Privacy Notice
- Who we are
In this privacy notice references to:
- we, us, or our mean Screwfix Direct (Ireland) Limited, a limited company registered in Ireland (company number: 645397), whose registered office is 6th Floor, 2 Grand Canal Square Dublin 2, Ireland ("Screwfix");
- you or your (“you/your”) mean you, the user; and
- digital services mean our website, our digital app and any software and web-based applications that we make available for your use (“Digital Services”).
You can find out how to contact us in Section 8 below.
- Your Privacy
In the course of your interactions with us, we will collect and process personal information about you. Personal information includes any information allowing us to identify you as an individual, including, but not limited to, your name, your postal or email address or your telephone number.
For the purposes of the General Data Protection Regulations (“GDPR”) and equivalent data protection laws, we are the data controller in respect of your personal information that we collect and process, however, we may share your personal information with other organisations that may further process your personal information as a controller in their own right, you can find out more in Section 6 below. We are committed to protecting your privacy and will use your personal information in accordance with all applicable laws and regulations that relate to data protection and privacy, including the GDPR.
This privacy notice outlines:
- what personal information we collect, use and why;
- how long we will keep personal information;
- who we share personal information with;
- your data protection rights; and
- how to contact us.
3. What personal information we collect, use and why
We collect and use the following personal information about you, to provide our services and, where necessary, management of your account:
When you register with us, we may collect:
- title;
- name;
- postal address;
- email address;
- telephone number;
- profession;
- password; for your own security this should be complex and unique to us, and never shared with others; and
- information about any devices you have used (including the manufacturer, model and operating system, IP address, browser type and mobile device identifiers).
(b) When you interact with us at our trade counters, via our customer service centre or a third party platform (such as X, Meta and/or other social media applications), or using our Digital Services or other organisations' websites where our adverts are shown
We may collect:
- details of your purchases with or through us;
- information relating to your engagement with our marketing campaigns, which includes data on conversions (e.g. where you engage with an advertisement and go on to make a purchase with us);
- CCTV footage in which you feature when you visit our premises (and, in the event that you have an accident while on our premises that you bring to our attention, we may record details of that accident and any injury you suffer in the relevant trade counter's accident log);
- information contained in and records of communications between us, including recordings of telephone calls when you contact us, and messages sent using instant messaging applications or third-party platforms;
- information about your use of our Digital Services;
- information that you provide to us by using our Digital Services, including any photos you have uploaded via our Digital Services or third-party platforms (such as information when you share content on social media, write a review, ask us a question, or provide an answer via our Q&A section);
- user generated content that you consent to us sharing on our Digital Services and/or on our social media channels, which may include any photos and information you have posted on your social media account about your Screwfix purchase or experience;
- information about your preferences in connection with our Digital Services, for the purposes of enhancing and personalising your experience;
- information about any devices you have used (including the manufacturer, model and operating system, IP address, browser type and mobile device identifiers); cookies and information about your online browsing and purchasing behaviour and history on our Digital Services, as further set out in our Cookies Policy;
- we will also place cookies on your device - please see our Cookies Policy for more information about the cookies we use and how you can change your cookie settings.
Where you register an account and/or shop on our digital services, we will be able to link your personal information collected from you before registration and/or your online purchase (such as your online browsing behaviour) to your account and personal information that we collect after registration and/or your online purchase. You can browse our website without providing us with any of this information.
You may also provide us with your personal information via our forums, product questions and reviews, customer service centre’s live chat, survey responses and competition entries.
When you shop with us at our trade counters, we may request your contact information and your payment information. You can also shop at our trade counters without providing any contact information or, payment information, if you are using cash.
When you place an order through our customer service centre or our Digital Services, we will need your contact and payment information to enable us to take payment and fulfil your order. When you want to place an order via our Digital Services, we ask you to login or register so you can open a customer profile, save your browsing information and your preferences, and retrieve them from any of your devices.
To ensure that your payment details are not being used without your consent, we will validate the name, address and any other personal information supplied by you (which may include further personal information being requested, such as your date of birth, driving licence number or passport number) during the order process against appropriate third-party databases. By placing an order through our Digital Services or our customer service centre you consent to such checks being made.
We will ask for or collect your personal information when you use our trade counters (if you have an account with us) and our customer support services, including telephone support and instant messaging via third party platforms.
When you use our Digital Services, we may collect information about your location. With your permission we may collect information about your location using your device specific API (which may include Wi-Fi, Bluetooth, magnetometer, barometer and cellular hardware) and GPS. This will enable an enhanced order collection experience, when you use the Screwfix click and collect facility. You can provide or withdraw your permission at any time, by changing the settings on your device.
We ask for your permission to send you marketing and promotional material via post, telephone, email, and SMS so that we can send you free gifts, discount vouchers, invitations to events, special offers, and any other marketing material that we believe may be of interest to you. If you give permission, you will be able to withdraw it at any time:
- online, where you are a registered user of our Digital Services, by using the Account section after logging in using your username and password and updating your preferences;
- email or SMS, using the unsubscribe option in each communication we send out which will opt you out of receiving either marketing emails or SMS messages, as applicable;
- by using the Contact Us enquiry form on our Digital Services;
- by telephoning us 1800 946 602; or
- by writing to Customer Correspondence, Screwfix Direct (Ireland) Limited, 6th Floor, 2 Grand Canal Square, Dublin 2
Please note that, even if you choose not to receive this marketing information, we may still use your personal information to provide you with important services communications, including communications in relation to any orders you submit or products you purchase. We may also offer you the opportunity to indicate the specific types of marketing communications you are particularly interested in receiving from us; where possible, we will tailor the communications you receive to reflect your choices, but we may send you other communications that we believe may be of interest to you.
We ask for your consent before using any user generated content on our website and/or on our social media channels. If you give us your consent, you will be able to withdraw it at any time by messaging us on the platform we used to contact you requesting your consent, or by contacting us using the contact details provided in Section 8.
When you use your payment card to make a purchase with us (either at our trade counters or via our Digital Services), we will link details of that purchase with other purchases made with the same payment card. (For security purposes, we do not keep your payment card details for this purpose.) We use this information to better understand how our customers purchase from us. If you opt in to receiving marketing communications from us, we will link details of your purchases with us with the other details that we hold about you, and we may use this information to make our communications with you more relevant.
- How do we use your personal information?
We have set out below the purposes for which we use your personal information. We are also required by law to state a "legal basis for processing", i.e., to tell you on what grounds we are allowed to use your information, and this is also set out below. The legal basis for each purpose is that we have your consent for the use of your personal information, or that we need to use your personal information to perform a contract with you, or to comply with legal obligation, or that the use of your personal information is necessary for our legitimate interests (in which case we will explain what those interests are).
|
PURPOSE OF PROCESSING |
OUR LEGAL BASIS |
|
to carry out our obligations under any contracts entered into between you and us. For example, we will use your payment details and delivery address to process and fulfil your order(s), and to communicate with you about your order for a service or product; |
Contractual necessity – we use your personal information in order to meet our obligations under our contract with you. |
|
in the event that you do not complete your registration or order, we may use any contact information you have provided us to follow up on your partial registration or order; |
Legitimate interests – we use your personal information in order to remind you of your partial registration or order and so that you can (if you wish) complete the registration or order. |
|
to contact you about leaving a review or providing feedback on a product or service once your order has been completed or the service has been provided; |
Legitimate interests - we use your personal information to contact you so that we can ask you to provide feedback on the product or service you have ordered. |
|
to share user generated content on our Digital Services and/or social media channels |
Consent - where we use your user generated content (such as your social media posts) we will ask for your consent before processing your personal information for this purpose. |
|
to notify you about changes to our services and to otherwise communicate with you. For example, we will use your contact details in order to respond to any queries that you submit to us; |
Legitimate interests - we use your personal information to keep you up to date with information about our services, and to respond to your queries. |
|
to provide you with information about products and services, including exclusive offers, vouchers, free gifts, deals, and information about products and events; |
Legitimate interests – we use your personal information to send you this information. In some cases (such as where we are required to do so by law) we will also ask for your consent before sending you this information (in which case we rely on consent and not legitimate interests as our legal basis). |
|
to review your past purchases and viewing history on our Digital Services to provide you with special offers or to tailor your experience online; |
Legitimate interests - we use your personal information to provide you with these offers and to tailor your experience when using our online services. |
|
to help us review, develop and improve the products and services we offer. For example, calls to our customer service centre are monitored and recorded for quality control and training purposes. We may also send you market research requests via email (which you can opt out of via that email). |
Legitimate interests – we use your personal information to help us deliver the best quality of service to you and our other customers. |
|
to monitor details of your visits to our Digital Services, including page views, and conversions, whether cookies are accepted or rejected, for business and data analysis purposes and to ascertain the products, services, promotions, special offers and discounts that are likely to be of particular interest to you and to use this to send tailored marketing information to you (where we are permitted to do so). |
Legitimate interests – we use your personal information to (i) help us deliver the best quality of service to you and our other customers; and (ii) provide you with tailored advertising and to tailor your experience when using our Digital Services. Consent – where cookies or similar technologies are accepted, we rely on consent (unless otherwise provided in our cookie policy). |
|
to improve and measure the effectiveness of our marketing communications, including online advertising. We require any such third parties to treat your personal information as fully confidential and to fully comply with all applicable data protection legislation. We sometimes compare limited information that we hold about you (for example, your email address or telephone number) with third parties that also hold your information or have an existing online relationship with you in order to identify you as our customer and to enable us (or third parties on our behalf) to provide you with relevant marketing online. |
Legitimate interests - we use your personal information to deliver you a tailored experience when using such Digital Services, to help us understand the effectiveness of our advertising, and to make sure you see adverts that are most relevant to you. Consent – where cookies or similar technologies are accepted, we rely on consent (unless otherwise provided in our cookie policy). |
|
We share limited data (such as an email address) which is hashed and securely share this with Google when you engage with our advertising and go onto make a purchase using our Digital Services where you are a Google account user, and that account is logged into the service that you accessed or received advertisement through. This is then reported within our conversion account. |
Legitimate interests – we use your personal information to help us deliver the best quality of service to you and our other customers. |
|
to provide, enhance and personalise your experience on our Digital Services; |
Legitimate interests - we use your personal information to deliver you a tailored experience when using our Digital Services. |
|
to carry out security checks to protect against fraudulent transactions and to prevent and detect criminal activity; |
Legitimate interests - we use your personal information to protect against unlawful activities. In some cases, we may also be under a legal obligation to disclose your personal information (for example, to law enforcement agencies). |
|
to ensure the safety and security of customers, employees and third parties at our premises; |
Legitimate interests - we use your personal information to protect against unlawful activities. |
|
to address any complaints or claims made against us. |
Legitimate interests - we use your personal information to address any claims you make against us. In some cases, we may also be under a legal obligation to disclose your personal information (for example, in connection with legal proceedings). Legal proceedings – where the personal information constitutes special categories of personal data (for instance, health information), we will process the information on the basis that it is necessary for the establishment, exercise or defence of legal claims (as the case may be). |
|
to comply with any legal obligation (including in connection with a court order); |
Compliance with legal obligation – we process your personal information in order for us to comply with our legal obligations. |
Our services are not intended for minors (individuals aged under 16 years old), and we do not knowingly process personal information in relation to minors.
- How long do we keep personal information
We are required by law to keep your personal information only for as long as is necessary for the purposes for which we are using it. The period for which we keep your personal information will be determined by a number of criteria, including the purposes for which we are using the personal information, the amount and sensitivity of the personal information, the potential risk from any unauthorised use or disclosure of the personal information, and our legal and regulatory obligations.
- Who we share personal information with
We are a member of the Kingfisher Group of companies, being companies, whose ultimate parent is Kingfisher plc and whose members include B&Q, Screwfix, Castorama and Brico Dépôt (for more information on the Kingfisher Group please visit www.kingfisher.com).
We may share your personal information with other members of the Kingfisher Group in connection with the purposes listed within this policy. Members of the Kingfisher Group may also use the personal information we share with them to improve their websites and other services and for analysis purposes or to offer you products and services that they believe may be of interest to you.
We may use automated decision-making when we make decisions by technological means without significant human involvement, and non-automated processes, to help generate business insights based on the customer experience and evaluate or predict customer purchasing preferences. This may include sharing information with Kingfisher plc, who may then, having received this information, use their own similar processes and then share the results with us for the same purposes and to help improve overall customer experience. This means Kingfisher plc may each be receiving and processing your information in their own right and subject to their own privacy notices which are available on their respective websites.
We may disclose your personal information to third parties, including in the following circumstances:
- We use third parties to carry out certain activities on our behalf that involve the processing of your personal information. For example, we may engage third party service providers to fulfil orders, deliver packages, send postal mail, SMS text messages and email, maintain and update our databases of customer details (including the removal of repetitive or incorrect information), analyse data to help us develop, provide, and improve our products and services, provide marketing assistance, process payments and refunds, carry out surveys, provide customer service and handle claims. These third parties have access to your personal information required to perform their functions but may not use it for any other purpose. We may use the information we receive from third parties to supplement, improve and add to our databases of customer details, for purposes such as credit checking and fraud prevention.
- Where we allow customers to pay for products and services via our Digital Services using online payment methods and digital wallets, your personal information may be shared with providers of those services for payment purposes to process the transaction, for example with PayPal when you choose to use PayPal for your payment. For more information on how PayPal uses your personal information that it collects from you, please see PayPal’s Privacy Policy.
- We may share information that we hold about you (for example, your email address and information about your purchases) with third parties that also hold your information or have an existing online relationship with you to identify you and to enable us (or Kingfisher Group companies, or other third parties on our behalf) to provide you with relevant marketing online.
- We may pass your personal information to external agencies and organisations (including the police and other law enforcement agencies) for the purpose of preventing and detecting fraud (including fraudulent transactions) and criminal activity. These external agencies may check the information we give them against public and private databases and may keep a record of such checks to use in future security checks. We may also disclose your personal information to the police and other law enforcement authorities in connection with the prevention and detection of crime.
- We may pass your personal information to our third-party claim handlers and insurers in connection with any claim made or reasonably likely to be made against us. For example, we may send CCTV footage and information contained in our accident logs to our insurers.
- In the event that we sell or buy any business or assets, we may disclose your personal information held by us to the prospective seller or buyer of such business or assets. If we or substantially all of our assets are acquired by a third party (or subject to a reorganisation within our corporate group), your personal information held by us will be one of the transferred assets.
- We may pass your personal information to third parties if we are under a duty to disclose or share your personal information to comply with any legal obligation (including in connection with a court order), or to enforce or apply any agreements we have with or otherwise concerning you (including agreements between you and us or one or more of our affiliates); or to protect our rights, property, or safety or those of our customers, employees or other third parties.
- We may pass your details to additional third parties for the purpose of improving the quality and accuracy of our database, suppressing inaccurate records, appending marketing information, for solvency and credit scoring purposes, market research purposes/to conduct research on our behalf, to enable functionality, analytics, and/or marketing communications).
- We may share anonymised customer analytics with selected vendors to provide campaign performance insights and help improve their offerings. This data does not identify individuals and cannot be used to re-identify them. Vendors are contractually prohibited from attempting re-identification, and all sharing complies with applicable data protection laws.
Links to external, third party websites and applications
We may provide links to external, third party websites and applications, or those of other Kingfisher Group companies. Each website, or application, operates its own policy regarding the processing of your personal information and the use of cookies on its website or through its application and you are advised to read their individual terms of use, privacy and cookie policy, available on those websites or applications individually.
Third party websites and applications are not under our control. When you access these websites, or applications, you leave the area controlled by us. Similarly, where you have contacted us or shared content with us using a third-party platform, the third party that provide these platforms will use your personal information in accordance with their own individual terms of use, privacy and cookie policy. We do not accept responsibility or liability for any issues arising in connection with the third party's use of your personal information.
Where will your personal information be processed?
Your personal information may be transferred to, and stored and processed in, one or more countries outside the country in which we are established (you can find out more in Who we are, above), including countries which do not provide equivalent protection for personal information. In these circumstances, we will take reasonable steps and implement appropriate measures to ensure that your personal information is adequately protected in accordance with the law.
These measures include either:
- Transferring your personal information to countries that have been deemed to provide an adequate level of protection for personal information under applicable data protection law; or
- Transferring your personal information where the recipient has agreed to an approved agreement in the form of the standard contractual clauses.
- Occasionally, we may transfer your personal information in circumstances where there are no adequate safeguards where this is permitted by data protection law.
Please contact us using the details below if you want further information on the specific safeguards used by us when transferring your personal information out of the country in which we are established.
- Your data protection rights
Under data protection law, you have rights including:
- your right of access; you have the right to ask us for copies of your personal information;
- your right to rectification; you have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete personal information you think is incomplete;
- your right to erasure; you have the right to ask us to erase your personal information in certain circumstances;
- your right to restriction of processing; you have the right to ask us to restrict the processing of your personal information in certain circumstances.
- your right to object to processing; you have the right to object to the processing of your personal information in certain circumstances.
- your right to data portability; you have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances; and
- your right to withdraw consent; when we use consent as our lawful basis you have the right to withdraw your consent.
Our security procedures mean that we may request proof of identity before we are able to comply with these requests.
You do not usually need to pay a fee to exercise your rights. If you make a request, we have one calendar month to respond to you. You can find out how to contact us in Section 8 below, to make a data protection rights request.
- How to contact us
If you have any concerns about our use of your personal information, to exercise your data protection rights, speak to our Data Protection Officer or contact us regarding any other matter, you can:
- click on this link to access our Data Subject Request Form;
- call us on 1800 946 602; or
- write to us at Customer Correspondence, Screwfix Direct (Ireland) Limited, 6th Floor, 2 Grand Canal Square, Dublin 2.
If you remain unhappy with how we’ve used your personal information after raising a complaint with us, you can also complain to the Data Protection Commission (DPC). For further details, see https://www.dataprotection.ie.
- Protecting your personal information
The transmission of information via the internet is not completely secure; this risk is common across the internet and not specific to us. We cannot guarantee the security of your personal information transmitted to us; any transmission is at your own risk.
It is important for you to protect against unauthorised access to your password and to your device. Be sure to sign off and close your browser when you have finished your session. We also recommend that you do not use the same password and email address combination for your Screwfix account as you use for other accounts. Using the same password and email address combination for multiple accounts puts your personal data at risk of compromise in credential stuffing attacks across multiple websites.
- Updates to this notice
We may update this notice from time to time. The latest version of this notice will be posted on our Digital Services.