This Privacy Policy governs the manner in which Control Components Anglia Ltd ("CCA Ltd") collects, uses, maintains and discloses information collected from users (each, a "User") of the website www.cca.co.uk ("Site"). This privacy policy applies to the Site and all products and services offered by CCA Ltd.

What is Personal Data? 

Personal data is defined by the UK GDPR and the Data Protection Act 2018 (collectively, "the Data Protection Legislation") as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.Personal data is, in simpler terms, any information about a User that enables it to be identified. Personal data covers obvious information such as a User’s name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers.

Personal identification information

Depending upon how the Site is used, we may collect personal identification information from Users in a variety of ways, including, but not limited to, when Users visit our site, place an order, subscribe to the newsletter, respond to a survey, fill out a form, and in connection with other activities, services, features or resources we make available on our Site. Users may be asked for, as appropriate, name, email address, mailing address, phone number.

Users may, however, visit our Site anonymously. We will collect personal identification information from Users only if they voluntarily submit such information to us. Users can always refuse to supply personally identification information, except that it may prevent them from engaging in certain Site related activities.

Non-personal identification information

We may collect and hold non-personal identification information about Users whenever they interact with our Site. Non-personal identification information may include the browser name, the type of computer and technical information about Users means of connection to our Site, such as the operating system, electronic location data, the Internet service providers utilised and other similar information.

Web browser cookies

Our Site may use "cookies" to enhance User experience. User's web browser places cookies on their hard drive for record-keeping purposes and sometimes to track information about them. User may choose to set their web browser to refuse cookies, or to alert you when cookies are being sent. If they do so, note that some parts of the Site may not function properly.

Cookie

 

Type

 

Duration

 

Further details

 

PHPSESSID

 

Strictly necessary

 

End of session

 

The PHPSESSID cookie stores serialised data and allows our website to keep track of data in relation to our basket, checkout and secure login areas.

 

__cfduid

 

Strictly necessary

 

End of session

 

Cloudflare. The __cfduid cookie is used to identify individual clients behind a shared IP address and apply security settings on a per-client basis.

 

_gat

 

Analytical

 

1 minute

 

This cookie name is associated with Google Universal Analytics, according to documentation it is used to throttle the request rate - limiting the collection of data on high traffic sites.

 

_ga

 

Analytical

 

2 years

 

This cookie name is associated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports.

 

_gid

 

Analytical

 

24 hours

 

This cookie is set by Google Analytics. It stores and update a unique value for each page visited and is used to count and track pageviews.

 



How we use collected information

Under the Data Protection Legislation, we must always have a lawful basis for using personal data. We may collect and use Users personal information for the following purposes:

  • To improve customer service
    Information you provide helps us respond to your customer service requests and support needs more efficiently.

 

  • To personalise user experience
    We may use information in the aggregate to understand how our Users as a group use the services and resources provided on our Site.

 

  • To improve our Site and administer our business
    We may use feedback you provide to improve and refine the Site, our products and services.

 

  • To process payments
    We may use the information Users provide about themselves when placing an order only to provide service to that order. We do not share this information with outside parties except to the extent necessary to provide the service.

 

  • Communicating with you
    We may use the email address to send Users information and updates pertaining to their order. It may also be used to respond to their inquiries, questions, and/or other requests.

With your permission and/or where permitted by law, we may also use personal data for marketing purposes, which may include contacting Users by email and telephone, with information, news, and offers on our products. Users will not be sent any unlawful marketing or spam. We will always work to fully protect Users’ rights and comply with our obligations under the Data Protection Legislation and the Privacy and Electronic Communications (EC Directive) Regulations 2003, and you will always have the opportunity to opt-out.

We will only use personal data for the purpose(s) for which it was originally collected unless we reasonably believe that another purpose is compatible with that or those original purpose(s) and need to use personal data for that purpose. If we do use personal data in this way, Users may contact us to invite us to explain how the new purpose is compatible with the original.

If we need to use personal data for a purpose that is unrelated to, or incompatible with, the purpose(s) for which it was originally collected, we will inform the User and explain the legal basis which allows us to do so.

In some circumstances, where permitted or required by law, we may process personal data without your knowledge or consent. This will only be done within the bounds of the Data Protection Legislation and a User’s legal rights.

 

How long we keep personal data

We will not keep personal data for any longer than is necessary in light of the reason(s) for which it was first collected.
Our standard policy is to retain identity information (e.g. name, date of birth, title), contact information (e.g. mailing address, email address, telephone number) and business information (e.g. business name, profession, job title) for a period of 5 years. We do not retain payment information (including card details and bank account numbers). Our standard policy is to retain technical information (e.g. IP address, browser type, operating system etc.) for a period of 1 year 

How we protect your information

We will only store personal data in the UK. This means it will be fully protected under the Data Protection Act. We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction of your personal information, username, password, transaction information and data stored on our Site.

We limit access to personal data to those employees, agents, contractors, and other third parties with a legitimate need to know and ensure that they are subject to duties of confidentiality.

 We have procedures for dealing with data breaches (the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data) including notifying Users and/or the Information Commissioner’s Office where we are legally required to do so;

Our Site is in compliance with PCI vulnerability standards in order to create as secure of an environment as possible for Users.

Sharing your personal information

We do not sell, trade, or rent Users’ personal identification information to others. We may share generic aggregated demographic information not linked to any personal identification information regarding visitors and Users with our business partners, trusted affiliates and advertisers for the purposes outlined above. We may use third party service providers to help us operate our business and the Site or administer activities on our behalf, such as sending out newsletters or surveys. We may share a User’s information with these third parties for those limited purposes provided that they have given us their permission for this.

Third party websites

Users may find advertising or other content on our Site that link to the sites and services of our partners, suppliers, advertisers, sponsors, licensors and other third parties. We do not control the content or links that appear on these sites and are not responsible for the practices employed by websites linked to or from our Site. In addition, these sites or services, including their content and links, may be constantly changing. These sites and services may have their own privacy policies and customer service policies. Browsing and interaction on any other website, including websites which have a link to our Site, is subject to that website's own terms and policies.

Changes to this privacy policy

CCA Ltd has the discretion to update this privacy policy at any time. When we do, we will revise the updated date at the bottom of this page. We encourage Users to frequently check this page for any changes to stay informed about how we are helping to protect the personal information we collect. You acknowledge and agree that it is your responsibility to review this privacy policy periodically and become aware of modifications.

This Privacy Policy was last updated on 28/09/2021