Privacy Policy
How we collect, use, store and protect your personal information when you visit this site or use our services.
Information we collect
We collect: contact details (name, email, phone) when you submit a form or sign up; order data (billing/shipping address, items purchased) when you buy from us; usage data (pages visited, browser type, IP address) automatically when you visit. Replace with your actual data inventory.
How we use your information
We use your data to: provide and improve our services, process and fulfil orders, respond to enquiries, send important account or order updates, send marketing communications (only with consent), comply with legal obligations.
Lawful basis for processing
Under GDPR we rely on: contract performance (orders, account management), legitimate interest (site analytics, fraud prevention), consent (marketing emails, optional cookies), legal obligation (tax records, regulatory compliance).
Sharing your information
We share data only with: service providers (payment processors, hosting, email delivery — bound by data-processing agreements), regulators or law enforcement (when legally required), business successors (in the event of merger or acquisition). We do not sell your data.
How long we keep your data
Account data: as long as the account is active + 12 months. Order data: 7 years (tax records). Marketing-list data: until you unsubscribe + 30 days. Analytics data: 26 months. Replace with your actual retention periods.
Your rights
You have the right to: access your data, correct inaccuracies, delete your data ("right to be forgotten"), restrict processing, port your data to another service, object to processing based on legitimate interest, withdraw consent at any time. To exercise these rights, contact us.
Cookies & tracking
We use cookies for: essential site function (cart, login, security), analytics (anonymised usage statistics), marketing (with your consent). You can manage preferences via the cookie banner or your browser settings.
International transfers
Some of our service providers process data outside your country. When we transfer data internationally we use safeguards: Standard Contractual Clauses (SCCs), adequacy decisions, or your explicit consent.
Security
We protect your data with: HTTPS encryption, access controls, regular security updates, hashed passwords, and limited access on a need-to-know basis. No system is 100% secure — we will notify you of breaches as required by law.
Changes to this policy
We may update this policy. Material changes will be flagged on this page and (where appropriate) notified by email. The "last updated" date above shows the current version.