Next B2B Privacy Policy
Last updated December 2022
Choosing to shop with Next B2B means you've placed a great deal of trust in us. With trust comes responsibility and we take this responsibility very seriously.
This privacy policy helps you to understand how we use your personal information and who we share it with.
We change the terms of this privacy policy from time to time and you should check it regularly. The last updated date is shown at the beginning of the document. If we make any material changes we will take steps to bring it to your attention.
Who we are
return to top ^
We are Next Plc (company number: 4412362), when we say “we”, “our” or “us” in this policy we are referring to the companies that are part of the Next Group,
which are: Next Retail Limited, Next Holdings Limited, Next Distribution Limited, Next Manufacturing Limited, Next Sourcing Limited, Next Retail Ireland Limited,
Next Germany, Next Beauty Limited, Lipsy Limited, Victoria’s Secret, GAP, Laura Ashley and Reiss.
We are the data controller, which means we are responsible for deciding how and why your personal information is used. We are also responsible for making sure it is kept safe,
secure and handled legally.
We operate to the highest standards when protecting your personal information and respecting your privacy. If you have any questions about your personal information, or how we use it,
you can contact our Data Protection Officer via email at dataprotection@next.co.uk or by writing to our registered office at the below address:
Data Protection Officer, Next Group, Desford Road, Enderby, Leicester, LE19 4AT.
Your rights
return to top ^
You have a number of “Data Subject Rights”, we have explained below what they are and how you can exercise them.
You can read more about these rights on the Information Commissioner's Office website at www.ico.org.uk.
- Right of access - You have the right to request a copy of the personal information that we hold about you.
- Right to rectification – If you think any of your personal information that we hold is inaccurate, you have the right to request it is updated. We may ask you for evidence to show it is inaccurate.
- Right to erasure(also known as the Right to be Forgotten) - You have the right to request that we delete your personal information that we hold.
- Right to restriction of processing – You have the right to request we restrict or suppress the personal data we hold about you.
- Right to data portability – You have the right to ask us to electronically transfer your personal information to another organisation in certain circumstances.
- Rights with regards to automated decision making, including profiling – We sometimes use your personal information to make decisions by automated means.
This involves us analysing your account activity including applications, orders, payments etc.
We do this to confirm your identity, prevent and detect crime, and lend responsibly.
This automated decision making is necessary if you would like to continue to shop with us online. You have a right to reject automated decisions,
but it may mean that you can only shop with us in our stores.
- Right to withdraw Consent – Where we are relying on your consent for processing you can withdraw or change your consent at any time.
The above rights may be limited in some circumstances, for example, if fulfilling your request would reveal personal information about another person or business,
if you ask us to delete information which we are required to have by law, or if we have compelling legitimate interests to keep it.
We will let you know if that is the case and will then only use your information for these purposes.
You may also be unable to continue using our services if you want us to stop processing your personal information.
If you have any general questions or want to exercise any of your rights, please contact dataprotection@next.co.uk
We encourage you to get in touch if you have any concerns with how we collect or use your personal information. You have the right to lodge a complaint directly with the Information Commissioner's Office,
the data protection regulator in the UK, you can do this by visiting the ICO website:https://ico.org.uk/make-a-complaint/
The lawful bases we use to process data
return to top ^
We will only ever process your information if we have a lawful basis to do so. The lawful bases we rely on are:
- Contract – This is where we process your information to fulfil a contractual arrangement we have made with you.
- Consent – This is where we have asked you to provide explicit permission to process your data for a particular purpose.
- Legitimate Interests – This is where we rely on our interests as a basis for processing. Generally this is to provide you with the best products and services in the most secure and appropriate way, but not where our interests are overridden by your interests.
- Legal Obligation – This is where we have a statutory or other legal obligation to process the information, such as for the investigation of crime or to meet responsible lending criteria.
The information we collect and how we use it
return to top ^
We collect and use the information that you provide to us directly, for example;
To process any orders that you place with us and to facilitate any returns (Contract)
- We use your account information plus your chosen delivery address details to; deliver your purchases and keep you informed of their status, and to process any
returns including (where appropriate) collecting the item from you (for example Evri or DHL).
- Payments are made using BACS and refunds are made by crediting the B2B account or by making a bank transfer to the business
To provide you with access to an account (Contract)
- To register an account with us we capture information such as your name, contact and delivery information, and a password to protect your account (account information).
We use the same information on an ongoing basis to manage and provide secure access to your account, and provide you with the services you request.
To provide customer service to you (Legitimate Interest)
- We record calls and keep correspondence (customer service records) when you contact our customer service teams or interact with us on social media.
We use these customer service records to manage your queries or complaints effectively, for quality monitoring and to continually improve our services
To personalise and improve your experience when you shop (Legitimate Interest)
- We keep a record of how you interact with our website and offline B2B ordering process and any marketing you are exposed to,
we use this data, along with purchase history, demographics, account information and third party information,
to show you products and offers from across our brands that we think you will be most interested in and to tailor your experience.
- We use your account information, information on the devices you use to access our sites and your interactions with us to operate
personalised features across our websites, apps and communication.
To inform you about products and services that may interest you (Legitimate Interest)
- We use technologies such as cookies within digital marketing networks, ad exchanges and social media networks such as Facebook’s Custom
Audience to get relevant marketing messages across to you and other customers. We share aggregated and anonymised information about the customer
segments we are interested in reaching with advertising partners, so they can focus on showing adverts to those who are most likely to be interested
in our products, services and offers, and to prevent them showing you irrelevant or repetitive advertisements.
- We share limited information with selected suppliers to enable them to identify new prospective customers on our behalf and to prevent us repeatedly
advertising products or services you have already bought
- We receive information on how you interact with our adverts and content on third party websites and social media platforms (such as Google or Facebook)
which we use to tailor the information that is displayed to you.
To keep in touch with you (Legitimate Interest)
- When you register for an account and shop with us we will keep you up to date with news of products and services including store events, offers,
promotions and sale information - unless you tell us you don’t want us to through the “my account” or using the link in every email that we send to you.
- When we send you communications we use records of how you interact with our website and any other marketing we have sent to you, along with purchase history,
to tailor the messages to include information you are most likely to be interested in.
- We use your account information to notify you about important service messages, such as material changes to this policy, product recalls or information about
your account.
- If you enter or apply for a prize draw or competition we will collect your contact details so that we can inform you if you are a winner (Contract).
n.b. If at any point you have made amendments to your contact preferences in the “my account” section of our website, selecting to receive communications from us,
we are operating under consent instead of legitimate interest.
To ensure the Website and the services we offer you operate properly (Legitimate Interest)
- We use cookies and other similar technologies to keep track of your preferences when using our site.
- We use other cookies and similar technologies to help us understand how you use the site, this allows us to optimise your shopping experience and continually improve our site.
- We gather information about the devices you use to access our sites (desktop and mobile) for example your IP address and device type, to ensure the site is secure and works across multiple platforms.
- We use information for logistics planning, demand forecasting, management information, dealing with errors on our site, and general research and development.
To develop and improve our products, range and services (Legitimate Interest)
- We share insights about our customers (in an anonymised and aggregated format) with the companies whose products we sell. This helps them better understand the different profiles of our customers,
focusing on those who buy their products or are interested in them.
- We may contact you to take part in customer satisfaction surveys, if you respond we collect your feedback and contributions (customer feedback). We use this information to develop the services we offer.
- We work with information providers that specialise in consumer profiling, such as Experian and Merkle. These organisations provide demographic or other data to help better understand customers' demographics,
lifestyles or shopping behaviours, usually linked to the areas where people live.
- We use information about how you browse and engage with our website to improve our websites.
- We use all information, including third party data in the development of new products, services and systems to ensure they work as expected and will be useful to our customers.
To prevent and detect crime and other incidents (Legitimate interest/Legal obligation)
- We use your account information, order history and payment history to assist in monitoring for fraudulent transactions or suspected money laundering.
- When you register an account, apply for credit or contact our call centres we use your account, application and purchase history information to confirm your identity.
- We use device identifiers and IP addresses in fraud prevention and investigation, and to maintain network and data security.
- We maintain a record of any health and safety incidents that occur in our stores or in our premises.
To fulfil our legal obligations (Legal obligation)
- We use your data to ensure we comply with any requirements imposed on us by law or court order, including disclosure to law or tax enforcement agencies and authorities or pursuant to legal proceedings.
- We will share data with regulatory and other official bodies if they make formal requests.
- We will maintain records to meet regulatory and tax requirements.
- We will use your account information to contact you in connection with product recalls or other similar product quality issues and to comply with our legal obligations in connection with the sale of age restricted products.
How long we keep your data for
return to top ^
We keep your personal information as long as you are a customer of ours and generally for 7 years afterwards to comply with legal requirements.
During that time we take steps to remove any personal data as soon as we no longer need it.
We consider you a customer:
- as long as you hold an open credit account,
- for 2 years from the point you last made a purchase from our website or offline B2B ordering process using a non-credit account, or
- during any time we are managing a request or purchase from you.
Third Parties we share data with and receive data from
return to top ^
We work with a number of trusted third parties to provide you high quality goods and services.
Anybody we work with is subject to stringent security and data privacy assessments before we begin to do business
with them and on an ongoing basis.
We always make efforts to anonymise data and only pass over personal information that is absolutely necessary for
the purposes it is being processed. We always do so securely.
We have contracts in place with all suppliers that help us to ensure security and privacy of your personal information,
these are reviewed and updated regularly and always in line with data protection laws.
- Next Group companies – We will share your personal information, in certain circumstances with
the other companies within the Next Group. This is so that we can provide personalised services across our Group.
- Delivery Partners – Helping us to deliver the goods you order to you including our brand partners
that dispatch and deliver goods to you directly.
- IT Companies – Supporting us in maintaining our website and other business systems including; providing phone lines,
data storage facilities, and providing and supporting Cloud based infrastructure used in providing our products and services.
- Marketing Companies and Online Advertising - Helping us to manage our electronic communications to you and to
help us show you the advertising you are most likely to be interested in, Companies that provide marketing and advertising
assistance (including management of email marketing operations, mobile messaging services such as SMS, and services that deploy
advertising on the internet or social media platforms, such as Facebook and Google) as well as analysis of the effectiveness of our
advertising and communications campaigns.
- We use technologies such as cookies, pixels, and device IDs – within digital marketing networks, ad exchanges and
social media networks such as Facebook’s Custom Audience to get relevant marketing messages across to you.
- Consumer profiling organisations - These organisations provide demographic or other data to help better understand customers'
demographics, lifestyles or shopping.
- Payment processors - Payment card processors to process credit and debit card payments and store payment information;
for example Worldpay and Paypal.
- Credit Reference Agencies (CRAs) - We share your personal information with CRAs on an ongoing basis, including details of
settled accounts and any debts not fully repaid on time. CRAs will share your information with other organisations.
The identities of the CRAs, and the ways in which they use and share personal information, are explained in more detail at:
We also take information from CRAs to allow us to make decisions about your credit account and credit facility.
- Fraud prevention services - Before we provide goods and services to you, we use third parties to
undertake fraud and money laundering checks and verify your identity. These organisations will report to us on
industry fraud indicators and if they have reason to believe an identity is fraudulent. If we have reason to suspect
fraud or other criminal offences we will pass your personal information to fraud prevention agencies (such as CIFAS)
or law enforcement agencies for the detection, investigation and prevention of crime. If we think there is a risk of
fraud, we may suspend activity on your account or refuse access to your account and/or cancel an order. If we do this
we will inform you by email or SMS and ask you to contact us.
- Debt collection agencies (DCAs) - If you default on repayments to your credit account we may share your
data with DCAs to allow them to collect the outstanding debts from you.
- Debt purchase companies – Where appropriate will share certain information on defaulted accounts with
prospective debt purchasers as part of the negotiations for sale of the debt.
- Debt management companies – where we have received appropriate instruction we will share information
about your credit account with debt management companies to allow them to assist you with managing your debts.
- Research and analytics companies - We may share personal details to allow research companies and feedback
providers to contact you directly on our behalf in order to capture your opinions on our products, services, websites and apps.
We may ask these research companies to analyse the results so that we can better understand your online experience, which will
help us to improve our services. We only provide them with the information they need to perform their function. This may take the
form of a survey, where you may be asked to review a product or service you’ve bought or provide general feedback on our products
and services. You will always have the choice about whether to take part in our market research or surveys. We may share information
with specialist companies to analyse customer information to help us better understand how you use our services and to tailor products,
services and offers that may be relevant for you. We utilise companies that help us track and record the way you navigate our website,
so that we can understand your online experience and use it to improve our services and offer a more personalised experience.
- Product technicians – We use professional third party companies to assist us in independently reviewing issues and complaints
with our products. We will share information with these technicians to allow them to review the product and return it to you or to review the
product in your home.
- General service companies - Such as insurance companies, printers and mailing houses that assist us in providing our products
and services
- Regulators and the Police - We will share data with regulators and other official bodies (including law enforcement)
if they make formal requests or pursuant to legal proceedings.
Sending information outside the United Kingdom
return to top ^
Our main operations are based in the UK and your personal information is generally processed, stored and used within the UK .
In some instances your personal information may be processed outside the European Economic Area. For example, Next operates a
call centre in Pune, India. Operatives in this location will have access to your account information in order to assist you with
your query. We also work with suppliers and partners who may make use of Cloud and /or hosted technologies across multiple geographies.
If and when this is the case we take steps to ensure there is an appropriate level of security so your personal information is protected
in the same way as if it was being used within the UK.
If you place an order with us and you are outside of the UK we will transfer the data that we hold on you to Next Plc in the UK to facilitate
your order.
Where we need to transfer your data outside the UK we will use one of the following safeguards:
- The use of European Commission approved standard contractual clauses in contracts for the transfer of personal data to third countries.
- The International Data Transfer Agreement and Addendum for the transfer of personal information to third countries.
- Transfers to a non-UK country with privacy laws that give the same protection as the UK.
Keeping your personal data secure
return to top ^
We always ensure that personal data is secure by continuously developing our security systems and training for our employees. We have
implemented appropriate technical and organisational security measures designed to protect your personal information against accidental
or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of
processing, in accordance with applicable law.
Third party apps, websites and services
return to top ^
If you use any third party apps, websites or services to access our services, your usage is subject to the relevant third party's terms and
conditions, cookies policy, and privacy policy. For example, if you interact with us on social media, your use is subject to the terms and
conditions and privacy policies of the relevant social media platform (Facebook, Twitter etc.). The same applies if you use third party
services, like Amazon's Alexa. In certain cases we may be required to share your personal information, in relation to transactions and
usage of the services, with the relevant third party.
How you can get in touch
return to top ^
Write to:
Data Protection Officer
Next Group Plc
Desford Road
Enderby, Leicester
LE19 4AT
or you can email: dataprotection@next.co.uk