Flux logo
Blog Help Legal
Bank Terms & Conditions Bank Privacy Policy Website Privacy Policy Offers Terms Of Use Offers Privacy Policy Flux Retailer Terms Of Use Portal Privacy Policy Portal Terms Of Use
  • 30/06/2021 Dozens

Dozens Bank Privacy Policy #

30th June 2021

Welcome to Flux!

We are Flux Systems Limited (“us”, “we”, “our” or “Flux”). We provide digital receipts, for customers who activate our services in their Dozens app (“you”, “your” or “customer”). In order to provide our service to you, we need to receive certain information about you and your transactions. This policy sets out the different services offered by Flux and explains the type of data we’ll collect about you. Our services are described in full in our Terms and Conditions.

1. How does Flux work? #

Activating Flux provides you with access to the following features:

  • Digital receipts: you’ll be able to see what you bought and how much you spent by clicking on any transaction made at a Flux-supported merchant;

In order for us to provide you with these features, Dozens will share some of your personal data with us. We are committed to looking after your personal data and making sure it’s kept secure.

Below, you’ll see which kinds of information we collect about you, what we do with this information, who we may share your information with and most importantly, your rights in relation to this information.

2. What kind of personal data do we collect and process? #

The term “personal data” refers to any information that identifies you or relates to you. The personal data we process will depend on the circumstances and the services you are using.

We may collect, use, store, transfer and otherwise process the following types of personal data:

Type of data Description
User details Your name, email address, customer or account ID, access token, and similar information
Payment account information The last 4 digits of your long payment card number, BIN, account number, sort code and other payment account information
Transaction information Information about all transactions made from your bank account including:
- Time and date of the transaction- Merchant name, ID and location
- Amount paid and transaction currency
- Payment card details, including the last 4 digits of the card number
- The card scheme authentication
- Payment method and BIN
Receipt information Information from the merchant required to create your receipt, including:
- Time and date of the transaction
- Merchant name and location
- Amount paid and transaction currency
- Payment card details, including the last 4 digits of the card number and auth code
- Items purchased
- Offers and discounts used
- VAT information (where applicable)
General usage data Information about how you access, navigate and engage with our services, emails, links and other features
Enquiry information Details of your requests, complaints or communications when you email, write to us or contact us.

3. How do we collect your personal data? #

The following table explains how we collect different kinds of personal data. Where information is provided by you to us, we will rely on the information as accurate, complete and up to date. Please inform us of any inaccuracy or change without delay.

Type of data How we collect it
User details We receive your name, email address and access token directly from Dozens
When you activate Flux, we create a unique customer and account ID to identify your account
You may provide your email address to us directly for the purposes of marketing or other communications
Payment account information We receive your payment account information directly from Dozens
Transaction information We receive your transaction information directly from Dozens
Receipt information We receive your receipt information directly from our merchant partners
General usage data We collect information about how you interact with our emails through our email marketing provider
We collect information about how you interact with our services from Dozens
Enquiry information You provide us with your information when you interact with us

4. How do we use your personal data and why? #

We’ll only use your personal data where we have a valid reason to do so. Below, we’ve set out the ways in which we use your personal data and the reason or “legal basis” we rely on to do so.

Purpose Data we process Legal basis
To generate digital receipts for your current and historic purchases made with Flux merchants User details
Transaction information
Payment account information
Receipt information
Processing is necessary for the performance of our contract with you
To provide our premium receipt services like returns User details
Transaction information
Payment account information
Receipt information
Processing is necessary for the performance of our contract with you
To send you service notifications to alert you to matters relevant to your use of our services, like updates to the Terms and Conditions User details Processing is necessary for the performance of our contract with you
To send you promotional emails about Flux services User details We rely on your consent to send you marketing emails
To provide statistical aggregated analytics about the use of Flux services to our merchants and other partners We anonymise and aggregate information from your:
Transaction information
General usage data
Receipt information
We rely on your consent to process and anonymise your information to produce analytics for our merchant partners
To provide aggregated market insights about UK retail trends to our merchants and other third parties We anonymise and aggregate information from your:
Transaction information
General usage data
Receipt information
We rely on your consent to process and anonymise your information to produce market insights
To ensure proper administration of our business, such as keeping appropriate records about how Flux services are used, developing our services or for resolving complaints User details
Enquiry information
General usage data
Processing is necessary for the performance of our contract with you
Processing may also be in the legitimate interest of administering our business
To monitor our networks, Flux service and systems for suspicious activities, test and audit our systems and deploy appropriate security measures User details
Usage data
Processing is necessary for our legitimate interest in ensuring the security of our organisation, people and services and necessary for compliance with our legal obligations
To process and share information as required for our compliance with the law and to establish, exercise or defend legal claims or comply with regulators or law enforcement agencies. Any information subject to mandatory processing or disclosure, where this is proportionate and lawful Necessary for compliance with any legal obligations we are subject to or to establish, exercise or defend legal claims

We’ll update you about any new purposes for processing your personal data and will obtain your prior consent for these new purposes if required by law.

5. Who do we share your personal data with? #

We may share or store your personal data as follows:

  • With Dozens as is necessary for the digital receipts to automatically appear in your Dozens app
  • With our third-party service providers, such as our IT providers and marketing platform provider
  • Where we are compelled by law or where it is necessary to enforce our rights
  • Where necessary for the purposes of a joint venture, collaboration, financing, sale, merger, reorganisation or similar event relating to our business
  • With other third parties where you have provided your consent for us to do so

6. Dozens may process your personal data #

We are not responsible for how Dozens may process your personal data. You should check the privacy statement of Dozens to find out more.

7. Where is your personal data processed? #

Generally, your personal data is held in the United Kingdom or the European Economic Area (EEA). However, we may transfer your personal data to our group companies, service providers and other third parties in countries different from your country of residence.

Where we transfer your personal data outside the UK or EEA, we will only do so, where we are satisfied that your data protection rights are adequately protected by appropriate technical, organisational and contractual safeguards in accordance with data protection laws.

For example, we adopt safeguards such as the standard contractual clauses issued by the European Commission or the Information Commissioner’s Office or similar transfer mechanism. You may request further information on the measures used for international transfers or access to your personal data from outside the UK or EEA.

8. How do we keep your personal data secure? #

We maintain appropriate organisational and technological safeguards to help protect against unauthorised use, access to or accidental loss, alteration or destruction of personal data. We also seek to ensure our partners and service providers do the same.

However, while we strive to ensure the security of our customers’ data and our business, we cannot guarantee that your personal data will always be safe, particularly when sent to and from the Dozens app through third-party infrastructure or when exposed to novel cyber threats.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a personal data breach where required by law.

We endeavour to use the least amount of personal data as is required for each purpose. We will employ pseudonymisation, anonymisation, and aggregation where appropriate.

Our staff will only access your personal data on a need-to-know basis.

9. How long do we keep your personal data? #

The following table sets out the retention periods for each type of data we process.

Type of data Description
User details We will retain this information for the duration you have Flux services active in your Dozens app
Once you deactivate Flux services, we will retain this information for two years before either anonymising or securely deleting it
Payment account information We will retain this information for the duration you have Flux services active in your Dozens app
Once you deactivate Flux services, we will retain this information for two years before either anonymising or securely deleting it
Transaction information For transaction information used to generate digital receipts (“matched data”):

We will retain this information for the duration you have Flux services active in your Dozens app
Once you deactivate Flux services, we will retain this information for two years before either anonymising or securely deleting it
For transaction information not used to generate a digital receipt (“unmatched data”):

We will retain this information for 24 months from the date of the transaction
After this period elapses, we will either anonymise or securely delete it
Receipt information We will retain this information for the duration you have Flux services active in your Dozens app
Once you deactivate Flux services, we will retain this information for two years before either anonymising or securely deleting it
General usage data We will retain this information for the duration you have Flux services active in your Dozens app
Once you deactivate Flux services, we will retain this information for two years before either anonymising or securely deleting it
We collect information about how you interact with our services from Dozens
Enquiry information We will retain this information for two years from the date of enquiry, after which it is securely deleted

When you deactivate the Flux service through Dozens, we will keep your information for the time periods specified in the table above, unless you ask us to erase it.

After these retention periods have expired, we will only keep your data if it is legally required for us to do so (such as for auditing purposes).

10. What are your rights? #

Subject to certain exemptions, limitations and providing appropriate proof of identity, you will have a right to:

  • Request further information about matters set out in this notice, including our retention policy and international data transfers
  • Make an access request to receive copies of your personal data
  • Ask us to rectify any inaccurate or incomplete personal data
  • Withdraw consent previously provided
  • Object to our processing of personal data based on our legitimate interests or any profiling or processing for direct marketing purposes
  • Request erasure of your personal data
  • Restrict our processing of your personal data
  • Data portability from one service provider to another, where applicable
  • Lodge a complaint with the Information Commissioner’s Office

All requests will be processed in a timely manner, generally within one month. If we cannot process your request within this period, we shall explain why and process it as soon as possible thereafter.

11. What happens when you deactivate Flux services? #

When you deactivate Flux via the Dozens app, we’ll stop receiving new information about your transactions from Dozens.

We’ll keep the information we’ve already received from Dozens on file and may continue to use it in accordance with the processing activities and retention periods set out in sections 4 and 9 above.

You can ask us to erase your data at any time by contacting us.

12. How can you contact us? #

We have appointed Tom Reay as our Data Protection Officer. If you’d like to contact our DPO, the easiest way to do this is by emailing DPO@tryflux.com. If you’d rather not use email our DPO’s other contact details are available here. If you don’t email DPO@tryflux.com, please make sure you mark your query as “FAO Flux DPO”.

Alternatively write to us at:

Data Protection Officer, Flux Systems Limited, 1 Morecambe Avenue, Caversham, Reading, RG4 7NL

13. Opting-out of marketing communications #

You can request to stop receiving our marketing communications at any time by clicking on the unsubscribe link at the bottom of each marketing message or by contacting us directly.

14. How to make a complaint #

You have the right to complain about how we have used your personal data by contacting us via email or post.

If you’re still not happy with how we have dealt with your complaint, you can also contact:

  • A data protection regulator, such as the Information Commissioner’s Office
  • The UK courts to seek a remedy if you think that your rights in relation to your personal data have been breached

15. Updates #

If we make any changes to our notice you’ll be able to see them on this page. You should regularly check for updates, as indicated by the “Last updated” date at the top. If any such changes significantly affect you, we will always ask for your prior consent where we are required to do so by law.

If you do not agree with the changes, please do not continue to use our Flux service.

© Flux Systems Limited is registered in England and Wales (No. 09882195) and regulated by the Financial Conduct Authority as an Account Information Services Provider under the firm reference number 791 567. EU and US Patent Pending (Application No. EP3396609)