Last Updated June 2024
Choosing to shop with REISS means you've placed a great deal of trust in us. In sharing your personal Information we hope you in return benefit from a tailored and convenient shopping experience. With trust comes responsibility and we take this responsibility very seriously.
This privacy policy helps you to understand how we use your personal data and who we share it with. It applies if you shop on a REISS website, use the REISS app, shop in a REISS store, contact our customer contact centre or if you have indicated you are happy to receive marketing and other communications from us.
We change the terms of this privacy policy from time to time and you should check it regularly. The last updated date is shown at the beginning of the document. If we make any material changes we will take steps to bring it to your attention.
NEXT and REISS are joint data controllers of your data which means we are jointly responsible for deciding how and why your personal data is used. We're both also responsible for making sure it is kept safe, secure and handled legally when we are processing it. We operate to the highest standards when protecting your personal data and respecting your privacy.
when we say "we", "our" or "us" in this policy we are referring to the companies that make up the NEXT Group.
We sometimes work with other organisations in connection with some of the processing activities described in this privacy policy, such as social media platforms. Where that data is collected and sent to other organisations for processing that is for a common purpose, we will be making decisions together in relation to that particular processing and will be ‘joint data controllers’ with the organisations involved. As joint data controllers, we and the other organisations involved in making these decisions will be jointly responsible to you under data protection laws for this processing.
If you have any questions about your personal data, or how we use it, you can contact our Data Protection Officer via email at dataprotection@next.co.uk or by writing to our registered offices below:
UK registered address: Data Protection Officer, NEXT Retail Limited, Desford Road, Enderby, Leicester, LE19 4AT.
EU registered address: Data Protection Officer, NEXT Retail (Ireland) Ltd, 13-18 City Quay, Dublin 2, D02 ED70, Ireland.
You have a number of "Data Subject Rights", we have explained below what they are and how you can exercise them. You can read more about these rights on the Information Commissioner's Office website at www.ico.org.uk/for-the-public, or on your local Data Protection Authority website.
The above rights may be limited in some circumstances, for example: if fulfilling your request would reveal personal data about another person; if you ask us to delete data which we are required to have by law; or if we have compelling legitimate interests to keep it. We will let you know if that is the case and will then only use your data for these purposes. You may also be unable to continue using our services if you want us to stop processing your personal data.
If you have any general questions or want to exercise any of your rights, please see the "how you can get in touch" section of this privacy policy. In order to maintain the security of our customers' personal details, we may need to request proof of identity before we disclose personal data to you in response to any request.
We encourage you to get in touch if you have any concerns with how we collect or use your personal data. You have the right to lodge a complaint directly with a Data Protection Authority. The Data Protection Authority in the UK, where we are based, is the Information Commissioner's Office (ICO), you can contact the ICO here:www.ico.org.uk/make-a-complaint. Our main supervisory authority in the EU is the Data Protection Commission (DPC) based in the Republic of Ireland, you can contact the DPC here: forms.dataprotection.ie/contact.
We will only ever process your data if we have a lawful basis to do so. The lawful bases we rely on are:
We collect and use the data that you provide to us directly, for example; when you register for an account; we use cookies and other similar technologies to collect data from your devices when you interact with our advertising or use our website (you can find out more information in the "Cookie Policy" section below); we keep records when you speak to our customer service teams; we take personal data from a number of third parties to help us manage your account and improve your shopping experience.
To process any orders that you place with us and to facilitate any returns (Lawful basis: Contract)
To provide you with access to an account (Lawful basis: Contract)
To provide customer service to you (Lawful basis: Legitimate Interest in providing customer support/Contract)
To offer and manage any credit we provide to you ( Lawful basis: Contract/Legitimate Interest in ensuring product suitability and managing debts)
To personalise and improve your experience when you shop (Lawful basis: Consent/Legitimate Interest in providing relevant and personalised experiences when you shop with us)
To inform you about products and services that may interest you (Lawful basis: Consent)
(Lawful basis: Legitimate Interest in assessing how and where to place advertising )
To personalise and engage with you on social media (Lawful basis: Consent/Legitimate Interest to personalise the marketing and services we provide to you)
To keep in touch with you (Lawful basis: Consent/Contract)
(Lawful basis: Legitimate interest in marketing to you and keeping customers updated )
To ensure the Website and the services we offer you operate properly (Lawful basis: Consent)
(Lawful basis: Legitimate Interest in planning and delivering efficient operations and to prevent and detect crime or fraudulent activity )
To develop and improve our products, range and services (Lawful basis: Legitimate Interest in understanding our customers’ needs and behaviours to provide a better experience)
You can view the privacy policy for Experian and Merkle, including the ways in which they use and share personal data here:
To prevent and detect crime and other incidents ( Lawful basis: Legitimate Interest in keeping our customers and staff safe, reducing theft and fraud )
To fulfil our legal obligations (Lawful basis: Legal Obligation)
We use a number of different social media platforms to communicate with you and to promote products and services. We process your personal data using these platforms in a variety of ways, as follows:
Meta also processes, as our processor, contact information that we submit for the purposes of matching, online targeting, measurement, reporting and analytics purposes. These services include the processing Meta carries out when they display our advertisements to you in your news feed at our request after matching contact details for you that we have uploaded to the social media platforms they operate.
What are cookies?
Cookies are small text files that are stored on your computer, mobile device or other web enabled device when you visit one of our websites or apps. Cookies allow us to "remember" your actions or preferences over a period of time, or they may contain data related to the function or delivery of our websites. We also use the term "cookie" to describe similar technologies such as pixels or tags.
What do we use cookies for?
Some cookies are required by our site to enable you to transact whilst other cookies enable us to give you an enhanced, personalised web experience. We use cookies for the following purposes:
We also offer you the facility to share your experience on our website through social sites such as facebook and twitter. More information about how these sites use cookies can be found on their websites.
What cookies do we use?
Can I turn off or block cookies?
We use cookies to ensure that we provide the best possible standard of service to our online customers. You can change your cookie preferences at any time by clicking on "Manually Manage Cookies" at the bottom of the page. You can then adjust the available sliders to on or off, then click "Confirm my choices". If you choose not to consent to the use of cookies your experience of our website may be impaired and many integral aspects of the website, including (but not limited to) adding items to your shopping bag and accessing your account, will not work.
Alternatively, most web browsers allow some control of most cookies through the browser settings. To find out more about how to manage cookies, including how to delete cookies, visit www.allaboutcookies.org
We keep your personal data as long as you are a customer of ours and generally for 7 years afterwards to comply with legal requirements. During that time we take steps to remove any personal data as soon as we no longer need it.
We consider you a customer:
We keep CCTV footage on our systems for up to 35 days, it is then deleted. Where accidents, incidents, criminal activities or breaches of our policies are recorded CCTV footage will be kept for longer, however only as long as necessary.
We work with a number of trusted third parties to provide you high quality goods and services. Anybody we work with is subject to stringent security and data protection assessments before we begin to do business with them and on an ongoing basis.
We always make efforts to anonymise data and only pass over personal data that is absolutely necessary for the purposes it is being processed. We always do so securely.
We have contracts in place with all suppliers that help us to ensure security and privacy of your personal data, these are reviewed and updated regularly and always in line with data protection laws.
The identities of the CRAs, and the ways in which they use and share personal data, are explained in more detail at:
- Experian Credit Reference Agency Information Notice
- TransUnion Credit Reference Agency Information Notice
- Equifax Credit Reference Agency Information Notice
We also take data from CRAs to allow us to make decisions about your credit account and credit facility.
The identities of the DCAs, and the ways in which they use and share personal data, are explained in more detail at:
Our main operations are based in the UK and your personal data is generally processed, stored and used within the UK. In some instances your personal data may be processed outside the UK. For example, we operate a customer contact centre in Pune, India. Operatives in this location will have access to your account data in order to assist you with your query. We also work with suppliers and partners who may make use of Cloud and /or hosted technologies across multiple geographies.
If you place an order with us and you are outside of the UK we will transfer the personal data that we hold on you to the UK to facilitate your order and may also transfer your personal data to third parties located in your country of residence to enable us to supply products you order from us. If and when this is the case we take steps to ensure there is an appropriate level of security so your personal data is protected in the same way as if it was being used within the UK.
Where we need to transfer your personal data outside the UK, and if the recipient country has not been determined as providing an equivalent adequate level of protection as the UK, we will use one of the following safeguards:
We always ensure that personal data is secure by continuously developing our security systems and training for our employees. We have implemented appropriate technical and organisational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of processing, in accordance with applicable law.
If you use any third party apps, websites or services to access our services, your usage is subject to the relevant third party's terms and conditions, cookies policy, and privacy policy. For example, if you interact with us on social media, your use is subject to the terms and conditions and privacy policies of the relevant social media platform (Facebook, X etc.). The same applies if you use third party services, like Amazon's Alexa. In certain cases we may be required to share your personal data, in relation to transactions and usage of the services, with the relevant third party.
In certain U.S. states consumers have certain rights regarding the personal data that businesses have about them, such as the California Consumer Privacy Act (the 'CCPA'). This includes the rights to request access or deletion of your personal data, as well as the right to direct a business to stop selling your personal data.
Categories of Personal data and Purposes
The categories of personal data we may collect about you (or have collected in the preceding 12 months) include:
Please see the section on "The data we collect and how we use it" above for more Informationon the purposes for which we collect your personal data.
Disclosing Your Personal Data
Please see the section on "Third Parties we share data with and receive data from" for a description of the third parties with whom we may share your personal data (or have shared your personal data in the last 12 months).
Your rights
Right to opt-out of sale:
While we do not sell personal data in exchange for any monetary consideration, we do share personal data for other benefits that could be deemed a "sale," as defined by the CCPA (Cal. Civ. Code 1798.140(t)(1)). We support the CCPA and wish to provide you with control over how your personal data is collected and shared. To make an opt-out of sale request, contact us according to the ‘How to get in touch’ section below and please include "Do Not Sell" in the subject line.
Right to request disclosure:
You have the right to request disclosure about what categories of personal data we have sold or disclosed for a business purpose about you and the categories of third parties to whom the personal data was sold or disclosed. You have a right to request disclosure of specific pieces of personal data. Below is a complete list of the personal data that you can include in your request.
The categories of personal data that we have collected about you.
The categories of sources from which we collected the personal data.
The business or commercial purpose for collecting or selling personal data.
The categories of third parties with whom we share personal data.
The specific pieces of personal data we collected about you.
The categories of personal data that we disclosed about you for business purposes.
The categories of personal data that we have sold about you, as well as the categories of third parties to whom we sold your personal data.
Right to request deletion:
You have the right to request that we delete any personal data about you that was collected from you. Please note that there are exceptions where we do not have to fulfil a request to delete personal data, such as when the deletion of data would create problems with completing a transaction or compliance with a legal obligation.
Right to non-discrimination:
We will not discriminate against you (e.g. through denying goods or services or providing a different level or quality of goods /or services) for exercising any of the rights afforded to you.
Right to rectification:
You have the right to request that we correct any incorrect personal data we hold on you to ensure that it is complete and as accurate as possible.
California shine the light:
Under California’s “Shine the Light” law California residents who use our website and who provide personal data to us in order to obtain our products and services may request certain Information regarding our disclosure of personal data to third parties for their own direct marketing purposes. This includes the categories of personal data and the names and addresses of those businesses with which we shared your personal data with in the previous calendar year. You may request this data once per calendar year. To make such a request, please send an email to dataprotection@next.co.uk.
Limit the use of my personal data:
You have the right to limit the use of your sensitive personal data in certain circumstances. We will only collect sensitive personal data, as defined by the applicable California or other local law, for the purposes allowed by law or with your consent.
We endeavour to respond to a verifiable consumer request within the required timeframes. If we need more time, we will inform you of the reason and extension period in writing. Any disclosures we provide will only cover the 12-month period preceding receipt of the verifiable consumer request. The response we provide will also explain why we cannot comply with a request, if applicable. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We do not knowingly collect or solicit personal data from anyone under the age of 13. If you are under 13, please do not attempt to register for services or send any personal data about yourself to us. If we learn that we have collected personal data from a child under age 13, we will delete that data as quickly as possible. If you believe that a child under 13 may have provided us their personal data, please contact us.
If you would like to exercise any of your rights mentioned within this privacy policy you can submit these through our privacy portal.
Alternatively, should you need to contact our Data Protection Officer please email: dataprotection@next.co.uk or you can write to:
UK registered address:
Data Protection Officer
NEXT Retail Limited
Desford Road
Enderby
Leicester
LE19 4AT
EU registered address:
Data Protection Officer
NEXT Retail (Ireland) Ltd
13-18 City Quay
Dublin 2
D02 ED70
Ireland