Privacy Policy
1- Introduction
“HOLDHAM SA, company under French law, with a share capital of 6,160,000 euros, registered with the RCS of Caen under the number 352 998 827, located 1 rue du Campus 14200 Hérouville Saint Clair France (hereinafter, “HOLDHAM”, “we”, “our”), is the data controller. This means that we decide on the way in which we store and use the personal data we collect.
Hamelin Brands Limited whose registered address is Kings Warren Business Park, Red Lodge, Suffolk IP28 8WG Registered Number 5680323 VAT no. GB864 4749 83 is a subsidiary of Holdham SA and is the data controller on behalf of Holdham SA for the UK Market.”
This Privacy Policy outlines the way in which we collect and use the personal data of users of “OXFORDNOTEBOOKS” (hereinafter, “you”, “your”) in accordance with the General Data Protection Regulation of 27th April 2016 (hereinafter, the “GDPR”) and the applicable national laws.
It also outlines the legal bases upon which we process the personal data, the people with whom we share them and how they are stored.
It is important for you to read this Privacy Policy, as well as any other information that we may provide on specific occasions when we collect or process your personal data, so that you know how and why we use this data.
By using “OXFORDNOTEBOOKS” you accept the terms set out in this Privacy Policy. If you disagree with certain terms that appear in the Privacy Policy, we recommend that you do not use “OXFORDNOTEBOOKS”.
2- How is your personal data collected?
We collect personal data in different ways, as outlined below.
- Data collected during the creation of a “OXFORDNOTEBOOKS” account
To use “OXFORDNOTEBOOKS” you must open an account by entering your email address. You will then receive an email containing an activation code enabling you to activate your account.
If you don’t provide us with your email address, you won’t be able to create an account and access the services provided by “OXFORDNOTEBOOKS”.
Please note: in the event of “cancellation of the email address” (e.g. in the event of leaving a company, if you have used a professional email address), you will no longer be able to access your account or data.
During the installation of the “OXFORDNOTEBOOKS” application we also collect the language and country of use by querying the IPStack service. We collect this information in order to determine the language to be displayed on “OXFORDNOTEBOOKS”, the language we will use to communicate with you and also the place where your data will be stored at the nearest data centres.
- Data collected during your use of the “OXFORDNOTEBOOKS” website
We collect personal data directly from you during your purchases on “OXFORDNOTEBOOKS” as indicated below.
- We collect information during the placing of your order and your delivery note (your last name, first name and delivery address). We do not collect your banking details during your online payment. These are collected securely by the payment partner we have chosen due to its privacy and security guarantees.
- We collect personal data from you when you contact us via the contact form.
- We also collect data in order to study the number of visits and the journeys of users by means of analytical tools integrated into the “OXFORDNOTEBOOKS” website. However, please note that this data is processed completely anonymously. This means that the link between the data and the user is broken and that on no account are we able to return to the user via the data.
- In addition, please note that we use cookies on the “OXFORDNOTEBOOKS” website by means of which we collect some of your browsing data. If you would like to find out more about the use of cookies on the “OXFORDNOTEBOOKS” website, please read the Cookies Policy.
3- For what purpose is your personal data collected?
We use your personal data for the purposes outlined below.
Purpose |
Legal basis |
To process the order and to allow delivery of the chosen products to the address provided |
Performance of a contract we have entered into with you (Terms of Sale) |
To allow the proper functioning of “OXFORDNOTEBOOKS”, including to process your comments and opinions, to manage your requests regarding your rights, to improve “OXFORDNOTEBOOKS” and the services we offer, to permit the settlement of disputes, to deal with complaints and to correct any operational problems |
Our legitimate interest: management and development of “OXFORDNOTEBOOKS” Execution of a contract we have entered into with you (General Terms and Conditions of Use) |
To contact you regarding “OXFORDNOTEBOOKS” |
Execution of a contract we have entered into with you (General Terms and Conditions of Use) |
To ensure the security of “OXFORDNOTEBOOKS” and to prevent unlawful activities on “OXFORDNOTEBOOKS” |
Our legitimate interest: management of “OXFORDNOTEBOOKS” and compliance with the legal obligations to which we are subject |
To send reminders in the case of a shopping cart awaiting validation. |
Our legitimate interest: management of “OXFORDNOTEBOOKS” and compliance with the legal obligations to which we are subject |
To send commercial information via the newsletter |
Upon the basis of your prior consent |
To perform statistical analysis and studies on your use of the “OXFORDNOTEBOOKS” Website |
Our legitimate interest in accordance with the provisions of the GDPR |
To organise competitions with prior registration |
Execution of the contract for the competition |
We believe that the risk related to the personal data we process upon the basis of our legitimate interests is not excessive or too intrusive. In particular, we have implemented measures to protect your rights by applying suitable retention periods and ensuring the appropriate security controls.
No profiling will be performed and, more generally, no automated decision will be made upon the basis of the data collected.
4- Commercial correspondence and opt-out
You may receive administrative emails from us (emails concerning changes to the functioning of “OXFORDNOTEBOOKS”, the Privacy Policy, etc.).
Furthermore, if you have granted your consent, you can receive the newsletter via emails containing offers and information concerning products compatible with “OXFORDNOTEBOOKS”.
You may withdraw your consent and request no further commercial emails be sent by using the “unsubscribe” link to be found in the message received or by writing to the following address: revision-data.protection@hamelinbrands.zendesk.com.
5- Duration of the storage of your personal data
We will retain your personal data in an active database for the period during which your user account is active. Then, 36 months after the last authentication of your “OXFORDNOTEBOOKS” account, we will retain your data in archive databases for the legally required period of time.
6- Recipients of the personal data
We will share your personal data with third parties when required to do so by law, when it is necessary to do so to manage the contractual relationship we have with you or when we have another legitimate interest in doing so. We will share your personal data with the following categories of third parties:
- the subsidiary of HOLDHAM which handles the processing and deliveries
- the HOLDHAM company that supports the order and delivery management activity
- the company that provides us with the Shopify hosting provider platform
- other service providers that support our activity, such as IT and logistics providers.
- Our banking partner that guarantees the online payment of orders.
Please note that your personal data will never be marketed. We will never rent out or sell your personal data.
We may also be required to disclose your personal data to third parties:
- if we sell or buy a business or assets, we may disclose your personal data to the seller or potential purchaser of said business or assets; and
- if HOLDHAM or part of its assets are acquired by a third party, in which case the personal data retained by HOLDHAM will form part of the transferred assets.
7- Data transfers outside the European Economic Area
We may have to transfer your personal data outside the European Economic Area (EEA) in the following cases:
- Within the framework of our customer base management, we may be required to share your contact details with a company that has become a member of the “Privacy Shield” programme established by the United States Department of Commerce located in the United States.
Within the framework of our use of the Google Analytics cookie, we may be required to share your connection data with the Google company that has become a member of the “Privacy Shield” programme established by the United States Department of Commerce.
Please note that we take the necessary precautions to ensure that these providers implement suitable guarantees and comply with the strict conditions regarding the privacy, use and protection of data.
8- Public authority
We may be required to disclose your personal data to bodies and authorities that are legally empowered within the framework of an investigation into unlawful activities which may involve our liability, your liability or the liability of another user of “OXFORDNOTEBOOKS”.
9- Your rights
As a data subject, you have certain rights with regard to your personal data. These rights are not absolute and each of them are subject to certain conditions in accordance with the GDPR and the applicable national laws.
- The right of access: you have the right to obtain confirmation from us as to whether or not your personal data is being processed by us, as well as certain other information (similar to that provided in this Privacy Policy) on the way in which they are being used. You also have the right to access all your personal data by writing an email to the following address: revision-data.protection@hamelinbrands.zendesk.com
- The right to rectification: you can rectify or correct certain personal data on “OXFORDNOTEBOOKS” if they are inaccurate or incomplete via “My Account”.
However, please note that your account is inherently linked to your email address. We are unable to modify the email address that is linked to your account.
- The right to erasure: also known as the “right to be forgotten”, this right enables you to erase or request the deletion or erasure of your personal data when, for example, there is no compelling reason for us to continue using them or their use is unlawful. However, this is not a general right to erasure and there are some exceptions, such as when we have to use the information to defend a legal action or to comply with a legal obligation.
You may at any time decide to definitively and irrevocably delete your account and your personal data. To do so, you should send your request by email to the following address: revision-data.protection@hamelinbrands.zendesk.com. Upon the deletion of your account and any related data stored in it, you will receive an email confirming the deletion of the account.
- The right to restrict the processing: you have the right to “block” or prevent further use of your personal data while we assess a request for rectification or as an alternative to deletion. While the processing is restricted we may still retain your personal data, but we may not use them anymore.
- The right to data portability: you have the right to obtain and re-use certain personal data for your own requirements in different companies (which are separate data controllers). This only applies to personal data that you have provided us with, which we process with your consent for the purposes of the performance of the contract and are processed by automated means. In this case we will provide you with a copy of your textual data in a structured, commonly used and machine-readable format.
- The right to object: you have the right to object to certain kinds of processing for reasons related to your particular situation at any time, insofar as this processing takes place for the purposes of legitimate interests pursued by HOLDHAM. We will be authorised to continue processing the personal data if we can demonstrate that the processing is justified by compelling and legitimate reasons that outweigh your interests, rights and freedoms or if we need them for the establishment, exercise or defence of legal actions. If you object to the processing of your personal data for direct marketing purposes, you may unsubscribe from email communication by using the “unsubscribe” button at the bottom of each message.
- The right to withdraw your consent: while we process your personal data upon the basis of your consent, you have the right to withdraw said consent at any time. However, such a withdrawal will not affect the lawfulness of the processing that has taken place prior to the withdrawal. You can unsubscribe from the e-mail newsletter by using the “unsubscribe” button at the bottom of each email or by sending your request by email to the following address: revision-data.protection@hamelinbrands.zendesk.com.
- The right to provide us with instructions on the use of your personal data after your death: you have the right to provide us with instructions on the management (e.g. storage, deletion and disclosure) of your data after your death. You may modify or revoke your instructions at any time.
If you would like further information on your rights, if you wish to exercise any of them or if you have a complaint, please contact us at the following address:
revision-data.protection@hamelinbrands.zendesk.com
If you are not satisfied with our reply to your complaint or if you believe that the processing of your personal data does not comply with the applicable laws on data protection, you can submit a complaint to a data protection supervisory authority. If you reside within the European Union, you can submit such a complaint to the supervisory authority of the country in which you reside. If you do not reside within the European Union, you can submit your complaint to the French Data Protection Authority (CNIL), which is the data protection authority in France.
We will examine all such requests and send our reply within the period of time stipulated by the applicable law. Please note, however, that certain personal data may be exempt from such requests in certain circumstances, particularly if we have to continue processing your personal data in pursuit of the legitimate interests or to comply with a legal obligation.
You will not have to pay any fees to access your personal data (or to exercise any other rights). However, we may charge a reasonable fee if your request for access is manifestly unfounded or excessive. We may also refuse to comply with the request in said circumstances.
We may need to ask you for specific information to help us to confirm your identity and to guarantee your right to access this information (or to exercise your other rights). This is another appropriate security measure to ensure that the personal data is not disclosed to anyone who does not have the right to receive them.
10- Security
We and our service providers have adopted physical, electronic and administrative security measures to protect your personal data, including the use of a threat and attack surveillance tool, passwords and encryption techniques enabling us to secure any access to your personal data.
11- Contacting the data protection officer
We have appointed Ms Virginie Ori as the Data Protection Officer to monitor compliance with this Privacy Policy. If you have any queries about this Privacy Policy or the way in which we process your personal data or if you wish to exercise any of your rights, you can contact our Data Protection Officer.
Email: data.protection@hamelinbrands.zendesk.com
Address: Holdham, for the attention of the Data Protection Officer, 1 Rue du Campus, 14200 Hérouville-Saint-Clair, France.
12- Amendments of this Privacy Policy
We reserve the right to update this Privacy Policy at any time. Please check this Privacy Policy regularly in order to be aware of any changes. From time to time, we may also inform you by any means of any changes in the processing of your personal data.
Please also read the General Terms and Conditions of Use of the Application and the “OXFORDNOTEBOOKS” Website.
Cookies Policy of the “OXFORDNOTEBOOKS” Website
During your visit to the “OXFORDNOTEBOOKS” Website, cookies are deposited on your computer, tablet or smartphone. This page will help you to better understand how cookies work and how to use the current tools in order to configure them.
1- What is a cookie?
A cookie is a small text file in alphanumeric format that is sent to your browser and stored on your computer’s hard drive. A cookie file allows its sender to identify the terminal in which it is stored during the period of validity or registration of the cookie.
2- Which cookies do we use?
We only use two kinds of cookies on the “OXFORDNOTEBOOKS” Website.
Technical cookies: the exclusive purpose of these cookies is to allow and facilitate browsing on a website, as well as access to the different products and services. In particular, technical cookies make it possible to recognise Internet users, flag their visits to such or such a page and thus improve their browsing comfort.
The cookies we use include: (https://fr.shopify.com/legal/cookies)
- User-centric security cookies to detect authentication abuses for a limited but continuous period of time, such as unsuccessful identification attempts. These cookies are configured for the specific task of improving the security of the service.
- Session cookies for multimedia content playback (flash cookies) are used for the duration of a session to record the technical data required for the playback of video or audio content (e.g. image quality, the speed of the network link and caching settings).
- Load balancing session cookies are used for the duration of the session to identify the server in the pool in order to enable the load balancer to redirect users’ requests in an appropriate manner.
- Persistent user interface customisation cookies are used to record a user’s preference for a service on multiple pages.
Audience measurement cookies: the purpose of these cookies is to obtain information on the browsing of internet users on a website in order to draw up statistics and audience measurements.
According to the Shopify website:
User experience is a fundamental issue and we use numerous tools to help us to improve our website. To this effect, we use performance cookies to collect information on the way in which and how often you use our website. These cookies only collect information for statistical purposes and do not compile any information that may identify you personally. However, as these cookies are not strictly necessary for the use of our website, we need your consent to use them. The performance cookies we use include:
- Proprietary analytical cookies - We use these cookies to calculate the number of unique visitors, to improve our website and to detect the most popular search engine words leading to a web page. These cookies are not used to target you with online marketing. We use these cookies to learn more about how our website works and to make relevant improvements to enhance your browsing experience.
- We also use Google Analytics and other third-party analytical providers to help us to gauge how users interact with the content on our website. These cookies “memorise” our users’ actions on previous pages and the way in which they interact with the website. For further information on Google Analytics, please visit the Google information page. See below to obtain instructions about how to opt out of Google Analytics.
Targeting cookies are used on our website to tailor our marketing to you and your interests and to provide you with a more personalised service in the future. These cookies remember your previous visit to our website and we may share this information with third parties such as advertisers. Although these cookies can track your visits to our and other websites, they generally cannot identify you personally. Without these cookies, the advertisements you see may be less relevant and less interesting for you. We do not use third-party advertising cookies.
Finally, social plugin tracking cookies are used by many social media that possess “social plugin modules”. We integrate these modules into our platform in order to offer services that may be regarded as “expressly requested” by our users. However, your consent is required because some third-party social plugin tracking cookies are used for purposes such as behavioural advertising, analyses and/or market research.
3- How to control cookies
The following options to reject/delete statistical cookies are available.
Configuring your browser:
Most browsers accept cookies by default. However, you can decide to block these cookies or ask your browser to warn you when a website attempts to implement a cookie in your terminal.
Each browser is configured differently for cookie management and the user’s choices. This is outlined in the help menu of the browser you use, enabling you to know how to modify your cookie-related requirements. For example:
Firefox Click on the menu button and select “Options”. Select the “Privacy” panel. Set the “Storage rules” menu to “Use custom settings for history”. Untick the “Accept cookies” box. Any changes you have made will be automatically saved.
Google Chrome Select the Chrome menu icon. Select “Settings”. Select “Show advanced settings” at the bottom of the page. Select “Content settings” in the “Privacy” section. Select “Prohibit all sites from storing data”. Select “OK”.
Internet Explorer Click on the Tools button and then click on “Internet Options”. Click on the “Privacy” tab and then press the “Advanced” button to bring up the Advanced Privacy Settings window. Then tick the “Ignore automatic cookie management” box and select “Decline” in the “Third-party cookies” column.
Safari Click on “Settings” > “Safari” > “Security”. Tick the box of your choice in the “Accept cookies” area.
Warning: setting your browser in this way may result in the deletion of all the cookies, including those allowing you to browse the “OXFORDNOTEBOOKS” Website properly. If you wish to delete only the “Google Analytics” audience measurement cookie, please refer to the option described below.
Download of a Google Analytics opt-out browser add-on:
If you do not wish to send information to Google Analytics, you can download and install the add-on available at https://tools.google.com/dlpage/gaoptout?hl=fr This add-on is compatible with Chrome, Internet Explorer 11, Safari, Firefox and Opera.
4- Further information on cookies
For further information on cookies please visit the website of the French Data Protection Authority: https://www.cnil.fr/fr/cookies-les-outils-pour-les-maitriser