Privacy Policy

EasyGates Direct Privacy Policy

What we’ve Changed

We updated this privacy policy on 20th October 2018 to make the following clarifications:

  • What data we regularly backup, where backups are held, and how long backups are retained for.
  • Clarified that Registration Information and Order Details will be passed on to PayPal (in addition to WorldPay) if it is chosen as the payment method during checkout.

About this Site

EasyGates Direct is a trading name of EasyGates Ltd.

The EasyGates Direct Trade Store and Blog are operated and maintained by EasyGates Ltd.

For more information about EasyGates Ltd, including our company registration number, VAT number and more, see the About Us & Legal Page.

Introduction

EasyGates Ltd is committed to protecting the privacy of our customers and visitors. Any information submitted to us will be handled in accordance with this privacy policy.

Your information will not be passed onto a third party unless:

  • specifically stated below in the What Information we Process section; or
  • we have your express permission beforehand; or
  • we are required to disclose it:
    • by or under any UK enactment;
    • by any rule of common law; or
    • by an order of a court or tribunal in any jurisdiction.

EasyGates Ltd may change this privacy policy from time to time by updating this page. Please revisit our Privacy Policy regularly in order familiarise yourself with it, and keep abreast of any changes.

Any minor amendments (such as spelling or grammar corrections, clarifications or additional links) will be highlighted on this page. Any significant changes to what data we collect or how it is handled will be highlighted prominently across the website prior to - and for a reasonable duration after - changes are made.

Any changes will be highlighted as soon as, and for a reasonable duration after, changes are made.

This is version 1.2.1 of the EasyGates Direct Privacy Policy. It was last revised on 20th October 2018.

Scope

This privacy policy sets out what information EasyGates Ltd collects when you use the various functions of the EasyGates Direct website, as well as how we use and handle this information.

This privacy policy applies to easygatesdirect.co.uk and any of its associated subdomains (unless otherwise specified).

What Information we Process

What Data we Collect What we use this data for How long is this data retained? What is our lawful basis for handling and holding the data? Is this data ever passed onto a third party?

Marketing Data

EasyGates Ltd uses a number of methods to keep previous and potential customers informed about our latest offerings and services.

Email Marketing

EasyGates Ltd maintains several email marketing lists across its various websites.

At the very least, the Marketing Data in these lists consists of your email address, as well as when and to which marketing list you signed up to.

Depending on the email list you opt-in to, additional information such as your name, company name, customer group and industry may be included in our Marketing Data.

When you sign up for an email marketing list, we will always make it clear what information is being added to our marketing list.

This data will not be used in combination with any other information we hold about you without your express permission (see Personalisation section).

Personalisation

In some instances, the information in our Email Marketing Lists may be combined with other information we hold about you (such as your previous Order Details or Cart Contents) in order to provide you with more personalised and relevant product recommendations.

Personalisation is always provided strictly on an opt-in basis, and we will always provide you with concise information about what information is provided for this purpose.

We use the Marketing Data you provide to give you regular updates about our latest products, services and offers via email.

If you opt-in to personalisation, we will provide you with tailored product recommendations, either via email or on our website.

The Marketing Data you provide to us for Email Marketing is stored for as long you stay subscribed to our marketing lists.

The information that is used for personalisation is retained for the periods set out in the Order Details or Cart Contents sections.

Consent: If you opt-in to email marketing or personalisation, you have given clear consent for us to process your personal data for a specific purpose. This data is shared with our email marketing provider, MailChimp. Mailchimp is operated by The Rocket Science Group LLC.

Google Analytics Data

EasyGates Ltd uses Google Analytics to analyse how visitors use our site.

If you opt-in to Google Analytics, a cookie is stored on your computer that contains a unique, anonymised ID. This unique ID is a random collection of letters, numbers and symbols, and does not contain any other personally-identifiable information which you may provide to us in another context. The client ID is used to differentiate you from other visitors, as well as determine whether you are a first time or returning visitor.

When Google Analytics is enabled, various details about your computer, browser and visit behaviour are passed on to Google. This information may include, but is not limited to:

  • Your IP Address
  • An estimate of what browser and operating system you are using to visit our site
  • What pages you visit and how long for

Your IP address is collected by the Google Analytics service purely for the purpose of determining the approximate geographic location of visits. Google does not share your IP address with us, and only provides us with an anonymous, approximated geographic location. EasyGates Ltd employs Google Analytics’ optional IP Anonymization feature. This features removes the final set of digits of your IP address, in order to provide a more anonymised and less accurate estimation of your location.

The techniques that Google employ do not collect personal information such as your name, email address, postal address, or telephone number.

We will not link, or seek to link, any of the above information with any personally identifiable information we hold about you.

The information we collect via Google Analytics is used to help us optimise and improve the way our website works, and ensure our users are able to easily find all the information and services we offer. We have set Google Analytics to remove all data related to an individual client ID 50 months after the final visit to this site (after opting in to analytics). Consent: If you opt-in to Google Analytics, you have given clear consent for us to process your personal data for a specific purpose. This data is passed on to Google Analytics in order to provide us with insights about our website and visitors. Google Analytics is operated by Alphabet Inc.

Raw Access Logs

EasyGates Ltd uses various technologies to log traffic across our websites. The majority of this data is anonymous, and is not linked to any IP addresses or other personally identifiable information.

However, in addition to this anonymous data, EasyGates Ltd keeps raw access logs. These raw access logs store the following information about visitors each time a page is accessed:

  • IP Address
  • User Agent String
  • What resource was accessed
  • What time it was accessed

These raw logs do not contain any other information. The data transferred between your computer and our servers is not logged, only the page accessed.

EasyGates Ltd keeps these raw logs in order to:

  • Ensure network and information security.
  • Ensure we can resist malicious actions that compromise the security of our systems and data, such as brute force entry, DDOS and DOS attacks.

Any data that contains personally identifiable information will be kept for no longer than one month.

However, if we believe an IP Address or range of IP addresses to be behind malicious actions that threaten the security and upkeep of our systems, they will be kept on file as long as we believe they may cause us harm, in order to prevent repeat behaviour.

Legitimate interests: the processing is necessary for our legitimate interests or the legitimate interests of a third party unless there is a good reason to protect your personal data which overrides those legitimate interests. This data will never be passed onto a third party unless we are required to do so by law (see Introduction section).

Registration Information

The following information is collected during registration, and can be amended at any time from the account section of the website or prior to checkout:

  • Your name and title
  • Your company name
  • Your contact information, including email address, telephone number and fax number (optional)
  • Your geographic information (addresses)

Additional shipping and billing addresses may be added or removed from your address book or amended at any time.

Your Registration Information is used to:

  • Create your EasyGates Direct account / log in, which can be logged into again in future to make additional purchases.
  • Allow us to contact you regarding any issues with your order (only if you order or attempt to order from us, see Order Details section for more information)
  • To inform you of new products, offers and other promotions via email (only when opted into marketing communications)

Your Registration Information is stored on our website database indefinitely (in order to allow customers to order again with as little delay and hassle as possible) or until such a time that you ask us to remove your account. If you request removal of your Registration Information, it may be retained for an additional seven days (after it is removed from our live / primary data source) in our regular backups. See the Backed up Data section for more information.

If at any time we choose to systematically delete Registration Information, customers will be contacted beforehand in good time if they meet our criteria for removal. We will provide customers with facilities to keep their account in our system if they so wish.

Notices will be posted on our website informing customers of the time of removal, as well as the criteria we used to determine which accounts will be removed (last order date, last login, etc.).

Consent: By creating an EasyGates Direct account, you have given clear consent for us to process your personal data for a specific purpose.
  • If you opt-in to marketing communications, your Registration Information will be passed onto our email marketing provider, MailChimp (as detailed in the Marketing Data section). Mailchimp is operated by The Rocket Science Group LLC.
  • When using the “Address Search” field, the postcode you enter is passed on to our address lookup service, PCA Predict. In addition, your IP address is shared with PCA Predict in order to prevent abuse and overuse of this facility. PCA Predict is the trading name and a trademark of GB Group plc. (Company registration number 02415211)
  • When attempting to pay for your goods, your Registration Information - in addition to your Order Details (see below for details) - are passed onto our Payment Provider WORLDPAY (UK) LIMITED (Company registration number 07316500). Additionally, if you choose to pay with PayPal, this data will be passed on to PayPal (Europe) S.à r.l. & Cie, S.C.A.
  • Registration information will be encrypted and transferred to another server operated by our backup provider on a regular basis, as outlined in the Backed up Data section.

Cart Contents

When adding products to your cart while logged in, the following details are stored in our database and associated with your Registration Information:

  • Items in cart
  • Quantity of items in cart
  • Prices to be paid for items, delivery and VAT
  • Any information added to text fields on customisable products.

If you do not log into or sign up for an account when adding products to the cart, this information is not linked to any personally identifiable information.

Your Cart Contents are associated with Registration Information so that they will persist between sessions. This means that items will stay in your basket for your convenience whenever you log in, even if you have been logged out.

This data is stored indefinitely for your convenience.

However, if at any time you would like this data to be removed, you can remove the items from your cart or contact us for assistance. If you remove items from your cart, they may be retained for an additional seven days (after they are removed from our live / primary data source) in our regular backups. See the Backed up Data section for more information.

Consent: By logging into your EasyGates Direct account and adding items to your cart, you have given clear consent for us to process your personal data for a specific purpose.

These details will never be passed onto a third party unless:

  • you proceed to the checkout to attempt to complete your order (see Order Details section below); or
  • we have your express permission beforehand (for example if you opt-in to Personalisation); or
  • are required to do so by law (see Introduction section).

Cart contents will be encrypted and transferred to another server operated by our backup provider on a regular basis, as outlined in the Backed up Data section.

Order Details

When you proceed to the checkout page and attempt to create an order, the following details are stored in our database, assigned an Order Number, and associated with your Registration Information and Cart Contents:

  • Purchase order number (optional)
  • Order comments (optional)
  • Finalised prices to be paid for items, delivery and VAT
  • Shipping and billing address chosen for this order

The above information is also stored in our database as a failed / incomplete order if:

  • you do not complete the order process; or
  • you are transferred to our payment provider (WorldPay) but your payment is not successful.

The Order Details we collect at checkout are used in combination with your Registration Information and Cart Contents in order to:

  • ensure your items reach you in a timely fashion; and
  • allow us to contact you regarding any issues with your order.

In order to comply with the Companies Act 2006, EasyGates Ltd keeps accounting records for 6 years from the end of the last company financial year they relate to, or longer if:

  • they show a transaction that covers more than one of the company’s accounting periods; or
  • we are otherwise required to by HMRC (for example for compliance check purposes).

After Order Details are removed from our system, they may be retained for an additional seven days (after they are removed from our live / primary data source) in our regular backups. See the Backed up Data section for more information.

  • Consent: By completing the checkout process, you have given clear consent for us to process your personal data for a specific purpose.
  • Contract: processing this data is necessary to fulfil our contractual obligations to you
  • When attempting to pay for your goods, your Order Details - in addition to your Registration Information (see above for details) - are passed onto our Payment Provider WORLDPAY (UK) LIMITED (Company registration number 07316500). Additionally, if you choose to pay with PayPal, this data will be passed on to PayPal (Europe) S.à r.l. & Cie, S.C.A.
  • If you opt-in to Personalisation, your Order Details may be combined with other Marketing Data we hold about you and passed on to our email marketing provider MailChimp in order to provide you with more relevant product recommendations. See Marketing Data section for more details. Mailchimp is operated by The Rocket Science Group LLC.
  • Order details will be encrypted and transferred to another server operated by our backup provider on a regular basis, as outlined in the Backed up Data section.

Enquiry Details

When completing our contact form or sending us an offline message through our live chat system (see Live Chat Data section for more information), the following information is passed on to our internal technical or sales support teams:

  • Name
  • Email
  • Any information inputted into the message field
The personally identifiable information we collect when filling out our contact form is used to ensure we can assist you with your enquiry in an efficient manner.

Our policies for email retention differ depending on the purpose of the email message, as well as the content of each particular message. Enquiries sent through this form will be kept at a minimum for as long as an enquiry or support case is still ongoing.

Emails may be archived for a longer period if we believe it necessary to keep the email as a record of fact (i.e. if we believe a dispute over the nature or timing of events may occur).

At most, email communications that do not need to be archived for any legal reasons (such as for accounting and VAT records, or if we believe an email may be relevant to any upcoming legal proceedings) will be kept for no longer than 2 years.

Consent: By submitting your details to our contact form, you have given clear consent for us to process your personal data for a specific purpose.

These details will never be passed onto a third party unless:

  • we have your express permission beforehand; or
  • are required to do so by law (see Introduction section).

Live Chat Data

Across the EasyGates Direct website, we use a live chat tool called Tawk.to to provide sales and technical support to visitors.

When you opt-in to Live Chat, Tawk.to sets a cookie on your machine containing a random unique identifier.

On Site Behaviour

When you opt-in use Live Chat, the following information about your on-site behaviour is transmitted to our support team:

  • What pages you navigate to.
  • When you end, maximise or minimise the live chat.
  • When you are typing a message

Contact Details and Chat Transcripts

In addition to the information above, we also require you to input the following information before engaging in live chat:

  • Name
  • Email address

The transcript of your chat is associated with your Contact Details stored in the Tawk.to system.

Offline Messages

If you use the live chat outside of EasyGates Ltd’s opening hours, the chat window will allow you to send us an Offline Message. As well as being stored in the Tawk.to system as a Chat Transcript, your details will be emailed to the EasyGates Support Team. This email will be handled as set out in the Enquiry Details section.

Your On-Site Behaviour is used to help our support staff to better assist you in your query. For example, by being able to what product you are viewing, our support team can give you more responsive and accurate advice.

At your request, we may use your Contact Details to assist you with your enquiry (such as checking whether your trade store account has been approved, or sending you additional materials like programming guides or brochures). If your issue is not solved or your query is not answered at the end of your live chat, we may use your contact details to provide additional support to you.

On Site Behaviour, Contact Details and Chat Transcripts

On the first weekday of each month (excluding Bank Holidays) we will remove all Live Chat Data that was created prior to the beginning of the previous month.

Your data will be held for no longer than two calendar months.

If you would like your data to be removed before it is scheduled to be deleted, please see the Your Data and Your Rights section.

Unique Identifier

The Unique Identifier cookie that the Tawk.to widget sets in your browser is set to expire after six months. If you would like to remove this unique identifier from your browser, please click here to opt-out of Live Chat.

Consent: By opting-in to live chat, you have given clear consent for us to process your personal data for a specific purpose.

If you would like to withdraw your consent to send us further behavioural data (see On Site Behaviour), please click here.

If you would like this information to be permanently removed from the Tawk.to system, please see the Your Data and Your Rights section.

Your Live Chat Data will be shared with our live chat provider, Tawk.to.

We do not hire any third-party support staff. You will be connected to a member of the EasyGates Support Team.

Backed up Data

The following personally identifiable data is backed up to a remote server (separate from our webserver) several times a day:

This data is encrypted using military-grade AES encryption standards before transport to the remote server, during transport, and when the data is at rest on the remote server.

This data is backed up regularly to minimise the potential data loss caused by system outages.

A “snapshot” of the data we store is taken several times and hour. These snapshots are stored on the remote server for seven days.

However, this snapshot of data will contain data older than seven days, in accordance with the retention policies outlined above for each type of data.

Legitimate interests: the processing is necessary for our legitimate interests or the legitimate interests of a third party unless there is a good reason to protect your personal data which overrides those legitimate interests.

Contract: processing this data is necessary to fulfil our contractual obligations to you

Backup data is transferred to a server operated by our backup provider Webhosting UK COM Limited (Company registration number 06471390).

Your Data and Your Rights

EasyGates Ltd cares deeply about your privacy. As such, whenever we handle data, we do so in accordance with the Data Protection Act 1998, the Privacy and Electronic Communications Directive 2002, the General Data Protection Regulation, and all other applicable regulations and laws.

Under the GDPR, you have the following rights with regards to your data:

Your Right How we will comply with GDPR
The right to be informed
  • We endeavour to provide you easily accessible information about how and why we collect and handle your data in a concise, transparent manner.
  • We aim to produce all such information in clear and plain language.
  • We will review our privacy policies on a regular basis, and update them whenever we change what data we process or how we handle it.
The right of access
  • We will comply with any requests to provide an individual with any data of theirs that we hold.
  • Access requests will be responded to free of charge and in a timely manner (at the latest within one month of receipt).
The right to rectification If you believe that any information we are holding about you is incorrect or incomplete, we will promptly correct any such information (at the latest within one month of receipt).
The right to erasure
  • Whenever we are legally allowed to do so, we will erase any data we hold when requested by the individual in question. For example, we will delete any user accounts from our websites or remove email addresses from marketing lists whenever a request is made.
  • In instances where we have to retain data for a certain period due to legal obligations, your data will be erased as soon as the legally binding period has passed. An example of data we are required to keep is accounting records for sales, which we are required to retain for 6 years in order to comply with the Companies Act 2006.
The right to restrict processing

We will comply with requests to restrict processing in accordance with the GDPR.

The right to data portability

We will comply with requests to transmit personal data to another controller in accordance with the GDPR.

The right to object

We will comply with objections to data processing in accordance with the GDPR.

Rights in relation to automated decision making and profiling

If we ever carry out any automated decision making and / or profiling, we will:

  • Inform you of the logic and nature of the automated decision making and / or profiling.
  • Take steps to prevent errors, bias and discrimination.
  • Comply with your right to challenge and request a review of any decision, and to obtain an explanation of the decision.
  • secure personal data in a way that is proportionate to the risk to the interests and rights of the individual, and that prevents discriminatory effects.

For more information about your data rights, please visit https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/

For more information about how to make a subject access request, please visit https://ico.org.uk/for-the-public/personal-information/

If you would to exercise any of the above rights (including removal, rectification and access of data) or simply have any questions, please contact us using the methods in the Contacting EasyGates Ltd section.

Acknowledgements

Contains public sector information licensed under the Open Government Licence v3.0.

Contacting EasyGates Ltd

By Post

EasyGates Ltd, Unit 16, James Scott Road, Halesowen, West Midlands, B63 2QT

By Telephone

01384 569 942

By Fax

0845 643 6814

By Email

info@easygatesdirect.co.uk