Privacy policy

PRIVACY NOTICE

EFFECTIVE DATE: 22 August 2022

At SAAHLU, we strive to provide the best shopping experience for our customers. This includes respecting your privacy and our commitment to safeguarding your personal data. 

This notice describes the information we collect or you share with us when you visit our website (regardless of where you visit it from), purchase products from SAAHLU, subscribe to any of our mailer lists, or otherwise interact with us across our website and media sites, how your data is used, stored and safeguarded, and your choices regarding this information. 

SCOPE

This policy outlines how we at SMSJ HOUSE LIMITED collects and processes your personal data through your use of this website (whether that is the desktop or app version), when you interact with us, including any data you may provide when you register an account and make purchases.

Our website and products are not, generally, intended for children under 13 years old. In general, children may access SAAHLU and our Services only with express consent of their parent or guardian. If you are a parent or guardian, please refer to the section below regarding Children’s Information.

It is important that you read this privacy policy together with any other policy on data processing or other notices we may provide on specific occasions so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them. 

DATA CONTROLLER AND CONTACT DETAILS

SMSJ HOUSE LIMITED is the data controller for the purposes of this privacy policy and is responsible for your personal data; all references to “we”, “use” or “our” refer to SMSJ HOUSE LIMITED

HOW TO CONTACT US ABOUT YOUR RIGHTS AND DATA

If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact us at contact@saahlu.com. 

We are regulated by the Information Commissioner’s Office and you have the right to make a complaint at any time to them. We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

PARTNERS & THIRD-PARTY LINKS

We utilise a range of third-party social media and communications organisations, including Facebook, and Instagram. We both receive and share data about you with these partners for the purposes of marketing our products and engaging with our consumer base.

Our Website and backend services are based on the Shopify platform and your data may be shared with Shopify in certain circumstances when you use our Website or purchase products from us. 

We may also include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

INFORMATION COLLECTED ABOUT YOU

We have set out below the personal data about you we may collect, use, store and transfer when you interact with us through SAAHLU. Personal data means any information from which you can identify you, it does not include information we collected on an anonymous basis.

  • Identity & Contact Data includes your email address, first name, surname, DoB, telephone number, username, delivery address, or similar identifier.

 

  • Financial & Transaction Data includes your payment card details, billing address, as well as details about payments to and from you and other details of any purchases you have made from us.

 

  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Website. 

 

  • Profile Data includes your username and password, purchases or orders made by you, your profile and account preferences, social media accounts, feedback and survey responses.  

 

  • Usage Data includes information about how you use our Website, including any content you post through our online communities, discussion boards, social media groups and leader boards. 

 

  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

We also collect, use and share aggregated data about you. This includes statistical or demographic data, which could be derived from your personal data but is not considered personal data in its own right as this data on its own would not allow anyone to directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.

We do not knowingly collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

How your data is collected

We use different methods to collect data from and about you including through:

Direct interactions. You may give us your Identity, Contact and Financial Data by signing up to SAAHLU through your use of our website making purchases, as well as by filling any forms or by corresponding with us. This includes personal data you provide when you:

  • create an account;
  • subscribe to our mailing lists;
  • make purchases; 
  • join or follow one of our social media pages;
  • link your social media account to us;
  • request marketing to be sent to you;
  • enter a competition, promotion or survey; or
  • give us feedback or contact us. 

Purchases. We will utilise and create Financial, Transaction, Profile, User and Communications Data when you make purchases with us. This includes personal data about:

  • your basket and purchase preferences;
  • your card and payment information;
  • your billing and shipping address;
  • information about delivery of your order; or,
  • your previous purchases with us; 
  • any feedback you have provided in respect of your purchases.

 

Automated technologies or interactions. As you interact with our Website, we automatically collect about the device you use when you interact with us, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. 

Third parties. We will receive personal data about you from various third parties as set out below: 

  • Social Media, such as Facebook and Instagram
  • Technical Data from analytics providers such as Google Analytics; 
  • Financial and Transaction Data from our providers of technical, payment and delivery services such as Shopify.

HOW WE USE YOUR INFORMATION

We collect, process, store and disclose personal data for a variety of different reasons, but in all cases when the law allows us to. We do not sell, share, disclose or use your data for anything else not covered by our policies.

The UK Data Protection Act 2018 and the General Data Protection Regulation (“GDPR”) requires that companies processing personal data of EU citizens set out the specific lawful basis on which they process that data. For the personal data identified in this notice we rely on the following lawful basis to process your data:

  1. Consent: when you register an account with SAAHLU we ask you to consent to us using your data for reasons such as processing your personal data for the purposes of marketing communications. You have the right to withdraw consent at any time by both deleting your SAAHLU account or by contacting us.
  2. Contractual Obligations: where we need to perform the contract we are about to enter into or have entered into with you, including the processing of your personal data in conjunction with your purchases of SAAHLU products.
  3. Regulatory or Legal Obligations: where we need to comply with a legal obligation.
  4. Legitimate Interests: where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

We have summarised below the various ways we use your personal data and our legal basis for doing so.

Purpose/Activity

Type of data

Lawful basis for processing including basis of legitimate interest

To register your SAAHLU account

(a) Identity 

(b) Contact

(c) Profile 

Performance of a contract with you

To facilitate and process your purchases including:

(a) Managing payments, fees and charges

(b) Collect and recover money owed to us

(a) Identity 

(b) Contact 

(c) Financial 

(d) Transaction 

(e) Marketing and Communications

(a) Performance of a contract with you 

(b) Necessary for our legitimate interests (to recover debts due to us)

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy

(b) Asking you to leave a review or take a survey

(c) Communicating with you about your orders or about our events.

(a) Identity 

(b) Contact 

(c) Profile 

(d) Marketing and Communications

(a) Performance of a contract with you 

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To enable you to partake in a prize draw, competition or complete a survey

(a) Identity 

(b) Contact 

(c) Profile 

(d) Usage 

(e) Marketing and Communications

(a) Performance of a contract with you 

(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)  

(a) Identity

(b) Contact

(c) Technical

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

(a) Identity 

(b) Contact 

(c) Profile 

(d) Usage 

(e) Marketing and Communications 

(f) Technical 

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

(a) Technical 

(b) Usage 

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

To make suggestions and recommendations to you about goods or services that may be of interest to you

(a) Identity 

(b) Contact 

(c) Technical 

(d) Usage 

(e) Profile 

(f) Marketing and Communications

Necessary for our legitimate interests (to develop our products/services and grow our business)

If you connect your social media to our respective channels.

(a) Identity 

(b) Contact 

(c) Technical 

(d) Usage 

(e) Profile 

(f) Marketing and Communications

(a) Performance of a contract with you 

(b) Consent (provided to the third-party when you link your accounts)

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

 

MARKETING

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. In general we employ the following data control mechanisms when we use your personal data for the purpose of direct marketing:

Consent

When you register for an account on SAAHLU, you are invited to consent to receiving marketing and other promotional information from us. You may withdraw this consent at any time by contacting us. Withdrawing consent will not prevent us from sending service messaging about SAAHLU (such as planned upgrades, changes to our terms and policies or about your product purchases).

Marketing-linked purchases

Where you have registered an account and made purchases, we will assume that you are interested in receiving marketing materials about other similar products on SAAHLU, including any promotional sales or special events. You can opt-out of receiving such communications at any time.

Promotional offers from us 

Where you have provided your consent, we may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you. 

You will receive marketing communications from us if you have requested information from us or made purchase from us and you have not opted out of receiving that marketing. Where you have made a purchase through us within the last 12-months we will automatically assume you have opted in to receive these communications unless you inform us otherwise (either at the time of purchase or through opting out).

Third-party marketing 

We will get your express opt-in consent before we share your personal data with any third party for marketing purposes. 

Opting out

You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time. 

Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase, warranty registration, product/service experience or other transactions.

COOKIES AND OTHER TECHNOLOGIES

Cookies come in a variety of forms but are essentially small data files used to collect and store information about you. We use them on our website for a variety of different functions: 

  • for the smooth and safe operation of our website;
  • to manage your preferences and remember you for future visits;
  • to analyse how you use our website in order to continually make improvements.

The majority of these cookies are linked to your browser session (session cookies) and disappear once you close your browser. Others remain on your device for a longer period (persistent cookies). 

For further information about the cookies we use, please see our Cookie Policy.

INFORMATION SHARING AND DISCLOSURE

We share the information we collect or that is provided to us as follows:

Sharing with our Partners

We may share your personal data with the parties set out below for the purposes we have identified above.

External Third Parties, who help us in providing our website and our Services. Currently, we use the following trusted Partners:

  • Payment Providers: we partner with Shopify  to securely process payments in respect of any purchases you make with SAAHLU;
  • Shopify, who host our platform, and e-commerce store and provide various aspects of our website.
  • Our Mailing and marketing providers (including Shopify): to send marketing information to you and manage your preferences.
  • Our logistics partners (such as Allegro Logistics), who supply SAAHLU products in your territory.
  • Our delivery partners (such as DPD etc) who help us in delivering products to you and processing any returns.
  • Social Media Providers (such as Facebook and Instagram).
  • Analytics providers (such as Google Analytics): to help us analyse who users interact and use SAAHLU which we then use to improve our website and user experience.

Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy. 

International Transfers

Unless identified, your data is hosted and processed within the UK or the EEA. Where we do utilize a third-party located outside the UK or the EEA, we ensure that any transfers are done on the basis of compliant transfer mechanisms.

HOW WE SAFEGUARD YOUR DATA

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. 

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

RETENTION AND DELETION

As a general rule, we retain your account data for as long as you keep your SAAHLU account active. In the event you decide to delete your account, we permanently delete your account data within 14 working days after closure of your account.

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

In some circumstances you can ask us to delete your data by contact us (see the below section for further information).

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you. 

YOUR DATA, YOUR RIGHTS

You have particulars rights to your data. In particular, if you are a citizen of the UK or an EU country you have a wide range of rights with regards to your data under the UK Data Protection Act 2018 and the General Data Protection Regulation (“GDPR”).

You can enforce your rights by contacting us, or in most cases, by deleting your SAAHLU account.

  1. Right to Correction: if you believe any of the information on your profile to be inaccurate you have a right to request that we correct this. This right also extends to various other information we collect about you which you can request a copy of (see Right to Copies below).
  2. Right to Copies of your data: you have a right to request a copy of the information that we hold about you along with an explanation from us as to why we process that information. We will provide this information to you free of charge for a first request, but will charge for reasonable administrative costs for further requests.
  3. Right to erasure: you have a right to request the deletion of your data at any time. If you submit such a request to us we will consider carefully and reply with an explanation as to why we are required to retain certain information either by law or for our own legitimate reasons. Where, after review, we identify any data we do not need to retain for these purposes, we will delete that data as per your request.
  4. Right to object or complain: you have a right to complain about how we are processing your data to our principal Data Protection Authority, the Information Commissioner’s Office here or in writing at the following address:

Customer Contact

Information Commissioner's Office

Wycliffe House

Water Lane

Wilmslow

SK9 5A

Should you have any concerns about how we are processing your data, we invite that you submit those questions to our contact@saahlu.com.

 

UPDATES TO OUR POLICY

As we further enhance our website and improve our services, we may make changes to this policy from time to time. If we make any major changes, or any changes which directly affect the services provided to you or the data collected or processed by us, we will notify you of those changes by a prominent banner on our website. However, we encourage you to periodically review this policy for the most up to date version.