1. Introduction and Objectives 2. About This General Privacy Policy 3. PII We Collect 4. How PII is Collected 5. How We Use PII 6. Information Sharing 7. Your Privacy Preferences 8. Our Sites and Children 9. Calls Recordings 10. Security and Links 11. Contact Us 12. Notice to Residents of Quebec 13. Your California Privacy Rights 14. Notice to Nevada Residents 15. Notice to Colorado, Connecticut, Virginia, and Utah Residents 16. Privacy Policy According to the GDPR 17. Changes to the General Privacy Policy and the Specific Policies Pertaining to Certain Jurisdictions
1. Introduction and Objectives
Each of Bath Fitter Distributing Inc. (“BF Distributing”) and its affiliates (which shall include any entity that directly or indirectly (including through one or more intermediaries), controls, is controlled by, or is under common control with BF Distributing, each a “BF Affiliate”, and collectively the “BF Affiliates”), and Bath Fitter® franchisees, who either post this General Privacy Policy on their websites, or use Website (as defined herein) as their website (the “Franchisees”, and collectively with BF Distributing and the BF Affiliates, and/or individually, “BF Group” “our”, “us” or “we”) values and respects the privacy of its customers and the visitors of the https://www.bathfitter.com website (the “Website”).
Accordingly, the purpose of this General Privacy Policy (the “General Privacy Policy”) is to provide you with information about how BF Group collects, uses, and shares personally identifiable information it gathers from customers and Website visitors (“PII”). The General Privacy Policy also describes the choices you can make about our use of your PII.
2. About This General Privacy Policy
This General Privacy Policy describes the privacy practices adopted by BF Group. However, this General Privacy Policy does not apply to Bath Fitter® franchisees, other than Franchisees, or PII shared with, or processed by, third-party websites you accessed through our Website.
The General Privacy Policy covers our interactions with customers and visitors, including, but not limited to:
Use of our Website, including any mobile interface, and web forms;
Entering into any agreement with any member of BF Group;
Visits to our Bath Fitter® stores or attendance at any of our events;
Any type of communication;
Social media interactions with us on our Website and other third-party websites, such as, but not limited to Facebook, YouTube, Pinterest, TikTok, Instagram and Twitter;
Viewing our online advertisements or emails; and
Any interactions with or through our authorized Service Providers (as defined herein).
3. PII We Collect
Our collection efforts are designed to improve your purchasing experience, and to provide relevant information about our products, services, and promotions. To do this, we may collect the following PII:
Contact information
We collect the names, cell or home phone numbers, email and/or postal address of customers and/or potential clients, who placed an order with us, entered into any agreement with us, completed our online form to request an estimate, appointment, and discuss a project, or to ask us any question, or contacted us for any other reason.
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our Email and Text Communication Terms and Conditions (available at: https://www.bathfitter.com/us-en/terms-and-conditions/).
Additionally, we may collect your purchase history, billing addresses, electronic signature (when necessary or advisable) and other digital contact information. We may also collect information that you provide to us about others.
Payment and Financing Information
When you make a purchase, we may collect your payment information, including information from your credit or debit card, check, PayPal account or gift card.
If you apply for a BF Group-administered loan or financing, we might collect any other information related to your application.
Demographic Information
We may collect information about reviews you submit and other data like your age and gender.
Usage Data
We collect and process usage data that includes information about how you use our Website, products and services.
We might also track the pages you visit, look at which website you came from, or which website you visit when you leave us. We collect this information using the tracking tools described in the Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/.
Aggregated Data
We also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your PII, but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific Website feature. However, if we combine or connect aggregated data with your PII so that it can directly or indirectly identify you, we treat the combined data as PII which will be used in accordance with this General Privacy Policy.
Social Media Information, and Information Provided Electronically
If you interact with us on social media, such as, but not limited to Facebook, YouTube, Pinterest, TikTok, Instagram and Twitter, we may collect your username, other PII, and any of the information or content that you provide through our Website, device applications, or online forums.
Technical and Geolocation Data
We collect technical data that includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform (collectively, the “Technical Data”), and other technology on the devices you use to access this Website.
If you use our mobile website (including the Website), mobile applications, or other smart device applications, we may collect location data obtained from your device (including the IP address). If you use our Website, we may collect location data obtained from your IP address. For more information, please consult our Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/.
Employment Information
If you apply for an employment opportunity, we may collect certain PII that you provide to us (whether it be in a resume, cover letter or similar employment-related materials, or any applicable pre-screening questions). With respect to our current respective employees, we collect their PII for employment-related purposes, as permitted by applicable law. We may also collect PII of our respective employees when it is necessary for rendering services by BF Group.
PII Collected Through the Free In-Home Consultation Form
The Free In-Home Consultation is an optional form to fill out if you are interested in a BF Group product. You do not have to fill out the form to browse our Website online. When filling out the form, you are asked for PII such as your name, address, phone number and email address that you select. This information may be used to help our sales representatives contact you to answer any questions or provide you with a free in-home consultation appointment. Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our Email and Text Communication Terms and Conditions (available at: https://www.bathfitter.com/us-en/terms-and-conditions/).
4. How PII is Collected
We collect PII directly from you or from others if they provide your PII to us.
To illustrate the manner we collect PII, below we list just some examples of how and when we may collect PII from you:
During your Website visit or through a completed form;
If you upload or share a photo, a video or a comment, submit a request, submit any information, or post other digital content through Website, applications or via social media interactions on third-party websites like Facebook or Twitter;
If you register for a referral program or apply for a BF Group managed loan or financing;
If you participate in a survey, provide feedback regarding BF Group services, or decide to post a review;
If you participate in a sweepstakes, contest, promotion, program, clinic or workshop;
If you request a quote, warranty or other information;
If you use a rebate;
If you apply, inquire about employment, or when you accept our employment offer;
If you provide PII to our employee or other agent during a phone conversation (please, note that such conversations are not recorded in California, Illinois, Texas and Washington) or in any other type of communication with any of our employees or other agents; or
In connection with your interactions with us as a registered user of our Website.
We may collect your PII through automated technologies or interactions, and as you interact with our Website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. More details thereon are included in our Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/.
5. How We Use PII
We use the PII we collect for our business purposes, including:
To respond to your questions and requests.
Examples include, but are not limited to:
Fulfilling orders, ensuring proper delivery/installation or providing services (e.g. delivering an electronic copy of your receipt);
Answering questions about services, products, projects, providing estimates, booking a consultation, making appointment;
Administering your participation in a contest, sweepstakes or other promotion, including shipping any prizes you might have won;
Registering you for a particular website, referral program, or extended warranty service or providing you with information regarding programs or services;
Processing a service request;
Responding to a product or service review.
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our Email and Text Communication Terms and Conditions (available at: https://www.bathfitter.com/us-en/terms-and-conditions/).
To enter into an agreement with you.
We may use your PII to negotiate an agreement with you, enter into an agreement with you, and store the agreement for our records.
To improve our products and services.
We may use your PII to make Website, device application, or product and service improvements, and also to identify certain trends or preferences in websites and mobile applications.
We might use your PII to customize your experience with us. We may collect information about your activities and interactions with various devices and link that information. Through cross-device linking, we provide customers with a consistent experience across devices used. We may also combine information we get from you with information about you we have received from third parties or publicly available sources to assess trends and interests.
For security and loss prevention purposes.
We may collect/use your PII to protect our business, our facilities, customers, our respective employees or our Website. For example, we might use cameras in our stores to track store traffic and stock.
For our marketing.
In certain circumstances, we may send you communications about special promotions or offers via regular mail, email, or other electronic channels, including ads on social media platforms. We may send you emails if you have registered on Website, indicated that you want to receive this information, or if you gave us your information at one of our stores or events. We may also notify you of new Website features or product and service offerings. To manage our communications with you, follow the instructions in the “Privacy Preferences” section of this General Privacy Policy below. We may use information collected across different online services and the various devices you use in order to deliver marketing communications (including online ads) based on your interests. For example, if you view a product on our Website, you may see ads for that product on our or third-party websites and applications.
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our Email and Text Communication Terms and Conditions (available at: https://www.bathfitter.com/us-en/terms-and-conditions/).
To communicate with you about your account, our programs, your feedback, and any rebates.
We may contact you to inform you about changes to this General Privacy Policy, the Terms of Use of our Website or device applications, or changes to any of our programs in which you might be enrolled. We may also tell you about issues with your orders or if there is a product or service rebate, or we may ask for your feedback or review of services rendered and/or products sold by BF Group.
For employment purposes.
We may use the PII you provide in connection with a job application or related inquiry for the purpose of processing and responding to your application or inquiry. We may further use your PII when you accept our employment offer to comply with obligations imposed on BF Group by applicable law, or when and as it is necessary for rendering services by BF Group.
For social media.
When you engage with our content through third-party social networking websites, plug-ins and applications, you may allow us to have access to certain social media account information (e.g., name, username, email address, gender) as determined by the settings of the social media services to deliver the content or as part of the operation of the Website, plug-in or application. Social media platforms may collect information about your use of our services and may notify other users of the platform about your activities on our Website and device applications. Social media services may also use cookies or other technologies to provide services or track your online activities over time and across multiple websites and device applications. Your interactions with social media features are governed by the respective privacy policies of the companies providing the features.
For quality purposes (including identifying trends and efficiencies)
Except California, Illinois, Texas and Washington, we may use PII recorded during phone calls for training and quality management purposes. Please, note that such recorded calls may be shared with Medallia, Inc., headquartered in San Francisco (“Medallia”) or some other third-party processor of our choice, that will be hosting, and/or processing the recordings and/or will be preparing a transcript thereof. For further information on call recordings, please refer to “Call Recordings” section of this General Privacy Policy.
For other uses we may disclose to you.
We may use your PII for other purposes consistent with those for which it was collected. We may also use your PII, as permitted or required by applicable law, including but not limited to, upon receiving, and in accordance with, your consent.
6. Information Sharing
We may share your PII for our business purposes and as legally required or permitted, including, but not limited to:
With third parties, who perform services on our behalf (the “Service Providers”).
We share PII with our Service Providers, such as, but not limited to, Google, Facebook, Medallia, RDI, TigerTel, Bullhorn, Ultipro and Bing. We might also authorize our Service Providers to collect PII on our behalf. Some Service Providers may be located outside of the United States and/or Canada. These Service Providers may also have their own privacy statements that stipulate the manner, in which they will collect, use and disclose (process) PII. We encourage you to review each Service Provider’s privacy statement. We might also share information with the vendors and manufacturers of our products and services to respond to your reviews and questions. No mobile information will be shared with Service Providers for marketing/promotional purposes. This opt-in is specific to text messaging.
To offer financial products.
We use Service Providers to offer financial products, such as Wells Fargo, Snap, Greensky, Aqua Finance, Fortiva & Genesis Creditloans/financings. We may share PII about you with these Service Providers in order to provide you with tailored information about products and services and special offers. These Service Providers also have their own privacy statements that stipulate the manner in which they will collect, host, process, use and disclose PII. We encourage you to review each Service Provider’s privacy statement at the time you submit your application for financial products.
With any buyer successor to all or part of our business.
We may share, dispose of, assign or otherwise disclose your PII to any prospective acquirer or assignee of all or part of the assets or shares of any of BF Group's businesses (or any portion thereof), either in the ordinary course or in connection with bankruptcy proceedings, in liquidation or other similar proceedings, to the extent that your PII is part of the transaction.
In order to comply with applicable law.
We will disclose PII to respond to a court order or subpoena. We may also disclose PII if a government agency or investigatory body files a request.
With our business partners.
We might share PII with one of our franchisees or a business partner, who is running a joint promotion with us, who provides a product or service in partnership with us, who is collecting from clients and prospective clients reviews of our services or feedback thereon, or with whom we share PII of clients and prospective clients due to the overlap between the location of business partners, and residency of such clients and prospective clients (so-called “lead sharing”). These franchisees and business partners could also have their own privacy statements that set out the manner, in which they will collect, process, host, use and disclose PII. We encourage you to review each such franchisee or business partner’s privacy statement before signing on with them.
To protect us, or a third party.
We will disclose PII if we suspect fraud, or in any other case to protect us, or any third party. We will also share PII as part of an investigation. We may also disclose PII to assist us in collecting a debt owed by you.
For quality insurance purposes (including identifying trends and efficiencies)
Except California, Illinois, Texas and Washington, where our phone conversations with you will not be recorded, we will share the recordings of our other conversations with you and the related PII collected during such conversations with Medallia or any other third party of our choosing to process the recordings and prepare a transcript thereof, so we can improve the quality of services we offer, as well as identify trends and efficiency gain opportunities.
By your request.
For example, if you ask us to provide your PII to a third-party to facilitate the resolution of a dispute.
7. Your Privacy Preferences
You can register or change your preferences to receive or not receive marketing communications from us by emailing us. Please allow sufficient time for your preferences to be processed. Even if you opt out of receiving marketing messages, we may still contact you for transactional purposes like confirming or following up on an order or service request, responding to customer service inquiries, asking you to review a product or service you have ordered, or notifying you of product or service rebates. If, in the future, you do indeed want to receive marketing communications from us we will remove your PII from our opt-out database.
For more information about how we may collect information to provide you with interest-based ads or learn about our users’ interests and how you may register your preferences, please visit our Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/.
8. Our Sites and Children
Our Website and device applications are not created for children. No minor may provide any PII to us or on Website. We do not knowingly collect PII from minors. If you are a minor, do not use or provide any PII on this Website or through any of its features, register on the Website, make any purchases through the Website, use any of the interactive or public comment features of this Website, or provide any PII about yourself to us, including your name, address, telephone number, email address, or any screen name or user name you may use. If we learn we have collected or received PII from a minor without verification of parental consent, we will delete that information. If you believe we might have any information from or about a minor, please contact us at privacy@bathfitter.com.
Minors in some jurisdictions may have additional rights with respect to their PII based on their age. As appropriate, please refer to the provisions applicable to these jurisdictions (Quebec, California, Nevada, Colorado, Connecticut, Virginia, and Utah, as well as Europe, including the United Kingdom).
9. Calls Recordings
Except for inbound and outbound calls by and between our employees or our agents/representatives and residents of California, Illinois, Texas and Washington, inbound and outbound calls by and between our employees or our agents/representatives and residents of all other States and provinces could be recorded for quality purposes.
In case of inbound calls, a pre-recorded message informing the calling party about the call being recorded will be played before the conversation may commence, and in case of outbound calls, our employees shall announce verbally to the other party, before the conversation may commence, that the conversation will be recorded.
The fact that you continue the conversation following this message or announcement shall be deemed to constitute your consent to the recording of the conversation. Please, note that your consent to having the calls recorded is voluntary and may be withdrawn at any time. To withdraw your consent, you will need to do so in clear terms. In such a case, we will cease the current recording, if any, and we will also promptly comply with your instructions regarding any prior or subsequent communications. Recorded conversations will further be shared with Medallia, or some other third-party processor of our choice, that will be hosting and processing the recordings and will be preparing a transcript thereof. Medallia’s privacy policy is available at: https://www.medallia.com/privacy-policy/.
The purpose for processing of call recordings and preparing a transcript thereof is to evaluate and improve the quality of our customer service and identify trends and efficiencies. Such transcripts will be further also used in the process of reviewing the quality of services rendered by our employees, and their overall performance.
The recordings may also be hosted on third-party servers or cloud.
10. Security and Links
While we use industry standard means to protect our Website and your PII, the Internet is not 100% secure. The measures we use are appropriate for the type of information we collect. We cannot guarantee use of our Website or mobile applications are 100% secure. We encourage you to use caution when using the Internet. Our Website contains links to third-party websites. If you click on one of those links, you will be taken to websites we do not control. This General Privacy Policy does not apply to the information collected or processed by those websites. You should carefully read the privacy policies of other websites. We are not responsible for third-party websites.
By providing your PII on the Website, or entering into an agreement with us, or interacting with us in such a way that you have provided your PII to us, you agree that your PII could be collected, hosted, transferred, stored and further used or processed in Canada, and/or in the USA and/or via cloud computing.
11. Contact Us
If you have additional questions you may call us at 1-800-764-5539 or reach us by email at privacy@bathfitter.com. You can write to us at 225 Roy Street, Saint-Eustache (Quebec) J7R 5R5, Canada.
12. Notice to Residents of Quebec
BF Group ("we") pays particular attention to the protection of the PII of individuals who, in Quebec, visit its Website or who are customers (potential or current). In this section, we explain how we collect, use and disclose to third parties PII about visitors to our websites www.bainmagique.com/qc-fr or www.bainmagique.com/qc-en (collectively and individually, the "Website") and our customers (potential and current) ("you").
This division has been adopted to take into account the requirements of the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1 – "PHIPA") as amended by the Act to modernize legislative provisions relating to the protection of personal information (2021, c. 25).
If you do not consent to our collection, use or disclosure of your PII to third parties in accordance with this section, please do not disclose any PII to us. Of course, certain services and/or goods can only be offered to you if you provide us with PII; therefore, we may not be able to offer you these services and/or goods if you decide not to provide us with the necessary PII.
Purpose of the collection
We collect your PII for the purposes specified in the "Introduction and Objectives" of our General Privacy Policy and in the "How We Use PII" section, which is primarily to:
Improve the purchasing process and provide relevant information about our products, services and promotions;
Meet our business needs (i.e. customer service, order tracking, marketing, promotion).
Means of collection
We collect your PII through our Website (i.e. cookies, booking or contact form), our mobile applications or social networks, and also when you communicate with us or we communicate with you by phone, SMS, email or any other means of communication. (See also the "How PII is Collected" section of the General Privacy Policy).
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our Email and Text Communication Terms and Conditions (available at: https://www.bathfitter.com/us-en/terms-and-conditions/).
PII Collected
As part of your relationship with us, you may be asked to provide certain PII about yourself. For example, we may ask you for your name, postal and e-mail addresses, telephone numbers, bank details and credit card data. We may also collect certain information about your health and that of the people you live with.
We may also collect information of a technical nature or relating to your location, your use of our Website, and your preferences. In such circumstances, we ensure that:
The functions that allow you to be identified, located or profiled are disabled while allowing you to activate them only if you want them to be ;
The technological services we offer you have privacy settings that ensure, by default, the highest level of security without any intervention on your part.
We ensure that we use and disclose your PII with your consent.
However, we may use or disclose them to the extent permitted by law, including:
When their use is necessary for the purpose of supplying or delivering a product or service that you have requested from us. See the section "Information Sharing – With Third Parties" of the General Privacy Policy;
When their communication is necessary for the performance of a service contract. In this case, we make commercially reasonable efforts to include in our contracts the measures that must be taken to ensure the protection of your PII or we try and negotiate that the measures adopted by our suppliers respect the confidentiality of your PII, whether they are in Quebec or outside the province. See the section "Information Sharing – To Offer Financial Products" of the General Privacy Policy;
When the communication is necessary for the purpose of concluding a commercial transaction to which we intend to be a party. In this case, we make commercially reasonable efforts to establish an agreement before disclosing your PII to the other party, in particular to ensure that the other party destroys or returns it to us without keeping a copy if the transaction is not concluded;
When communication is necessary in our dealings with our business partners;
When disclosure is required by law or a court order.
Storage and Security
We may store and process your PII in Quebec or outside the province. In order to guarantee the confidentiality of your PII, we have put in place procedures to restrict access to your PII only to the categories of authorized persons within BF Group (mainly, finance, legal, IT, marketing, customer experience, sales, and installation departments) or to make all our staff aware of the confidentiality and security requirements of PII.
Shelf life
We retain your PII only for as long as necessary to fulfill the purposes for which it was collected, except where the law provides for a different retention period.
For example, we retain PII that is linked to your customer account until it is closed. In some cases, your PII may be retained for a longer period of time, for example, to allow us to honor the guarantees we offer or as part of a remedy.
Minor
In Quebec, a minor under the age of 14 cannot consent alone to the collection, use and disclosure of his or her PII to third parties. Therefore, we do not collect PII from minors under the age of 14 and should this happen we will take the necessary steps to delete this information.
Rights with respect to your PII
You can submit an application
access to your PII, including the portability of your PII to another service provider;
rectification of your PII;
limiting the use or disclosure of your PII;
cessation of the dissemination of your PII;
by contacting the Person in Charge of the Management of Personal Information, 225 Roy Street, Saint-Eustache (Quebec) J7R 5R5 at the following email address: privacy@bathfitter.com .
If you consider that we are not responding to your request or that you wish to file a complaint about our processing of your PII, you can contact the Commission d'accès à l'information du Québec (https://www.cai.gouv.qc.ca/english/).
13. Your California Privacy Rights
Privacy Notice for California Residents According to the CCPA
This Privacy Notice for California Residents applies solely to all visitors, users, and others who reside in the State of California (“consumers” or “you”). We have adopted this notice to comply with the California Consumer Privacy Act of 2018 (“CCPA”) and any terms defined in the CCPA have the same meaning when used in this Section of the General Privacy Policy.
Information We Collect
We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“Personal Information”). Personal Information does not include:
Publicly available information from government records.
Deidentified or aggregated consumer information.
Information excluded from the CCPA’s scope, like:
health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.
In particular, we have collected the following categories of Personal Information from consumers within the last twelve (12) months:
Category
Examples
Collected
A. Identifiers.
A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
Name, postal address, IP address, email address, phone number, social media handlers.
B. Personal Information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.
C. Protected classification characteristics under California or federal law.
Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
If a Project is VA financed or subsidized, we collect information about veteran or military status.
D. Commercial information.
Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Records of products and services purchased from us by customers; information about service calls and any other business relationship with customers.
E. Biometric information.
Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
None.
F. Internet or other similar network activity.
Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.
Browsing history, search history, information on customers’ interaction with a website, application, or advertisement.
G. Geolocation data.
Physical location or movements.
IP address, actual physical address of that IP address while customers interact with our website.
H. Sensory data.
Audio, electronic, visual, thermal, olfactory, or similar information.
None.
I. Professional or employment-related information.
Current or past job history or performance evaluations.
None.
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
None.
K. Inferences drawn from other Personal Information.
Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Use of Personal Information
Purposes of use or disclosure of your Personal Information are set forth in Section “How We Use Information” of this General Privacy Policy.
Sharing Personal Information
We may disclose your Personal Information to a third party for a business purpose, which may include sharing information about our customers or our visitors with third parties, including, but not limited to Facebook. When we disclose Personal Information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract.
Disclosures of Personal Information for a Business Purpose
In the preceding twelve (12) months, BF Group has disclosed Personal Information for a business purpose. In particular, the following categories of Personal Information collected by BF Group’ have been disclosed for a business purpose:
Personal Information Category
Business Purpose Disclosures
A. Identifiers.
Advertising networks; Internet service providers; Data analytic providers; Operating systems and platforms; Social networks; Data brokers or aggregators; Service Providers; BF Affiliates; Partners; Parent or subsidiary organizations; Internet cookie data recipients.
B. Personal Information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
Advertising networks; Internet service providers; Data analytic providers; Operating systems and platforms; Social networks; Data brokers or aggregators; Service Providers; BF Affiliates; Partners; Parent or subsidiary organizations; Internet cookie data recipients.
C. Protected classification characteristics under California or federal law.
N/A
D. Commercial information.
Service Providers; BF Affiliates; Partners; Parent or subsidiary organizations.
E. Biometric information.
N/A
F. Internet or other similar network activity.
Advertising networks; Internet service providers; Data analytic providers; Operating systems and platforms; Social networks; Data brokers or aggregators; Service providers; BF Affiliates; Partners; Parent or subsidiary organizations; Internet cookie data recipients.
G. Geolocation data.
Advertising networks; Internet service providers; Data analytic providers; Operating systems and platforms; Social networks; Data brokers or aggregators; Service Providers; BF Affiliates; Partners; Parent or subsidiary organizations; Internet cookie data recipients.
H. Sensory data.
N/A
I. Professional or employment-related information.
N/A
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
N/A
K. Inferences drawn from other Personal Information.
Advertising networks; Internet service providers; Data analytic providers; Operating systems and platforms; Social networks; Data brokers or aggregators; Service Providers; BF Affiliates; Partners; Parent or subsidiary organizations; Internet cookie data recipients.
Sales of Personal Information
In the preceding twelve (12) months, BF Group has not sold any Personal Information.
Your Rights and Choices
The CCPA provides consumers (California residents) with specific rights regarding their Personal Information. This section describes your CCPA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
The categories of Personal Information we collected about you;
The categories of sources for Personal Information we collected about you;
Our business or commercial purpose for collecting or selling that Personal Information;
The categories of third parties with whom we share that Personal Information;
The specific pieces of Personal Information we collected about you (also called a “data portability request”);
If we sold or disclosed your Personal Information for a business purpose, two separate lists disclosing:
sales, identifying the Personal Information categories that each category of recipient purchased; and
disclosures for a business purpose, identifying the Personal Information categories that each category of recipient obtained.
Deletion Request Rights
You have the right to request that we delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our Service Providers to delete) your Personal Information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our Service Provider(s) to:
Complete the transaction for which we collected the Personal Information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you;
Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
Debug products to identify and repair errors that impair existing intended functionality;
Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law;
Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.);
Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent;
Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us;
Comply with a legal obligation;
Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described in the sections “Access to Specific Information and Data Portability Rights” and “Deletion Request Rights” above, please submit a verifiable consumer request to us at privacy@bathfitter.com, or mail us at 225 Roy Street, Saint-Eustache (Quebec) J7R 5R5, Canada.
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a twelve (12) month period. The verifiable consumer request must:
Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative;
Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you.
Making a verifiable consumer request does not require you to create an account with us.
We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
For instructions on exercising sale opt-out rights.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to ninety (90) days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
Deny you goods or services;
Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
Provide you a different level or quality of goods or services;
Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your Personal Information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
14. Notice to Nevada Residents
The categories of Personal Information that BF Group collects through its Website or online service about consumers, who use or visit the Website or online service are described in Section “INFORMATION WE COLLECT” of the General Privacy Policy.
The categories of third parties with whom BF Group may share Personal Information are described in Sections “Sharing Personal Information” and “Disclosures of Personal Information for a Business Purpose” of the General Privacy Policy.
Nevada residents, who use or visit the Website or online service and desire to review and request changes to any of their Personal Information that is collected through the Website or online service, shall submit their request thereon to privacy@bathfitter.com;
The process by which BF Group notifies consumers, who use or visit the Website or online service of material changes to the notice is described in “Changes to this General Privacy Policy” section of the General Privacy Policy.
Third parties, who may collect Personal Information about Nevada residents’ online activities over time and across different Internet websites or online services when such Nevada residents use the Website or online service of BF Group are listed in “THIRD PARTIES” section of the General Privacy Policy;
Nevada residents, who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address: privacy@bathfitter.com. However, please know we do not currently sell data triggering that statute's opt-out requirements;
The effective date of the notice is indicated at the top of this General Privacy Policy.
15. Notice to Colorado, Connecticut, Virginia, and Utah Residents
Colorado, Connecticut, Virginia, and Utah in their respective privacy laws provide their state residents with rights to:
Colorado, Connecticut, and Virginia also provide their state residents with rights to:
To exercise any of these rights please email BF Group at any time at: at any time at privacy@bathfitter.com. To appeal a decision regarding a consumer right request you should file an appeal to the local data privacy authority, indicated by each privacy state law, and follow the procedure indicated therein.
16. Privacy Policy According to the GDPR
INTRODUCTION
If processing of your personal information falls within the scope of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (as defined by the GDPR) and on the free movement of such data, known as the General Data Protection Regulation (the “GDPR”), then Bath Fitter Limited, an Irish entity that, with respect of personal information governed by the GDPR serves as a controller. (for the purposes of this GDPR section, “Bath Fitter Ltd.”) shall perform such processing in accordance with GDPR requirements. Therefore, in such case, in addition to the above terms, Bath Fitter Ltd. provides you with the following information:
1. IMPORTANT INFORMATION AND WHO WE ARE
2. THE DATA WE COLLECT ABOUT YOU
3. HOW IS YOUR PERSONAL DATA COLLECTED?
4. HOW WE USE YOUR PERSONAL DATA
5. DISCLOSURES OF YOUR PERSONAL DATA
6. INTERNATIONAL TRANSFERS
7. DATA SECURITY
8. DATA RETENTION
9. YOUR LEGAL RIGHTS
10. GLOSSARY
1. IMPORTANT INFORMATION AND WHO WE ARE
PURPOSE OF THIS GDPR PRIVACY POLICY
This GDPR Privacy Policy that is incorporated into the General Privacy Policy (the “GDPR Privacy Policy”) aims to give you information on how Bath Fitter Ltd. collects and processes personal data that is governed by the GDPR, through your use of its Website, including any data you may provide through the Website when you sign up to our newsletter or marketing emails, or make any enquiry for information from us, or contact us to set up an appointment.
The Website is not intended for children and we do not knowingly collect data relating to children.
CONTROLLER
Bath Fitter Limited, Units 25 & 41 Eastlink Business Park, Ballysimon, Limerick, Ireland
CONTACT DETAILS
If you have any questions about this GDPR Privacy Policy or Bath Fitter Ltd.’s privacy practices with respect to personal information governed by the GDPR, please contact Bath Fitter Ltd. in the following ways:
Postal address: Units 25 & 41 Eastlink Business Park, Ballysimon, Limerick, Ireland
Telephone: +1 450 472 0027 x6789
You have the right to make a complaint at any time to the appropriate Data Protection Commission. Bath Fitter Ltd. would, however, appreciate the chance to deal with your concerns before you approach the Data Protection Commission so please contact Bath Fitter Ltd. directly in the first instance.
CHANGES TO THE GDPR PRIVACY POLICY AND YOUR DUTY TO INFORM US OF CHANGES
Bath Fitter Ltd. keeps its GDPR Privacy Policy under regular review.
It is important that the personal data Bath Fitter Ltd. holds about you is accurate and current. Please keep Bath Fitter Ltd. informed if your personal data changes during your relationship with us.
THIRD-PARTY LINKS
The Website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. Bath Fitter Ltd. does not control these third-party websites and is not responsible for their privacy statements. When you leave the Website, we encourage you to read the privacy policy of every website you visit.
2. DATA WE COLLECT ABOUT YOU
Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
Bath Fitter Ltd. may collect, use, store and transfer different kinds of personal data about you which it has grouped together as follows:
Identity Data includes name, username or similar identifier, title.
Contact Data includes location address, email address and telephone numbers.
Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Website.
Profile Data includes your interests, preferences, feedback and any survey responses.
Usage Data includes information about how you use our Website, products and services.
Marketing and Communications Data includes your preferences in receiving marketing from Bath Fitter Ltd. and your communication preferences.
Bath Fitter Ltd. also does collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, Bath Fitter Ltd. may aggregate your Usage Data to calculate the percentage of users accessing a specific Website feature. However, if Bath Fitter Ltd. does combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, Bath Fitter Ltd. does treat the combined data as personal data which will be used in accordance with this GDPR Privacy Policy.
Except for employment-related information, and subject to applicable law, Bath Fitter Ltd. does not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Except for employment-related information, and subject to applicable law, Bath Fitter Ltd. does not collect information about criminal convictions and offences.
IF YOU FAIL TO PROVIDE PERSONAL DATA
Where Bath Fitter Ltd. needs to collect personal data by law, or under the terms of a contract it has with you, and you fail to provide that data when requested, Bath Fitter Ltd. may not be able to perform the contract it has or is trying to enter into with you (for example, to provide you with goods or services). In this case, Bath Fitter Ltd. may have to cancel a product or service you have therewith, but Bath Fitter Ltd. will notify you if this is the case at the time.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
Bath Fitter Ltd. uses different methods to collect data from and about you including through:
Direct interactions. You may give Bath Fitter Ltd. your personal data by filling in forms or by corresponding with Bath Fitter Ltd. by post, phone, email or otherwise. This includes personal data you provide when you:
contact Bath Fitter Ltd. with an enquiry;
request marketing to be sent to you or subscribe to any newsletters or other information we make available from time to time;
enter a promotion or survey;
talk to any of Bath Fitter Ltd. Employees over the phone or
give Bath Fitter Ltd. feedback.
Automated technologies or interactions. As you interact with the Website, Bath Fitter Ltd. will automatically collect Technical Data about your equipment, browsing actions and patterns. Bath Fitter Ltd. does collect this personal data by using cookies, server logs and other similar technologies. Bath Fitter Ltd. may also receive Technical Data about you if you visit other websites employing our cookies. Please, see the Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/for further details.
Third parties. Bath Fitter Ltd. will receive Technical Data relating to you from Google Analytics.
4. HOW BATH FITTER LTD. USES YOUR PERSONAL DATA
Bath Fitter Ltd. will only use your personal data when the law allows it to. Most commonly, Bath Fitter Ltd. will use your personal data in the following circumstances:
Where Bath Fitter Ltd. needs to perform the contract it is about to enter into or has entered into with you.
Where it is necessary for its legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Where Bath Fitter Ltd. needs to comply with a legal obligation.
Generally, Bath Fitter Ltd. does not rely on consent as a legal basis for processing your personal data although it will get your consent before sending direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting Bath Fitter Ltd.
PURPOSES FOR WHICH BATH FITTER LTD. WILL USE YOUR PERSONAL DATA
Bath Fitter Ltd. has set out below, in a table format, a description of all the ways Bath Fitter Ltd. plans to use your personal data, and which of the legal bases it relies on to do so. Bath Fitter Ltd. has also identified what its legitimate interests are where appropriate.
Note that Bath Fitter Ltd. may process your personal data for more than one lawful ground depending on the specific purpose for which it is using your data. Please contact Bath Fitter Ltd. if you need details about the specific legal basis it is relying on to process your personal data where more than one ground has been set out in the table below.
Purpose/Activity
Type of data
Lawful basis for processing including basis of legitimate interest
To register you as a new customer/lead/potential client
(a) Identity (b) Contact
(a) Performance of a contract with you; (b) Necessary for our legitimate interests (to develop and grow our business) (c) Consent
To manage our relationship with you which will include: (b) Asking you for feedback on business or to take a survey (c) Sending appropriate marketing communications to you
(a) Identity (b) Contact (c) Profile (d) Marketing and Communications
(a) Performance of a contract with you (b) Necessary for legitimate interests (to keep records updated and to study how customers use products/services and to develop and grow its business) (c) Consent
To enable you to partake in a prize draw, competition or complete a survey
(a) Performance of a contract with you (b) Necessary for legitimate interests (to study how customers use products/services and to develop and grow its business)
To administer and protect Bath Fitter Ltd.’s business and this Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
(a) Identity (b) Contact (c) Technical
(a) Necessary for legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) (b) Necessary to comply with a legal obligation
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you
(a) Necessary for legitimate interests (to study how customers use products/services, to develop them, to develop and grow business and to inform of marketing strategy) (b) Consent
To use data analytics to improve Website, products/services, marketing, customer relationships and experiences
(a) Technical (b) Usage
Necessary for legitimate interests (to define types of customers for products and services, to keep Website updated and relevant, to develop and grow business and to inform of marketing strategy)
For quality purposes (including identifying trends and efficiencies)
(a) Necessary for legitimate interests (to develop products/services and develop and grow business) (b) Consent
MARKETING
Bath Fitter Ltd. strives to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. Where you no longer wish to receive marketing information from us, please contact Bath Fitter Ltd. at privacy@bathfitter.com at any time to let it know and it will cease all marketing communications to you.
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our Email and Text Communication Terms and Conditions (available at: https://www.bathfitter.com/us-en/terms-and-conditions/).
PROMOTIONAL OFFERS FROM US
Bath Fitter Ltd. may use your identity, contact, technical, usage and profile data to form a view on what it thinks you may want or need, or what may be of interest to you. This is how Bath Fitter Ltd. decides which products, services and offers may be relevant for you (Bath Fitter Ltd. calls this marketing).
You will receive marketing communications from Bath Fitter Ltd. if you have requested information from Bath Fitter Ltd. or purchased goods or services therefrom and you have not opted out of receiving that marketing, or where you give Bath Fitter Ltd. consent to market to you.
OPTING OUT
You can ask Bath Fitter Ltd. to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting Bath Fitter Ltd. at any time at privacy@bathfitter.com.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to Bath Fitter Ltd. as a result of a product/service purchase, warranty registration, product/service experience or other transactions.
Bath Fitter Ltd. will only use your personal data for the purposes for which it has collected it, unless Bath Fitter Ltd. reasonably considers that it needs to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact Bath Fitter Ltd.
If Bath Fitter Ltd. needs to use your personal data for an unrelated purpose, it will notify you and explain the legal basis which allows Bath Fitter Ltd. to do so.
Please note that Bath Fitter Ltd. may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
5. DISCLOSURES OF YOUR PERSONAL DATA
Bath Fitter Ltd. may share your personal data with the parties set out below for the purposes set out in the table “Purposes for which we will use your personal data” above.
Internal Third Parties as set out in the Glossary.
External Third Parties as set out in the Glossary.
Third parties, to whom Bath Fitter Ltd. may choose to sell, transfer or merge parts of its business or assets. Alternatively, Bath Fitter Ltd may seek to acquire other businesses or merge with them. If a change happens to Bath Fitter Ltd.’s business, then the new owners may use your personal data in the same way as set out in this GDPR Privacy Policy.
Bath Fitter Ltd. requires all third parties to respect the security of your personal data and to treat it in accordance with the law. Bath Fitter Ltd. does not allow its third-party Service Providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with its instructions.
6. INTERNATIONAL TRANSFERS
Bath Fitter Ltd. shares your personal data with BF Affiliates, including Bath Fitter Distributing Inc., incorporated in Canada and located at 225, rue Roy, Saint-Eustache (Québec) Canada J7R 5R5. In case of a data transfer outside the European Economic Area (EEA), such transfer will, where required, take place pursuant to written agreements, which contain provisions (including, but not limited to, European Contractual Clauses) to safeguard your data.
7. DATA SECURITY
Bath Fitter Ltd. has put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, Bath Fitter Ltd. limits access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on Bath Fitter Ltd.’s instructions, and they are subject to a duty of confidentiality.
Bath Fitter Ltd. has put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where Bath Fitter Ltd. is legally required to do so.
8. DATA RETENTION
HOW LONG WILL YOU USE MY PERSONAL DATA FOR?
Bath Fitter Ltd. will only retain your personal data for as long as reasonably necessary to fulfil the purposes it collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. Bath Fitter Ltd. may retain your personal data for a longer period in the event of a complaint or if it reasonably believes there is a prospect of litigation in respect to Bath Fitter Ltd.’s relationship with you.
To determine the appropriate retention period for personal data, Bath Fitter Ltd. considers the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which Bath Fitter Ltd. processes your personal data and whether Bath Fitter Ltd. can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
By law Bath Fitter Ltd. has to keep basic information about its customers for six years after they cease being customers for certain regulatory purposes.
In some circumstances you can ask Bath Fitter Ltd. to delete your data: see Section 9 of this GDPR portion of this General Privacy Policy “Your Legal Rights” below for further information.
In some circumstances Bath Fitter Ltd. will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case Bath Fitter Ltd. may use this information indefinitely without further notice to you.
9. YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the following:
Request access to your personal data. This enables you to receive a copy of the personal data Bath Fitter Ltd. holds about you and to check that Bath Fitter Ltd. is lawfully processing it; Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data Bath Fitter Ltd. holds about you corrected, though Bath Fitter Ltd. may need to verify the accuracy of the new data you provide thereto; Request erasure of your personal data. This enables you to ask Bath Fitter Ltd. to delete or remove personal data where there is no good reason for Bath Fitter Ltd. continuing to process it. You also have the right to ask Bath Fitter Ltd. to delete or remove your personal data where you have successfully exercised your right to object to processing (see section “Object to processing” of this GDPR Privacy Policy below), where Bath Fitter Ltd. may have processed your information unlawfully or where Bath Fitter Ltd. is required to erase your personal data to comply with local law. Note, however, that Bath Fitter Ltd. may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request; Object to processing of your personal data where Bath Fitter Ltd. is relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts your fundamental rights and freedoms. You also have the right to object where Bath Fitter Ltd. is processing your personal data for direct marketing purposes. In some cases, Bath Fitter Ltd. may demonstrate that it has a compelling legitimate ground to process your information which override your rights and freedoms;Request restriction of processing of your personal data. This enables you to ask Bath Fitter Ltd. to suspend the processing of your personal data in the following scenarios:
If you want Bath Fitter Ltd. to establish the data’s accuracy.
Where you need Bath Fitter Ltd. to hold the data even if it no longer requires it as you need it to establish, exercise or defend legal claims.
You have objected to Bath Fitter Ltd.’s use of your data but Bath Fitter Ltd. needs to verify whether it has an overriding legitimate ground to use it; Request the transfer of your personal data to you or to a third party. Bath Fitter Ltd. will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for Bath Fitter Ltd. to use or where Bath Fitter Ltd. used the information to perform a contract with you; and Withdraw consent at any time where Bath Fitter Ltd. is relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, Bath Fitter Ltd. may not be able to provide certain products or services to you. Bath Fitter Ltd. will advise you if this is the case at the time you withdraw your consent.If you wish to exercise any of the rights set out above, please contact Bath Fitter Ltd.’s data privacy manager.
NO FEE USUALLY REQUIRED
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, Bath Fitter Ltd. may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, Bath Fitter Ltd. could refuse to comply with your request in these circumstances.
WHAT WE MAY NEED FROM YOU
Bath Fitter Ltd. may need to request specific information from you to help Bath Fitter Ltd. confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person, who has no right to receive it. Bath Fitter Ltd. may also contact you to ask you for further information in relation to your request to speed up its response.
TIME LIMIT TO RESPOND
Bath Fitter Ltd. tries to respond to all legitimate requests within one month. Occasionally it could take Bath Fitter Ltd. longer than a month if your request is particularly complex or you have made a number of requests. In this case, Bath Fitter Ltd. will notify you and keep you updated.
10. GLOSSARY
LAWFUL BASIS
Legitimate Interest means the interest of Bath Fitter Ltd.’s business in conducting and managing its business to enable it to give you the best service/product and the best and most secure experience. Bath Fitter Ltd. makes sure it considers and balances any potential impact on you (both positive and negative) and your rights before Bath Fitter Ltd. processes your personal data for its legitimate interests. Bath Fitter Ltd. does not use your personal data for activities where its interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how Bath Fitter Ltd. assesses its legitimate interests against any potential impact on you in respect of specific activities by contacting Bath Fitter Ltd.’s data privacy manager.
Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request (or in response to an enquiry from you) before entering into such a contract.
Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that Bath Fitter Ltd. is subject to.
THIRD PARTIES
INTERNAL THIRD PARTIES
Other companies in the BF Group including Bath Fitter Distributing Inc. and who are based in Canada and other countries acting as controllers and processors and who provide IT, system administration, support and maintenance, management, hosting of data, financial and business support services
EXTERNAL THIRD PARTIES
Service providers acting as processors based in the EEA and outside of the EEA who provide business support services, IT, HR, marketing, customer experience and system administration services.
Service providers acting as processors based in the EEA and outside of the EEA who provide surveying, measurements, photographic, design, fabrication, repair and installation services.
Professional advisers acting as processors and controllers including lawyers, marketing agencies, bankers, auditors and insurers based in the EEA and outside of the EEA who provide consultancy, banking, legal, insurance and accounting services.
The Revenue Commissioners, regulators and other authorities acting as controllers based in Ireland who require reporting of processing activities in certain circumstances.
Contractors for after sale/installation services
17. Changes to the General Privacy Policy and the Specific Policies Pertaining to Certain Jurisdictions
From time to time we may change our General Privacy Policy and/or our specific policies pertaining to certain jurisdictions where we do business. We will notify you of any material changes to any of the above policies by posting an updated copy on our Website. Please check our Website periodically for updates.
General Privacy Policy
Effective Date: 14/06/2019
Last Revision Date: 4/4/2023
Policies Specific to Certain Jurisdictions
California: Effective Date: 14/06/2019 – Last Revision Date: 23/09/2022
Nevada: Effective Date: 20/07/2021 – Last Revision Date: 23/09/2022
Europe: Effective Date: 14/6/2019 – Last Revision Date: 23/09/2022