Privacy Policy

HJ Extensions GDPR Privacy Policy

We (HJ Extensions) collect personal information from you when you complete our online contact form at www.hjextensions.co.uk we use this information to ensure we can contact you in reply to your questions and enquiries.

The information we collect is:

  • Your name – so we know what to call you when we write back to you or call you.
  • Email address – so we can email you a response to your question/enquiry.
  • Telephone number – we’ll only call you if you request so in your message or we receive no response to our email within 2 working days.
  • Subject – To guide us on your question/enquiry.
  • Message – so we know what you would like to know from us.

We use the latest secure server technology to ensure this information is protected to the highest standards. We will store personal data for a period of 15 years after your last interaction with our website.

GENERAL DATA PROTECTION REGULATION (GDPR)

HJ Extensions are bound by General Data Protection Regulation (GDPR).

The only circumstance where we may share some of your data with others:

  1. In the unlikely event that our business assets are ever sold to or purchased by another company. Our data records are part of our business.

Right of Access

You have the right to access your personal data and supplementary information. The right of access allows you to be aware of and verify the lawfulness of the processing. You can make a request verbally or in writing. Details of how to make a request are at the bottom of the page.

Right to Rectification

The GDPR includes a right for you to have inaccurate personal data rectified, or completed if it is incomplete. You can make a request verbally or in writing. Details of how to make a request are at the bottom of the page.

Right to Erasure

You have a right to have your personal data erased. The right to erasure is also known as ‘the right to be forgotten’. The right is not absolute and only applies if:

  • The personal data is no longer necessary for the purpose which you originally collected or processed it for;
  • HJ Extensions is relying on consent as its lawful basis for holding the data, and you withdraw your consent;
  • HJ Extensions is relying on legitimate interests as its basis for processing, you object to the processing of your data, and there is no overriding legitimate interest to continue this processing;
  • HJ Extensions is processing the personal data for direct marketing purposes and you object to that processing;
  • HJ Extensions has processed the personal data unlawfully (ie in breach of the lawfulness requirement of the 1st principle);
  • HJ Extensions has to do it to comply with a legal obligation; or
  • HJ Extensions has processed the personal data to offer information society services to a child.

The right to erasure does not apply if processing is necessary for one of the following reasons:

  • To exercise the right of freedom of expression and information;
  • To comply with a legal obligation;
  • For the performance of a task carried out in the public interest or in the exercise of official authority;
  • For archiving purposes in the public interest, scientific research historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing; or
  • For the establishment, exercise or defence of legal claims.

The GDPR also specifies two circumstances where the right to erasure will not apply to special category data:

  • If the processing is necessary for public health purposes in the public interest (eg protecting against serious cross-border threats to health, or ensuring high standards of quality and safety of health care and of medicinal products or medical devices); or
  • If the processing is necessary for the purposes of preventative or occupational medicine (eg where the processing is necessary for the working capacity of an employee; for medical diagnosis; for the provision of health or social care; or for the management of health or social care systems or services). This only applies where the data is being processed by or under the responsibility of a professional subject to a legal obligation of professional secrecy (eg a health professional).

You can make a request verbally or in writing. Details of how to make a request are at the bottom of the page.

Right to Restrict Processing

You have the right to restrict the processing of your personal data in certain circumstances. This means that you can limit the way that HJ Extensions uses your data. This is an alternative to requesting the erasure of your data.

You have the right to restrict the processing of your personal data where you have a particular reason for wanting the restriction. This may be because you have issues with the content of the information HJ Extensions holds or HJ Extensions have processed your data. In most cases we will only need to have the restriction in place for a certain period of time.

You have the right to request that we restrict the processing of your personal data in the following circumstances:

  • You contest the accuracy of your personal data and HJ Extensions is verifying the accuracy of the data;
  • The data has been unlawfully processed (ie in breach of the lawfulness requirement of the first principle of the GDPR) and you oppose erasure and you request restriction instead;
  • HJ Extensions no longer need the personal data but you need to keep it in order to establish, exercise or defend a legal claim; or
  • You have objected to HJ Extensions processing your data under Article 21(1) of the GDPR, and HJ Extensions is considering whether our legitimate grounds override those of yours.

Although this is distinct from the right to rectification and the right to object, there are close links between those rights and the right to restrict processing:

  • if you have challenged the accuracy of HJ Extensions data and asked HJ Extensions to rectify it (Article 16), you also have a right to request HJ Extensions restrict processing HJ Extensions considers your rectification request; or
  • if you exercises your right to object under Article 21(1), you also have a right to request HJ Extensions restrict processing while HJ Extensions considers your objection request.

You can make a request verbally or in writing. Details of how to make a request are at the bottom of the page.

Right to Data Portability

The right to data portability allows you to obtain and reuse your personal data for your own purposes across different services. It allows you to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability.

You can make a request verbally or in writing. Details of how to make a request are at the bottom of the page.

Right to Object

You have the right to object to processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling); direct marketing (including profiling); and processing for purposes of scientific/historical research and statistics.

HJ Extensions will stop processing personal data for direct marketing purposes as soon as we receive an objection. There are no exemptions or grounds to refuse. HJ Extensions must deal with an objection to processing for direct marketing at any time and free of charge.

You can make a request verbally or in writing. Details of how to make a request are at the bottom of the page.

Rights related to automated decision making including profiling

Automated individual decision-making is a decision made by automated means without any human involvement.

Examples of this include:

  • An online decision to award a loan; and
  • A recruitment aptitude test which uses pre-programmed algorithms and criteria.
  • The GDPR has provisions on:
    • automated individual decision-making (making a decision solely by automated means without any human involvement); and
    • profiling (automated processing of personal data to evaluate certain things about an individual). Profiling can be part of an automated decision-making process.
  • The GDPR applies to all automated individual decision-making and profiling.
  • Article 22 of the GDPR has additional rules to protect individuals if you are carrying out solely automated decision-making that has legal or similarly significant effects on them.
  • You can only carry out this type of decision-making where the decision is:
    • necessary for the entry into or performance of a contract; or
    • authorised by Union or Member state law applicable to the controller; or
    • based on the individual’s explicit consent.
  • You must identify whether any of your processing falls under Article 22 and, if so, make sure that you:
    • give individuals information about the processing;
    • introduce simple ways for them to request human intervention or challenge a decision;
    • carry out regular checks to make sure that your systems are working as intended.

You can make a request verbally or in writing. Details of how to make a request are at the bottom of the page.

How to make a request regarding your personal data.

To see all the information we have about you, to correct any inaccuracies, to delete your personal data or any other enquiry to do with personal data please write to:

The Data Protection Officer

HJ Extensions
Office 3

Winnings Courtyard

Newburn

Newcastle Upon Tyne

NE15 8HA

 

If you have questions about your personal data or our privacy policy, please contact us at e hjextensions@hotmail.co.uk You can also call us on 07719545235. We will need to verify the identity of the person making the request. If the request for information about your personal data is made electronically, we will provide the information in a commonly used electronic format. Information will normally be provided within 1 month of receipt. Where requests are complex or numerous we may extend the response period by a further two months. If this is the case, we will inform you within one month of the receipt of the request and explain why the extension is necessary. Where requests are manifestly unfounded or excessive, in particular because they are repetitive, we may:

  • charge a reasonable fee taking into account the administrative costs of providing the information; or
  • refuse to respond.

If we refuse to respond to a request, we will explain why, informing you of your right to complain to the supervisory authority and to a judicial remedy without undue delay and at the latest within one month.

You have the right to contact the Information Commissioners Office regarding how HJ Extensions uses your personal Data. They can be contacted via the ICO helpline telephone: 0303 123 1113.

WEBSITE PRIVACY STATEMENT

SECTION 1 – WHAT DO WE DO WITH YOUR INFORMATION?

When you make an online enquiry through our ‘contact’ tab or email us from the email address provided on the website, we collect the personal information you give us such as your name, phone number and email address.

When you browse our site, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.

Email marketing (if applicable): With your permission, we may send you emails about new products, special offers and other updates.

SECTION 2 – CONSENT

How do you get my consent?

When you provide us with personal information through an enquiry/contact form you provide your consent to our collecting it and using it for that specific reason only.

If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent and will ask you to specify your preference for all your marketing channels rather than a single ‘unsubscribe’ option and will also provide you with an opportunity to say no.

How do I withdraw my consent?

If after you opt-in, you change your mind, you may withdraw your consent for us to contact you by contacting us at hjextensions@hotmail.co.uk or mailing us at:

HJ Extensions
Office 3

Winnings Courtyard

Newburn

Newcastle Upon Tyne

NE15 8HA

 

SECTION 3 –

We do not use an online e-commerce platform that allows us to sell our products to you. If this changes in the future, we will update our policies and inform you.

Any future e commerce data collected would be stored through the host’s data storage, databases and the general application systems. They would store your data on a secure server behind a firewall. This provider would also bound by General Data Protection Regulation (GDPR).

SECTION 4 – THIRD-PARTY SERVICES

In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.

For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.

In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.

As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.

Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.

Links

When you click on links on our site, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.

SECTION 5 – SECURITY

To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.

Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.

COOKIES

We use cookies when you visit our website, or mobile website and may collect information using them.

Cookies are small bits of text that are downloaded to your computer or mobile device when you visit a website. Your browser sends these cookies back to the website every time you visit the site again (see our cookie policy for more details).

SECTION 6 – AGE OF CONSENT

By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.

SECTION 7 – CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.

QUESTIONS AND CONTACT INFORMATION

If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Data Controller at hjextensions@hotmail.co.uk or by mail at HJ Extensions

[Re: Data Controller] [HJ Extensions
Office 3

Winnings Courtyard

Newburn

Newcastle Upon Tyne

NE15 8HA]