Privacy policy

Hälsa Trä Privacy Policy (UK GDPR Compliant)

This Privacy Policy outlines how Hälsa Trä ("we", "us", "our") collects, uses, stores, and protects your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Information We Collect

We collect personal data when:

- You visit our website

- You make a purchase

- You sign up for our newsletter

- You contact our support team

Types of data collected may include:

- Full name

- Email address

- Postal address

- Phone number

- Payment details (via secure third parties)

- IP address, browser type, and device information

2. Lawful Basis for Processing

We process your data only where there is a legal basis to do so, including:

- Contract: To process your order and deliver products.

- Consent: For marketing communications (opt-in).

- Legitimate interest: To improve our website, marketing, and customer service.

- Legal obligation: To comply with UK laws and tax regulations.

3. How We Use Your Data

Your personal data is used for:

- Processing and fulfilling orders

- Responding to enquiries

- Sending marketing emails (if you opt-in)

- Improving our website and services

- Preventing fraud

4. Cookies & Tracking Technologies

We use cookies for functionality, analytics, and personalised marketing.

You can manage cookie preferences in your browser settings. For more details, see our [Cookie Policy].

5. Data Sharing

We only share your personal data with:

- Payment providers (e.g., PayPal, Stripe)

- Delivery partners

- Email marketing platforms (e.g., Mailchimp)

- Analytics tools (e.g., Google Analytics)

We ensure these third parties meet UK GDPR compliance standards. Data transfers outside the UK are protected by Standard Contractual Clauses or equivalent safeguards.

6. Data Retention

We retain your data only as long as necessary for the purpose it was collected, including satisfying legal, accounting, or reporting obligations. Typically:

- Order data: up to 6 years (for tax/reporting)

- Newsletter data: until you unsubscribe

7. Your Rights

Under the UK GDPR, you have rights including:

- Right to access

- Right to rectification

- Right to erasure ("right to be forgotten")

- Right to restrict processing

- Right to data portability

- Right to object to marketing

To exercise these rights, email: privacy@halsatra.co.uk

8. Security

We use secure protocols (HTTPS, SSL) and store data on secure servers. Payment data is handled only by PCI-compliant providers.

9. Changes to This Policy

We may update this policy occasionally. Changes will be posted on this page with an updated revision date.

Last updated: April 2025

10. Contact Us

If you have questions or complaints about this policy or your data, please contact us here.