In this Privacy Statement, we describe who we are, how and for which purposes we process your personal data within The Sweet Stop, how you can exercise your privacy rights, and all other information that may be relevant to you.
We have done our best to provide you with all information in a clear and readable format. However, if you have any questions about our use of your personal data after reading this Privacy Statement, you can contact us through the contact details provided below.
Who are we?
The Sweet Stop is the data controller for The Sweet Stop activities. Our contact details are:
contact@the-sweet-stop.co.uk
For which purposes do we process your personal data?
The Sweet Stop processes your personal data for the following purposes:
We process your personal data to prepare, receive and carry out the purchase agreement(s) as agreed upon.
Back office activities – We process your personal data for administrative and financial business activities, such as reporting and the managing and processing of invoices and collections.
Communication, marketing and loyalty program purposes – We process your personal data for the purposes of customer service and support, to manage our relationship with you, to carry out marketing activities, to make (personalised) offers, to include you in our loyalty program, and/or to provide and share information about our services.
Legal purposes – We process your personal data for identification purposes, to counter fraud, to perform audits, to initiate legal action, to secure safety within the company and to comply with legal obligations.
What personal data do we collect about you?
Contact details (name, address, e-mail, telephone number)
Company details (address, VAT number,)
Order details (date and item of purchase, order status, order amount, order price, etc.)
Customer service details (contact with our customer service or digital and/or written correspondence)
Web details (cookies, etc.)
On which legal grounds do we base the processing of your personal data?
To be lawful, each processing of personal data has to be based on a so called ‘legal ground’ as listed in the EU General Data Protection Regulation (GDPR). We process personal data associated with Cold Candy LTD based on four legal grounds;
for the performance of a (service) contract with you; or
(3) for compliance with a legal obligation; or
(4) for legitimate interests pursued by us; or
(4) your consent.
Performance of a contract
We use your personal data for processing necessary for performance of the service contract with you. Without this data, we would not be able to fulfil our side of the contract. The processing of orders and service requests falls under this legal ground.
Legal obligation
We are legally obliged to process your personal data in order to comply with fiscal and other legal obligations.
Legitimate interest
We use your personal data for our legitimate interests:
To be able to maintain a lasting relationship with you as a customer and to offer you products and services (e.g. direct marketing).
To be able to detect fraud and security incidents on our website.
To defend ourselves in legal proceedings.
To improve the effectiveness of our service through statistical analysis
We may use personal data in a personal, pseudonymous form to understand how we can develop and improve the service, as well as for reporting purposes, general statistical and analytical purposes. When circumstances make this necessary we may process personal data for fraud investigation or to fulfil legal obligations. Processing personal data for these purposes serves a legitimate business interest of ours.
Consent
In those cases where the previous three legal grounds do not apply, we process data with your unambiguous consent.
Note that you can always withdraw your given consent. Under the headline ‘Can you withdraw you given consent later on?’ you can read how to do so.
To whom do we provide your personal data?
We can provide your personal data to third parties in accordance with this Privacy Statement and in so far as permitted by law. Without your consent, we will not provide your personal data to recipients for their own marketing purposes.
Your personal data can be received by the following categories of recipients:
Internal Departments and Group companies
We may share personal data internally with other departments (such as Accounts Receivable) and with other entities of The Sweet Stop for the purpose of providing you with information, products and/or services (such as registration and customer support), the development of new products, websites, applications, services, promotions and communication, and to prevent, trace and examine possible illegal activities, infringements of our policies, fraud and/or breaches of our data security.
Authorities
We may provide your personal data to supervisory authorities such as Tax and Customs Administration, the police and other statutory bodies. We provide your personal data:
To comply with a statutory obligation or court order; or
If this is necessary to prevent, trace or prosecute criminal acts; or
If this is necessary to enforce our policies, or to protect the rights and freedoms of others.
Business service companies (data processors)
We make use of business service companies to help us execute our business. These organisations act only on our instructions and are contractually bound by us not to use your data for their own purposes.
Payment service providers
When you purchase a service/product, you will also receive a request to provide your payment details. Those personal data may be collected and processed directly by the payment service provider. This provider is responsible for processing your payment details within the limits set by law.
Other
In certain cases, we may provide your personal data to third parties. We refer specifically to third parties which belong to the The Sweet Stop or parties which will be part of The Sweet Stop and/or its legal successor as a result of a restructuring, merger or acquisition.
How do we store your personal data?
Your personal data will be removed or made anonymous when your personal data is no longer necessary for the purposes set out in this privacy statement.
There are instances where certain elements of your personal data are stored for a longer period of time due to certain legal obligations set out by public institutions. We may also store elements of your personal data for our own legitimate interest, such as detecting fraud, handling potential disputes, or facilitating our contractual arrangements with third parties such as vendors.
How can you exercise your privacy rights (data subject rights)?
At any desired moment, you can request to access, rectify or erase your personal data or you can object to direct marketing and profiling. In addition to this, you may also have the right of restriction of processing concerning your personal data, the right to object to processing as well as the right to data portability. These rights are known as your ‘data subject rights’.
To invoke your data subject rights, please contact us by using the contact details at the bottom of this Privacy Statement.
Please keep in mind that we may ask for additional information to verify your identity.
If you no longer want to receive direct marketing communication, please contact us by using the contact details at the bottom of this Privacy Statement.
Can you withdraw your consent?
Once given, you may always withdraw your consent. Please keep in mind that withdrawal does not have a retrospective effect.
You can withdraw your consent for commercial communications using the unsubscribe link in the last communication you received.
If you want to withdraw your consent for other processing activities, please contact us by using the contact details at the bottom of this Privacy Statement.