Making a privacy request
What you can ask for, what we need in order to answer, and how long we take.
What you can ask for
These come from the law, not from us. Asking costs nothing, and we will not treat you differently for having asked.
- A copy of what we hold
- Everything we have about you, and why we have it.
- A correction
- Anything wrong or incomplete, put right.
- Deletion
- Removed, apart from records we are required by law to keep — we will tell you which, and until when.
- A restriction
- We keep it but stop using it, while something is in dispute.
- An objection
- To anything we do on the basis of our legitimate interests, including server logs and visitor counts.
- A portable copy
- What you gave us, in a form you can take somewhere else.
- Withdrawal of consent
- For analytics or trade news. As easy as giving it was.
How to make one
Write to us with three things: what you are asking for, the company and email address your records are under, and the country you are based in — the last one because it decides which rules apply and which regulator you can complain to.
Opens a message to sales@patersonjewellery.com with the headings already in it. If you would rather write it yourself, put “Privacy request” in the subject line so it is routed rather than treated as sales mail.
Proving it is you
We may ask something to confirm you are who you say you are — usually just that you can reply from the address already on the account. We will not ask for identity documents to answer a request about data we hold, because collecting more data in order to hand back less would be an odd way to respect your privacy.
How long we take
Thirty days. If a request is genuinely complex we may need longer, in which case we will tell you inside the thirty days why, and when to expect the answer — rather than letting the deadline pass quietly.
If we get it wrong
Complain, and you do not have to come to us first. In Thailand, the Personal Data Protection Committee. In the European Economic Area, your own national supervisory authority. In the United Kingdom, the Information Commissioner’s Office. In Canada, if this is about email we sent you, the CRTC.
What we hold and why is set out in the privacy policy.