RockCyprus, RockX and Strategical Online BV ['we' / 'our'] are committed to protecting our customer privacy and takes its responsibility regarding the security of customer information very seriously. We will be clear and transparent about the information we are collecting and what we will do with that information.
This Policy sets out the following:
• What personal data we collect and process about you in connection with your relationship with us as a customer and through your use of our website, mobile applications and online services;
• Where we obtain the data from;
• What we do with that data;
• How we store the data;
• Who we transfer/disclose that data to;
• How we deal with your data protection rights;
• And how we comply with the data protection rules.
All personal data is collected and processed in accordance with United Kingdom and EU data protection laws.
We are the “data controller” of all personal information that is collected and used about our customers.
What personal data we collect
Personal data means any information relating to you which allows us to identify you, such as your name, contact details, order number, payment details and information about your access to our website.
We may collect personal data from you when create a account, use our website and other websites accessible through our website, participate in a survey or competition, or when you contact us.
Specifically, we may collect the following categories of information:
a. Name, home address, e-mail address, telephone number or other payment details;
b. Information about your purchases of our trusted partners’ products and services;
c. Information about your use of our website;
d. The communications you exchange with us or direct to us via letters, emails, chat service, calls, and social media.
e. Location, such as IP Address.
What do we use your personal data for, why and for how long
Your data may be used for the following purposes:
a. Providing products and services you request: we use the information you give us to perform the services you have asked;
b. Contacting you: we send you communications about the services you have asked for and any upgrades to our products. These communications are not made for marketing purposes and cannot be opted-out of;
c. Administrative or legal purposes: we use your data for statistical and marketing analysis, systems testing, customer surveys, maintenance and development, or in order to deal with a dispute or claim;
d. Security, health, administrative, crime prevention/detection: we may pass your information to government authorities or enforcement bodies for compliance with legal requirements;
e. Customer Services communications: we use your data to manage our relationship with you as our customer and to improve our services and enhance your experience with us ;
f. Marketing: from time to time we will contact you with information about promotions and ancillary products via e-communications. You will have the choice to opt in or opt out of receiving such communications by indicating your choice or updating your account settings.
We will only process your personal data where we have a legal basis to do so. The legal basis will depend on the reasons we have collected and need to use your personal data for.
In most cases we will need to process your personal data so we can perform service for you.
We will not retain your data for longer than is necessary to fulfil the purpose it is being processed for. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the purposes for which we process it and whether we can achieve those purposes through other means.
When we no longer need your personal data, we will securely delete or destroy it. We will also consider if and how we can minimise over time the personal data that we use, and if we can anonymise your personal data so that it can no longer be associated with you or identify you, in which case we may use that information without further notice to you.
Security of your personal data
We follow strict security procedures in the storage and disclosure of your personal data, and to protect it against accidental loss, destruction or damage. The data you provide to us is protected using SSL (Secure Socket Layer) technology. SSL is the industry standard method of encrypting personal information and credit card details so that they can be securely transferred over the Internet.
All payment details are transmitted over SSL across dedicated network infrastructure (Multiprotocol Label Switching-MPLS) and stored in compliance with Payment Card Industry Data Security Standards (PCI DSS).
Sharing your personal data
a. Government authorities, law enforcement bodies, regulators for compliance with legal requirements;
b. Credit and debit card companies which facilitate your payments to us, and anti-fraud screening, which may need information about your method of payment;
c. Legal and other professional advisers, law courts and law enforcement bodies in all countries we operate in, in order to enforce our legal rights in relation to our contract with you;
We understand the importance of taking extra precautions to protect the privacy and safety of children. Accordingly, children under 18 will not be permitted to open a account. We will delete any account created by a child under 18, as soon as we are made aware of it.
You will have the option to stay signed-in into your account by checking the “keep me logged in” box. This option will only apply to the computer / device and the browser that you're using when you select the box. If you do not wish to stay signed on a particular browser, simply sign out of account on that browser.
When our use of your personal data is based on your consent, you have the option to withdraw your consent to our processing and delete your personal data at any time. You can do this by submitting your request through our dedicated web-form.
We keep your personal information contained in your account for as long as you hold the account. You can change the personal data in your account directly in the account. Any changes made by you will only show in orders made after these changes have been made and not in existing orders.
Please note that general retention periods apply to any personal data we collect to enter into a contract with you or to perform that contract or because we have a legal obligation to process it.
Cookies and site tracking
Cookies are small text files that are transferred to your computer's hard drive through your web browser to enable us to recognise your browser and help us to track visitors to our site; thus enabling us to understand better the products and services that will be most suitable to you. Most Web browsers automatically accept cookies, but, if you wish, you can change these browser settings by accepting, rejecting and deleting cookies. The "help" portion of the toolbar on most browsers will tell you how to prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether. If you choose to change these settings, you may find that certain functions and features will not work as intended. The cookies we use do not detect any information stored on your computers.
For more information about cookies and how to stop cookies being installed visit the following website: http://www.allaboutcookies.org.
We use tracking software to monitor customer traffic patterns and site usage to help us develop the design and layout of the websites.
Your Data Protection Rights
Under certain circumstances, by law you have the right to:
• Request information about whether we hold personal information about you, and, if so, what that information is and why we are holding/using it.
• Request access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it. A small fee will be payable.
• Request rectification of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected. You can make corrections to your personal data through your account. Any changes made by you will only show in orders made after these changes have been made and not in existing orders. Terms & conditions apply in relation to the correction of any errors on your existing orders.
• Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below). You can delete that personal data where our use of this data is based on your consent by updating your account.
• Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes. You can object to our processing of your data for direct marketing purposes by unsubscribing from our mailing list or updating the settings for your App (see section ‘What do we use your personal data for, why and for how long’ for more details).
• Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
• Withdraw consent. In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law. You can withdraw your consent to our use of your personal data through your account or by unsubscribing from our e-marketing mailing or push notification list (see section ‘What do we use your personal data for, why and for how long’ for more details).
We have also added new tools in your account, allowing you to directly change personal data.
This policy should help you to better understand how we use your personal information, it explains in detail the types of personal information we collect, what we use it for and who we may share it with. If you have any further questions about this policy or how we handle your personal information, which are not dealt with here or through our webform or through your account, please get in touch with us.
Please note that requests for data access, erasure, etc. are dealt with via the webform referred to above (click here). Requests to unsubscribe from our mailing list can be made by clicking on the “unsubscribe” link in any of our marketing emails addressed to you. Changes to your personal data in your account can be done directly in the account. These requests cannot be processed if made via email, due to their volume and the need to verify your identity before we can act on your request. This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.