Last updated: 20 November 2023This privacy notice explains the personal data the THE FLOORR Limited collects, uses and shares, for what purposes, and under what legal bases. It applies to our customers, partners and web site visitors.
About us
THE FLOORR Limited is a limited-liability company based in the UK. We are registered at Companies House, registration number 11485658. For data protection purposes, we are registered with the UK Information Commissioner, registration number ZA781607.
Contacting us
You may contact us about this privacy notice, or to make a rights request, in any of the following ways:
- Email: privacy@thefloorr.com
- Post: THE FLOORR LTD, 2nd Floor Butler House, 177-178 Tottenham Court Road, London W1T 7AF, UK
- Instagram: @thefloorrfashion
- Facebook: @thefloorr
How we get your personal data
Directly from you
- You signed up via our website
- You opened an account with us
- You save information to your account, such as favourites, preferences, moodboards and other information you choose to share with us
- You contacted us, such as via our social media accounts, email or WhatsApp
- You use our consultation or clienteling services directly, or via a brand or retailer that we provide clienteling services for
- You gave us your details in person
- We have a business or affiliate relationship with you
- You have applied for a job or contract with us
Indirectly via others
- You are a client of a brand, retailer or other third party that we provide clientelling services to, and we are processing your data in accordance with our contract with them, as data processor or joint controller
- Someone recommended you to us
- Someone included or mentioned you in communications with us
- We received a reference from a previous employer or other contact about you
Automatically
- With your consent, we may gather information automatically through a user interface feedback tool that provides us with data on how you use our sites
- We log activity and statistics about your use of our site or newsletter
- We capture pseudonymised click-through data when you follow affiliate links from THE FLOORR to brand or retailer product pages
- When you have a business or affiliate relationship with us that allows you to create trackable affiliate or promotional links, we receive data from affiliate networks, social media platforms and other sites where you have placed such trackable links, so that we can associate clicks on those links with you
- We use certain cookies as part of the functionality of our site; for a list of those cookies we use, see our Cookie Page
Our processing of your personal data
This is a summary of how we process your personal data
A more detailed breakdown of the categories of individuals, the purposes of processing, the categories of personal data, the lawful bases for processing, and the third-party recipients of the data is available on request.
The purposes we process your data for
We use the personal data we collect to provide our services, to monitor and improve what we do, and to protect you, us and our partners. This may include using your personal data to:
- provide services to you, such as our website, mobile app and newsletter
- invite you to participate in special programs and services that we offer
- operate your account, if you choose to open one
- send you relevant news and information
- maintain such records as the law requires of us
- engage you as a contractor, staff member or supplier
- associate clicks on promotional or trackable links with you, if you have a business or affiliate relationship with us that permits you to create them
- derive insights from aggregated, anonymised service use data
- monitor, maintain and protect the services we provide to you
- provide services for you when you are a client of a brand, retailer or other third party that uses clienteling services we provide to that brand, retailer or other third party
- provide services to you and your clients when you are offering clienteling services to your clients, or when you are a client of a personal shopper who uses our platform
The lawful bases we rely on
We rely on the following lawful bases to process personal data:
Contract
- Where there is a contractual agreement between you and us, such as for the provision of services to you; this includes those activities that lead up to the creation of the agreement.
- Where there is a contractual agreement between you and a brand, retailer or other third party, and they are using our clienteling services to provide services to you, where we are acting as data processor or joint controller of your data.
Consent
- Where we provide you with a newsletter, and you do not already have a relationship with us, such as being an account holder; each newsletter will include information on how to unsubscribe.
- Where we must otherwise obtain your consent to process your data, such as granting other registered users of our services access to your purchase authorisation for the purposes of shopping on your behalf.
Legitimate interests
- Where you do have an existing relationship with us, such as being an account holder, we may contact you with related, relevant information.
- We may also rely on this basis in order to perform actions, such as fraud checks, technical investigations, anti-hacking measures, or any other actions that we believe are appropriate and necessary to protect us, you, our other customers, or our partners and affiliates.
- Where you do not yet have a relationship with us, we may rely on this basis to reach out to you; you have the right to object, and we will honour that.
Legal obligation
- Where we are required by law to process your personal data, such as for tax or employment records, to verify your right to be employed or engaged by us, or to maintain consent records.
Your data protection rights
You have the following rights relating to your personal data, and how we process it.
Informed
- You have the right to know what personal data we process, the purposes for which we process it, the legal bases upon which we process it, and information about exercising your rights.
Access
- You may ask us if we are processing your personal data, and for a copy of the data we hold.
Rectification
- You may ask us to correct any incorrect or incomplete personal data we hold about you.
Erasure
- You may ask us to remove any personal data we hold about you. Note that there are limitations on what can be erased; in particular, records we are legally obliged to retain may not be erased. We may choose to anonymise, or otherwise deidentify your personal data, such that it can no longer be associated with you.
Objection
- You may object to the processing of your personal data when it is processed under our legitimate interests, such as when we contact you with information related to a service we are providing to you.
Restriction
- In certain circumstances, you may request that we retain your personal data but do not use it, such as in the process of establishing or defending a legal claim.
Portability
- You may ask us to provide you with a copy of your data in a form that can be easily processed by computer. Note that this right is limited to data you have provided to us either as part of a contract between us, or with your consent.
Automated processing
- You may contest any automated decision we take, including profiling, that has a significant or legal effect on you; we will take your point of view into account when conducting a manual review of the decision.
Making a data rights request
In the first instance, contact us at privacy@thefloorr.com with the details of your request. We will acknowledge your request and let you know what additional information we may require in order to process your request. For example, to prevent illicit access to your personal data, we may request that you verify your identity using appropriate secure means before we continue.
How we store your personal data
We rely on a number of third parties to process personal data on our behalf, and have a list on our third-party processors page. Each third party processes personal data in accordance with a written contract that lays out what they process and how long they may retain it.
Where your personal data goes
Where we can, we have asked our third-party processes to process your personal data within the UK, or within the EEA. Where data is transferred outside of the EEA, we have contractual terms in place to safeguard the data according to UK and EU law.
How long we retain your personal data
We hold data no longer than is necessary for the purpose for which it is processed. This varies dependent on the purpose, from perhaps just a few minutes for session cookies to several years for legally required tax records or as part of a long-term contract with you.
How we secure your personal data
We, and our third-party processors, use appropriate organisational and technical measures to keep personal data secure. These include, but are not limited to, strong encryption, physical access control, role-based authorisation, and two-factor authentication.
How to complain
If we have been unable to resolve any questions you may have regarding this privacy notice, or if you are dissatisfied with how we have handled your rights request or processes your personal data, you may contact the Information Commissioner's Office at the following address:
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; +44 (0)303 123 1113