Privacy Policy
Welcome to Felted Wool privacy notice.
Felted Wool respects your privacy and is committed to protecting your personal data. This privacy notice will inform you as to how we look after your personal data when you visit our website, register to use our products and services, and tell you about your privacy rights and how the law protects you.
For the purposes of this privacy notice, the term “Website” shall refer to feltedwoolshop.com as well as any other sites we operate that link to this privacy notice.
1. Who is the data controller?
The data controller for the processing described in this notice is Felted Wool.
2. Information we collect and how we collect it
In the following, we will tell you which types of personal data we may collect about you and how we collect it. In section 3, we have explained in a table the purposes for which we process your personal data and the lawful basis we rely on.
We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:
- Identity Data includes name, username, or similar identifier.
- Contact Data includes email address and delivery address.
- Financial Data includes payment card details.
- Transaction Data includes details about payments from you and other details of products you have purchased from us.
- Technical Data includes IP address, your login data, browser type and version, time zone setting and location, operating system and platform, and other technology on the devices you use to access this website.
- Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback, and survey responses.
- Usage Data includes information about how you use and interact with our website, products, and services.
- Marketing and Communications Data includes your preferences in receiving marketing from us.
In most situations, the information is collected directly from you when you place an order, request marketing from us, or otherwise communicate with us.
As you interact with our website, we may automatically collect Technical Data and Usage Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies and similar technologies.
3. The purposes and the lawful basis
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation.
- Where you have provided your consent.
We have set out below, in a table format, a description of the ways we plan to use your personal data and which of the legal bases we rely on to do so.
| Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
|---|---|---|
| To register you as a new customer | (a) Identity (b) Contact | Performance of a contract with you |
| To manage and perform our contract with you including: (a) Process and deliver your order (b) Manage payments (c) Collect money owed to us | (a) Identity (b) Contact (c) Financial (d) Transaction (e) Profile | (a) Performance of a contract with you (b) Necessary to comply with a legal obligation |
| To send you newsletters or other marketing | (a) Identity (b) Contact (c) Marketing and Communications | (a) Your consent (b) Necessary for our legitimate interests to send you relevant marketing |
| To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data) | (a) Identity (b) Contact (c) Technical (d) Usage | Necessary for our legitimate interests for running our business, provision of administration and IT services, network security, and to prevent fraud |
| To use data analytics to improve our website, products/services, marketing, customer relationships, and experiences | (a) Technical (b) Usage | (a) Your consent(s) to our use of cookies (b) Necessary for our legitimate interests to keep our website updated and relevant, to develop our business, and to inform our marketing strategy |
4. Sharing of information collected
- Third-Party Service Providers: We share information with our third-party service providers that we use to provide hosting for and maintenance of our Website, payment processing, marketing, analytics, and other services for us. These providers may have access to or process your personal information for the purpose of providing these services for us. We do not permit them to use your personal information for any other purpose.
- Compliance with Laws and Law Enforcement Requests: In certain situations, we may be required to disclose personal information in response to lawful requests by public authorities. We may also disclose personal information to establish or exercise our legal rights or defend against legal claims.
- Testimonials: From time to time, we may post testimonials on the Website that may contain personal information. We will obtain your consent before posting your name along with your testimonial.
- Business Transfers: We may assign or transfer your account and related information, including any personal information, to any person or entity that acquires all or substantially all of our business, stock, or assets, or with whom we merge.
5. Transfer to third countries
We will not transfer your personal data to recipients outside the EU or EEA unless we have ensured compliance with GDPR Chapter V. Some of our third-party service providers may be established outside the EEA. To ensure your personal information receives an adequate level of protection, we ascertain that sufficient safety measures have been implemented, such as standard contractual clauses approved by the European Commission.
6. Data retention
We retain the personal information we collect where we have an ongoing legitimate business need to do so. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it.
- Identity, Contact, Financial, and Transaction Data is saved for bookkeeping and tax purposes for up to five full fiscal years after the year of your purchase.
- Your consent to receive e-marketing will be saved for two years after the last time we relied on it. We will stop sending you e-marketing when you withdraw your consent.
- Technical and Usage Data will be deleted within a reasonable period after you cease interacting with our services.
7. How to exercise your data protection rights
You have certain choices available to you regarding your personal information. Below is a summary of those choices and how to exercise them:
- Request access to your personal information. This enables you to receive a copy of the personal information we hold about you.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it.
- Object to processing of your personal information where we are relying on a legitimate interest. You also have the right to object where we are processing your personal information for direct marketing purposes. You may manage this by clicking the “unsubscribe” link in our marketing emails.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you.
- Request the transfer of your personal information to another party.
- Withdraw your consent at any time where our processing is solely based on your specific consent. Such withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.
If you wish to exercise any of these rights, please contact us, and we will action your request in accordance with applicable data protection laws.
You also have the right to complain to your local data protection authority if you are unhappy with our data protection practices.
I hope this revised Privacy Policy meets all your requirements. Let me know if you need any further adjustments.
