Tablet

Tablet - Ox Brookes

Mobile

Mobile - Ox Brookes

 

Privacy Policy

 

1. Who we are

Blue Blood Sports Ltd ("Blue Blood", "we", "us" or "our") is the controller of personal information described in this notice, except where another organisation is expressly identified as the controller for a particular activity.

Company number: 11716729. Registered in England and Wales. Business address: Unit 3, North Weston Business Estate, Thame, OX9 2HA.

Privacy enquiries: info@bluebloodoxford.co.uk | Telephone: 01865 590 900

2. Scope of this notice

This notice explains how we use personal information when you browse our website, create or use an account, place an order, request personalisation, contact us, receive marketing, or use a branded store that we operate for a school, college, university, club or business.

3. Information we collect

  • Identity and contact data, such as name, organisation, email address, telephone number, billing address and delivery address.
  • Account data, such as login and account preferences. We do not ask you to disclose your password to us.
  • Transaction and order data, such as products, sizes, personalisation instructions, order history, delivery, returns and refund information.
  • Payment-related data. Payments are handled through payment service providers. We do not intend to retain full payment-card details.
  • Communications data, including enquiries, emails, telephone notes, complaints and customer-service correspondence.
  • Marketing preferences and records of consent, objection or unsubscribe requests.
  • Technical and usage data, such as IP address, browser, device, operating system, referring page, pages viewed, interactions, security events and cookie identifiers.
  • Information supplied by an organisation operating a branded store, where needed to verify eligibility, administer an agreed scheme or fulfil an order.

4. How and why we use personal information

Purpose

Information

Lawful basis

Provide quotations and respond to enquiries

Identity, contact and communications data

Legitimate interests in responding to customers and developing our business; contract where steps are requested before purchase

Create and manage accounts

Identity, contact, account and technical data

Contract; legitimate interests in administering accounts and protecting the service

Take, personalise and fulfil orders

Identity, contact, account, transaction and personalisation data

Contract

Process payment, refunds and prevent fraud

Identity, contact, transaction, technical and payment-related data

Contract; legal obligation; legitimate interests in preventing fraud and protecting our business

Deliver goods and manage returns

Identity, contact and transaction data

Contract

Provide customer service and handle complaints

Identity, contact, transaction and communications data

Contract; legitimate interests in resolving issues and maintaining service quality

Keep accounting, tax and legal records

Identity, contact, transaction and communications data

Legal obligation; legitimate interests in establishing, exercising or defending legal claims

Operate, secure and troubleshoot the website

Technical, usage, account and security data

Legitimate interests in maintaining a secure and reliable service

Measure website use and improve services

Technical, usage and cookie data

Consent where non-essential cookies or similar technologies are used

Send electronic marketing

Identity, contact, purchase history and preference data

Consent, or the electronic-mail soft opt-in where legally available; legitimate interests for limited business-to-business marketing where permitted

Administer branded online stores

Identity, contact, account, eligibility and transaction data

Contract; legitimate interests in delivering the branded-store service and meeting agreed requirements

5. Cookies and similar technologies

We use essential technologies required for the operation, security and functionality of our website, customer accounts, shopping basket and checkout process.

Where non-essential analytics, advertising or personalisation technologies are used, these will only be activated where the user has provided the required consent through our cookie preference tool.

Users may accept, reject or amend their cookie preferences at any time through the cookie preference tool.

Further information about the technologies we use, including their purpose, category and duration, is available through our cookie notice and cookie preference centre.

6. Who we share information with

  • E-commerce, website-hosting and content-delivery providers.
  • Payment, fraud-prevention and banking providers.
  • Couriers, postal operators, fulfilment partners and suppliers involved in completing an order.
  • Email, cloud productivity, customer-service, RMM, EDR, cyber-security, backup and business-system providers.
  • Analytics, consent-management and marketing providers, where enabled and permitted.
  • Accountants, auditors, insurers, legal advisers and other professional advisers.
  • Schools, colleges, universities, clubs or businesses connected with a branded store, but only where there is a defined and lawful need to share the information.
  • Police, regulators, courts, public authorities or other parties where disclosure is required or permitted by law.

We require service providers acting as processors to use personal information only on our documented instructions, keep it secure and assist us with our data-protection obligations.

7. Oxford Brookes University branded store

Blue Blood operates the Oxford Brookes University branded store and is responsible for order processing, payment handling, fulfilment, delivery, returns and customer-service enquiries. Oxford Brookes University authorises use of its name, logos and branding. The University is not responsible for those retail activities unless expressly stated otherwise. If information is shared with the University for a separate purpose, the relevant controller roles and purpose will be explained at the point of collection or in an updated notice.

8. International transfers

Some providers may store or access personal information outside the United Kingdom. Where UK data-protection law requires safeguards, we will use an approved transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with additional measures where appropriate. The final processor review should record the destination and safeguard used for each relevant provider.

9. How long we keepinformation

Record

Proposed retention rule

Orders, invoices and accounting records

Normally 6 years after the end of the relevant financial year, or longer where legally required

Customer-service correspondence

Normally 24 months after closure, unless linked to an order, complaint or legal claim requiring longer retention

Account data

For the life of the account and normally 24 months after closure or inactivity, subject to order-record requirements

Unsuccessful quotations and general enquiries

Normally 12 months after the last meaningful contact

Marketing records

While marketing continues, plus a suppression record after opt-out so that the preference can be respected

Consent records

For as long as needed to demonstrate the consent and manage withdrawal

Security logs

According to a documented operational schedule proportionate to the security purpose

Cookie and analytics data

According to the durations displayed in the cookie preference centre and provider settings

We may retain information for longer where necessary to comply with law, respond to a dispute, prevent fraud or establish, exercise or defend legal claims. Blue Blood should approve these periods against operational and legal requirements before publication.

10. Security

We use appropriate organisational and technical measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure or access. Measures are selected according to risk and may include access controls, multi-factor authentication, device management, endpoint protection, patching, encryption, monitoring, backups, staff awareness and supplier oversight. No internet service can be guaranteed completely secure.

11. Your rights

  • Be informed about how your information is used.
  • Request access to your personal information.
  • Ask us to correct inaccurate or incomplete information.
  • Ask us to erase information where the law permits.
  • Ask us to restrict use of information in certain circumstances.
  • Object to processing based on legitimate interests and object at any time to direct marketing.
  • Receive certain information in a portable format where the right applies.
  • Withdraw consent at any time, without affecting earlier lawful processing.
  • Complain to the Information Commissioner’s Office.

To exercise a right, contact us using the details in section 1. We may need information to verify your identity and locate the relevant records. Rights are not absolute and exemptions may apply.

12. Complaints

Please contact us first so that we can investigate. You may also complain to the Information Commissioner’s Office at https://ico.org.uk/.

13. Children

Our products may be bought for children, but the online store is intended to be used by a parent, guardian or other person able to enter into the purchase. We have names supplied only for the purpose of embroidery or print naming and no other personal details on the child held.

14. Third-party links

Our website may link to services operated by other organisations. Their use of personal information is governed by their own privacy information. We are not responsible for those external services.

15. Changes to this notice

We may update this notice when our services, suppliers or legal obligations change. The current version will be published on our website with its review date. Material changes may also be brought to your attention by an appropriate additional notice.