1.1 William Morgan Group, composed of North Oxford Ltd and Wollaston Motors Ltd together with any group companies (“we” “us” “our”) are committed to protecting and respecting your privacy. For the purposes of data protection legislation, we are the data controller and we will process your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 and national laws which relate to the processing of personal data. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
- VISITORS TO OUR WEBSITE
2.1.1 when you complete forms on our website (“Site”). This includes name, address, telephone number and email address which is provided at the time of registering to use our Site, where you ask us to contact you about our goods or services, subscribe to our mailing list, or subscribe/request or goods or services;
2.1.2 whenever you provide information to us when reporting a problem with our Site, making a complaint, making an enquiry or contacting us for any other reason. If you contact us, we may keep a record of that correspondence;
2.1.3 details of your visits to our Site including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise, and the resources that you access (see section 2.2.2 on Cookies below);
2.1.4 whenever you disclose your information to us, or we collect information from you in any other way, through our Site.
2.2 We may also collect data in the following ways:
2.2.1 We may collect information about your device, including where available your Internet Protocol address, for reasons of fraud protection. We may also collect information about your device’s operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users' browsing actions and patterns, and does not identify any individual.
2.3 We may use your personal data for our legitimate interests in order to:
2.3.1 provide you with information, or services that you requested from us;
2.3.2 allow you to participate in interactive features of our Site, when you choose to do so;
2.3.3 ensure that content from our Site is presented in the most effective manner for you and for your device;
2.3.4 improve our Site and services;
2.3.5 process and deal with any complaints or enquiries made by you; and
2.3.6 contact you for marketing purposes where you have signed up for these (see section 7 for further details).
2.4 Our Site may, from time to time, contain links to and from the websites of third parties. Please note that if you follow a link to any of these websites, such websites will apply different terms to the collection and privacy of your personal data and we do not accept any responsibility or liability for these policies. When you leave our Site, we encourage you to read the privacy notice/policy of every website you visit.
3.1 We will collect details such as name, address, email, telephone number, and where you request finance we will collect your bank details, national insurance number, employment information, marital status and other information which we will provide to our finance partners, when you order goods or services from us either via our Site, over the telephone or in person at one of our centres. We will use this information to process your order and comply with our contractual obligations.
3.2 In order to perform our contract with you, we may also need to share personal data with third parties such as finance providers, insurance companies and other third parties to assist in the delivery of goods or services you have ordered. The following third parties are examples of these companies we may need to share your data with in order to assist you, this list is non exhaustive; CITnow, Cooper Solutions, AIG, AXA Insurance Company, Accident Exchange, British Car Auctions, BMW Financial Services, BMW, Alphabet. On occasion, we may provide your data to mailing houses and email marketing platforms where the law allows them to send you information on our behalf.
3.3 We may also advertise your feedback on our website and marketing materials (subject to obtaining your prior consent where necessary);
3.4 Except as otherwise permitted or required by applicable law or regulation, we will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legitimate interest, contractual obligation, legal, accounting, or reporting requirements, and we will review this from time to time. In any event this will not usually exceed six years from our last engagement after which the personal information will be securely destroyed. Under some circumstances we may anonymise your personal data so that it can no longer be associated with you. We reserve the right to use such anonymous data for any legitimate business purpose without further notice to you or your consent.
Where you have subscribed to receive marketing correspondence from us we will keep your personal data for the period of time described in section 7 below.
4.1 We will collect details such as names, email addresses, telephone numbers and bank details in order to contact you about goods or services ordered with you, to place further orders and to pay you for the goods and/or services supplied. We will keep the personal data for 6 years further to being provided with the goods/services.
- IF YOU FAIL TO PROVIDE PERSONAL DATA
5.1 Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide the data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example to provide you with our goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
6.1 In addition to the uses described in sections 2-4 above, where you indicate you would like to receive marketing correspondence from us, subscribe to our mailing lists or newsletters, enter into any of our competitions or provide us with your details at networking events we may use your personal data for our legitimate interests in order to provide you with details about our products, services, offers, events and business updates which we think may be of interest.
6.2 You have the right to opt-out of receiving the information detailed in section 7.1 at any time. To opt-out of receiving such information you can:
6.2.1 tick the relevant box situated in the form on which we collect your information; or
6.2.2 inform the member of our team who is processing your order;
6.2.3 update your marketing preferences by following the link contained in any such communication received; or
6.2.4 email us at firstname.lastname@example.org or call 01604 232000 providing us with your name and contact details.
6.3 Where you have subscribed to receive marketing correspondence from us we will keep personal data for up to 6 years from your last contact with us.
6.4 We may share your details with BMW Group Companies for marketing purposes. To unsubscribe from these please email email@example.com
- MONITORING AND RECORDING
7.1 We may monitor and record communications with you, such as telephone communications and emails, for the purpose of quality assurance, training, fraud prevention and compliance. We also have CCTV cameras installed in our premises for the purpose of crime prevention and for health and safety reasons. We retain email and call recordings for 90 days and CCTV recordings for 6 months.
- AUTOMATED PROCESSING
8.1 We do not undertake automated decision making with your personal data We may from time to time review our database using automated processes for our legitimate businesses Interests.
- LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA
9.1 We will only use your personal data where the law allows us to. Most commonly, we will use your personal data in the following circumstances:
9.1.1 for performance of a contract we enter into with you;
9.1.2 where necessary for compliance with a legal or regulatory obligation we are subject to;
9.1.3 to protect your interest in the event there is a product safety notification or recall; and
9.1.4 for our legitimate interests (as described within this policy) and your interests and fundamental rights do not override these interests.
- DISCLOSURE OF PERSONAL DATA to third parties
10.1 In addition to the third parties mentioned above, we may disclose your information to third parties for our following legitimate interests as follows:
10.1.1 to staff members in order to facilitate the provision of goods or services to you;
10.1.2 to our affiliated entities to support internal administration;
10.1.3 IT software providers that host our website and store data on our behalf;
10.1.4 professional advisers including consultants, lawyers, bankers and insurers who provide us with consultancy, banking, legal, insurance and accounting services;
10.1.5 HM Revenue and Customs, regulators and other authorities who require reporting of processing activities in certain circumstances; and
10.2 We may disclose personal data to the police, regulatory bodies, legal advisors or similar third parties where we are under a legal duty to disclose or share personal data in order to comply with any legal obligation, or in order to enforce or apply our
website terms and conditions and other agreements; or to protect our rights, property, or safety of our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
10.3 We will not sell or distribute personal data to other organisations without your approval.
- CROSS-BORDER DATA TRANSFERS
11.1 We will not transfer your personal data outside the European Economic Area.
- DATA SECURITY
12.1 Where we have given you (or where you have chosen) a password which enables you to access certain parts of our Site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
12.2 Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your information transmitted to our Site; any transmission is at your own risk.
12.3 Information you provide to us is shared on our secure servers. We have implemented appropriate physical, technical and organisational measures designed to secure your information against accidental loss and unauthorised access, use, alteration or disclosure. In addition, we limit access to personal data to those employees, agents, contractors and other third parties that have a legitimate business need for such access.
- ACCESS TO, UPDATING, DELETING AND RESTRICTING USE OF PERSONAL DATA
13.1 It is important that the personal data we hold about you is accurate and current. Please keep us informed if the personal data we hold about you changes.
13.2 Data protection legislation gives you the right to object to the processing of your personal data in certain circumstances or withdraw your consent to the processing of your personal data where this has been provided. You also have the right to access information held about you and for this to be provided in an intelligible form. If you would like a copy of some or all of your personal information, please send an email to firstname.lastname@example.org In certain circumstances we reserve the right to charge a reasonable fee to comply with your request.
13.3 You can also ask us to undertake the following:
13.3.1 update or amend your personal data if you feel this is inaccurate;
13.3.2 remove your personal data from our database entirely;
13.3.3 send you copies of your personal data in a commonly used format and transfer your information to another entity where you have supplied this to us, and we process this electronically with your consent or where necessary for the performance of a contract; or
13.3.4 restrict the use of your personal data.
13.4 We may request specific information from you to help us confirm your identity and your right to access, and to provide you with the personal data that we hold about you or make your requested changes. Data protection legislation may allow or require us to refuse to provide you with access to some or all the personal data that we hold about you or to comply with any requests made in accordance with your rights referred to above. If we cannot provide you with access to your personal data, or process any other request we receive, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
13.5 Please send any requests relating to the above to our Data Lead Katie Harmer, Group Business Compliance Officer, email@example.com 00604 232000 specifying your name and the action you would like us to undertake.
- RIGHT TO WITHDRAW CONSENT
14.1 Where you have provided your consent to the collection, processing and transfer of your personal data, you have the legal right to withdraw your consent under certain circumstances. To withdraw your consent, if applicable, please contact us at firstname.lastname@example.org.
- CONTACT US
Last updated: 10 May 2018.