Russums is committed to ensuring the security of your information. To prevent unauthorised access, maintain data accuracy and ensure the appropriate use of information, we have put in place appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect.
Russums provides this online privacy statement to make you aware of our privacy policy and practices and of the choices you can make about the way your personal data* is collected and used. To make this notice easy to find, we make it available on our homepage.
*Personal data means any information that may be used to identify an individual. This includes (although is not limited to) names, addresses, email addresses or other contact information.
You may provide us with personal data on an order form, online or over the telephone. This may include your name, address, email, telephone number and payment instructions. We use this information in order to manage your orders and purchase activity. We may also keep information contained in any correspondence with us, for example by email or post.
This provision of personal data is essential for us to be able to administer your account, for example to collect payments for your purchases and verify your identity when you contact us.
When you use our websites, we may collect, store and use the following kinds of data:
Russums would like to emphasise that information of this nature is used only to enhance the customer shopping experience of the website.
Personal data submitted to us will be used (by Russums as the controller and processor) for the purposes specified in this section or as found elsewhere in the relevant parts of the website. We may use your personal information to:
Russums use SSL-128bit encryption Secure Server Technology to ensure that all of your personal and transactional information is protected to the highest standards. We never make your personal details available to companies other than Russums for marketing purposes (see also ‘Third Parties’). ‘E Russum & Sons Ltd’ is registered with the Information Commissioners Office as a Data Controller. We will comply with the standard, procedures and requirements as laid down in the General Data Protection Regulation 2018 and Data Protection Acts 1984 and 1998 to ensure that your personal data is kept secure and processed lawfully. Our full Data Protection policy can be found below.
When you enter this website we will use cookies. Cookies are tiny text files that identify your computer to our server. These cookies in no way allow us access to your computer and do not store any details relating to you or your credit cards. They are used to record the areas of the site that you have visited and for how long, which provides us with useful usage information that helps us make our site more accessible to our customers in line with their needs. You may also see Russums adverts and content on other websites. For these adverts, our third party providers may use cookies so that Russums can monitor whether you see the adverts, click on them and buy from our website. Cookies are placed on your computer if your browser is set to allow these. If you wish to 'turn off' cookies, then please check your browser's help files for guidance on how to do so. The Help section is usually found in the Menu bar at the top of the browser. Some browsers provide help if the F1 key is pressed. However, you may lose some of the functionality of this website.
With your consent, we would like to keep you up to date with key information about new ranges, promotional offers and what's coming soon to the Russums website. We may also use your details to send you information about other goods and services we sell or for our research purposes. If you have registered to receive email newsletters from us, you can remove your email address from our list by using the 'unsubscribe' links in the emails we send you.
The UK Data Protection Act and consumer legislation requires that we do not release your personal information to any external company for mailing or marketing purposes unless we have your prior approval. We will only disclose your information with other third parties with your express consent with the exception of the following categories of third parties:
(for example DPD and Royal Mail)
(for example Feefo)
We do not currently transfer your personal data outside the EEA. In accordance with the terms of this Policy, if in the future we transfer your personal data outside of the EEA we will make sure that the receiver agrees to provide the same or similar protection as we do and that they will only use your personal data in accordance with our instructions.
Retention periods are in line with the length of time we need to keep personal data information in order to manage and administer your account. This may include any claims or requests for assistance made to us and takes into account our need to meet any legal, statutory and regulatory obligations. Our need to use your personal data information will be reassessed on a regular basis; information no longer required will be disposed of.
Within our site there are links to third party websites which we feel may be relevant and interesting to our customers. Following these links will take you to external websites which Russums do not have any control over. For this reason we cannot be held responsible or liable for any content on these sites.
Russums accepts major credit and debit cards, including Visa and MasterCard, through our payment service provider SagePay. All credit card details are secured with 128bit encrypted sessions and all sensitive information is stored on a heavily encrypted database that is protected by multiple government approved firewalls.
The General Data Protection Regulation (GDPR) grants you (the "data subject") the right to access particular personal data held about you. This is known as a ‘subject access request’. We shall respond promptly, certainly within one month from the point of receiving the request and any necessary information from you. Our formal response shall include details of the personal data we hold about you, including the purpose for processing the personal data and the person or entity we may be sharing the information with.
The data subject has the right to obtain the rectification of inaccurate personal data we may hold concerning them, without undue delay. The data subject has the right to have incomplete personal data completed, taking into account the purposes of the processing.
The data subject has the right to obtain the erasure of personal data concerning them in certain circumstances (for example where the data held is no longer required for the purposes for which it was collected), without undue delay. (Please note that this may affect future product warranty rights if we are not able to verify the authenticity of a possible future claim).
The data subject has the right to obtain restriction of processing where one of the following applies:
(and personal data is restricted until the accuracy has been verified)
We shall communicate any rectification, erasure or restriction of processing of personal data (as described above) to each recipient to whom the personal data has been disclosed, unless this proves impossible or requests are manifestly unfounded or excessive. The data subject shall be provided with information about these recipients if they request it.
The data subject has the right to receive the personal data they have provided to us in a machine-readable format (for example CSV) and can request the transfer of this data to another controller.
The data subject has the right to object, on grounds relating to their particular situation, to the processing of their personal data including any personal profiling, unless the processing is necessary for the performance of a task carried out in the public interest or exercise of official authority vested in us. There must be demonstrable compelling legitimate grounds to override the interests, rights and freedoms of the data subject, or for the establishment / exercise / defence of potential legal claims.
The data subject has the right not to be subject to automated processing based on their personal data and be able to obtain human intervention, express their point of view, obtain an explanation of the decision and challenge it.
Please contact us at gdpr@russums.co.uk or write to us at Russums, Edward House, Tenter Street, Rotherham, S60 1LB if you would like to invoke any of the data subject rights with us.
Please help us to maintain accurate records by informing us if changes occur, for example with names and addresses. We need to keep accurate personal data in order to provide a high level of customer service and reasonable steps are taken to ensure the accuracy of any personal data or sensitive information obtained. The source of any personal data or sensitive information should be clear and any challenges to the accuracy of the information will be carefully considered.
If you have any complaints regarding the use of your personal data, please email gdpr@russums.co.uk and we will try to resolve the issue. If you are unsatisfied with the outcome of your complaint, you can make a formal complaint to the Information Commissioner’s Office (ICO) by phone on 01625 545745 or 0303 123 1113.
We reserve the right, at all times, to update, modify or amend our Policies. Please check and review this Privacy and Cookies Policy from time to time to ensure you are aware of any changes we may have made.
The General Data Protection Regulation (GDPR), effective
This policy document has been produced to inform individuals about the data that Russums processes and on which grounds. Through this, we aim to eliminate doubt regarding safety of personal details and to show our commitment to GDPR compliancy.
Russums will continue to follow industry-standard procedures to maintain the privacy and security of your data. Where necessary, we have been actively assessing and improving our procedures in data processing to eliminate excess data handling, as well as considering privacy for each aspect of processing.
If you have any questions regarding the information in this policy please email gdpr@russums.co.uk
The regulation provides individuals further rights regarding the use of their personal data. Full descriptions of the data subject rights can be found in our privacy policy. The following definitions are quoted from article 4 of the GDPR and may aid in the understanding of the data subject rights and the sections below:
Personal Data – “information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”
Processing – “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction”
Restriction of processing – “the marking of stored personal data with the aim of limiting their processing in the future”
Profiling – “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements”
Pseudonymisation – “the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person”
Controller – “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law”
Processor – “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller”
Recipient – “a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with
Third party – “a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data”
Consent – “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”
The following processes are carried out on the basis of legitimate business interest:
The above processing procedures are carried out under the following legal bases: performance of contract, legitimate business interest, consent, and legal obligation.
We reserve the right, at all times, to update, modify or amend our Policies. Please check and review this Data Protection Policy from time to time to ensure you are aware of any changes we may have made.