• Account
  • Account
    Country
    Language
    Select

    Privacy Policy

    1. INTRODUCTION

    Boardman is an award-winning bicycle brand, and renowned international bicycle manufacturer and retailer, leading the way in both design and function. We also manage the Boardman Performance Centre, which offers best-in-class services from industry specialists in physiological fitness, function and health, bike-fitting, positional biomechanics and aerodynamics.

    As an essential part of our business, we collect and manage customer data. In doing so, we observe UK data protection legislation, and are committed to protecting and respecting customers’ privacy and rights. Specifically, we act as “Data Controller” in respect of the information gathered and processed by this website.

    In order that you are reliably informed about how we operate, we have developed this Privacy Statement. Together with any additional Privacy Notices which you may see as you navigate around this website, this Privacy Statement describes the ways in which we collect, manage, process, store and share information about you as a result of you visiting this site. This Privacy Statement also provides you with information about how you can have control over our use of your data.

    If you have any comments or queries regarding our use of your data, please contact our Data Protection Officer by email at dataprotectionofficer@boardmanbikes.com or by post at Data Protection Officer, Boardman Bikes, Icknield Street Drive, Washford West, Redditch B98 0DE.

    Boardman is a subsidiary of the Halfords Group - a full list of Halfords’ companies is available at www.halfordscompany.com.


    2. WHAT INFORMATION DO WE COLLECT ABOUT YOU?

    In general terms, we seek to collect information about you so that we can:

    • manage bookings for our Performance Centre, which offers a range of services including physiology, biomechanics and aerodynamics;
    • fulfil orders that you may make in the Boardman store;
    • provide high-levels of customer care and support across our full range of products and services;
    • communicate with you effectively whether this is about your booking, or so that you don't miss out on great promotions, offers and helpful reminders.

    Most of the data that we need for these purposes is known as your “personal data”. This includes your name, home address and e-mail address. We collect this in a number of different ways. For example, you may provide this data to us directly when filling in forms on this website, or when corresponding with us by telephone, e-mail or letter.

    If you are booking a service with us, or making a purchase instore, we may also take your credit card details: however, we do not save this data on any of our systems.

    More specifically, if you are booking an appointment for the Performance Centre, we will also need to collect special categories of data (sensitive data) about you, specifically data about your health. Please be advised that we treat all such data with extra security, ensuring that only the minimum amount of data necessary is sought, and that only authorised individuals are able to access it. This security is additional to the technical controls that we routinely apply to all data, as described in section 6 below.

    Please also be advised that when you visit this website, cookies will be used to collect information about you such as your Internet Protocol (IP) address which connects your computer or mobile device to the internet, and information about your visit such as the pages you viewed or searched for, page response times, download errors etc. We do this so that we can measure our website’s performance and make improvements in the future. Cookies are also used to enhance this website’s functionality and personalisation, which includes sharing data with third party organisations. You can control this by adjusting your cookies settings as described in section 4 of our Cookies Policy here.


    3. HOW WILL WE USE THAT INFORMATION?

    We use the data collected from you for the specific purposes listed in the table below. Please note that this table also explains:

    • the lawful basis for processing your data, linked to each processing purpose;
    • in what circumstances your data will be shared with a third party organisation; and
    • for how long we keep your data.

    Data that is collected by cookies is not included in the table below, but is explained in section 3 of our Cookies Policy here.


    Purpose for processing data

    Lawful basis for processing data

    Third party organisations with whom data is shared

    Data retention period

    Performance Centre Bookings

    To administer a booking for a physiology, biomechanic and/or aerodynamic service from the Performance Centre

    To meet the requirements of contract law. However, given that we will also be collecting medical data, we will additionally seek explicit consent

    Customers’ demographic information will be held by Bluebox, who administers our website. Health data will be captured and retained by Smart Survey

    8 years from the end of a customer’s final transaction

    To validate a customer’s eligibility to participate in a requested service from the Performance Centre, based upon self-certification

    To meet the requirements of contract law. In some circumstances, customers will be asked to provide additional evidence of their medical history: this will be collected with explicit consent

    This information will be stored on our network to which no third parties have access

    However, if we had any concerns regarding a customer’s health which required additional advice and support from a medical professional, we would seek to exchange information with either Gebiomized and/or Bioracer: however, we would always provide the customer with further details before instigating any communication with these third parties, and seek their explicit consent

    8 years from the end of a customer’s final transaction

    To assess a customer’s eligibility to participate in a requested service from the Performance Centre, based upon tests or assessments conducted by our clinical team (i.e. blood tests)

    To meet the requirements of contract law. However, given that we will also be collecting medical data, we will additionally seek explicit consent

    This information will be stored on our network to which no third parties have access

    8 years from the end of a customer’s final transaction

    To capture and interpret data relating to a customer’s results from their chosen physiology, biomechanics and aerodynamics assessment(s): this may include photographic images which are routinely captured as part of the wind tunnel assessment

    To meet the requirements of contract law. However, given that we will also be collecting medical data, we will additionally seek explicit consent

    This information will be stored on our network to which no third parties have access

    8 years from the end of a customer’s final transaction

    To share data with customers via email relating to their physiology, biomechanics and aerodynamics assessment results

    To meet the requirements of contract law

    Email addresses are validated so as to ensure that data is delivered to the correct customer

    8 years from the end of a customer’s final transaction

    To share medical information with an appropriate authority where there are justifiable concerns or overriding reasons for doing so

    Data will be shared with a medical professional, without necessarily seeking a customer’s consent, where this is in the vital interests of the customer (i.e. life and death circumstances) or where there are legitimate concerns, for example safeguarding

    This information will be stored on our network to which no third parties have access. Additionally, data may be shared with a medical or social care professional where there are legitimate concerns

    8 years from the end of a customer’s final transaction

    To process credit / debit card payments online, including checks for fraud prevention purposes. Also, to communicate with you about your payment if there are any issues

    To meet the requirements of contract law

    Data will be shared with Worldpay, our payment acquirers. Data will also be shared with Mastercard who provide our online payment gateway. Alternatively, customers can choose to share their data with PayPal if they select this payment option

    Boardman does not record credit / debit card information: however, anonymised token data is retained for 6 years from the end of a customer’s final transaction

    To enable you to set up an online account

    This is deemed legitimate as it is in customers’ interest to set up an online account (if they choose) as this will provide a quicker, smoother experience, and enable them to easily manage their communication preferences

    By setting up an online account, customers’ details will be held by Bluebox who administers this website on our behalf, and Planning-Inc who manages our customer database

    8 years from the end of the final transaction

    Boardman Store Purchases

    To fulfil purchases and orders in the Boardman store

    To meet the requirements of contract law

    In order to fulfil a purchase or order, it may be necessary to share relevant information with third party organisations, such as suppliers and manufacturers. We use many different providers, and it is therefore not possible to list them all here

    Customer details will also be captured by Aptos who supports our till system, and Planning-Inc who manages our customer database. Order information is also saved within our SAP sales system

    6 years from the end of a customer’s final transaction or the end of the corresponding warranty period

    To process customer requests for finance instore (please note that this includes processing for the purposes of fraud prevention)

    Customers will be asked to provide informed consent before their data is processed for the purposes of applying for finance

    Finance will be arranged on request through V12 Retail Finance Limited

    6 years following expiry of the finance agreement

    To process credit / debit card payments instore including checks for fraud prevention purposes

    To meet the requirements of contract law

    Data will be shared with Worldpay, our payment acquirers. Data will also be shared with FIS Global who provide our instore payment gateway

    Boardman does not record credit / debit card information: however, anonymised token data is retained for 6 years from the end of a customer’s final transaction or end of the corresponding warranty period

    To process a request for an eReceipt

    Customer consent will be sought before an eReceipt is issued instore: this is separate to consent for marketing purposes

    If customers choose an eReceipt rather than a paper receipt, their data will be automatically shared with OneMarket, who manages the eReceipt service on our behalf

    2 years for the purposes of delivering and/or validating an eReceipt

    To communicate with you via email, SMS text or telephone in order to update you as necessary about your specific order or purchase, for example to confirm your order, or to notify you that a reservation is available instore

    To meet the requirements of contract law

    Sales activities will be recorded on Salesforce, our Customer Relationship Management System, which is supported by Brightgen, a Salesforce Platinum Partner

    6 years from the end of the final transaction or end of the corresponding warranty period

    After-sales Data Processing

    To provide customer services support by telephone, email or letter: this includes the recording of telephone conversations for monitoring and quality purposes

    This is deemed legitimate as it is in customers’ interest that we can access their data in order to resolve any queries, questions, concerns or complaints

    Customer services information will be recorded on Salesforce, our Customer Relationship Management System, which is supported by Brightgen, a Salesforce Platinum Partner. Additionally, the information will be shared with Planning-Inc who manages our customer database

    6 years from the end of the final transaction or end of the corresponding warranty period

    To communicate with you via email, SMS text or telephone in respect of a product recall or other safety information about a purchase which you have made from us

    This is deemed legitimate as it is in customers’ interest to be alerted about any safety issues which may affect a product which they have purchased

    Depending upon the nature of the recall or safety information, this may also help protect the vital interests of the customer concerned or another person

    Details will be held in Salesforce, our Customer Relationship Management System, which is supported by Brightgen, a Salesforce Platinum Partner. Information will also be held in our customer database which is managed on our behalf by Planning-Inc. Emails will be sent by MailChimp

    6 years from the end of the final transaction or end of the corresponding warranty period

    To send you emails reminding you about a service which forms part of your original purchase (i.e. a bike service plan)

    This is deemed legitimate as it is in customers’ interest to be reminded about services to which they are entitled under the terms of their original purchase from us

    Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Emails will be sent by MailChimp

    6 years from the end of the final transaction or end of the corresponding warranty period

    Data Processing For Marketing

    To send emails about special offers and promotions that are relevant to you, as well as helpful reminders: this includes, for example, emails about offers during peak periods (i.e. New Year, Black Friday), abandoned baskets, as well as products or services that you have asked us to tell you about. In some cases, this requires us to profile you as described more fully in section 5.8 below

    Customers will be asked for their consent before we send marketing communications

    Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Emails will be sent by MailChimp

    6 years from the end of the final transaction or end of the corresponding warranty period

    Other Data Processing

    To match data that we hold in order to acquire improved insight about our customers both individually and at aggregate level: this requires us to profile you as described more fully in section 5.8 below

    This is deemed legitimate as it is in customers’ interest that we understand their preferences and buying behaviours so that the information we provide, is tailored to them

    Customer details will be held in our customer database which is managed on our behalf by Planning-Inc. Additionally, we will use CoMetrics to improve our performance and impact

    6 years from the end of the final transaction or end of the corresponding warranty period

    4. OVERSEAS TRANSFERS

    None of the data that we collect, process or store about you is transferred outside the European Economic Area (EEA). This includes information that is exchanged with any third party organisation as described in section 3 of this Privacy Statement.


    5. YOUR RIGHTS

    Under the terms of data protection legislation, you have the following rights as a result of using this website:


    5.1. RIGHT TO BE INFORMED

    This Privacy Statement, together with our Cookies Policy, fulfils our obligation to tell you about the ways in which we use your information as a result of you using this website.


    5.2. RIGHT TO ACCESS

    You have the right to ask us, in writing, for a copy of any personal data that we hold about you. This is known as a “Subject Access Request”. Except in exceptional circumstances (which we would discuss and agree with you in advance), you can obtain this information at no cost. We will send you a copy of the information within 30 days of your request.

    To make a Subject Access Request, please write to our Data Protection Officer at Boardman Bikes, Icknield Street Drive, Washford West, Redditch B98 0DE.


    5.3. RIGHT TO RECTIFICATION

    If any of the information that we hold about you is inaccurate, you can either:

    • visit the “My Account” section of the website where you can make changes to some of the information that we hold about you;
    • contact our Data Protection Officer at dataprotectionofficer@boardmanbikes.com. Any corrections that you request will be made as soon as possible, and certainly no later than 30 days following your notification.

    5.4. RIGHT TO BE FORGOTTEN

    From 25 May 2018, you can ask that we erase all personal information that we hold about you. Where it is appropriate that we comply, your request will be fully actioned within 30 days. For further information, please contact our Data Protection Officer at dataprotectionofficer@boardmanbikes.com.


    5.5. RIGHT TO OBJECT

    You have the right to object to:

    • the continued use of your data for any purpose listed in section 3 of this Privacy Statement for which consent is identified as the lawful basis of processing (i.e. you have the right to withdraw your consent at any time);
    • the continued use of your data for any purpose listed in section 3 of this Privacy Statement for which the lawful basis of processing is that it has been deemed legitimate.

    In some circumstances (i.e. consent to marketing communications), you can exercise your objection by updating your preferences within the “My Account” section of this website. For all other circumstances, you can contact our Data Protection Officer at dataprotectionofficer@boardmanbikes.com.

    Please note that you can also exercise your right to object to our use of cookies by following the guidance in section 4 of our Cookies Policy here.


    5.6. RIGHT TO RESTRICT PROCESSING

    If you wish us to restrict the use of your data because (i) you think it is inaccurate but this will take time to validate, (ii) you believe our data processing is unlawful but you do not want your data erased, (iii) you want us to retain your data in order to establish, exercise or defend a legal claim, or (iv) you wish to object to the processing of your data, but we have yet to determine whether this is appropriate, please contact our Data Protection Officer at dataprotectionofficer@boardmanbikes.com.


    5.7. RIGHT TO DATA PORTABILITY

    If you would like us to move, copy or transfer the data that we hold about you to another organisation, please contact our Data Protection Officer at dataprotectionofficer@boardmanbikes.com.

    Please be advised that this only applies to certain data which has been submitted by you electronically for specific purposes only. Our Data Protection Officer can provide further advice.


    5.8. RIGHTS RELATED TO AUTOMATED DECISION-MAKING

    In order that we can understand your interests and preferences - and deliver communications that will be most of interest to you - we employ profiling techniques (which include automated decision-making) based upon the information that you have provided to us, as well as your purchasing history and engagement with us. We do not believe that these processes have any potential to significantly or negatively affect you i.e. they will not lead to any form of discrimination against you or impact your legal rights.

    Examples of how we use profiling are as follows:

    • if you repeatedly look at certain bike ranges on our website, we are more likely to send you information about these particular ranges;
    • if you do not engage or interact with special offer emails that we send you (even though you will have consented to receive these), we are likely to send you fewer emails than customers who are more actively involved with us.

    Where we hold a customer’s details, we will also seek to ensure that, as far as possible, we maintain a single composite record of their interactions with us, which may require us to match their different activities. Where customers have indicated that they do not want us to us their data for receiving communications (other than those deemed legitimate), we will use this information purely for anonymised internal analytics and reporting, for example, looking at sales trends which does not identify individual customers.

    If you do not want us to undertake this form of data processing, you may either:

    • object to the processing of your data (see section 5.5 of this Privacy Statement above); or
    • request that we erase all personal data about you (see section 5.4 of this Privacy Statement above).

    6. DATA PRIVACY AND SECURITY

    At Boardman, we maintain a comprehensive data management work programme, which includes processes for ensuring that data protection is a key consideration of all new and existing IT systems that hold customers’ personal data. Where any concerns, risks or issues are identified, we conduct relevant impact assessments in order to determine any actions that are necessary to ensure optimum privacy.

    We also maintain an active information security work programme which seeks to protect the availability, confidentiality and integrity of all physical and information assets. Specifically, this helps us to:

    • protect against potential breaches of confidentiality;
    • ensure all IT facilities are protected against damage, loss or misuse;
    • increase awareness and understanding of the requirements of information security, and the responsibility of our colleagues to protect the confidentiality and integrity of the information that they handle; and
    • ensure the optimum security of this website.

    We recognise that the security of data and transactions on this website is of primary importance. We therefore ensure that all connections to secure parts of the website (such as when you login) are encrypted and authenticated using strong protocols, key exchanges and ciphers.


    7. CARD PAYMENT SECURITY

    We are proud to have been awarded the Payment Card Industry Data Security Standard (PCI-DSS), which recognises the robust processes that we apply when handling card transactions from the major card schemes. This independent certification gives our customers assurance that our transactional systems protect your data with appropriate levels of security.


    8. LOCATION TRACKING

    This website only uses geo-location tracking, which shows us where you are in the UK, for specific situations. These include:

    • click and collect: on the product pages, you can check the availability of any selected item in your local store;
    • retailer locator: you can search for your local retailer using your current location.

    In both situations, your permission will be sought before geo-tracking is used, and then, it is only used to personalise your experience.

    This service is supported by Google Maps. Users are bound by the Google Maps / Google Earth Additional Terms of Service (https://maps.google.com/help/terms_maps.html) which includes the Google Privacy Policy (https://www.google.com/intl/ALL/policies/privacy/index.html).


    9. DISCLAIMERS

    Every effort is made to ensure that the information provided on this website, and in this Privacy Statement, is accurate and up-to-date, but no legal responsibility is accepted for any errors or omissions contained herein.

    We cannot accept liability for the use made by you of the information on this website or in this Privacy Statement, nor do we warrant that the supply of the information will be uninterrupted. All material accessed or downloaded from this website is obtained at your own risk. It is your responsibility to use appropriate anti-virus software.

    This Privacy Statement applies solely to the data collected by us, and therefore does not also apply to data collected by third party websites and services that are not under our control. Furthermore, we cannot be held responsible for the Privacy Statements on third party websites, and we advise users to read these carefully before registering any personal data.


    10. ACCESSIBILITY

    We are committed to providing a website in which content is accessible to everyone. We therefore update our website regularly in order to make it as adaptable as possible.

    For example, users can control the text size of each page within their browser. On a PC, holding the “Ctrl” key while pressing the “+” (plus) key will increase text size, and holding the “Ctrl” key while pressing the “-“ (minus) key will decrease the text size.


    11. GENERAL

    Questions and comments regarding this Privacy Statement are welcomed, and should be sent to our Data Protection Officer at dataprotectionofficer@boardmanbikes.com

    You can also contact our Data Protection Officer if you have any concerns or complaints about the ways in which your personal data has been handled as a result of you using this website.

    Alternatively, you have the right to lodge a complaint with the Information Commissioner’s Office who may be contacted at Wycliffe House, Water Lane, Wilmslow SK9 5AF or https://ico.org.uk.