1. Introduction and Objectives
2. About This General Privacy Policy
3. PII We Collect
4. How PII is Collected
5. How We Use PII
6. Information Sharing
7. Your Privacy Preferences
8. Our Sites and Children
9. Calls Recordings
10. Security and Links
11. Contact Us
12. Notice to Residents of Quebec
13. Your California Privacy Rights
14. Notice to Nevada Residents
15. Notice to Colorado, Connecticut, Virginia, and Utah Residents
16. Privacy Policy According to the GDPR
17. Changes to the General Privacy Policy and the Specific Policies Pertaining to Certain Jurisdictions
Each of Bath Fitter Distributing Inc. (“BF Distributing”) and its affiliates (which shall include any entity that directly or indirectly (including through one or more intermediaries), controls, is controlled by, or is under common control with BF Distributing, each a “BF Affiliate”, and collectively the “BF Affiliates”), and Bath Fitter® franchisees, who either post this General Privacy Policy on their websites, or use Website (as defined herein) as their website (the “Franchisees”, and collectively with BF Distributing and the BF Affiliates, and/or individually, “BF Group” “our”, “us” or “we”) values and respects the privacy of its customers and the visitors of the https://www.bathfitter.com website for the Canada and US residents, the https://www.bathfitter.ie website for the Ireland residents and the https://www.bathfitter.co.uk website for the UK residents (collectively and individually, the “Website”).
Accordingly, the purpose of this General Privacy Policy (the “General Privacy Policy”) is to provide you with information about how BF Group collects, uses, and shares personally identifiable information it gathers from customers and Website visitors (“PII”). The General Privacy Policy also describes the choices you can make about our use of your PII.
This General Privacy Policy describes the privacy practices adopted by BF Group. However, this General Privacy Policy does not apply to Bath Fitter® franchisees, other than Franchisees, or PII shared with, or processed by, third-party websites you accessed through our Website.
The General Privacy Policy covers our interactions with customers and visitors, including, but not limited to:
Our collection efforts are designed to improve your purchasing experience, and to provide relevant information about our products, services, and promotions. To do this, we may collect the following PII:
Contact information
We collect the names, cell or home phone numbers, email and/or postal address of customers and/or potential clients, who placed an order with us, entered into any agreement with us, completed our online form to request an estimate, appointment, and discuss a project, or to ask us any question, or contacted us for any other reason. Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our
Email and Text Communication Terms and Conditions (available at: https://www.bathfitter.com/us-en/terms-and-conditions/for Canada and US residents, at: https://www.bathfitter.eu/terms-and-conditionsfor Ireland residents and at https://www.bathfitter.eu/terms-and-conditionsfor UK residents).
Additionally, we may collect your purchase history, billing addresses, electronic signature (when necessary or advisable) and other digital contact information. We may also collect information that you provide to us about others.
Payment and Financing Information
When you make a purchase, we may collect your payment information, including information from your credit or debit card, check, PayPal account or gift card.
If you apply for a BF Group-administered loan or financing, we might collect any other information related to your application.
Demographic Information
We may collect information about reviews you submit and other data like your age and gender.
Usage Data
We collect and process usage data that includes information about how you use our Website, products and services.
We might also track the pages you visit, look at which website you came from, or which website you visit when you leave us. We collect this information using the tracking tools described in the Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at https://www.bathfitter.eu/cookie-policy for UK residents.
Aggregated Data
We also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your PII, but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific Website feature. However, if we combine or connect aggregated data with your PII so that it can directly or indirectly identify you, we treat the combined data as PII which will be used in accordance with this General Privacy Policy.
Social Media Information, and Information Provided Electronically
If you interact with us on social media, such as, but not limited to Facebook, YouTube, Pinterest, TikTok, Instagram and X, we may collect your username, other PII, and any of the information or content that you provide through our Website, device applications, or online forums.
Technical and Geolocation Data
We collect technical data that includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform (collectively, the “Technical Data”), and other technology on the devices you use to access this Website.
If you use our mobile website (including the Website), mobile applications, or other smart device applications, we may collect location data obtained from your device (including the IP address). If you use our Website, we may collect location data obtained from your IP address. For more information, please consult our Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at https://www.bathfitter.eu/cookie-policyfor UK residents.
Employment Information
If you apply for an employment opportunity, we may collect certain PII that you provide to us (whether it be in a resume, cover letter or similar employment-related materials, or any applicable pre-screening questions). With respect to our current respective employees, we collect their PII for employment-related purposes, as permitted by applicable law. We may also collect PII of our respective employees when it is necessary for rendering services by BF Group.
PII Collected Through the Free In-Home Consultation Form
The Free In-Home Consultation is an optional form to fill out if you are interested in a BF Group product. You do not have to fill out the form to browse our Website online. When filling out the form, you are asked for PII such as your name, address, phone number and email address that you select. This information may be used to help our sales representatives contact you to answer any questions or provide you with a free in-home consultation appointment.
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our Email and Text Communication Terms and Conditions (available at:
https://www.bathfitter.com/us-en/terms-and-conditions/ for Canada and US residents, at:https://www.bathfitter.eu/terms-and-conditions for Ireland residents and at https://www.bathfitter.eu/terms-and-conditions for UK residents).
We collect PII directly from you or from others if they provide your PII to us.
To illustrate the manner we collect PII, below we list just some examples of how and when we may collect PII from you:
We may collect your PII through automated technologies or interactions, and as you interact with our Website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. More details thereon are included in our Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at https://www.bathfitter.eu/cookie-policy for UK residents.
We may get PII about you from other sources, such as third-party business partners, such as Google Analytics. We may collect PII about you from a friend or other relative. For example, if your friend provides your PII through one of our refer-a-friend type features. If you use one of these features, please ensure that you only submit email addresses and other PII of individuals, with whom you have a close personal or family relationship, who would be interested in receiving the communication, and who have authorized you to share their email address and other PII
We use the PII we collect for our business purposes, including:
To respond to your questions and requests.
Examples include, but are not limited to:
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our
Email and Text Communication Terms and Conditions (available at:
https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at:
https://www.bathfitter.eu/cookie-policy for Ireland residents and at
https://www.bathfitter.eu/cookie-policy for UK residents).
To enter into an agreement with you.
We may use your PII to negotiate an agreement with you, enter into an agreement with you, and store the agreement for our records.
To improve our products and services.
We may use your PII to make Website, device application, or product and service improvements, and also to identify certain trends or preferences in websites and mobile applications.
We might use your PII to customize your experience with us. We may collect information about your activities and interactions with various devices and link that information. Through cross-device linking, we provide customers with a consistent experience across devices used. We may also combine information we get from you with information about you we have received from third parties or publicly available sources to assess trends and interests.
For security and loss prevention purposes.
We may collect/use your PII to protect our business, our facilities, customers, our respective employees or our Website. For example, we might use cameras in our stores to track store traffic and stock.
For our marketing.
In certain circumstances, we may send you communications about special promotions or offers via regular mail, email, or other electronic channels, including ads on social media platforms. We may send you emails if you have registered on Website, indicated that you want to receive this information, or if you gave us your information at one of our stores or events. We may also notify you of new Website features or product and service offerings. To manage our communications with you, follow the instructions in the “Privacy Preferences” section of this General Privacy Policy below. We may use information collected across different online services and the various devices you use in order to deliver marketing communications (including online ads) based on your interests. For example, if you view a product on our Website, you may see ads for that product on our or third-party websites and applications.
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our
Email and Text Communication Terms and Conditions (available at:
https://www.bathfitter.com/us-en/terms-and-conditions/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at
https://www.bathfitter.eu/cookie-policyfor UK residents).
To communicate with you about your account, our programs, your feedback, and any rebates.
We may contact you to inform you about changes to this General Privacy Policy, the Terms of Use of our Website or device applications, or changes to any of our programs in which you might be enrolled. We may also tell you about issues with your orders or if there is a product or service rebate, or we may ask for your feedback or review of services rendered and/or products sold by BF Group.
For employment purposes.
We may use the PII you provide in connection with a job application or related inquiry for the purpose of processing and responding to your application or inquiry. We may further use your PII when you accept our employment offer to comply with obligations imposed on BF Group by applicable law, or when and as it is necessary for rendering services by BF Group.
For social media.
When you engage with our content through third-party social networking websites, plug-ins and applications, you may allow us to have access to certain social media account information (e.g., name, username, email address, gender) as determined by the settings of the social media services to deliver the content or as part of the operation of the Website, plug-in or application. Social media platforms may collect information about your use of our services and may notify other users of the platform about your activities on our Website and device applications. Social media services may also use cookies or other technologies to provide services or track your online activities over time and across multiple websites and device applications. Your interactions with social media features are governed by the respective privacy policies of the companies providing the features.
For quality purposes (including identifying trends and efficiencies)
Except California, Illinois, Texas and Washington, we may use PII recorded during phone calls for training and quality management purposes. Please, note that such recorded calls may be shared with Medallia, Inc., headquartered in San Francisco (“Medallia”) or some other third-party processor of our choice, that will be hosting, and/or processing the recordings and/or will be preparing a transcript thereof. For further information on call recordings, please refer to “Call Recordings” section of this General Privacy Policy.
For other uses we may disclose to you.
We may use your PII for other purposes consistent with those for which it was collected. We may also use your PII, as permitted or required by applicable law, including but not limited to, upon receiving, and in accordance with, your consent.
We may share your PII for our business purposes and as legally required or permitted, including, but not limited to:
With third parties, who perform services on our behalf (the “Service Providers”).
We share PII with our Service Providers, such as, but not limited to, Google, Facebook, Medallia, RDI, TigerTel, Bullhorn, Ultipro and Bing. We might also authorize our Service Providers to collect PII on our behalf. Some Service Providers may be located outside of the United States and/or Canada. These Service Providers may also have their own privacy statements that stipulate the
manner, in which they will collect, use and disclose (process) PII. We encourage you to review each Service Provider’s privacy statement. We might also share information with the vendors and manufacturers of our products and services to respond to your reviews and questions. No mobile information will be shared with Service Providers for marketing/promotional purposes. This opt-in is specific to text messaging.
To offer financial products.
We use Service Providers to offer financial products, such as Wells Fargo, Snap, Greensky, Aqua Finance, Fortiva & Genesis Credit loans/financings. We may share PII about you with these Service Providers in order to provide you with tailored information about products and services and special offers. These Service Providers also have their own privacy statements that stipulate the manner in which they will collect, host, process, use and disclose PII. We encourage you to
review each Service Provider’s privacy statement at the time you submit your application for financial products.
With any buyer successor to all or part of our business.
We may share, dispose of, assign or otherwise disclose your PII to any prospective acquirer or assignee of all or part of the assets or shares of any of BF Group's businesses (or any portion thereof), either in the ordinary course or in connection with bankruptcy proceedings, in liquidation or other similar proceedings, to the extent that your PII is part of the transaction.
In order to comply with applicable law.
We will disclose PII to respond to a court order or subpoena. We may also disclose PII if a government agency or investigatory body files a request.
With our business partners.
We might share PII with one of our franchisees or a business partner, who is running a joint promotion with us, who provides a product or service in partnership with us, who is collecting from clients and prospective clients reviews of our services or feedback thereon, or with whom we share PII of clients and prospective clients due to the overlap between the location of business partners, and residency of such clients and prospective clients (so-called “lead sharing”). These franchisees and business partners could also have their own privacy statements that set out the manner, in which they will collect, process, host, use and disclose PII. We encourage you to review each such franchisee or business partner’s privacy statement before signing on with them.
To protect us, or a third party.
We will disclose PII if we suspect fraud, or in any other case to protect us, or any third party. We will also share PII as part of an investigation. We may also disclose PII to assist us in collecting a debt owed by you.
For quality insurance purposes (including identifying trends and efficiencies)
Except California, Illinois, Texas and Washington, where our phone conversations with you will not be recorded, we will share the recordings of our other conversations with you and the related PII collected during such conversations with Medallia or any other third party of our choosing to process the recordings and prepare a transcript thereof, so we can improve the quality of services we offer, as well as identify trends and efficiency gain opportunities.
By your request.
For example, if you ask us to provide your PII to a third-party to facilitate the resolution of a dispute.
You can register or change your preferences to receive or not receive marketing communications from us by emailing us. Please allow sufficient time for your preferences to be processed. Even if you opt out of receiving marketing messages, we may still contact you for transactional purposes like confirming or following up on an order or service request, responding to customer service inquiries, asking you to review a product or service you have ordered, or notifying you of product
or service rebates. If, in the future, you do indeed want to receive marketing communications from us we will remove your PII from our opt-out database.
For more information about how we may collect information to provide you with interest-based ads or learn about our users’ interests and how you may register your preferences, please visit our Cookie Policy available at: available at: https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at
https://www.bathfitter.eu/cookie-policy for UK residents.
Our Website and device applications are not created for children. No minor may provide any PII to us or on Website. We do not knowingly collect PII from minors. If you are a minor, do not use or provide any PII on this Website or through any of its features, register on the Website, make any purchases through the Website, use any of the interactive or public comment features of this Website, or provide any PII about yourself to us, including your name, address, telephone number, email address, or any screen name or user name you may use. If we learn we have
collected or received PII from a minor without verification of parental consent, we will delete that information. If you believe we might have any information from or about a minor, please contact us at privacy@bathfitter.com.
Minors in some jurisdictions may have additional rights with respect to their PII based on their age. As appropriate, please refer to the provisions applicable to these jurisdictions (Quebec, California, Nevada, Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Delaware, Nebraska, New Hampshire, New Jersey, Iowa and Montana as well as Europe, including the United Kingdom).
Except for inbound and outbound calls by and between our employees or our
agents/representatives and residents of California, Illinois, Texas and Washington, inbound and outbound calls by and between our employees or our agents / representatives and residents of all other States and provinces could be recorded for quality purposes.
In case of inbound calls, a pre-recorded message informing the calling party about the call being recorded will be played before the conversation may commence, and in case of outbound calls, our employees shall announce verbally to the other party, before the conversation may commence, that the conversation will be recorded.
The fact that you continue the conversation following this message or announcement shall be deemed to constitute your consent to the recording of the conversation. Please, note that your consent to having the calls recorded is voluntary and may be withdrawn at any time. To withdraw your consent, you will need to do so in clear terms. In such a case, we will cease the current recording, if any, and we will also promptly comply with your instructions regarding any prior or
subsequent communications. Recorded conversations will further be shared with Medallia, or some other third-party processor of our choice, that will be hosting and processing the recordings and will be preparing a transcript thereof. Medallia’s privacy policy is available at: https://www.medallia.com/privacy-policy/.
The purpose for processing of call recordings and preparing a transcript thereof is to evaluate and improve the quality of our customer service and identify trends and efficiencies. Such transcripts will be further also used in the process of reviewing the quality of services rendered by our employees, and their overall performance.
The recordings may also be hosted on third-party servers or cloud.
While we use industry standard means to protect our Website and your PII, the Internet is not 100% secure. The measures we use are appropriate for the type of information we collect. We cannot guarantee use of our Website or mobile applications are 100% secure. We encourage you to use caution when using the Internet. Our Website contains links to third-party websites. If you click on one of those links, you will be taken to websites we do not control. This General Privacy
Policy does not apply to the information collected or processed by those websites. You should carefully read the privacy policies of other websites. We are not responsible for third-party websites.
By providing your PII on the Website, or entering into an agreement with us, or interacting with us in such a way that you have provided your PII to us, you agree that your PII could be collected, hosted, transferred, stored and further used or processed in Canada, and/or in the USA and/or via cloud computing.
If you have additional questions you may call us at 1-800-764-5539 or reach us by email at privacy@bathfitter.com. You can write to us at 225 Roy Street, Saint-Eustache (Quebec) J7R 5R5, Canada.
BF Group ("we") pays particular attention to the protection of the PII of individuals who, in Quebec, visit its Website or who are customers (potential or current). In this section, we explain how we collect, use and disclose to third parties PII about visitors to our websites www.bainmagique.com/qc-fr or www.bainmagique.com/qc-en (collectively and individually, the "Website") and our customers (potential and current) ("you").
This division has been adopted to take into account the requirements of the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1 – "PHIPA") as amended by the Act to modernize legislative provisions relating to the protection of personal information (2021, c. 25).
If you do not consent to our collection, use or disclosure of your PII to third parties in accordance with this section, please do not disclose any PII to us. Of course, certain services and/or goods can only be offered to you if you provide us with PII; therefore, we may not be able to offer you these services and/or goods if you decide not to provide us with the necessary PII.
Purpose of the collection
We collect your PII for the purposes specified in the "Introduction and Objectives" of our General Privacy Policy and in the "How We Use PII" section, which is primarily to:
Means of collection
We collect your PII through our Website (i.e. cookies, booking or contact form), our mobile applications or social networks, and also when you communicate with us or we communicate with you by phone, SMS, email or any other means of communication. (See also the "How PII is Collected" section of the General Privacy Policy).
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our
Email and Text Communication Terms and Conditions (available at:
https://www.bathfitter.com/us-en/terms-and-conditions/ for Canada and US residents, at: https://www.bathfitter.eu/terms-and-conditions for Ireland residents and at https://www.bathfitter.eu/terms-and-conditions for UK residents).
PII Collected
As part of your relationship with us, you may be asked to provide certain PII about yourself. For example, we may ask you for your name, postal and e-mail addresses, telephone numbers, bank details and credit card data. We may also collect certain information about your health and that of the people you live with.
We may also collect information of a technical nature or relating to your location, your use of our Website, and your preferences. In such circumstances, we ensure that:
(See also the section "PII We Collect", "Your Privacy Preferences" of the General Privacy Policy and the Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at https://www.bathfitter.eu/cookie-policy for UK residents.)
Use and Disclosure of Your PII
We ensure that we use and disclose your PII with your consent.
However, we may use or disclose them to the extent permitted by law, including:
Storage and Security
We may store and process your PII in Quebec or outside the province. In order to guarantee the confidentiality of your PII, we have put in place procedures to restrict access to your PII only to the categories of authorized persons within BF Group (mainly, finance, legal, IT, marketing, customer experience, sales and installation departments) or to make all our staff aware of the confidentiality and security requirements of PII.
Shelf life
We retain your PII only for as long as necessary to fulfill the purposes for which it was collected, except where the law provides for a different retention period.
For example, we retain PII that is linked to your customer account until it is closed. In some cases, your PII may be retained for a longer period of time, for example, to allow us to honor the guarantees we offer or as part of a remedy.
Minor
In Quebec, a minor under the age of 14 cannot consent alone to the collection, use and disclosure of his or her PII to third parties. Therefore, we do not collect PII from minors under the age of 14 and should this happen we will take the necessary steps to delete this information.
Rights with respect to your PII
You can submit an application
by contacting the Person in Charge of the Management of Personal Information, 225 Roy Street, Saint-Eustache (Quebec) J7R 5R5 at the following email address: privacy@bathfitter.com.
If you consider that we are not responding to your request or that you wish to file a complaint about our processing of your PII, you can contact the Commission d'accès à l'information du Québec (https://www.cai.gouv.qc.ca/english/).
Privacy Notice for California Residents According to the CCPA
This Privacy Notice for California Residents applies solely to all visitors, users, and others who reside in the State of California (“consumers” or “you”). We have adopted this notice to comply with the California Consumer Privacy Act of 2018 (“CCPA”) and any terms defined in the CCPA have the same meaning when used in this Section of the General Privacy Policy.
Information We Collect
We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“Personal Information”). Personal Information does not include:
In particular, we have collected the following categories of Personal Information from consumers within the last twelve (12) months:
Use of Personal Information
Purposes of use or disclosure of your Personal Information are set forth in Section “How We Use Information” of this General Privacy Policy.
Sharing Personal Information
We may disclose your Personal Information to a third party for a business purpose, which may include sharing information about our customers or our visitors with third parties, including, but not limited to Facebook. When we disclose Personal Information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract.
Disclosures of Personal Information for a Business Purpose
In the preceding twelve (12) months, BF Group has disclosed Personal Information for a business purpose. In particular, the following categories of Personal Information collected by BF Group’ have been disclosed for a business purpose:
Sales of Personal Information
In the preceding twelve (12) months, BF Group has not sold any Personal Information.
Your Rights and Choices
The CCPA provides consumers (California residents) with specific rights regarding their Personal Information. This section describes your CCPA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
Deletion Request Rights
You have the right to request that we delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our Service Providers to delete) your Personal Information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our Service Provider(s) to:
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described in the sections “Access to Specific Information and Data Portability Rights” and “Deletion Request Rights” above, please submit a verifiable consumer request to us at privacy@bathfitter.com, or mail us at 225 Roy Street, Saint-Eustache (Quebec) J7R 5R5, Canada.
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a twelve (12) month period. The verifiable consumer request must:
We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you.
Making a verifiable consumer request does not require you to create an account with us.
We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
For instructions on exercising sale opt-out rights.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to ninety (90) days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
However, we may offer you certain financial incentives permitted by the CCPA that can resultin different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your Personal Information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
The categories of Personal Information that BF Group collects through its Website or online service about consumers, who use or visit the Website or online service are described in Section“INFORMATION WE COLLECT”of the General Privacy Policy.
The categories of third parties with whom BF Group may share Personal Information are described in Sections“Sharing Personal Information”and“Disclosures of Personal Information for a Business Purpose”of the General Privacy Policy.
Nevada residents, who use or visit the Website or online service and desire to review and request changes to any of their Personal Information that is collected through the Website or online service, shall submit their request thereon to privacy@bathfitter.com;
The process by which BF Group notifies consumers, who use or visit the Website or online service of material changes to the notice is described in“Changes to this General Privacy Policy”section of the General Privacy Policy.
Third parties, who may collect Personal Information about Nevada residents’ online activities over time and across different Internet websites or online services when such Nevada residents use the Website or online service of BF Group are listed in“THIRD PARTIES”section of the General Privacy Policy;
Nevada residents, who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address: privacy@bathfitter.com. However, please know we do not currently sell data triggering that statute's opt-out requirements;
The effective date of the notice is indicated at the top of this General Privacy Policy.
Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, Delaware, Nebraska, New Hampshire, New Jersey, and Iowa in their respective privacy laws provide their state residents with rights to:
Colorado, Connecticut, Virginia, and Utah in their respective privacy laws provide their state residents with rights to:
Colorado, Connecticut, and Virginia also provide their state residents with rights to:
To exercise any of these rights please email BF Group at any time at: at any time at privacy@bathfitter.com. To appeal a decision regarding a consumer right request you should file an appeal to the local data privacy authority, indicated by each privacy state law, and follow the procedure indicated therein.
INTRODUCTION
If processing of your personal information falls within the scope of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (as defined by the GDPR) and on the free movement of such data, known as the General Data Protection Regulation (the “GDPR”), then Bath Fitter Limited, an Irish entity that, with respect of personal information governed by the GDPR serves as a controller. (for the purposes of this GDPR section, “Bath Fitter Ltd.”) shall perform such processing in accordance with GDPR requirements. Therefore, in such case, in addition to the above terms, Bath Fitter Ltd. provides you with the following information:
PURPOSE OF THIS GDPR PRIVACY POLICY
This GDPR Privacy Policy that is incorporated into the General Privacy Policy (the “GDPR Privacy Policy”) aims to give you information on how Bath Fitter Ltd. collects and processes personal data that is governed by the GDPR, through your use of its Website, including any data you may provide through the Website when you sign up to our newsletter or marketing emails, or make any enquiry for information from us, or contact us to set up an appointment and/or where
we interact with you in relation to installation, after sales service or warranty issues related to our products and services.
The Website is not intended for children and we do not knowingly collect data relating to children.
CONTROLLER
Bath Fitter Limited, Units 25 & 41 Eastlink Business Park, Ballysimon, Limerick, Ireland
CONTACT DETAILS
If you have any questions about this GDPR Privacy Policy or Bath Fitter Ltd.’s privacy practices with respect to personal information governed by the GDPR, please contact Bath Fitter Ltd. in the following ways:
Email address: privacy@bathfitter.com
Postal address: Units 25 & 41 Eastlink Business Park, Ballysimon, Limerick, Ireland
Telephone: +1 450 472 0027 x6789
You have the right to make a complaint at any time to the appropriate Data Protection Commission. The Irish supervisory authority being the Data Protection Commission is contactable via its website available at www.dataprotection.ie. Bath Fitter Ltd. would, however, appreciate the chance to deal with your concerns before you approach the Data Protection Commission so please contact Bath Fitter Ltd. directly in the first instance.
CHANGES TO THE GDPR PRIVACY POLICY AND YOUR DUTY TO INFORM US OF CHANGES
Bath Fitter Ltd. keeps its GDPR Privacy Policy under regular review.
It is important that the personal data Bath Fitter Ltd. holds about you is accurate and current. Please keep Bath Fitter Ltd. informed if your personal data changes during your relationship with us.
THIRD-PARTY LINKS
The Website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. Bath Fitter Ltd. does not control these third-party websites and is not responsible for their privacy statements. When you leave the Website, we encourage you to read the privacy policy of every website you visit.
Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
Bath Fitter Ltd. may collect, use, store and transfer different kinds of personal data about you which it has grouped together as follows:
Bath Fitter Ltd. also does collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, Bath Fitter Ltd. may aggregate your Usage Data to calculate the percentage of users accessing a specific Website feature. However, if Bath Fitter Ltd. does combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, Bath Fitter Ltd. does treat the combined data as personal data which will be used in accordance with this GDPR Privacy Policy.
Except for employment-related information, and subject to applicable law, Bath Fitter Ltd. does not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Except for employment-related information, and subject to applicable law, Bath Fitter Ltd. does not collect information about criminal convictions and offences.
IF YOU FAIL TO PROVIDE PERSONAL DATA
Where Bath Fitter Ltd. needs to collect personal data by law, or under the terms of a contract it has with you, and you fail to provide that data when requested, Bath Fitter Ltd. may not be able to perform the contract it has or is trying to enter into with you (for example, to provide you with goods or services). In this case, Bath Fitter Ltd. may have to cancel a product or service you have therewith, but Bath Fitter Ltd. will notify you if this is the case at the time.
Bath Fitter Ltd. uses different methods to collect data from and about you including through:
Third parties.Bath Fitter Ltd. will receive Technical Data relating to you from Google Analytics.
Bath Fitter Ltd. will only use your personal data when the law allows it to. Most commonly, Bath Fitter Ltd. will use your personal data in the following circumstances:
Where Bath Fitter Ltd. needs to perform the contract it is about to enter into or has entered into with you.
Where it is necessary for its legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Where Bath Fitter Ltd. needs to comply with a legal obligation.
Generally, Bath Fitter Ltd. does not rely on consent as a legal basis for processing your personal data although it will get your consent before sending direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting Bath Fitter Ltd.
PURPOSES FOR WHICH BATH FITTER LTD. WILL USE YOUR PERSONAL DATA
Bath Fitter Ltd. has set out below, in a table format, a description of all the ways Bath Fitter Ltd. plans to use your personal data, and which of the legal bases it relies on to do so. Bath Fitter Ltd. has also identified what its legitimate interests are where appropriate.
Note that Bath Fitter Ltd. may process your personal data for more than one lawful ground depending on the specific purpose for which it is using your data. Please contact Bath Fitter Ltd. if you need details about the specific legal basis it is relying on to process your personal data where more than one ground has been set out in the table below.
MARKETING
Bath Fitter Ltd. strives to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. Where you no longer wish to receive marketing information from us, please contact Bath Fitter Ltd. at privacy@bathfitter.com at any time to let it know and it will cease all marketing communications to you. You can also contact us by post at our postal address: Units 25 & 41 Eastlink Business Park, Ballysimon, Limerick, Ireland or by
Telephone: +1 450 472 0027 x6789
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our
Email and Text Communication Terms and Conditions (available at:
https://www.bathfitter.com/us-en/terms-and-conditions/ for Canada and US residents, at: https://www.bathfitter.eu/terms-and-conditions for Ireland residents and at https://www.bathfitter.eu/terms-and-conditionsfor UK residents).
PROMOTIONAL OFFERS FROM US
Bath Fitter Ltd. may use your identity, contact, technical, usage and profile data to form a view on what it thinks you may want or need, or what may be of interest to you. This is how Bath Fitter Ltd. decides which products, services and offers may be relevant for you (Bath Fitter Ltd. calls this marketing).
You will receive marketing communications from Bath Fitter Ltd. if you have requested information from Bath Fitter Ltd. or purchased goods or services therefrom and you have not opted out of receiving that marketing, or where you give Bath Fitter Ltd. consent to market to you.
OPTING OUT
Where you opt out of receiving marketing messages, this will not apply to personal data provided to Bath Fitter Ltd. as a result of a product/service purchase, warranty registration, product/service experience or other transactions.
COOKIES
The Cookie Policy applicable to Bath Fitter Ltd. is included in the Cookie Policy available at:https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at
https://www.bathfitter.eu/cookie-policy for UK residents.
CHANGE OF PURPOSE
Bath Fitter Ltd. will only use your personal data for the purposes for which it has collected it, unless Bath Fitter Ltd. reasonably considers that it needs to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact Bath Fitter Ltd.
If Bath Fitter Ltd. needs to use your personal data for an unrelated purpose, it will notify you and explain the legal basis which allows Bath Fitter Ltd. to do so.
Please note that Bath Fitter Ltd. may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law
We may store and process your PII on secure servers in an European country. In order to guarantee the confidentiality of your PII, we have put in place procedures to restrict access to your PII only to the categories of authorized persons within BF Group (mainly, finance, legal, IT, marketing, customer experience, sales and installation departments) or to make all our staff aware of the confidentiality and security requirements of PII.
Bath Fitter Ltd. may share your personal data with the parties set out below for the purposes set out in the table “Purposes for which we will use your personal data” above.
Internal Third Parties as set out in the Glossary.
External Third Parties as set out in the Glossary.
Third parties, to whom Bath Fitter Ltd. may choose to sell, transfer or merge parts of its business or assets. Alternatively, Bath Fitter Ltd may seek to acquire other businesses or merge with them. If a change happens to Bath Fitter Ltd.’s business, then the new owners may use your personal data in the same way as set out in this GDPR Privacy Policy. Bath Fitter Ltd. requires all third parties to respect the security of your personal data and to treat it in accordance with the law. Bath Fitter Ltd. does not allow its third-party Service Providers to use your personal data for their own purposes and only permit them to process your personal
data for specified purposes and in accordance with its instructions.
Bath Fitter Ltd. shares your personal data with BF Affiliates, including Bath Fitter Distributing Inc., incorporated in Canada and located at 225, rue Roy, Saint-Eustache (Québec) Canada J7R 5R5. In case of a data transfer outside the European Economic Area (EEA), such transfer will comply with the requirements of the GDPR and where required, take place pursuant to written agreements, which contain provisions (including, but not limited to, European Contractual Clauses) to safeguard your data.
.
Bath Fitter Ltd. has put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, Bath Fitter Ltd. limits access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on Bath Fitter Ltd.’s instructions, and they are subject to a duty of confidentiality.
Bath Fitter Ltd. has put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where Bath Fitter Ltd. is legally required to do so.
HOW LONG WILL YOU USE MY PERSONAL DATA FOR?
Bath Fitter Ltd. will only retain your personal data for as long as reasonably necessary to fulfil the purposes it collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. Bath Fitter Ltd. may retain your personal data for a longer period in the event of a complaint or if it reasonably believes there is a prospect of litigation in
respect to Bath Fitter Ltd.’s relationship with you.
To determine the appropriate retention period for personal data, Bath Fitter Ltd. considers the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised
use or disclosure of your personal data, the purposes for which Bath Fitter Ltd. processes your personal data and whether Bath Fitter Ltd. can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
By law Bath Fitter Ltd. has to keep basic information about its customers for six years after they cease being customers for certain regulatory purposes.
In some circumstances you can ask Bath Fitter Ltd. to delete your data: see Section 9 of this GDPR portion of this General Privacy Policy “Your Legal Rights” below for further information.
In some circumstances Bath Fitter Ltd. will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case Bath Fitter Ltd. may use this information indefinitely without further notice to you.
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the following:
Request access to your personal data. This enables you to receive a copy of the personal data Bath Fitter Ltd. holds about you and to check that Bath Fitter Ltd. is lawfully processing it; Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data Bath Fitter Ltd. holds about you corrected, though Bath Fitter Ltd. may need to verify the accuracy of the new data you provide thereto; Request erasure of your personal data. This enables you to ask Bath Fitter Ltd. to delete or remove personal data where there is no good reason for Bath Fitter Ltd. continuing to process it. You also have the right to ask Bath Fitter Ltd. to delete or remove your personal data where you have successfully exercised your right to object to processing (see section “Object to processing” of this GDPR Privacy Policy below), where Bath Fitter Ltd. may have processed your information unlawfully or where Bath Fitter Ltd. is required to erase your personal data to comply with local law. Note, however, that Bath Fitter Ltd. may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request; Object to processing of your personal data where Bath Fitter Ltd. is relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts your fundamental rights and freedoms. You also have the right to object where Bath Fitter Ltd. is processing your personal data for direct marketing purposes. In some cases, Bath Fitter Ltd. may demonstrate that it has a compelling legitimate ground to process your information which override your rights and freedoms;Request restriction of processing of your personal data. This enables you to ask Bath Fitter Ltd. to suspend the processing of your personal data in the following scenarios:
You have objected to Bath Fitter Ltd.’s use of your data but Bath Fitter Ltd. needs to verify whether it has an overriding legitimate ground to use it; Request the transfer of your personal data to you or to a third party. Bath Fitter Ltd. will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for Bath Fitter Ltd. to use or where Bath Fitter Ltd. used the information to perform a contract with you; and Withdraw consent at any time where Bath Fitter Ltd. is relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, Bath Fitter Ltd. may not be able to provide certain products or services to you. Bath Fitter Ltd. will advise you if this is the case at the time you withdraw your consent.If you wish to exercise any of the rights set out above, please contact Bath Fitter Ltd.’s data privacy manager.
NO FEE USUALLY REQUIRED
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, Bath Fitter Ltd. may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, Bath Fitter Ltd. could refuse to comply with your request in these circumstances.
WHAT WE MAY NEED FROM YOU
Bath Fitter Ltd. may need to request specific information from you to help Bath Fitter Ltd. confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person, who has no right to receive it. Bath Fitter Ltd. may also contact you to ask you for further information in relation to your request to speed up its response.
TIME LIMIT TO RESPOND
Bath Fitter Ltd. tries to respond to all legitimate requests within one month. Occasionally it could take Bath Fitter Ltd. longer than a month if your request is particularly complex or you have made a number of requests. In this case, Bath Fitter Ltd. will notify you and keep you updated.
LAWFUL BASIS
Legitimate Interest means the interest of Bath Fitter Ltd.’s business in conducting and managing its business to enable it to give you the best service/product and the best and most secure experience. Bath Fitter Ltd. makes sure it considers and balances any potential impact on you (both positive and negative) and your rights before Bath Fitter Ltd. processes your personal data for its legitimate interests. Bath Fitter Ltd. does not use your personal data for activities where its interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how Bath Fitter Ltd. assesses its legitimate interests against any potential impact on you in respect of specific activities by contacting Bath Fitter Ltd.’s data privacy manager.
Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request (or in response to an enquiry from you) before entering into such a contract.
Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that Bath Fitter Ltd. is subject to.
THIRD PARTIES
INTERNAL THIRD PARTIES
Other companies in the BF Group including Bath Fitter Distributing Inc. and who are based in Canada and other countries acting as controllers and processors and who provide IT, system administration, support and maintenance, management, hosting of data, financial and business support services
EXTERNAL THIRD PARTIES
Service providers acting as processors based in the EEA and outside of the EEA who provide business support services, IT, HR, marketing, customer experience and system administration services.
Service providers acting as processors based in the EEA and outside of the EEA who provide surveying, measurements, photographic, design, fabrication, repair and installation services.
Professional advisers acting as processors and controllers including lawyers, marketing agencies, bankers, auditors and insurers based in the EEA and outside of the EEA who provide consultancy, banking, legal, insurance and accounting services.
The Revenue Commissioners, regulators and other authorities acting as controllers based in Ireland who require reporting of processing activities in certain circumstances.
Contractors for after sale/installation services
INTRODUCTION
If processing of your personal information falls within the scope of the UK GDPR which shall mean
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic
Communications (Amendments etc) (EU Exit) Regulations (the “UK GDPR”), then BFBM UK Limited, an entity incorporated in England, shall serve as a controller with respect to personal data governed by the UK GDPR and processed as set out below. For the purposes of this UK
GDPR section, “BFBM UK Limited” shall perform such processing in accordance with UK GDPR
requirements. Therefore, in such case, in addition to the above terms, BFBM UK Limited provides
you with the following information:
1. IMPORTANT INFORMATION AND WHO WE ARE
2. THE DATA WE COLLECT ABOUT YOU
3. HOW IS YOUR PERSONAL DATA COLLECTED?
4. HOW WE USE YOUR PERSONAL DATA
5. STORAGE AND SECURITY
6. DISCLOSURES OF YOUR PERSONAL DATA
7. INTERNATIONAL TRANSFERS
8. DATA SECURITY
9. DATA RETENTION
10. YOUR LEGAL RIGHTS
1. IMPORTANT INFORMATION AND WHO WE ARE
PURPOSE OF THIS UK GDPR PRIVACY POLICY
This UK GDPR Privacy Policy that is incorporated into the General Privacy Policy (the “UK GDPR Privacy Policy”) aims to give you information on how BFBM UK Limited collects and processes personal data that is governed by the UK GDPR, through your use of our Website, including any data you may provide through the Website when you sign up to our newsletter or marketing emails, or make any enquiry for information from us, or contact us to set up an appointment or
when you engage us to provide you with products or services via your use of our Website or otherwise.
The Website is not intended for children and we do not knowingly collect data relating to children.
CONTROLLER
BFBM UK Limited with registered office address at Suite Lg, 11 St. James's Place, London, England, SW1A 1NP. CONTACT DETAILS If you have any questions about this UK GDPR Privacy Policy or BFBM UK Limited’s privacy practices with respect to personal information governed by the UK GDPR, please contact BFBM
UK Limited in the following ways: Email address: privacy_UK@bathfitter.com
Postal address: Suite Lg, 11 St. James's Place, London, England, SW1A 1NP
Telephone: 1-800-764-5539 You have the right to make a complaint at any time to the Information Commissioner’s Office (“ICO”), the UK regulator for data protection issues (www.ico.org.uk). BFBM UK Limited would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact BFBM UK Limited directly in the first instance.
CHANGES TO THE UK GDPR PRIVACY POLICY AND YOUR DUTY TO INFORM US OF CHANGES BFBM UK Limited keeps its UK GDPR Privacy Policy under regular review. It is important that the personal data BFBM UK Limited holds about you is accurate and current. Please keep BFBM UK Limited informed if your personal data changes during your relationship
with us.
THIRD-PARTY LINKS
The Website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. BFBM UK Limited does not control these third-party websites and is not responsible for their privacy statements. When you leave the Website, we encourage you to read the privacy policy of
every website you visit.
2. DATA WE COLLECT ABOUT YOU
“Personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data,an online identifier or to one or more factors specific to the physical, physiological, genetic, mental,economic, cultural or social identity of that natural person” . It does not include data where the natural person cannot be identified, directly or indirectly (“anonymous data”). BFBM UK Limited may collect, use, store and transfer different kinds of personal data about youwhich it has grouped together as follows:
• Identity Data includes name, user name or similar identifier and title.
• Contact Data includes billing address, delivery address, email address and telephone numbers.
• Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Website.
• Profile Data includes your interests, preferences, feedback and any survey responses.
• Usage Data includes information about how you use our Website, products and services.
• Marketing and Communications Data includes your preferences in receiving marketing from BFBM UK Limited and your communication preferences.
BFBM UK Limited also does collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, BFBM UK Limited may aggregate your Usage Data to calculate the percentage of users accessing a specific Website feature. However, if BFBM UK Limited does combine or connect Aggregated Data with your personal data so that it can directly or indirectly
identify you, BFBM UK Limited does treat the combined data as personal data which will be used in accordance with this UK GDPR Privacy Policy.
Except for employment-related information, and subject to applicable law, BFBM UK Limited does not collect from you any Special Categories of Personal Data meaning any personal data that needs more protection because it is sensitive (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Except for employment-related information, and subject to applicable law, BFBM UK Limited does not collect
information about criminal convictions and offences.
IF YOU FAIL TO PROVIDE PERSONAL DATA
Where BFBM UK Limited needs to collect personal data by law, or under the terms of a contract it has with you, and you fail to provide that data when requested, BFBM UK Limited may not be able to perform the contract it has or is trying to enter into with you (for example, to provide you with goods or services). In this case, BFBM UK Limited may have to cancel a product or service you have therewith, but BFBM UK Limited will notify you if this is the case at the time.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
BFBM UK Limited uses different methods to collect data from and about you including through:
• Direct interactions. You may give BFBM UK Limited your personal data by filling in forms or by corresponding with BFBM UK Limited by post, phone, email or otherwise. This includes personal data you provide when you:
o contact BFBM UK Limited with an enquiry;
o provide us with information in order to allow us to provide you with our services
and/or products or otherwise fulfil our obligations pursuant to any contract we have
with you;
o request marketing to be sent to you or subscribe to any newsletters or other
information we make available from time to time;
o enter a promotion or respond to any survey;
o talk to any of BFBM UK Limited employees over the phone; or
o give BFBM UK Limited feedback.
• Automated technologies or interactions. As you interact with the Website, BFBM UK Limited will automatically collect Technical Data about your equipment, browsing actions and patterns. BFBM UK Limited does collect this personal data by using cookies, server hnologies. BFBM UK Limited may also receive Technical Data about you if you visit other websites employing our cookies. Please, see the Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at https://www.bathfitter.eu/cookie-policy for UK residents for further details.
• Third parties. BFBM UK Limited will receive Technical Data relating to you from Google Analytics.
4. HOW BFBM UK LIMITED USES YOUR PERSONAL DATA
BFBM UK Limited will only use your personal data when the law allows it to. Most commonly, BFBM UK Limited will use your personal data in the following circumstances:
• Where BFBM UK Limited needs to perform the contract it is about to enter into or has entered into with you1.
• Where it is necessary for its legitimate interests (or those of a third party) and your interests
and fundamental rights do not override those interests2.
• Where BFBM UK Limited needs to comply with a legal obligation3.
• Where you have provided BFBM UK Limited with your explicit consent.
PURPOSES FOR WHICH BFBM UK LIMITED WILL USE YOUR PERSONAL DATA BFBM UK Limited has set out below, in a table format, a description of all the ways BFBM UK Limited plans to use your personal data, and which of the legal bases it relies on to do so. BFBM UK Limited has also identified what its legitimate interests are where appropriate. Note that BFBM UK Limited may process your personal data on more than one lawful ground depending on the specific purpose for which it is using your data. Please contact BFBM UK Limited if you need details about the specific legal basis it is relying on to process your personal data where more than one ground has been set out in the table below.
From time to time we may change our General Privacy Policy and/or our specific policies pertaining to certain jurisdictions where we do business. We will notify you of any material changes to any of the above policies by posting an updated copy on our Website. Please check our Website periodically for updates.
MARKETING
BFBM UK Limited strives to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. Generally, BFBM UK Limited does not rely on consent as a legal basis for processing your personal data although it will get your consent before sending direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time. Where you no longer wish to receive marketing information from us, please contact BFBM UK Limited at privacy@bathfitter.com at any time to
let it know and it will cease all marketing communications to you.
Note that if you wish to unsubscribe from our email campaigns, please click on the Unsubscribe link at the bottom of any marketing email sent from us. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations. If you wish to stop receiving text messages from us, reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any text message sent from us. For more information, see our
Email and Text Communication Terms and Conditions (available at:
https://www.bathfitter.com/us-en/terms-and-conditions/ for Canada and US residents, at: https://www.bathfitter.eu/terms-and-conditions for Ireland residents and at https://www.bathfitter.eu/terms-and-conditions for UK residents).
PROMOTIONAL OFFERS FROM US
BFBM UK Limited may use your Identity Data, Contact Data, Technical Data, Usage Data and Profile Data to form a view on what it thinks you may want or need, or what may be of interest to you. This is how BFBM UK Limited decides which products, services and offers may be relevant for you (BFBM UK Limited calls this marketing).
You will receive marketing communications from BFBM UK Limited if you have requested information from BFBM UK Limited or purchased goods and/or services therefrom and you have not opted out of receiving that marketing, or where you give BFBM UK Limited consent to market to you.
OPTING OUT
Where you opt out of receiving marketing messages, this will not apply to personal data provided to BFBM UK Limited as a result of any products and/or services you have purchased from us, warranty registration, product/service experience or other transactions.
COOKIES
The Cookie Policy applicable to Bath Fitter Ltd. is included in the Cookie Policy available at: https://www.bathfitter.com/us-en/cookie-policy/ for Canada and US residents, at: https://www.bathfitter.eu/cookie-policy for Ireland residents and at
https://www.bathfitter.eu/cookie-policyfor UK residents.
CHANGE OF PURPOSE
BFBM UK Limited will only use your personal data for the purposes for which it has collected it, unless BFBM UK Limited reasonably considers that it needs to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact BFBM UK Limited
If BFBM UK Limited needs to use your personal data for an unrelated purpose, it will notify you and explain the legal basis which allows BFBM UK Limited to do so.
Please note that BFBM UK Limited may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
5. STORAGE AND SECURITY
We will store and process your PII on secure servers maintained in secure physical environments within UK. In order to guarantee the confidentiality of your PII, we have put in place procedures to restrict access to your PII only to the categories of authorized persons within BF Group (mainly, finance, legal, IT, marketing, customer experience, sales and installation departments) or to make all our staff aware of the confidentiality and security requirements of PII.
6. DISCLOSURES OF YOUR PERSONAL DATA
BFBM UK Limited may share your personal data with the parties set out below for the purposes set out in the table “Purposes for which we will use your personal data” above:
BFBM UK Limited requires all third parties to respect the security of your personal data and to treat it in accordance with the law. BFBM UK Limited does not allow its third-party Service Providers to use your personal data for their own purposes and only permits them to process your personal data for specified purposes and in accordance with its binding instructions.
7. INTERNATIONAL TRANSFER
BFBM UK Limited shares your personal data with BF Affiliates who are located outside of the United Kingdom including Bath Fitter Distributing Inc., incorporated in Canada and located at 225, rue Roy, Saint-Eustache (Québec) Canada J7R 5R5.
Whenever BFBM UK Limited transfers your personal data out of the UK, it conducts a risk assessment to ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.
8. DATA SECURITY
BFBM UK Limited has put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, BFBM UK Limited limits access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on BFBM UK Limited’s instructions, and they are subject to a duty of confidentiality.
9. DATA RETENTION
HOW LONG WILL YOU USE MY PERSONAL DATA FOR?
BFBM UK Limited will only retain your personal data for as long as reasonably necessary to fulfil the purposes it collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. BFBM UK Limited may retain your personal data for a longer period in the event of a complaint or if it reasonably believes there is a prospect of litigation in respect to BFBM UK Limited’s relationship with you.
To determine the appropriate retention period for personal data, BFBM UK Limited considers the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which BFBM UK Limited processes your personal data and whether BFBM UK Limited can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
By applicable law, BFBM UK Limited has to keep basic information related to contractual relationship about its customers for six years after they cease being customers for certain regulatory and/or legislative purposes. However, given that BFBM UK Limited offers lifetime warranty, certain personal data that is indispensable for performance of warranty services (such as: name and last name of the purchaser, the address of installation, contact details including the phone number and the email address), shall be retained indefinitely.
In some circumstances you can ask BFBM UK Limited to delete your data: see Section 9 of this UK GDPR portion of this General Privacy Policy “Your Legal Rights” below for further information.
In some circumstances BFBM UK Limited will anonymize your personal data (so that it can no longer be associated with you) for research, analytical or statistical purposes, in which case BFBM UK Limited may use this information indefinitely without further notice to you.
10. YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the following:
TIME LIMIT TO RESPOND
BFBM UK Limited tries to respond to all legitimate requests within one month from the day we received the request. Occasionally it could take BFBM UK Limited longer than a month if your request is particularly complex or you have made a number of requests. In this case, BFBM UK Limited will notify you and keep you updated
18. Changes to the General Privacy Policy and the Specific Policies Pertaining to Certain Jurisdiction
From time to time we may change our General Privacy Policy and/or our specific policies pertaining to certain jurisdictions where we do business. We will notify you of any material changes to any of the above policies by posting an updated copy on our Website. Please check our Website periodically for updates
General Privacy Policy
o Effective Date: 14/06/2019
o Last Revision Date: 23/12/2024
Policies Specific to Certain Jurisdictions
o California: Effective Date: 14/06/2019 –Revision Date: 23/09/2022 - Last Revision Date 2/27/2024
o Nevada: Effective Date: 20/07/2021 – Last Revision Date: 23/09/2022
o Europe: Effective Date: 14/6/2019 – Revision Date: 23/09/2022 –Revision Date 11/20/2023 - Last Revision Date 2/27/2024
o Quebec: Effective Date: 22/09/2022 - Last Revision Date 2/27/2024
o Connecticut: Effective Date: 8/15/2023
o Utah: Effective Date: 8/15/2023
o Virginia: Effective Date: 8/15/2023
o Colorado: Effective Date: 8/15/2023
o Oregon: Effective Date:
o Texas: Effective Date:
o Montana: Effective Date:
o Delaware: Effective Date
o Nebraska: Effective Date:
o New Hampshire: Effective Date
o New Jersey: Effective Date:
o Iowa: Effective Date:
o UK: Effective Date: 11/20/2023 - Last Revision Date 2/27/2024