This Privacy Policy describes how nodrillbath (“we”, “us”, or “our”) collects, uses, retains, and protects personal information obtained from individuals (“you”) visiting or making purchases via www.nodrillbath.com. We are strictly committed to processing personal data in full compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable European Union General Data Protection Regulations (EU GDPR).

Our commercial operations and order fulfillment services are provided exclusively to customers residing within the United Kingdom and European Union member states.

1. Data Controller Information

nodrillbath operates as an independent sole proprietorship established in the United Kingdom and serves as the primary Data Controller responsible for your personal information.

  • Brand & Official Website: nodrillbath (www.nodrillbath.com)
  • Legal Structure: Sole Proprietorship
  • Operating Address: 19 Adler Street, London, E1 1EG, United Kingdom
  • Data Protection Contact Email: dashboard@nodrillbath.com
  • Telephone Contact: +44 2073771465

2. Personal Information We Collect

To execute order contracts and deliver website functionality, we collect personal data provided directly by you during interaction with our store:

  • Identity & Contact Data: Full name, billing address, shipping address, email address, and contact telephone number.
  • Order & Transaction Data: Information regarding purchased items, transaction reference numbers, order history, and delivery instructions.
  • Technical & Usage Data: IP address, browser classification, time zone settings, network access logs, and website navigation patterns collected via essential cookies and analytical diagnostic tools.

3. Legal Basis for Data Processing

We process personal data under the explicit legal frameworks established by UK and EU privacy legislation:

  • Contractual Necessity: Processing is required to fulfill purchase orders, secure payment authorizations, organize courier delivery, and provide post-purchase customer support.
  • Legal & Statutory Obligations: Processing is mandatory to satisfy statutory tax, accounting, audit, and consumer protection reporting duties.
  • Legitimate Interests: Processing is conducted to maintain network security, perform fraud monitoring and prevention, and support operational website administration.

4. Payment Processing & Payment Data Security

All financial transactions conducted through www.nodrillbath.com are securely processed through our licensed third-party payment gateway provider, Stripe.

  • Role of Payment Processor: Stripe acts as an independent Data Controller for the purposes of payment authorization, security monitoring, fraud protection, and financial transaction settlement.
  • Payment Card Data Handling: Financial details (including complete card numbers, expiration dates, and security codes) are submitted directly to Stripe via encrypted channels. Financial credentials are never received, processed, held, or stored on our servers.
  • Compliance Standards: Transactions transferred to Stripe are processed in accordance with PCI-DSS Level 1 compliance standards and Stripe’s Global Privacy Policy.

5. Third-Party Data Sharing & Infrastructure Service Providers

We do not sell, rent, lease, or trade your personal information to any third parties. Personal data is shared strictly with essential operational service providers under contract:

  • Logistics & Delivery Partners: Customer names, shipping addresses, and contact phone numbers are shared with courier partners solely to execute dispatch, transport, and final delivery.
  • Technical Infrastructure Providers: Hosting, server, database storage, and security providers operating strictly under bound Data Processing Agreements (DPAs).
  • Legal & Regulatory Disclosure: Data may be disclosed to law enforcement, government bodies, or legal authorities if required under enforceable statutory laws or judicial orders.

6. International Data Transfers

As an entity operating in the United Kingdom, some of our third-party infrastructure partners (such as cloud hosting or payment processing infrastructure) may process data outside the UK or the European Economic Area (EEA).

Where international transfers occur, we ensure appropriate safeguards are implemented in compliance with UK GDPR and EU GDPR guidelines, including relying on Adequacy Decisions issued by the relevant regulatory bodies or executing standard contractual safeguards such as the UK International Data Transfer Agreement (IDTA) and EU Standard Contractual Clauses (SCCs).

7. Data Retention Schedule

We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected or to satisfy legal retention mandates:

  • Order & Financial Records: Retained for up to 6 years following transaction completion in accordance with UK statutory tax requirements (HM Revenue & Customs) and corporate financial reporting obligations.
  • Customer Support Inquiries: Retained for up to 24 months from the date of ticket resolution to maintain service continuity and address follow-up customer inquiries.
  • Technical Security Logs: Retained in line with standard web server logging protocols for diagnostic and cybersecurity auditing.

Upon the expiration of applicable legal retention periods, personal data is permanently destroyed, deleted, or fully anonymized.

8. Your Data Protection Rights

Under UK GDPR and EU GDPR regulations, you hold the following statutory rights regarding your personal information:

  • Right to Access: Request confirmation of and access to a copy of the personal information we process about you.
  • Right to Rectification: Request correction of inaccurate, outdated, or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of personal data where retention is no longer legally or contractually mandated.
  • Right to Restrict or Object: Limit or object to specific processing activities under legal grounds.
  • Right to Data Portability: Request transfer of structured personal data to yourself or another controller.

To exercise any of these statutory rights, please contact us at dashboard@nodrillbath.com. You also maintain the statutory right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or your local EU Data Protection Authority.

9. Cookies and Tracking Technologies

www.nodrillbath.com utilizes strictly necessary functional cookies for store navigation, cart persistence, and checkout security, as well as optional analytical cookies to evaluate site activity. Users can control and manage cookie preferences through their individual web browser settings or on-site consent prompts.

10. Updates to This Privacy Policy

We reserve the right to amend this Privacy Policy periodically to reflect operational, legal, or regulatory updates. Any changes will be published directly on this page and will take effect immediately upon posting.