Privacy Policy & Cookie Consent

This policy is intended to provide information about how Tower Supplies will use (or “process”) personal data about individuals including: its staff (and prospective staff); users of its digital services; its customers (including prospective customers), and the employees of its customers; its suppliers (including prospective suppliers), and the employees of its suppliers.

This Privacy Notice applies alongside any other information that Tower Supplies may provide about its use of personal data, for example when collecting data via an online or paper form.

This Privacy Notice also applies in addition to Tower Supplies’ other relevant terms and conditions and policies, including:

Tower Supplies Terms of Trading;

any contract between Tower Supplies and its staff or customers;

the Tower Supplies’ CCTV policy;

the Tower Supplies’ retention of records policy;

as to how concerns or incidents are recorded;

the Tower Supplies’ IT policies; and

the Tower Supplies’ health and safety policies, including:

Anyone who works for, or acts on behalf of, the Tower Supplies (including staff, work experience and service providers) should also be aware of and comply with this Privacy Notice and the Tower Supplies Data Protection Policy for staff, which also provides further information about how personal data about those individuals will be used.

This privacy notice aims to explain:

  • Why we need to process personal data;
  • The types of personal data that we collect and process;
  • How we collect data;
  • The legal basis of our use of your personal data;
  • Where we disclosure your information to other parties;
  • How long we will keep your information for;
  • Your rights in regard to your personal data;
  • Our use of cookies on our website;
  • Our use of data collected from IT systems and assets;
  • How we protect your data;
  • Your acceptance of these terms;
  • How to contact us.

Why Tower Supplies needs to process personal data

To carry out its ordinary duties to staff and customers, Tower Supplies needs to process a range of personal data about individuals as part of its daily operations.

Some of this activity Tower Supplies will need to carry out to fulfil its legal rights, duties or obligations – including those under a contract with its staff, or customers.

Other uses of personal data will be made in accordance with Tower Supplies’ legitimate interests, provided that these are not outweighed by the impact on individuals and provided it does not involve special category or sensitive types of data.

The types of personal data we collect and process

This may include the following categories, by way of example:

  • names, addresses, telephone numbers, e-mail addresses and other contact details;
  • garment sizing details requiring for supplying related garments;
  • bank/card details and other financial information, e.g. about customers who purchase directly from Tower Supplies;
  • online identifiers, e.g. IP addresses of users/devices accessing digital services;
  • personnel files;
  • where appropriate, information about individuals’ health and welfare, and contact details for their next of kin;
  • references given or received by Tower Supplies about prospective employees, current employees, and relevant information provided by previous employers and/or other professionals or organisations working with employees;
  • correspondence with and concerning staff and customers, including recorded telephone communications; and
  • images captured by the Tower Supplies CCTV system (in accordance with the Tower Supplies CCTV policy);

How Tower Supplies collects data

Generally, Tower Supplies receives personal data from the individual directly. This may be via a sales order, an account application form, correspondence, submission of a CV or simply in the ordinary course of interaction or communication, including use of digital services.

However, in some cases personal data will be supplied by third parties (for example via a business customer providing personal data of an employee to fulfil an order, or from an agency with whom an individual has provided data for the purposes of seeking employment).

The legal basis of our use of your personal data

Tower Supplies identifies that personal data is used under the following legal bases:

On the basis of fulfilling our contractual obligations:

  • To enable us to run the business and manage our relationship with employees effectively, lawfully and appropriately, during the recruitment process, and whilst within Tower Supplies employment.
  • To safeguard employees’ welfare and meet our duty of care.
  • To give and receive information and references about past, current and prospective employment.
  • For managing our relationships with our suppliers including assessing a suppliers’ qualification or conducting supply-chain assurance activity on our suppliers.
  • To fulfil customer orders where a business customer has provided delivery information such as names, addresses and contact details to enable delivery of goods to one of their sites, employees or contractors.

On the basis of its legitimate interests:

  • To conduct day-to-day business operations such as the recording of personal data in Management Review records, to format personal data for storage within the businesses’ CRM, and the exchange data with Agencies to facilitate the placement of temporary staff.
  • To monitor (as appropriate) use of Tower Supplies’ IT and communications systems in accordance with the Tower Supplies’ IT acceptable use policy;
  • For security purposes, including CCTV in accordance with the Tower Supplies’ CCTV policy;
  • To carry out or cooperate with any Tower Supplies or external complaints, disciplinary or investigation process; and
  • Where otherwise reasonably necessary for Tower Supplies’ purposes, including to obtain appropriate professional advice and insurance for Tower Supplies.
  • To provide training and educational services to support employees in meeting their roles and responsibilities.

On the basis of meeting our legal or regulatory obligations:

  • For the purposes of research and statistical analysis, including that imposed or provided for by law (such as tax, diversity or gender pay gap analysis);
  • To enable relevant authorities to monitor Tower Supplies’ performance and to intervene or assist with incidents as appropriate;

On the basis of consent:

  • To receive speculative submission of job search letters and CVs.
  • To distribute newsletters and marketing material to our customer base such as when a customer or prospective customer signs up to receive marketing emails via our website.

Where Tower Supplies is relying on consent as a means to process personal data, any person may withdraw this consent at any time.

In addition, Tower Supplies will on occasion need to process special category personal data (e.g. concerning health, ethnicity, religion, biometrics or gender) or criminal records information (such as when carrying out DBS checks) in accordance with rights or duties imposed on it by law, or from time to time by explicit consent where required. These reasons will include:

  • As part of any Tower Supplies or external complaints, disciplinary or investigation process that involves such data; or
  • For legal and regulatory purposes (for example diversity monitoring and health and safety) and to comply with its legal obligations and duties of care.

On The basis of Vital Interests:

  • To safeguard employees’ welfare and to take appropriate action in the event of an emergency, incident or accident, including by disclosing details of an individual’s medical condition or other relevant information where it is in the individual’s interests to do so: for example, for medical advice and cooperation with police, for insurance purposes or to caterers or organisers of functions to be made aware of dietary or medical needs;

Disclosure of your details to others

Occasionally, Tower Supplies will need to share personal information relating to its operations with third parties, such as:

  • professional advisers (e.g. lawyers and accountants);
  • government authorities (e.g. HMRC, DfE, police or the local authority); and
  • appropriate regulatory bodies

For the most part, personal data collected by Tower Supplies will remain within the business and will be processed by appropriate individuals only in accordance with access protocols (i.e. on a ‘need to know’ basis). Particularly strict rules of access apply in the context of medical records held and accessed only by the HR Manager or otherwise only with the express consent of the individual.

Finally, in accordance with Data Protection Law, some of the Tower Supplies’ processing activity is carried out on its behalf by third parties, such as IT support providers, web developers or cloud storage and other digital service providers. This is always subject to contractual assurances that personal data will be kept securely and only in accordance with the Tower Supplies’ specific directions.

How long we will keep your information for?

Tower Supplies will retain personal data securely and only in line with how long it is necessary to keep for a legitimate and lawful reason. Typically, the legal recommendation for how long to keep ordinary staff personnel files is up to 7 years following departure from the business. However, incident reports and safeguarding files will need to be kept much longer, in accordance with specific legal requirements.

We have defined retention periods for different categories of personnel data according to these principles and this information is held in the Tower Supplies Retention Policy.

Your rights

Individuals have various rights under Data Protection Law to access and understand personal data about them held by Tower Supplies, and in some cases ask for it to be erased or amended or have it transferred to others, or for Tower Supplies to stop processing it – but subject to certain exemptions and limitations.

Any individual wishing to access or amend their personal data, or wishing it to be transferred to another person or organisation, or who has some other objection to how their personal data is used, should put their request in writing (see ‘Contact us’ section below).

Tower Supplies will endeavour to respond to any such written requests as soon as is reasonably practicable and in any event within statutory time-limits (which is one month in the case of requests for access to information).

Tower Supplies will be better able to respond quickly to smaller, targeted requests for information. If the request for information is manifestly excessive or similar to previous requests, Tower Supplies may ask you to reconsider, or require a proportionate fee (where Data Protection Law allows it).

The right of access is limited to your own personal data, and certain data is exempt from the right of access. This will include information which identifies other individuals, or information which is subject to legal privilege (for example legal advice given to or sought by Tower Supplies, or documents prepared in connection with a legal action).

The rights under Data Protection Law belong to the individual to whom the data relates.

Access of our digital services and our use of cookies

When someone visits our websites, we collect standard internet log information and details of visitor behaviour patterns. This is to allow us to monitor user behaviour and visit rates. This information is anonymous. Where we gather personal information, this will be made clear.

Our website makes use of cookies to improve your browsing experience. A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.

Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.

Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies.

We use cookies for the following purposes:

(a) analysis - we use cookies to help us to analyse the use and performance of our website and services;

(b) user experience – we use cookies to personalise the user experience; and

(c) cookie consent - we use cookies to store your preferences in relation to the use of cookies more generally.

Where we link to third party websites, they will have their own privacy and cookies policies and it is your responsibility to review these. We cannot accept any responsibility or liability for the policies of third party websites.

Force24 Cookies & Tracking

Our organisation utilises Force24’s marketing automation platform.

Force24 cookies are first-party cookies and are enabled at the point of cookie acceptance on this website. They allow us to understand our audience engagement thus allowing better optimisation of marketing activity.

f24_autoId – This is a temporary identifier on a local machine or phone browser that helps us track anonymous information to be later married up with f24_personid. If this is left anonymous it will be deleted after 6 months . Non-essential, first party, 10 years, persistent.

f24_personId – This is an ID generated per individual contact in the Force24 system to be able to track behaviour and form submissions into the Force24 system from outside sources per user. This is used for personalisation and ability to segment decisions for further communications. Non-essential, first party, 10 years, persistent.

The information stored by Force24 cookies remains anonymous until:

  • Our website is visited via clicking from an email or SMS message, sent via the Force24 platform and cookies are accepted on the website.
  • A user of the website completes a form containing email address from either our website or our Force24 landing pages.

The Force24 cookies will remain on a device for 10 years unless they are deleted.

Other Tracking

We also use similar technologies including tracking pixels and link tracking to monitor your viewing activities

Device & browser type and open statistics

All emails have a tracking pixel ( a tiny invisible image ) with a query string in the URL. Within the URL we have user details to identify who opened an email for statistical purposes.

Link Tracking

All links within emails and SMS messages sent from the Force24 platform contain a unique tracking reference, this reference help us identify who clicked an email for statistical purposes.

How we protect your data

We conduct information processing in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures.

Your acceptance of these terms

Through engaging with Tower Supplies, you signify your acceptance of this policy. Your continued engagement following a change to this policy will be deemed your acceptance of those changes.

How to contact us

If you have any questions about this privacy notice or our treatment of your personal

data, including withdrawal of previously given consent, please write to us by email or by letter to this address:

data.protection@towersupplies.com

Data Projection, Tower Supplies, 3 Yarrow Road, Poole, Dorset. BH12 4TS

List of cookies we collect

The table below lists the cookies we collect and what information they store.

COOKIE nameCOOKIE Description
CARTThe association with your shopping cart.
CATEGORY_INFOStores the category info on the page, that allows to display pages more quickly.
COMPAREThe items that you have in the Compare Products list.
CURRENCYYour preferred currency
CUSTOMERAn encrypted version of your customer id with the store.
CUSTOMER_AUTHAn indicator if you are currently logged into the store.
CUSTOMER_INFOAn encrypted version of the customer group you belong to.
CUSTOMER_SEGMENT_IDSStores the Customer Segment ID
EXTERNAL_NO_CACHEA flag, which indicates whether caching is disabled or not.
FRONTENDYou sesssion ID on the server.
GUEST-VIEWAllows guests to edit their orders.
LAST_CATEGORYThe last category you visited.
LAST_PRODUCTThe most recent product you have viewed.
NEWMESSAGEIndicates whether a new message has been received.
NO_CACHEIndicates whether it is allowed to use cache.
PERSISTENT_SHOPPING_CARTA link to information about your cart and viewing history if you have asked the site.
POLLThe ID of any polls you have recently voted in.
POLLNInformation on what polls you have voted on.
RECENTLYCOMPAREDThe items that you have recently compared.
STFInformation on products you have emailed to friends.
STOREThe store view or language you have selected.
USER_ALLOWED_SAVE_COOKIEIndicates whether a customer allowed to use cookies.
VIEWED_PRODUCT_IDSThe products that you have recently viewed.
WISHLISTAn encrypted list of products added to your Wishlist.
WISHLIST_CNTThe number of items in your Wishlist.