Grafton International Limited ("We") are committed to protecting and respecting your privacy.
This policy and any other documents referred to on it sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of the Data Protection Act 1998 (the Act), the data controller is Grafton International Limited of 301 Relay Drive, Relay Business Park, Tamworth, Staffordshire B77 5PT.
INFORMATION WE MAY COLLECT FROM YOU
We may collect and process the following data about you: • Information that you provide by filling in forms on our site www.graftons.co.uk (our site). This includes information provided at the time of registering to use our site, subscribing to our service, posting material or requesting further services. We may also ask you for information when you report a problem with our site.
• If you contact us, we may keep a record of that correspondence.
• We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
• Details of transactions you carry out through our site and of the fulfilment of your orders.
• Details of your visits to our site including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise and the resources that you access.
We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our third parties. This is statistical data about our users' browsing actions and patterns, and does not identify any individual.
Cookies help us to improve our site and to deliver a better and more personalised service. Some of the cookies we use are essential for the site to operate.
The cookies we use are:
Name: PSCMS-SESSION [32 Character randomly generated salted MD5 hash]
Expires: At End of Session
The PSMS_SESSION cookie is a randomly generated used to allow users to log in. When the user logs in, the value of the cookie is stored in the contact_e_sessions table of the web database against their contact ID so that when they browse the site they do not have to log in each time. The session ID is also used to track ecommerce baskets that are modified before a user has logged in, upon logging in any baskets created with their session ID will be transferred to the contact they have logged in as. Logging out will delete the contact_e_session record in the database. Closing the browser will delete the cookie.
Value: [22 character randomly generated base 64 hash]
Path: /cms and /
Expires: At End of Session
The two JSESSIONID cookies are automatically generated by the java server but are not used. The / cookie is generated by the url rewrite package and the /cms cookie is generated by the CMS engine itself. Depending on your path through the site, you may end up with one or both of these cookies, but they are not in use and we have no plan to use them in future. Denying these cookies or deleting them at any point should have no effect.
We also have Google Analytics running on the site. Further details of this can be found at: http://code.google.com/apis/analytics/docs/concepts/gaConceptsCookies.html
WHERE WE STORE YOUR PERSONAL DATA
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
USES MADE OF THE INFORMATION
We use information held about you in the following ways:
• To ensure that content from our site is presented in the most effective manner for you and for your computer.
• To provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes.
• To carry out our obligations arising from any contracts entered into between you and us.
• To notify you about changes to our service.
We may also use your data, or permit selected third parties to use your data, to provide you with information about goods and services which may be of interest to you and we or they may contact you about these by post or telephone.
If you are an existing customer, we will only contact you by electronic means (e-mail or SMS) with information about goods and services similar to those which were the subject of a previous sale to you.
If you are a new customer, and where we permit selected third parties to use your data, we (or they) will contact you by electronic means only if you have consented to this.
If you do not want us to use your data in this way please let us know.
We do not disclose information about identifiable individuals to our advertisers, but we may provide them with aggregate information about our users (for example, we may inform them that 500 men aged under 30 have clicked on their advertisement on any given day). We may also use such aggregate information to help advertisers reach the kind of audience they want to target (for example, women in SW1). We may make use of the personal data we have collected from you to enable us to comply with our advertisers' wishes by displaying their advertisement to that target audience.
DISCLOSURE OF YOUR INFORMATION
We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
We may disclose your personal information to third parties:
• In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
• If Grafton International Limited or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
• If we are under a duty to disclose or share your personal data in order to comply with any legal obligation or in order to enforce or apply any agreements with you or to protect the rights, property, or safety of Grafton International Limited, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
You have the right to ask us not to process your personal data for marketing purposes. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at 301 Relay Drive, Relay Business Park, Tamworth, Staffordshire B77 5PT or firstname.lastname@example.org.
Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
ACCESS TO INFORMATION
The Act gives you the right to access information held about you. Your right of access can be exercised in accordance with the Act. Any access request may be subject to a fee of £10 to meet our costs in providing you with details of the information we hold about you.