Who are Lyreco?
Lyreco is the exclusive distributor of Nespresso Professional coffee solutions for the office environment in the UK & Ireland*.
* Excluding London & South East England with the following postcodes: AL1-AL10, BN1-BN99, BR1-BR8, CB1-CB25, CM1-CM77, CR0-CR9, CT1-CT21, DA1-DA18, E1-9, EC1-EC4Y, EN1-EN11, GU1-GU52, GY1-GY9, HA0-HA9, HP1-HP27, IG1-IG11, JE1-JE4, KT1-KT24, LU1-LU7, ME1-ME20, MK1-MK46, N1-N22, NW1-NW11, OX1-OX49, PO1-PO41, RG1-45, RH1-RH20, RM1-RM20, SE1-SE28, SG1-SG19, SL0-SL9, SM1-SM7, SO14-SO53, SS0-SS17, SW1-SW20, TN1-TN40, TW1-TW20, UB1-UB11, W1-W9, WC1-WC2R, WD3-WD25.
Lyreco Data Privacy Policy
At Lyreco, we believe privacy is important. That’s why we have established a comprehensive privacy program, including a global privacy office and a chief privacy officer, designed to help us protect privacy rights.
To protect your privacy, Lyreco will ensure all Personal Data is handled in a secure way and used only as outlined in the sections below. This privacy policy informs you what Personal Data we collect, how we use it and the measures we take to keep it safe.
This policy is our commitment to privacy concerning the processing of Personal Data related to Customers. (hereinafter referred as “Privacy Policy”)
In this Privacy Policy, “you”, “yours”, refer to the Customer whose customer Personal Data are processed by or on behalf of Lyreco and “we”, “our”, “us”, refer to Lyreco.
Lyreco UK Limited, a company incorporated in England and Wales under number 00442696 whose registered office is at LYRECO Deer Park Court, Donnington Wood, Telford, Shropshire TF2 7NB and all its Affiliated Companies (hereinafter referred as “Lyreco”) – is a company specialised in workplace solutions, including notably office supplies, personal protective equipment and packaging distribution. Lyreco is exclusively supplying to other companies in business-to-business relationships.
1. Definitions
1.1 “Affiliated Companies” means any companies being controlled by, or under common control with Lyreco and any companies, which, either directly or indirectly, control Lyreco.
1.2 “Applicable Data Protection Law(s)” means the relevant local personal data protection, data security, data retention, and data privacy laws and regulations to which the Personal Data are subject, including the GDPR.
1.3 “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
1.4 “Customer” means the natural or legal person, public authority, agency or other body which is receiving a Service from Lyreco.
1.5 “Customer Data Subjects” means any employee, consultant, agent, or any other authorised natural person placing a purchase order towards Lyreco on behalf of the Customer.
1.6 “Customer Personal Data” means Personal Data of the Customer Data Subjects processed by Lyreco as a Controller while supplying its Services to the Customer.
1.7 “General Data Protection Regulation” or “GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
1.8 “Personal Data” means any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
1.9 “process,” “processes,” “processing,” and “processed” means any operation or set of operations which is performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.10 “Service” means the supply and sale of products and all associated services proposed globally or at local level by Lyreco.
1.11 “Third Party(ies)” means Lyreco authorised auditors, accountants, contractors, agents, and third party service providers that process Personal Data.
2. Scope
2.1 This Privacy Policy only applies to Customer Personal Data processed by or on behalf of Lyreco.
2.2 Lyreco processes Personal Data fairly and lawfully in accordance with Applicable Data Protection Laws.
2.3 In the event of any conflict between this Privacy Policy and Applicable Data Protection Laws, the provisions of Applicable Data Protection Laws shall prevail.
2.4 Our nominated data protection contact is John Mason who may be contacted at uk.gdpr@lyreco.com.
3. What Personal Data do we collect and use?
In the course of supplying its Services to Customers, Lyreco will need to process Customer Personal Data. Indeed the Customer Data Subjects are the sole end-users of the Lyreco’s website acting on behalf of the Customers, which are in business relationships with Lyreco. The Customer Personal Data to be processed through the website is primarily the Personal Data required in order for Lyreco to be able to supply the Services to the Customers, that is to say mainly to place and follow-up a purchase order placed on the website.
4. Lyreco processes the following categories of Customer Personal Data:
4.1 Your name, telephone number and email address
4.2 Company name, ID number and address
4.3 Credit card information
4.4 Location information (i.e.: IP address)
4.5 For the avoidance of doubt, mandatory information required in online forms are identified by an asterix field.
5. What do we use that information for?
The GDPR allows us to process Personal Data, so long as we have a basis or “ground” under the law to do so. It also requires us to tell you what those grounds are. As a result, when we process your Personal Data we will rely on one of the following processing conditions:
5.1 Performance of a contract: this is when the processing of your personal information is necessary to perform our obligations under a contract;
5.2 Legal obligation: this is when we are required to process your personal information to comply with a legal obligation, such as keeping records for tax purposes or providing information to a public body or law enforcement agency;
5.3 Legitimate interests: we will process information about you where it is in our legitimate interest in running a lawful business to do so to further that business, provided that your right to privacy does not outweigh such interest;
5.4 Your consent. In some cases, we will ask you for specific permission to process some of your personal information, and we will only process your Personal Data in this way if you agree to us doing so. This will be the case when we ask you if you wish to receive a newsletter, or information about our products or services. You may withdraw your consent at any time by contacting us according to the section below in this document.
6. Your Personal Data are used by Lyreco to:
6. 1 Create a Customer Account on our website;
6.2 Answer Customer’s enquiries;
6.3 Perform Customer management operations regarding orders, deliveries, invoices, accounting (management of accounts receivable);
6.4 Conduct marketing campaigns and inform Customers about our products and services;
6.5 Monitor our relationship with our Customers, conduct Customer satisfaction surveys and conduct sales statistics;
6.6 Manage unpaid invoices recovery and disputes with our Customers;
6.7 Monitor Customer’s experience on our website.
6.8 We also use Cookies in order to enhance your customer experience on our website, please refer to the cookie policy section below in this document.
7. For How long do we keep your Personal Data?
We will keep your Personal Data during the term of our commercial relationship and up to 3 years after your last contact or order with Lyreco, unless applicable legislation prevents us from doing so, notably for archiving purposes. For example, Customer Personal Data mentioned in our invoices will be kept for a longer period, in accordance with any applicable law and regulations from time to time.
8. With whom do we share your information?
8.1 Your Personal Data are accessed and processed by authorised members of the commercial, financial and support departments of Lyreco, for the purposes described above.
8.2 Lyreco do not share Personal Data with unaffiliated third parties, except as necessary for its legitimate professional and business needs, to carry out your requests, and/or as required or permitted by law. This would include:
8.2.1 Third Party Providers Lyreco may grant access to Customer Personal Data:
8.2.2 To its service providers or contractors:
8.2.3 Lyreco transfer Personal Data to its third party service providers, such as (IT) systems providers, hosting providers, consultants and other goods and services providers or contractors. Lyreco work with such providers so that they can process your Personal Data on its behalf. Lyreco will only transfer Personal Data to them when they meet Lyreco strict standards on the processing of data and security. Lyreco only share Personal Data in order to provide its Services to Customers.
8.2.4 When you enter into transactions with others or make payments on Lyreco’s website, Lyreco will share transaction information with those third parties necessary to complete the transaction. We will require those third parties to respect your privacy, and adequately protect your Personal Data.
8.2.5 Courts, tribunals, law enforcement or regulatory bodies: Lyreco reserves the right to share your information to respond to duly authorised information requests of governmental authorities or where required by law. In exceptionally rare circumstances where national, state or company security is at issue (such as terrorist attacks), Lyreco reserves the right to share our entire database of Customers and Customer Personal Data with appropriate governmental authorities.
8.2.6 Internal auditors, professional accountants, legal advisers may access to documents, such as invoices, which contain Customer Personal Data, for the purpose of their mission.
8.2.7 Lyreco may transfer your Personal Data to a potential buyer, transferee, merger partner or seller and their advisers in connection with an actual or potential transfer or merger of part or all of Lyreco’s business or assets, or any associated rights or interests, or to acquire a business or enter into a merger with it.
8.2.8 Lyreco never sells your Personal Data to third parties, such as marketers.
Lyreco do not provide any Personal Data to “people finder,” “public directory” or “white pages” sites.
9. What about the localisation and transfer of your Personal Data?
Lyreco transmits your Personal Data only within countries of the European Economic Area (EEA) and/or to countries that provide adequate protection as confirmed by the European Commission except under the conditions below. If the processing involves a transfer of your Personal Data to a country outside the European Union and which does not provide adequate protection as confirmed by the European Commission, Lyreco undertakes to secure the transfer by one of the following mechanisms:
9.1 Standard Contractual Clauses approved by the European Commission (such as Standard Contractual Clauses for Data Controllers 2004/915/EC or Standard Contractual Clauses for Data Processors 2010/87/EU or any subsequent version);
9.2 Binding Corporate Rules: in case the Third Parties concerned have adopted EU Binding Corporate Rules that cover the Personal Data that Third Parties Process.
9.3 Any other mechanism officially recognized by Applicable Data Protection Laws as ensuring an adequate level of protection of Personal Data.
9.4 Lyreco processes and shall cause Third Parties to process Personal Data in adequate jurisdictions as defined in Applicable Data Protection Law(s). These jurisdictions include countries of the European Economic Area and countries recognized as providing an adequate level of protection by the European Commission (For more information, see European Commission, “Commission Decisions on the Adequacy of the Protection of Personal Data in Third Countries”).
10. How do we secure the processing of your Personal Data?
Lyreco implements commercially reasonable technical and organisational security controls to protect your Personal Data against theft, loss or misuse. Your Personal Data will be stored in a secure operating environment that is not accessible without authorisation. Lyreco applies mitigation measures following periodic risk assessments to ensure an adequate level of protection of your Personal Data.
10.1 When you enter sensitive information (such as credit card numbers and passwords):
10.1.1 We encrypt that information to protect against eavesdropping using SSL.
10.1.2 This data is further protected by encryption in storage.
10.1.3 We also use measures to enhance security, such as analyzing account behavior for fraudulent or otherwise anomalous behaviour.
10.1.4 We may limit use of site features in response to possible signs of abuse, may remove inappropriate content or links to illegal content, and may suspend or disable accounts for violations of our terms and conditions.
11. What are your rights concerning our processing(s) of your Personal Data?
You have the following rights concerning the processing(s) of your Personal Data made by or on behalf of Lyreco:
11.1 Access
In addition to the information that is available on Lyreco’s website, you have the right to access the Personal Data that Lyreco holds about you, all subject to the exemptions as contained in Applicable Data Protection Laws. If you request the data, then Lyreco will assist you. Your identity will need to be confirmed before you are provided with access to your Personal Data. Generally, Lyreco does not charge for providing information, but if the request is manifestly unfounded or excessive, in particular, because of their repetitive character, Lyreco reserves the right to charge a fee for such requests.
We ask you to submit your request in writing. An access request form is available on Lyreco’s website and in all locations for you to fill out. If you choose to write a letter rather than fill out a form, please include the following:
- Your full mailing address
- Your daytime telephone number
- Names of specific files or types of records to which you request access, including specific dates of those records, where possible
- Please provide as much detail as possible.
- All formal access requests will be directed to the data privacy officer, who will then review each request to determine whether Lyreco will disclose the requested information. The data privacy officer can be reached at the directly at the following address: uk.gdpr@lyreco.com.
12. Modification
If you believe there is a mistake in your Personal Data, you have a right to ask for the information to be corrected. We may ask you to provide documentation to show where Lyreco’s files are incorrect. We will amend the erroneous data within a month and will notify you once the correction you have requested has been completed. GDPR provides you with the right to request correction of your Personal Data held by Lyreco if you believe there is an error or omission. You are entitled to attach a statement of disagreement with the information, reflecting any correction you requested, but which was not made by Lyreco. Lyreco will notify any person or organization to which your Personal Data was disclosed within the year as from your requested correction and advise them about the correction or statement of disagreement.
13. Portability
You may obtain and reuse the Personal Data held by Lyreco for your own purposes across different services. Lyreco allows you to move, copy or transfer Personal Data easily from one IT environment to another in a safe and secure way, without hindrance to usability. This right applies to your Personal Data held by Lyreco, where the processing was automated and used in the light of Lyreco Services provision within the contract the Customer has with Lyreco, or where such processing was based on the consent you gave Lyreco for it. You may Log in to Lyreco’s online web portal and download the information provided in the “Export” section of the portal.
14. Deletion
Lyreco does not store Personal Data without a predefined and documented purpose. We follow laws that require us to delete Personal Data if the reason for its collection and storage no longer exists. We believe this fulfills the requirements of the privacy principle of “the right to be forgotten”.
Where the Personal Data that Lyreco holds is based on the execution of a contract, and you wish to be removed from our systems prior to the retention period indicated in the “How Long Do We Use Personal Data” section, please contact our Data Privacy point of contact at the following address: uk.gdpr@lyreco.com.
If you have registered your personal details with us, you can deactivate your account at any time. For safety reasons, we have implemented a seven-day grace period after your request for the account to be deleted; however, logging on to your account during the grace period will reactivate the account. To prevent impersonation, once your account is deactivated and after expiration of the grace period, your account will be irrevocably suspended, ensuring that nobody can use that account identifier again.
15. Object to processing
You have the right to object to us processing your Personal Data if we are not entitled to use it any more. In this case, Lyreco shall no longer process the Personal Data unless Lyreco demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms of the or for the establishment, exercise or defense of legal claims.
16. How can you contact, raise questions and/or complaints to Lyreco?
To exercise your rights, express a concern, raise a question, make a complaint, or to obtain additional information about the processing of your Personal Data by Lyreco, you may send an e-mail to the following address: uk.gdpr@lyreco.com or contact Lyreco customer support accompanied by a valid proof of ID.
Lyreco undertakes to respond to your request within one month and up to 3 months depending on the complexity of the request and/or of the number of requests received by the company.
In case of dispute, you may lodge a complaint with the Information Commissioners Office.
How do we update/amend this Privacy Policy?
17. Lyreco may occasionally update or modify this Privacy Policy.
Lyreco will notify you by placing a prominent notice on the home page of its website or, if legally required, by directly sending you a notification. Lyreco encourages you to periodically review this Privacy Policy to stay informed about how Lyreco is helping to protect the Customer Personal Data collected. Your continued use of the Lyreco Services constitutes your agreement to this Privacy Policy and any updates.
18. What is our Cookie Policy?
18.1 Definition:
Cookies, or other similar trackers, are files used by a server to interact with the browser (herein referred as “Cookies”). Cookies are used to send status information when a user visits a site. Status information can be, for example, a session ID, language, expiration date, response domain, and so on. Cookies make it possible to store status information during their validity period when a browser accesses the various pages of a website or when this browser returns to the said site later.
18.2 Retention:
There are different types of Cookies used by Lyreco:
18.2.1 Session cookies that disappear as soon as you leave the browser or the site;
18.2.2. Permanent cookies such as analytic cookies that remain on your device until they expire (up to 13 months) or until you delete them using your browser’s features.
18.3 What about Google Analytics cookies and usage on our website?
Lyreco uses Google Analytics. More information about how Google Analytics is used by Lyreco can be found here: Google Analytics Privacy
To provide website visitors with more choice on how their data is collected by Google Analytics, Google have developed the Google Analytics Opt-out Browser Add-on. The add-on communicates with the Google Analytics JavaScript (ga.js) to indicate that information about the website visit should not be sent to Google Analytics. The Google Analytics Opt-out Browser Add-on does not prevent information from being sent to the website itself or to other web analytics services.