Here at Superdry, your privacy and data security matters to us. When you provide any personal information to us, we make sure we follow 4 Key Principles:
We use and process your data to help you get the most out of your relationship with us – and always in compliance with the law.
We keep your data under lock and key – in secure and highly restricted environments.
We aim to be 100% transparent with you about what data we collect and why we collect it.
You are in charge. You can ask to see the data we hold for you or ask for it to be deleted.
This policy tells you a little bit more about these principles and how we work hard every day to live by them and respect them.
We want to be open with you about:
We also want to tell you all about your rights and how we can help you stay in control.
You’ve probably heard of “Superdry” the brand, but like many organisations the brand is underpinned by a corporate business structure.
Superdry is the trading name of the Superdry Plc group of companies. Superdry Plc of Unit 60, The Runnings, Cheltenham, Gloucestershire GL51 9NW, United Kingdom is a public company listed on the London Stock Exchange. Superdry Plc has many different subsidiary operating companies (collectively referred to as “Superdry”, “we”, “us” and “our” in this policy) that do different things for us and operate different parts of our business around the world.
The part of the Superdry group with which you are interacting is normally the entity which is processing your personal information and is therefore the controller of your data. For example, we have wholly owned trading subsidiaries which operate stores for us around the world - the name of the entity you bought your product from will normally be on your receipt. We also have a company called Supergroup Internet Limited which operates our ecommerce and online business, except in the USA where it’s operated by Superdry Retail LLC.
Regardless of where you are based and regardless of which part of our group may be a controller of your personal information, any queries you have regarding your personal information will be dealt with by Superdry Plc. This means that we are responsible for deciding how and why your personal information is used. We’re also responsible for making sure it is kept safe, secure and handled legally.
Note that Superdry is a multi-channel business. This means that we also sell Superdry branded products to other retailers. We also operate a franchise business, meaning that many of our stores are operated by our licensed and trusted franchisees rather than by us directly. In the event you buy Superdry products from another one of these retailers or our franchisees, they are responsible for handling your personal data. Please refer to their individual privacy terms for more information.
We will only ever process your information if we have a lawful basis to do so. The lawful bases we rely on are:
This is where we process your information to fulfil a contractual arrangement we have made with you.
This is where we have asked you to provide explicit permission to process your data for a particular purpose, and you have provided such consent.
This is where we rely on our interests as a reason for processing your information, generally this is to provide you with the best products and service in the most secure and appropriate way.
This is where we have a statutory or other legal obligation to process the information, such as for the investigation of crime or to notify you of certain things.
We want our relationship with you to be open, strong and mutually beneficial. Throughout the different stages of our relationship, you may give us certain information. We use your information in a number of different ways, and what we do depends on the information. Failing to provide some of the personal information we require may have an adverse impact on our ability to interact with you, for example we may not be able to provide you with products or services you would like to receive.
It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during the period of your interactions with us. This can be done by emailing care@superdry.com or in your account if you have one.
The tables below set this out in detail, showing what we use, how we use it and why we use it.
While our website is designed for a general audience, we will not knowingly collect any data from children under the age of 13 or sell products to children. If you are under the age of 13, you are not permitted to use or submit your data to the website.
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
What we do and how we do it :
Why we do it :
The Legal Bit :
We do not, and will not, sell any of your personal data to any third party for pure financial gain. We want to earn and maintain your trust, and we believe this is absolutely essential in order to do that.
However, we share your data with the following categories of companies as an essential part of being able to provide our services to you:
Companies in the Superdry group, as sometimes different bits of our group are responsible for different activities.
Companies that do things to get your purchases to you, such as, warehouses, order packers, and delivery companies.
Professional service providers, such as marketing agencies, advertising partners and website hosts, who help us run our business or help us obtain feedback from you.
Affiliates who help us reach out to potential new customers or promote our products on their websites.
Credit reference agencies, law enforcement and fraud prevention agencies, so we can help tackle fraud.
If we do share your personal data with third parties, it will only be done in order to achieve a legitimate and lawful purpose or with your consent. We will always assess the relevant third party and their security measures to ensure that when a transfer such as this takes place, you can expect a similar degree of protection in respect of your personal information.
If you would like to know more about the third parties we may share personal data with, or how to find out more on how they will use your data, please contact us using the form here.
We take information security very seriously and do all we can to ensure that we keep your information safe and secure.
We have numerous security measures in place to protect against the loss, misuse, and alteration of information under our control. We will always aim to implement the best security systems across our networks and hardware to ensure access and information are protected. Our technical and organisational security measures include:
- Encryption of personal information where appropriate.
- Regular cyber security assessments of all service providers who may handle your personal information.
- Regular planning and assessments to ensure we are ready to respond to cyber security attacks and data security incidents.
- Regular penetration testing of systems.
- Security controls which protect our information technology systems infrastructure and our premises from external attack and unauthorised access.
- Regular backups of information technology systems data with functionality to correct errors or accidental deletion/modification to data.
- Internal policies setting out our information security rules for our staff.
- Regular training for our staff to ensure staff understand the appropriate use and processing of personal information.
If you have opted in to receive marketing communications from us and want to opt out, you can control the marketing communications you receive from us:
To opt out of receiving Emails:
-In your account: By changing your contact preferences in the Account Information section.
-By clicking “unsubscribe”:You can also click on the ‘unsubscribe’ link in any marketing email you receive, and this will take you to an area where you can unsubscribe from that method of communication.You can also customise your marketing preferences here.
-By email:You can contact our Customer Care team – care@superdry.com.Once you do this, we will update our records to ensure that you don’t receive further marketing messages.
To opt out of receiving Text Messages:
- By texting “STOP” in response to our text messages.
If you tell us that you don’t want to receive marketing messages it might take a few days for all our systems to be updated, so we would ask for your patience as you might get messages from us while we process your request.
We use online advertising to keep you aware of what we’re up to and to help you see and find our products.
You may see Superdry banners and ads when you are on other websites and apps, such as Social Media. We manage this through a variety of digital marketing networks and ad exchanges. We also use a range of advertising technologies and some of these are designed to personalise you experience.
The banners and ads you see are based on information we hold about you, or your previous use of the Superdry website (for example, your Superdry search history, and the content you read on Superdry) or on Superdry banners or ads you have previously clicked on.
For more information on our use of advertising technologies and cookies, please see our Cookie Notice
Superdry is a global business with operations inside and outside of the United Kingdom and we use suppliers and fulfilment centres located across the world.
It is sometimes necessary to share your personal information outside of the UK and / or the European Economic Area (the EEA) or it will be collected outside of the UK and / or the EEA. This will typically occur when service providers to our business are located outside the EEA or if you are based outside the EEA. These transfers are subject to special rules under data protection laws.
The same applies to any transfer of personal information to another part of our group of companies based outside of the UK and / or the EEA. We also apply the same standards to any transfer of personal information between members of our group, regardless of where the group company is based.
If we transfer your personal information outside of the UK and / or the EEA, we will ensure that the transfer will be compliant with data protection laws and all personal information will be secure. Our standard practice is to assess the laws and practices of the destination country and relevant service provider and the security measures that are to be taken as regards the personal Information in the overseas location. This means that when a transfer such as this takes place, you can expect a similar degree of protection in respect of your personal information.
Our directors and other key staff working for us may in limited circumstances access personal information from outside of the UK and EEA if they are working abroad outside of the UK or EEA. If they do so they will be using our security measures and the same legal protections will apply that would apply to accessing personal information from our premises. In limited circumstances the people to whom we may disclose personal information may be located outside of the UK and EEA and we will not have an existing relationship with them, for example a foreign police force. In these cases we will impose any legally required protections to the personal information as required by law before it is disclosed.
Also if you are based outside of the UK and / or the EEA, then your personal data may be held and used outside of the UK and / or EEA anyway, but in most cases as described at the start the controller of your personal information will be Superdry in the UK. If you would like any more details about how we protect your personal information in relation to international transfers then please use the form here to contact our DPO.
We’ll hold on to your information for as long as you continue to be a Superdry customer and for as long as we are required to keep it to ensure we meet our legal requirements across the globe.
Unless you have opted in to receive marketing communications from us or retain an active customer profile with us by ordering product in at least three year intervals, we will keep your information for the following periods of time:
Web: If you set up an account through one of our Superdry websites, we will retain your personal data within the website for three years after your last order. If you use a guest check out without setting up an account, we will retain your personal data within the website database for 90 days. Data relating to each of your orders will be kept for seven years.
E-receipts: If you sign up to receive e-receipts in a Superdry store, we will retain your personal data for seven years.
Competitions, promotions: If you enter a competition or promotion, we will delete your personal data as soon as we have completed the competition or promotion.
Customer services: If you contact our customer services representatives, we retain your personal data for seven years.
If you would like us to delete the information we hold about you, then please use the form here and request that we close your account or delete your personal information. However, we have a legal requirement to keep some of your personal data even after you have asked us to delete it. We will only keep what we absolutely need to, and only to make sure we can meet our legal or regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our Terms Conditions.
You have a number of ‘Data Subject Rights’. Set out below is some information on what they are and how you can exercise them.
You have the right to request a free copy of the personal information that we hold about you.
If you think any of your personal information that we hold is inaccurate, you have the right to request it is updated. We may ask you for evidence to show it is inaccurate.
You have the right to request that we stop processing, or delete, all of your personal information that we hold. If you exercise this right we will keep a note of your name linked to your request and it won’t prevent us from processing any new information you provide to us subsequently.
You have the right to ask us to electronically move, copy or transfer your personal information in a machine readable format.
We sometimes use your personal information to make decisions by automated means. This involves us analysing your account activity including applications, orders, payments etc. We do this to confirm your identity and to prevent and detect crime. This automated decision making is necessary if you would like to continue to shop with us online. You have a right to reject automated decisions but it may mean that you can only shop with us in our stores.
Where we are relying on your consent for processing you can withdraw or change your consent at any time.
The above rights may be limited in some circumstances, for example, if fulfilling your request would reveal personal information about another person, if you ask us to delete information which we are required to have by law, or if we have compelling legitimate interests to keep it. We will let you know if that is the case and will then only use your information for these purposes. You may also be unable to continue using our services if you want us to stop processing your personal information.
If you have any general questions or want to exercise any of your rights please use the form here. Our security procedures mean that we may need to request proof of identity before we disclose personal information to you in response to any request.
We encourage you to get in touch if you have any concerns with how we collect or use your personal information. You do however also have the right to lodge a complaint directly with the Information Commissioners Office, the data protection regulator in the UK, their contact details can be found on their websitewww.ico.org.uk.If you are located elsewhere in the EEA, then you are free to contact your local Supervisory Authority.A list of those Supervisory Authorities can be found here - https://edpb.europa.eu/about-edpb/board/members_en .
If you are a resident of California you may have some additional rights in regards to your personal information under the California Consumer Privacy Act 2018 or (“CCPA”).
We have detailed the information we may collect in our main Privacy Policy.We have also provided information on how we may collect this information and the commercial purpose for collecting or sharing your personal information.We have also made it clear that we do not sell personal data purely for financial gain.
Sale of personal information under the CCPA is broad and includes disclosing personal information to third parties for valuable consideration, not solely for money. We share pseudonymised identifiers such as masked email addresses and cookies with our advertising partners for advertisement purposes.
Your rights are similar to those applicable under the GDPR.Specifically in California, you have the following rights:
You can request to access the categories and specific pieces of personal information we have collected about you, the categories of sources of such collection, the commercial purpose for collecting or selling personal information, the categories of third parties with whom we share personal information, the categories of personal information we have disclosed and sold about you in the preceding 12 months and the categories of third parties to whom the personal information was sold to.
You can request for us to delete any of your personal information which we have collected (subject to some exceptions).
You can request to opt-out of the sale of your personal information to third parties.
You will receive equal service and price if you exercise your rights under the CCPA.
How to exercise your rights
·Rights request (except opt-out) please use the form here.
·Opt-out of the sale of your information: Click Do Not Sell My Personal Information
When you make a request, we will require certain information from you to be able to verify your identity and request that may include your name, email address and home address.
We may change this page from time to time, to reflect how we are processing your data.
If we make significant changes, we will make that clear on the Superdry website or other Superdry services, or by some other means of contact such as email, so that you are able to review the changes before you continue to use our services.
If you have any questions, comments, requests or concerns relating to this policy, please contact our Data protection officer by clicking here. If we are unable to resolve your complaint, you may refer your complaint to the Information Commissioner’s Office by clicking here: https://ico.org.uk/make-a-complaint/. If you are located elsewhere in the EEA, then you are free to contact your local Supervisory Authority.
A list of those Supervisory Authorities can be found here - https://edpb.europa.eu/about-edpb/board/members_en
For any customer service related enquiries or enquires about a recent order, please contact our customer services team by emailing care@superdry.com
This policy was last updated on 15 March 2021.We made changes to this policy to establish our privacy principles and to more clearly explain how we handle your data, including in relation to the different purposes for which we use it.