural or legal person (other than an employee of the data controller), public authority, agency or another body who processes personal data under the direction of, and on behalf of a data controller. Best Menswear, Boom 22 and Mail Chimp is considered a data processor. Additionally, Third Parties engaged by Best Menswear to process personal data are considered data processors.

Data Protection Law and Regulation – means all legislation, regulation and applicable codes of practice relating to the processing, protection and privacy of personal data.

General Data Protection Regulation (‘GDPR’) – is a regulation intended to strengthen and unify data protection for all individuals within the European Union (‘EU’). Non-compliance of GDPR can result in fines. The aim of the GDPR is to reinforce data protection rights of individuals and facilitate the free flow of personal data. It applies to all data controllers and processors established in the EU, as well as those established outside the EU that process the data of EU citizens.

Lawful Basis – Processing of data is lawful only if and to the extent that at least one of the following applies:

  • Personal data may be processed on the basis that processing is necessary in order to enter into or perform a contract with a customer.
  • Personal data may be processed on the basis that there is a legal obligation for the processing.
  • Personal data may be processed where Best menswear has a legitimate interest in processing the data.
  • Personal data may be processed in order to protect the vital interests of the data subject.

 
Personal Data – is any data relating to an identified or identifiable natural person (‘data subject’), who may be identified from the data either on its own (directly) or in conjunction with other data (indirectly), in particular by reference to an identifier such location data, an online identifier or to one or more factors specific to the physical, physiological, economic, cultural or social identity of that natural person.

Processing – means obtaining, recording or holding the information or data, whether or not by automated means, or carrying out any operation or set of operations on the information including:

Collection of data

Organisation, adaption or alteration of the information or data

Retrieval, consultation or use of the information or data

Disclosure of the information, or data by transmission, dissemination or otherwise making available, or

Alignment, combination, blocking, erasure or destruction of the information or data

Supervisory Authority – means an independent public authority which is established by a Member State. In the Republic of Ireland the Office of the Data Protection Commissioner (‘ODPC’) are the public authorities established to monitor the application of Data Protection Law.