null
Cart

Privacy Policy

You can contact our voluntarily appointed Data Protection Officer, Simon Ghent at DPO@hattons.co.uk if you have any concerns or wish to exercise your rights.

If you prefer you can write to us at 243 Cockeysville Road, Unit A, Cockeysville, MD 21030.

 

Our Promises:
ModelTrainStuff.com never forget it’s your right to total transparency and control on how we use your data. As such we give you these promises:

  • We will only collect data about you that is relevant and necessary;
  • Your data will only be held on systems that meet compliance standards;
  • Your data will only be accessed by those who need it and we will minimise the amount of data that is processed, wherever possible;
  • We won’t share except for the marketing of our own services to you, where we are required to share it by law, if we need to inform a regulatory body or we need to fulfil our service commitments to you through a third party that meets our own privacy standards;
  • We will always remember that it is your personal data, not ours. As such we will ensure complete transparency and openness with you wherever possible.
  • We respect your rights as outlined in the next section and will respond to all requests promptly

 

Your Rights:

You have the following rights over any data we hold about you:

  • Right to object to processing at any time
  • Right to opt out of marketing at any time
  • Right to have inaccurate data corrected
  • Right to erasure of personal data from our database
  • Right to export of personal data

You can read more about your rights here.

If you would like to uphold your rights then please contact our Data Protection Officer at DPO@hattons.co.uk if you have any concerns or wish to exercise your rights.

 

How we Collect your Data

We mainly only process the data you have provided to us. This may be from:

  • Filling in a form or placing an order on our website,
  • Sending us your details
  • Providing your details to us at events

If you belong to an organisation including trade or account customers, we may also source your information from public databases and other sources for our Legitimate Interests.

 

 

What Data we Collect

We try and minimise the data held and the exact data elements we hold will be dependent on your journey with us. Typically, data elements we collect is restricted to:

  • Your personal contact details – first and last name, email address, delivery and billing address, IP Address, phone numbers, phone number, browser and device information including cookies;
  • Your company details – name, business email, telephone number, company address, website and other public held information including credit rating and invoicing details if relevant;
  • o Transmitted information – such as emails, texts, messaging, phone call information and recordings, voice mails, email, meeting notes, CVs and document tracking information.

Calls may also be recorded for information holding, quality and training purposes.


How we Process your Data:

Data is processed/stored mainly on encrypted cloud services such Big Commerce, Google, including Hotjar for marketing.


As a multinational service provider, we operate in several jurisdictions and we are owned by Hatton’s Ltd in the United Kingdom. We use the following safeguards with respect to data transferred outside the UK and European Union where an “adequacy decision” is not in place:

  • The processing is within the same corporate group as our business or organisation and is obligated to uphold the same standards of Data Protection and Security as our UK entity.
  • Further to Section 119A of the Data Protection Act 2018 and noting Case C-311/18 in the European Court of Justice, if your data is transferred or processed outside of the UK or EEA where adequacy decisions are not in place we ensure the safeguards of International Data Transfer Agreements (IDTAs) or Addendums are enforced. Where this is not possible, we ensure that appropriate UK or European Standard Contractual Clauses are entered. For data transfer between the USA we mat rely on the Data Privacy Framework or the UK Extension Data Bridge.

We regularly review suppliers for data security compliance to ensure your data is safe and track where your data is held.

All our processes are subject to various internal policies to ensure that your data privacy and security is upheld.

 

What we use your Data for:

We process your data for several reasons:

  • To fulfil a contractual obligation or service to you
  • To better understand your needs.
  • To improve our services and products.
  • To send you promotional emails and mailings about products, services, offers and other things that we think may be relevant to you if we have the legal basis to do so
  • For audits, regulatory purposes, and compliance with industry standards

We always ensure we have a “legal basis” to use your data for the purpose we have collected it for.

 

If you have started to buy one of our products, but have not completed the purchase, you may have
provided partial information, such as your email. In that case, we might send you an email to remind
you about your interest. If you are not comfortable in receiving further emails of this kind, we will
give you a simple opportunity to opt-out

 

Third Parties:

We may use remarketing services from third parties. These may rely on the use of cookies. You can read more about these in our Cookies Policy.

We also share information where agents, resellers or suppliers are involved in the delivery of your service. For example – we need to share your information with our shipping agents. We may also share or transfer your data with third parties should all or some of its business transfer to another party.

Our website and other materials sent to you may contain links to other third-party websites. We may also offer buttons to social media that link to third party services. We’re not responsible for the content or your data privacy these sites provide through their tools or sites.

Finally, we may need to share your data where we have a legal obligation to, for example with government and security agencies.

 

Data Retention

Dependant on the data you provide us and for what purpose it is provided we may need to retain your data based on your journey with us. Typically, we will retain your data for 6 years following the mend of engagement with us.

If you wish to find out more about your specific data retention, please contact us.


Data Permissions:

Every marketing email sent from Us allows you to opt out of receiving emails from us, except for the purposes of fulfilling any contractual arrangements.

You can also contact us at the email address above and request to opt out, view, export or delete your data. If you request for your data to be deleted, your name and email address will be added to an exceptions list and all other data removed to the extent possible.

 

Legal Compliance:

We seek to uphold our legal obligations. You agree that all disputes will be under the jurisdiction of the Courts of England & Wales. 

Due to our global reach, we do not warrant compliance with all legal obligations in countries that we operate in outside of the UK.

This Privacy Policy is reviewed on a regular basis and was last reviewed in November 2023. We will post the most current version on our website.