GDPR Compliance
Last updated: February 2026 · Please read this document carefully.
Our Commitment
We are committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR) and applicable data protection law. This page explains how we act as a data controller, the legal bases for processing your data, and the rights you have under GDPR.
Data Controller
We act as the data controller for the personal information we collect on this website. This means we are responsible for determining how and why your data is processed. For any data protection enquiries, please contact us.
Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract — processing is necessary to fulfil your orders and manage your account
- Legal obligation — processing is required to comply with tax, financial, and regulatory requirements
- Legitimate interests — processing is necessary for fraud prevention, security, and improving our services, where your fundamental rights do not override these interests
- Consent — for marketing communications and optional cookies; you may withdraw consent at any time
Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data ("right to be forgotten"), subject to legal obligations
- Right to restriction — request that we limit how we process your data in certain circumstances
- Right to data portability — receive your data in a structured, commonly used, machine-readable format
- Right to object — object to processing based on legitimate interests or direct marketing
- Rights related to automated decision-making — not be subject to decisions made solely by automated processing that significantly affects you
To exercise any of your rights, please contact us. We will respond within 30 days of receiving your request.
Data Retention
We retain personal data only as long as necessary for the purposes it was collected:
- Account data — retained for the duration of your account, plus 12 months after closure
- Order records — retained for 7 years for accounting and legal compliance
- Marketing data — retained until you withdraw consent or unsubscribe
- Support communications — retained for 3 years
International Data Transfers
Where we transfer personal data outside your country, we ensure appropriate safeguards are in place — such as standard contractual clauses approved by the relevant data protection authority — to protect your data to an equivalent standard.
Cookies & Tracking
Our use of cookies is detailed in our Cookie Policy. We use a consent management approach to ensure we obtain valid consent before placing non-essential cookies on your device.
Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include SSL encryption, access controls, and regular security reviews.
Complaints
If you have concerns about how we handle your personal data, we encourage you to contact us first so we can resolve the issue directly. You also have the right to lodge a complaint with your national data protection supervisory authority.
Have Questions?
Our support team is happy to help with any queries.