Last Updated: November 2022
What personal information do we collect?
In order to process customer requests, those of the manufacturer and for legal reasons, we collect personal data. This data can include the following:
- Phone number
- Date of Birth
- Email address
- Vehicle information (including registration, VIN, service reminders, mileage and warranty repair information
- The date and time you used our services
- The pages you visited on our website and how long you visited us for
- Your IP address
- The internet browser and devices you are using
- Cookies and any other data cookies may track
- The website address from which you accessed our website
- Details of any transactions between you and us
- Where you engage with us in a business context, we may collect your job title, company contact details (including email address), fleet size, and company details.
- Any information within correspondence you send us
The way we use it
There are various ways in which we may use or process your personal information as either a data controller or processor. We list these below.
Where you have provided consent, we may use and process your information to:
- Contact you occasionally about, promotions, events, products, services or information which we think may be of interest and relevant to you
- Provide information to our Franchise Partners
- Provide your personal information with a very small number of third party partners. The information that is shared is very limited, and very occasional. You can request the details regarding this, and why it is used. You can remove your consent by unsubscribing to any of the messages received, or by contacting us. We assume that consent has been given when you have responded in person, via telephone, email or website form by positively selecting your contact preferences.
- Your email address will help us support your shopping experience throughout the site such as abandoned cart reminders and offers applicable to your previous purchases.
In order to perform a contract with you we may use your personal information. This will enable the contract to be fulfilled.
- Contact for the purposes of advising of a vehicle lease concluding and advising the customer of his/her options.
- Contact for the purposes of a finance Hire Purchase agreement concluding.
- Contact for the purposes of an ‘Options’ or similar PCP agreement concluding and advising the customer of his/her options.
- Service maintenance, whereby occupant and/or vehicle safety or warranty may be adversely affected
- Interval or safety checks, whereby occupant and/or vehicle safety or warranty may be adversely affected
- MOT test reminders, where applicable to the vehicle, a legal requirement.
- Extended maintenance, whereby occupant and/or vehicle safety or warranty may be adversely affected.
- Recalls and Field Service Actions, where vehicle safety may be affected
- Follow up reminders for any work which has been identified as being necessary
It is the policy of P J Nicholls Ltd, that customer contact is made for the purposes of advice opposed to the marketing of products unless specified by the customer.
We may use your data to contact you when it is everyone’s interest, the most obvious reason is a safety notice or product recall.
How we keep your data secure
Our routers are protected by Firewalls, as well as any servers. Any server which is off site is subject to the same level of security, and the security policy must be in line with our own. PCs etc are password protected, as are the email system – both of which have password change requirements to ensure up to date logins. Our Dealer Management System is password protected, and access level is set dependent on the role of the member of staff. Any information sent to our selected 3rd parties is secured, and their own policies must be aligned to our own. We do not allow for any customer information to be left unattended in customer accessible areas. We have in place a confidential shredding procedure, from which we obtain certificates of destruction to allow for a transparent audit trail.
Our CMS is also password protected with 2-factor authentication setup for senior admins.
How long do we keep your information for?
The length of time we keep your information is determined by the relationship you have with us. We are bound by legal reason to keep data for certain periods of time. If you enter in to a contract with us then we will keep your data for at least 6 years. We carry out a data cleanse periodically to keep the information we hold up to date and valid. Example exceptions to this are where you have requested for your data to be deleted, or have opted in for further marketing information, or you have raised a complaint or concern about a product or service we have provided.
Who do we share your information with?
Once you have entered in to contract with us, then certain parts of your information are shared. In the main this is to facilitate the contract, for example registering a vehicle, or logging a service with the manufacturer. A limited amount of data is shared with a very small number of 3rd parties, an example of this is for follow up reminders for safety related items, or customer service questionnaires to continually monitor and improve our levels or customer service.
You can withdraw your consent or choose to have your data erased at anytime.
As per ICO guidelines, the policy we have ensures that data has been erased within one calendar month, however it is in anticipated that this will typically be dealt with within a 5 working day period. This is dependent on there being no ongoing lawful reason why we must retain your information. You can object to the use of your information where we rely on legitimate interest to process it, again dependent on us not requiring your information for ongoing legal reasons.
Any information or data we hold can be updated or amended at anytime. We can process these requests provided we can confirm it is your information. You can request if we hold any information on you, and can request a copy if this is the case.
You can contact us via the following methods:
In writing to Data Office, P J Nicholls Ltd, The Motor House, Station Road, Pershore, Worcs WR10 2DJ, or email firstname.lastname@example.org
The data protection regulator for the UK is:
Information Commissioner’s Office
0303 123 1113