Cult Pens is the trading name of The SQL Workshop Limited and is a member of the WHSmith High Street Group of companies. More information on the WHSmith Group can be found here: https://www.whsmithplc.co.uk
Cult Pens is the Data Controller of your data and we want to ensure that you are able to shop with confidence on our site. We respect your privacy and are committed to protecting your personal data.
This Privacy Notice explains what personal information we collect, what we do with information, our legal basis for processing and how we secure personal information. We will also explain your rights in relation to the personal information we hold and how you can exercise your rights or register a complaint.
Data Protection Officer, WHSmith PLC, Greenbridge Road, Swindon, SN3
3LD, United Kingdom
Telephone: 01793 616161
Legal Basis for Processing
In most instances our legal basis for collecting personal data will be to meet our contractual obligations when you purchase or enquire about our products or services. In some instances, we need to collect information during the sales process to meet financial, legal or regulatory obligations. When we collect personal data for our legitimate interests, we carry out balancing, proportionality and necessity tests. We may process your personal data without your knowledge or consent (for example, in relation to fraud management or to assist with investigations by the police or other regulatory bodies) where this is required or permitted by law.
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.
Generally, we do not rely on consent as a legal basis for processing personal data, other than for our own marketing purposes in some situations, and always for third party marketing. You can opt-out of direct marketing communications via email or text message at any time.
In limited situations, we may approach you for your written consent to allow us to process certain particularly sensitive data. If we do so, we will provide you with full details of the information we require and the reason we need it, to enable you to carefully consider whether you wish to consent. You should be aware that it is not a condition of your contract with us that you agree to any request for consent from us.
Personal Data We Collect
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
When you complete an online form, register or shop with us online, or engage with us through feedback or complaints, we may collect, process and store different kinds of personal data about you such as your name, gender, date of birth, billing/delivery address, e-mail address, telephone number and IP address. We may also collect and retain information about your interactions with us online, via social media, or through our contact centres so that we can process your transactions and deal with any future queries. When collecting personal data, we will always make clear which data is necessary in connection with a particular contractual or legal requirement. We also collect, use and share aggregated data such as statistical or demographic data. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific website feature. If we combine or connect aggregated data with personal data, we treat the combined data as personal data which will be used in accordance with this privacy notice. Where we need to collect personal data to meet our legal obligations, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract.
Our payment providers, Shop Pay, PayPal and others through Global-e, process card details on our behalf, we do not have access to this financial information. Please consult the privacy notices of these service providers for information on how they process data.
We do not collect any special category data or information about criminal convictions and offences.
Purposes For Which We Will Use Your Personal Data
Our main purpose for collecting your personal data is to meet our obligations in respect of the service your requested or the products you purchased.
We will also use the information provided to:
- Register you as a new customer.
- Process and deliver your order(s).
- Manage payments, fees and charges.
- Collect and recover money owed to us.
- Request a product or service review or request participation in a survey.
- Send you reminders if you abandon (exit the site) after a search, product view, basket or do not complete your order. You can opt-out of these reminders at any time.
- To enable you to partake in a prize draw or competition.
- To administer and protect our business and website (including troubleshooting, data analysis, testing, system maintenance, development, support, reporting and hosting of data).
- To use data analytics to improve our website, products/services, marketing, customer relationships and experiences.
- To make suggestions and recommendations to you about goods or services that may be of interest to you.
How We Collect Personal Data
We collect information through our website and through correspondence with us or our Group companies. When visiting any of our Group company websites we may automatically collect technical data about the equipment used, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies. We may collect technical information about your journey through our websites with Google Analytics. We and our authorised partners use this data to improve your site experience.
We also collect information through your interactions with us in the following ways:
- Purchasing any of our products or services.
- Creating an account on our website.
- Subscribing to our newsletters or other publications.
- Entering a competition, promotion or survey.
- Providing feedback about our services or products by leaving a review on Trustpilot (https://uk.trustpilot.com/review/www.cultpens.com)
- Interacting with our social media channels or engaging with our external advertising on third party sites.
We may use unique identifiers, contact data, technical information, usage data and profile data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you and display them to you on the website. We use technology partners such as Klevu to surface products and content that may be of interest to you.
Disclosure of Personal Data
In most instances the sharing of personal information will be related to the contracted services we are providing to you. We also share data within our Group of companies for analytical purposes and with professional advisors. In some cases, we are required to share information with regulatory authorities to comply with our obligations. We will also share data with third parties where there is a legal obligation to do so.
Where there is no legal obligation, third parties are required to only use personal data for limited and specified purposes and in accordance with our instructions.
We may also share personal data for the following purposes:
- With other WHSmith Group entities, details of which can be found in our Annual Reports.
- Third party partners to execute contractual obligations or to provide services to you through our website such as our Chat function provided by hCaptcha! of Intuition Machines, Inc
- Trusted technical partners for the purposes of site development and improvements.
- We may, from time to time, expand, reduce or sell Cult Pens and this may involve the transfer of divisions or the whole business to new owners. If this happens, your personal data will, where relevant, be transferred to the new owner or controlling party, under the terms of this Privacy Notice.
We require all third parties to respect the security of your personal data. Third-party service providers may only process your personal data for specified purposes and in accordance with our instructions.
International Data Transfers
We use processors who are based outside of the United Kingdom and the EEA. When we are required to transfer data, or grant access, to service providers in these locations, we ensure that appropriate safeguards such as standard contractual clauses, international data transfer agreements, adequacy or other restricted transfer safeguarding measures are used.
We have put in place appropriate organisational and technical measures to meet our legal obligation to ensure the security of your personal information. We maintain physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of your information. We keep personal information for only as long as necessary for our business purposes and to meet our legal and contractual obligations. In addition, we limit access to your personal data to those employees, agents, technical partners, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We will only retain personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
In most instances, our retention period will come to an end when we no longer require your information and is deleted six years after your relationship with us ends. In some instances, we are required to retain data for longer to meet regulatory and legal requirements and for insurance, warranty and guarantee purposes.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. In some circumstances we may anonymise personal data for research or statistical purposes in which case we may use this information indefinitely without further notice.
Under data protection law, you have individual rights pertaining to your personal information, including:
- Your right of access - You have the right to ask us for copies of your personal information we hold.
- Your right to rectification - You have the right to ask us to correct information you think is inaccurate or complete information you think is incomplete.
- Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances. We maintain a retention policy and will inform you if we are not able to delete your information immediately or have a legal obligation to retain data for longer periods.
- Your right to restriction of processing - You have the right to ask us to restrict the processing of your information in certain circumstances.
- Your right to object to processing - You have the right to object to the processing of your personal data where we are relying on our legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
- Your right to data portability - You have the right to ask that we transfer the information you gave us to another organisation, or to you, in certain circumstances.
- You have the right to withdraw consent at any time where we are relying on consent to process your personal data. You have the right to withdraw consent to marketing (or to object to receiving marketing where we do not rely on consent to send it) at any time.
We do not make use of automated decision-making.
You can ask us or third parties to stop sending you marketing messages at any time by contacting us at firstname.lastname@example.org or by unsubscribing from marketing communications in any e-mail sent to you. You do not need to pay a fee for exercising your rights. However, we may charge a reasonable administration fee if your access request is manifestly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request where it is manifestly unfounded, repetitive or excessive.
If you make a request, we are required to respond to you within one month unless there are reasons why it will take longer to collect the information you requested. If that is the case, we will inform you. In some cases, we will require proof of identity if we are unable to confirm identity through other information we hold. This is required to ensure the security of the personal information we hold and to meet our legal obligations. We may also contact you to ask you for further information in relation to your request to speed up our response.
We may send you marketing about our own goods and services if either you have opted in to receive our marketing messages, or you have previously bought or enquired about similar goods or services from us (including by placing items in your basket but not completing an order) and you have not opted out from receiving our marketing messages. You can unsubscribe to any or all of our marketing material at any time. You can also contact us at any point to opt out of any or all marketing communications. Email email@example.com to do this.
Whilst browsing other websites you may see Cult Pens promotional messages, these will be displayed based on cookies placed during your recent visit to our website. Please see our Cookie Notice for more detail.
You are in control of any information we share with third parties for marketing purposes. As you go through our checkout or account creation processes you will be asked to advise us which communications you wish to receive. If you have opted in to receive marketing, you can opt out of these marketing communications at any time by contacting us or by unsubscribing from communications sent to you.
Clicking on links to third-party websites, plug-ins and applications contained within this website, or enabling those connections, may allow third parties to collect or share data about you. We do not control these third-party websites. When you leave our website, we encourage you to read the privacy notice of every website you visit.
How to complain
In the first instance please send complaints to our Data Protection Officer: firstname.lastname@example.org
You can write to: Data Protection Officer, WHSmith PLC, Greenbridge Road, Swindon, SN3 3LD, UK
If you are not happy with the response you receive, you can contact the UK Information Commissioner’s Office (ICO) or the regulatory authority in your country. We would, however, be grateful for the chance to deal with your concerns before you approach the ICO so please contact us in the first instance. ICO: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline number: 0303 123 1113 www.ico.org.uk
Changes to our policies may result in periodic changes to this Privacy Notice. The date released will always be listed below.
Last updated: 10 November 2023