We are The Stationery Office Limited (referred to in this document as We, Us, Our and TSO).
We are a member of the Williams Lea Group of companies.
We sell and publish products on behalf of a number of organisations. In the majority of cases, we are the Data Controller under the Data Protection Legislation for any information that you share with us when accessing our products and services.
In certain circumstances we are acting as a Data Processor for an organisation whose products and services we provide through this website.
Our office address is:
18 Central Avenue
St. Andrews Business
Park
Norwich
England
NR7
0HR.
We are registered with the ICO under Registration number; Z717712X.
We understand the importance of your personal data and are committed to meeting the requirements of the Data Protection Legislation. To help us meet our obligations, and your expectations, we have developed this privacy notice to ensure that you are fully aware of:
This notice applies to all of our data collection and processing activities including:
Throughout this notice, where we refer to Data Protection Legislation, we mean the Data Protection Act 2018 (DPA2018), United Kingdom General Data Protection Regulation (UK GDPR), the Privacy and Electronic Communications (EC Directive) Regulations 2003 and any legislation implemented in connection with this legislation.
When you are based in the EU, it also includes the EU General Data Protection Regulation (EU GDPR). This includes any replacement legislation coming into effect from time to time.
We will use your information as set out in this Privacy Policy. If we need to use your personal information for any other purpose, we will take steps to provide you with additional information and we will update this privacy notice.
We only collect personal information that we genuinely need to provide our services to you and in accordance with the Data Protection Legislation.
We collect information about you from various sources depending on the services that you are engaging with - some information is collected directly from you; some is generated when you interact with our website.
Information we collect directly from you may include:
If you are a business customer, we may also collect information about your employer and your role.
In your use of our services, we may generate information about you such as:
We collect limited technical information about your visit to our site, this helps us to better understand how our customers move around, and interact with, our website.
We do not routinely collect or process any Special Category information about you in the provision of our services.
We will only ever process your personal data if we have a lawful basis to do so. The lawful bases we rely on are:
Contract - This is where we process your information to fulfil a contractual arrangement, we have made with you such as the delivery of any Items that you purchase.
Consent - This is where we have asked you to provide permission to process your data for a particular purpose such as to send you marketing material. Please note, if we are relying on your Consent, you can withdraw your consent at any time by contacting us or using the opt out link in any emails that we send to you.
Legitimate interests - This is where we rely on our interests as a reason for processing, generally this is to provide our service in the most secure and appropriate way.
Legal obligation - This is where we have a statutory or other legal obligation to process the information, such as for the investigation of crime.
You have a number of Rights under the Data Protection Legislation. If you would like to exercise any of these rights, you can contact us using the contact details in the "Contact Us" Section.
Your rights under the Legislation are:
You have the right to be informed about the collection and use of your personal data. This privacy notice gives you this information.
You have the right to access the personal information that we hold about. This is sometimes termed 'Subject Access Request.' If we agree that we are obliged to provide personal information to you (or someone else on your behalf), we will provide it to you or them free of charge and aim to do so within 1 month from the point that we are able to confirm your identity. We will ask for proof of identity and sufficient information about your interactions with us that we can locate your personal information.
If any of the personal information we hold about you is inaccurate, incomplete or out of date, you can ask us to correct it. You can update your information thorough your online account or by contacting our customer services team.
In some cases, we are not responsible for the content of the documents that are available through our website and as such we are unable to make corrections. In such circumstances we will seek to assist you in contacting the relevant company or organisation.
You have the right to ask us to restrict the processing of your personal data. For example, this may be because you have issues with the accuracy of the data we hold or the way we have processed your data. The right is not absolute and only applies in certain.circumstances. As with the right to correction, in some cases we are not responsible for the content of the documents that are available through our website and as such we are unable to make corrections.
You have the right to have personal data erased. This is also known as the 'right to be forgotten'. The right is not absolute and will only apply in certain circumstances.
The right to portability gives you the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format. It also gives you the right to request that we transmit this data directly to another controller.
You have the right to object to our processing of some or all of the personal data that we hold about you. This is an absolute right when we use your data for direct marketing but may not apply in other circumstances where we have a compelling reason to do so, for example if we have a legal obligation.
The Information Commissioner's Office (ICO) regulates data protection and privacy matters in the UK. They make lots of information accessible to consumers on their website and they ensure that the registered details of all data controllers such as ourselves are available publicly. You can access the ICOs consumer information at https://ico.org.uk/for-the-public.
You can make a complaint to the ICO at any time about the way we use your information. However, we hope that you would consider raising any issue or complaint you have with us first. Details of how to contact us can be found in the Contact Us section of this notice.
Your satisfaction is extremely important to us, and we will always do our absolute best to solve any problems you may have.
We will use your personal information for a number of purposes namely to ensure we are providing our services to you in the ways that you would expect. We will particularly use personal information for the below purposes:
We will use certain personal and technical information including information from Cookies to:
Note - You can unsubscribe from marketing communications at any time using the unsubscribe link in our email, by contacting our customer services team or through your online account by navigating to "Email Preferences" and follow the instruction to "Unsubscribe!.
We retain a record of your personal information in order to provide you with a high quality and consistent service and to evidence the actions we have taken on your behalf.
In line with the Data Protection Legislation, we only keep your personal information for the length of time we need it to:
In some circumstances we may need to share your personal data with third parties in order to:
We may share your personal information with:
In some cases, the products offered for sale on our site are published by an independent third party, in these cases we are acting as a reseller only. In such cases, depending on our relationship with the organisation, we may share limited information about the products and services that you have ordered along with personal information, with these third parties in order for them to manage demand, dispatch goods to you directly or to manage their business.
We may also provide such information back to these organisations if we cease to be a reseller for their goods or services. In these situations, you will be provided with additional privacy information by the organisation directly.
In all cases we:
In some instances, your personal information may be processed outside the UK and the European Economic Area. For example, we work with suppliers and partners who may make use of cloud and /or hosted technologies across multiple geographies and jurisdictions.
If and when this is the case, we take steps to ensure there is an appropriate level of security so your personal information is protected in the same way as if it was being used within the UK or the EEA.
Where we need to transfer your data outside the UK or EEA, we will use one of the following safeguards:
Data security is of great importance to Us and to protect your data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure any information that we control. TSO hold ISO27001 certification, covering our information governance and security standards and are audited against this standard annually.
At a high level we have put the below measure in place:
Our websites may include links to external websites operated by other organisations. They may collect personal information from visitors to their site. We cannot guarantee the content or privacy practices of any external websites and does not accept responsibility for those websites.
We may change this privacy notice from time to time (for example, if the law changes). If the changes are material, we will take steps to inform you via email or through our services.
If you would like to:
You can contact us using the details below: