1. INTRODUCTION
We are committed to safeguarding your privacy and to processing your personal data in a transparent, secure and legal manner.
Vitamin Well Ltd, reg.no. 10821384 (“Company” “we,” “us” or “our”) will process your personal data when you are visiting and using the services provided at https://barebells.co.uk (the “Site”) or in other ways interacting with us as stated herein. Below you will find information on what kind of personal data we process, why we do it, what we use it for and how we may share it and what rights you have as a data subject. The Company is the data controller of any processing of your personal data, unless otherwise stated in this privacy policy.
We will only use your personal data for the purposes, on the legal grounds and for the storage periods set out below.
2. WHAT IS PERSONAL DATA?
Personal data is any information relating to an identified or identifiable natural person (“data subject”), i.e. any type of data that can be associated with a person. Examples include names, email addresses or phone numbers if they can be associated to a certain living physical person, but also e.g. a photo in which the person can be recognized.
3. WHAT DOES “PROCESSING” PERSONAL DATA MEAN?
The term “processing” covers all sorts of operations that are performed on personal data. The definition is very wide and includes all forms of handling data from collection, recording, storage and adaptation, to use, dissemination and even erasure of personal data.
4. WHAT PERSONAL DATA DO WE PROCESS, FOR WHAT PURPOSES AND ON WHAT LEGAL BASES?
We process personal data to be able to fulfil or enter into an agreement with you:
The legal basis for our processing of this personal data relating to you is that the processing is necessary to enter into or to fulfil an agreement with you.
We process personal data based on our legitimate interests.
Advertising to Existing Customers and New Audiences: If you are an existing customer of ours and have provided us with personal information, we may share your email address, name, address, and phone number in the services of our partners (such as Google Ads and Facebook) with the purpose of reaching you and new potential customers with similar interests and characteristics when they visit Google’s and Meta’s websites (e.g., Google search engine, Gmail, YouTube, Facebook, Instagram, and Audience Network). Google and Meta process the data solely in hashed, de-identified form and only for the purpose of matching personal information to target our campaign ads to you and to new audiences. To learn more about how your personal information is processed for this purpose, please refer to:
Google: https://support.google.com/google-ads/answer/2676774?hl=enMeta: https://www.facebook.com/business/help/341425252616329?id=2469097953376494
We process this personal data based on our assessment that it is necessary for the purposes of our legitimate interest to promote our products and trademarks, to remain competitive as a company and carry out our business. We assess that our legitimate interest in this case is not overridden by your interest or fundamental rights and freedoms that require protection of personal data, as you have yourself or even on your initiative provided us with your personal data and we process the data for purposes that should be in line with your expectations.
If we have concluded an agreement regarding any of the above listed activities, our processing of associated personal data will instead be based on the fulfilment of that agreement.
Legal requirements, public interest and consent.
We may need to process your personal data to fulfil legal requirements (e.g. obligations to keep records) and at the instruction of courts or public authorities (e.g. for tax reasons). We may also be legally required or compelled by public interest to process personal data relating to product issues in order to trace and monitor potential health risks.
In addition, we may process your personal data based on your consent. We will in that case obtain your consent in advance, for a specific purpose, and ensure that it is freely given, specific, informed and unambiguous. You have the right to withdraw a given consent at any time and are in that case welcome to adjust your privacy setting or contact our Data Protection Officer, see contact details below. Please note that a withdrawal will not retroactively apply for already performed processing.
You can learn more about how our advertising partners help us achieve this purpose by visiting their sites (the relevant links can be found in our Cookie Settings
5. WHO ARE THE RECIPIENTS OF THE PERSONAL DATA?
Only the people who need to process personal data for the purposes mentioned above have access to your personal data. We may need to share your personal data with our group companies. Your personal data will, where and to the extent necessary, be processed by the Company’s employees and its advisors, suppliers, service providers, partners and distributors. For instance, our e-commerce team will have access to personal data related to your purchases, our product managers will primarily have access to incoming questions and complaints on our products, whereas our HR department primarily will process employee information.
The Company concludes data processing agreements with third parties who through their services or collaboration gain access to or process personal data on our behalf. We thereby ensure that the third parties we work with process data in the same legal and secure way as us. More specifically, personal data is shared with the following categories of service providers that process such data on our behalf:
The Company currently has sister companies in Norway, Denmark, Germany, France, Austria, Spain, Hong Kong and the U.S.A., as well as a sister branch office in Finland, and is continuing to expand internationally. The Company’s parent company is based in Sweden. We may also work with partners in many countries both within and outside of the UK and may therefore also need to share personal data with e.g. service providers and legal advisors not based in the UK.
This means that your personal data may be transferred outside of the UK. Such transfers will be based on adequacy decisions by the UK authorities where possible, and otherwise primarily on the performance of an agreement concluded between us. In other cases, any third country transfer of your personal data will rely on adequate safeguards such as standard contractual clauses. Exceptionally, we may also perform such transfers based on your explicit consent, important reasons of public interest, the management of legal claims, or to protect your or someone else’s vital interests.
We do also share your personal data with other controllers of personal data. Such controllers could be authorities (police, tax authority or other authorities), if we are obliged to share it according to law or suspected criminal activities, payment providers and banks to facilitate transactions, external counsel (lawyers and auditors) as well as courts to safeguard our rights, companies that purchase all or part of our business/assets and transport companies in order for them to handle and deliver your order. When your personal data is shared with other controllers, they will be responsible for your personal data and we refer to them for more information on how they process your personal data.
We use Klarna as the provider of our checkout. This means that we might transfer your personal data in the form of contact and order details to Klarna when the checkout is loaded, in order for Klarna to manage your purchase. Your personal data transferred is processed in line with Klarna’s own privacy notice.
6. DOES THE COMPANY PROCESS SPECIAL CATEGORIES OF PERSONAL DATA?
The Company never processes sensitive information such as information on racial or ethnic origin, political opinions, religious beliefs, or sexual orientation. In some cases, however, we are required to collect and, for a limited period of time, process data concerning health for safety reasons, such as information on allergies or other conditions that we need to know of when organizing trips or training events. Such data will always be deleted as soon as the purpose for which it was collected is no longer applicable.
7. FOR HOW LONG IS THE PERSONAL DATA RETAINED?
7.1 When we process personal data is based on an agreement.
We will retain your personal data during the term of the agreement and erase it when the agreement is terminated. However, the following exceptions apply:
7.2 When we process personal data based on our legitimate interest.
News updates: We will retain your personal data for as long as you remain signed up for or indicate your interest in our news updates. You may at any time cancel our news updates by opting-out or unsubscribe from our marketing.
Events and competitions: We will retain your personal data until the event or competition is completed (including a possible evaluation thereof). Photos and films from the event will, however, not automatically be erased after completion of the event, but may be used for as long as they are relevant for our marketing purposes.
Product questions and complaints: We will process the personal data for two years upon receiving it, in order to perform statistical analyses on questions and complaints, to investigate, trace and report potential health risks or product issues, to monitor and improve our customer service, pay compensation, and to prevent fraudulent behaviour (e.g. unfounded compensation claims).
Website visitors: We will process your personal data until you reject our website cookies.
Ideas etc.: We process any spontaneously received personal data for as long as it is relevant to us.
7.3 When we process personal data based on your consent, we will do it until the consent is revoked.
7.4 Please note that the above storage periods do not apply to the extent the Company is required to retain your personal data (partly or in full) under applicable mandatory law (e.g. accounting laws).
8. WHAT ARE YOUR RIGHTS AS A DATA SUBJECT?
You are entitled to the following rights under applicable laws:
The right to object: on grounds relating to your particular situation, you may at any time object to processing activities conducted by us in relation to your personal data which are based on our or a third parties legitimate interest. We will no longer process the personal data for purposes you have objected to unless we demonstrate compelling legitimate ground for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.
The right to object also applies to processing of your personal data for direct marketing purposes. Where personal data are processed for direct marketing purposes you may at any time and without any condition object to such processing.
If you have any questions or wish to invoke any of your rights, please contact our DPO at dpo@vitaminwell.com
COOKIES
As part of our approach to providing personalized services on our website, we use cookies to store and sometimes track information about you. A cookie is a small data file sent to your browser from a web server and stored on your hard drive that allows easier access the next time the same page is visited. If you do not want your personal information to be stored by cookies, you can configure your browser so that it notifies you whenever a cookie is received. This way you can decide each time to accept cookies or not. However, the use of cookies may be necessary to provide certain features and choosing to reject cookies may reduce the functionality of our website. Your browser should include precise instructions explaining how to control the acceptance of cookies.
If you prefer not using our Cookie Setting, please follow the below links to receive instructions on how to change your browser settings from some of the most common browser providers (please note that these are links to third party websites for which we have no control):
Please note that by restricting cookies you might not be able to access all parts of our website since some functionality of the website are dependent on cookies.
To be transparent, we have summarized the cookies used on our website below.
By clicking on the Cookie Settings you will find a detailed list of the cookies we use on our website. We classify cookies in the following categories:
If you have accepted consented to all cookies, you can optwithdraw your consentopt-out of these cookies (except for strictly necessary cookies) by accessing our Privacy Settings.
DATA SECURITY
We employ appropriate technical and organizational security measures to help protect your personal data against loss and to guard against access by unauthorized persons. Appropriate security measures we have taken include implementing secure private connections, traceability, disaster recovery and access limitations.
9. OTHER
We would like the chance to resolve any complaints you have, however you also have the right to complain to the UK data protection regulator (the “ICO”) about how we have used your personal data. Their website is https://ico.org.uk/your-data-matters/raising-concerns/.
This Privacy Policy will regularly be updated to align with our business operations and to comply with applicable UK laws. This version was last updated on 7 January 2022.
10. CONTACT INFORMATION
The Site is operated by Vitamin Well Ltd located at 3rd Floor, 8-10 Charterhouse Buildings, London EC1M 7AN, UK.
Registered in England and Wales. Company no: 10821384. VAT no: 285398941.
If you have any questions relating to our handling of your personal data or our use of cookies or if you would like to invoke any of your rights under applicable privacy legislation, please contact us at: dpo@vitaminwell.com.
Alternatively, you can contact us at the postal address mentioned above.
11. COOKIE AUDIT
This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website and to carry out advertising for our products. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary Cookies
These cookies are essential for you to browse the Site and use its features, such as accessing secure areas of the Site. Cookies that allow our Site to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
Advertisement Cookies
These cookies track your online activity to help us and our advertisers deliver more relevant advertising or to limit how many times you see an ad. These cookies may be set through our Site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
Analytics Cookies
Analytics Cookies — Also known as “performance cookies,” these cookies collect information about how you use our Site, like which pages you visited and which links you clicked on. None of this information can be used to identify you. It is all aggregated and, therefore, anonymized. Their sole purpose is to improve website functions and if you do not allow these cookies we will not know when you have visited our Site, and will not be able to monitor its performance.
Functional
Functional cookies — Also known as “Preference Cookies,” these cookies allow the Site to remember choices you have made in the past, like what language you prefer, or what your user name and password are so you can automatically log in (if we provide a log in function). They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.