Who we are
Our website address is https://essentiaselectuk.com.
This Privacy Policy explains how Essentia Select UK (“we,” “us,” “our”), operating through the website essentiaselectuk.com, collects, uses, stores, and protects your personal data. We are committed to handling your information responsibly and in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using our website and services, you acknowledge that you have read and understood this policy.
If you have any questions or concerns about how we handle your personal data, please do not hesitate to contact us using the details provided at the end of this document.
1. Who We Are
Essentia Select UK is the data controller responsible for your personal data. This means we determine the purposes and means by which your personal information is processed. Our website is located at essentiaselectuk.com, and we are based in the United Kingdom. As data controllers, we are legally accountable for ensuring that any personal data we hold about you is processed lawfully, fairly, and transparently.
For all data protection inquiries, you can reach us at info@essentiaselectuk.com.
2. What Personal Data We Collect
We may collect various types of personal data from you depending on how you interact with our website. The categories of data we collect include the following:
Identity and Contact Information: This includes your full name, email address, phone number, billing address, and delivery address. We collect this information when you create an account, place an order, or contact us directly.
Transaction and Order Data: When you make a purchase, we collect details about the products you have ordered, the transaction amount, payment method type (e.g., credit card, PayPal), and order history. Please note that we do not store your full card details directly—payment processing is handled securely by our third-party payment providers.
Technical and Usage Data: When you visit our website, we automatically collect certain technical information, including your IP address, browser type and version, operating system, referring URLs, pages viewed, time spent on pages, and other diagnostic data. This information helps us understand how visitors use our website and allows us to improve the experience.
Communications Data: If you contact us via email, a contact form, or live chat, we retain records of those communications, including the content of your messages, to help us respond effectively and resolve any issues.
Marketing and Preference Data: With your consent, we may collect information about your preferences for receiving marketing communications from us, including email newsletters and promotional offers. We also track whether you have opened our emails or clicked on links to help us understand engagement and improve our communications.
We do not intentionally collect sensitive personal data (also known as special category data) such as health information, racial or ethnic origin, or financial account details beyond what is necessary to process your payment. If you provide such information voluntarily, we will handle it with additional care.
3. How We Collect Your Data
We collect personal data through several means, which can be summarized as follows:
- Direct interactions: Data you provide when registering for an account, placing an order, subscribing to our newsletter, completing a contact form, or communicating with our customer service team.
- Automated technologies: Data collected automatically as you browse our website through the use of cookies, web beacons, and similar tracking technologies. Please refer to Section 6 for more detail on our use of cookies.
- Third parties: In some circumstances, we may receive data about you from third parties such as analytics providers (e.g., Google Analytics), social media platforms (e.g., if you use a social login feature), and payment processors who may share transaction confirmation data with us.
4. Legal Basis for Processing Your Data
Under the UK GDPR, we are required to identify a lawful basis for processing your personal data. The following explains the purposes for which we use your data and the corresponding legal basis under Article 6 of the UK GDPR:
Performance of a Contract (Article 6(1)(b)): We process your identity, contact, and transaction data to fulfill orders you place with us, manage your account, arrange delivery of your purchases, and provide post-sale support. Without this processing, we would be unable to provide our services to you.
Legitimate Interests (Article 6(1)(f)): We process technical and usage data to analyze website traffic, understand how our site is being used, detect fraud and ensure site security, and improve the overall user experience. We have assessed that these interests are not overridden by your rights and freedoms, given the minimal intrusiveness of the processing and the expected nature of it for a retail website.
Consent (Article 6(1)(a)): Where we send you marketing emails or use non-essential cookies, we do so only with your explicit consent. You may withdraw your consent at any time by unsubscribing from our emails or adjusting your cookie preferences.
Legal Obligation (Article 6(1)(c)): In certain circumstances, we are required by law to process and retain your data, such as for tax record-keeping purposes under HMRC requirements or to comply with court orders.
5. How We Use Your Data
In addition to the purposes described above, we use your personal data for the following specific activities:
- Processing and fulfilling your orders, including arranging payment, delivery, and any returns or refunds.
- Creating and managing your customer account, where applicable.
- Sending you order confirmations, shipping updates, and other transactional communications essential to your purchase.
- Responding to your inquiries, complaints, or feedback promptly and effectively.
- Sending you marketing emails, promotional offers, and newsletters where you have opted in to receive them.
- Personalizing your browsing experience and showing you products that may be relevant to your interests.
- Monitoring and analyzing trends, usage, and activities in connection with our website to improve our product offerings and user experience.
- Detecting and preventing fraudulent transactions, unauthorized access, and other illegal activities.
- Complying with legal and regulatory obligations.
We will not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without first obtaining your explicit consent.
6. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your experience, understand how you use our site, and support our marketing efforts. A cookie is a small text file placed on your device when you visit a website. Some cookies are essential for the website to function, while others are optional and require your consent.
Essential Cookies: These are strictly necessary for the website to operate correctly. They enable core functionality such as shopping cart management, user account sessions, and security features. These cookies cannot be disabled without significantly affecting the functionality of the site, and they do not require your consent under the Privacy and Electronic Communications Regulations (PECR).
Analytics Cookies: We use analytics tools, including Google Analytics, to understand how visitors interact with our website. These cookies collect information such as which pages are visited most frequently, how long users spend on the site, and what actions they take. This data is aggregated and anonymized. Analytics cookies require your consent before being set.
Marketing and Advertising Cookies: These cookies are used to deliver advertisements relevant to you and your interests. They may also be used to limit the number of times you see an advertisement and to measure the effectiveness of advertising campaigns. These cookies require your consent before being set.
Functional Cookies: These cookies allow the website to remember choices you make (such as your language or region preferences) and provide enhanced, more personalized features. They require your consent before being set.
You can manage your cookie preferences at any time through the cookie consent banner displayed when you first visit our site or by adjusting the settings in your browser. Please note that if you disable all cookies, some features of our website may not work as intended.
7. Sharing Your Personal Data
We take the privacy of your personal data seriously and do not sell, rent, or trade your information to third parties for their own marketing purposes. However, we may share your data with trusted third parties in the following circumstances:
Payment Processors: We use third-party payment service providers (such as Stripe or PayPal) to process transactions securely. These providers receive only the information necessary to process your payment and are bound by their own privacy policies and security standards. We do not receive or store your full card details.
Delivery and Logistics Partners: In order to fulfill your orders, we share your name and delivery address with courier and logistics companies. These partners are authorized to use this information solely for the purpose of completing your delivery.
Email Marketing Platforms: Where you have opted in to receive marketing communications, we may share your email address and communication preferences with email marketing providers (such as Mailchimp or Klaviyo) to manage and send our newsletters and promotional emails.
Analytics Providers: We share anonymized and aggregated usage data with analytics providers to help us understand website performance and user behavior. Individual users are not identifiable through this data.
IT and Hosting Service Providers: Our website and data are hosted on third-party servers. Our hosting providers may have access to your data as part of providing infrastructure services and are bound by data processing agreements.
Legal and Regulatory Authorities: We may disclose your personal data to law enforcement agencies, courts, regulatory bodies, or other public authorities where required by law or where we believe it is necessary to protect our legal rights or the safety of others.
All third parties with whom we share your data are required to maintain appropriate technical and organizational security measures and are only permitted to process your data in accordance with our instructions and applicable data protection law.
8. International Data Transfers
Some of our third-party service providers are based outside the United Kingdom. When we transfer personal data to countries outside the UK, we ensure that appropriate safeguards are in place to protect your information. These safeguards may include:
- Transfers to countries that have been granted an adequacy decision by the UK Government, meaning they are considered to provide a level of data protection equivalent to the UK.
- Use of UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) approved by the Information Commissioner’s Office (ICO), which contractually obligate the recipient to protect your data to UK GDPR standards.
- Binding Corporate Rules or other approved transfer mechanisms where applicable.
If you would like more information about the specific safeguards we use in relation to international transfers, please contact us at privacy@essentiaselectuk.com.
9. Data Retention
We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. The following retention periods apply:
- Order and transaction records: Retained for 7 years from the date of the transaction, in accordance with HMRC tax record-keeping obligations.
- Customer account data: Retained for the duration of your account and for a period of 2 years following account closure, to facilitate any post-closure queries or disputes.
- Marketing consent records: Retained until you withdraw your consent or unsubscribe from marketing communications, plus a further 12 months for compliance purposes.
- Website analytics data: Retained for up to 26 months, with anonymization of identifiable elements after 14 months.
- Customer service communications: Retained for up to 3 years to assist with any ongoing disputes or follow-up queries.
Once your data is no longer required, we will securely delete or anonymize it in accordance with our data retention and disposal procedures.
10. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organizational measures to protect it against accidental loss, unauthorized access, disclosure, alteration, or destruction. These measures include:
- SSL/TLS encryption for all data transmitted between your browser and our website.
- Secure server environments with access controls, firewalls, and intrusion detection systems.
- Restricted access to personal data on a need-to-know basis, with all staff who handle customer data trained on data protection obligations.
- Regular security assessments and updates to our systems and software.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by UK GDPR.
While we take all reasonable steps to protect your data, please be aware that no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
11. Your Rights Under UK GDPR
Under the UK General Data Protection Regulation, you have a number of important rights in relation to your personal data. These rights are explained in detail below:
Right of Access: You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will provide this information within one calendar month of receiving your request, free of charge in most circumstances.
Right to Rectification: If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or update it without undue delay.
Right to Erasure (‘Right to be Forgotten’): In certain circumstances, you have the right to request that we delete your personal data. This right applies where the data is no longer necessary for the purpose it was collected, you withdraw consent (where consent was the legal basis), you object to the processing and we have no overriding legitimate grounds, or the data has been unlawfully processed.
Right to Restriction of Processing: You may request that we restrict the processing of your personal data in certain circumstances, for example, whilst we verify the accuracy of data you have disputed or whilst we consider an objection you have raised.
Right to Data Portability: Where we process your data based on your consent or for the performance of a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object: You have the right to object at any time to our processing of your personal data where that processing is based on legitimate interests or carried out for direct marketing purposes. If you object to direct marketing, we will stop processing your data for that purpose immediately.
Rights in Relation to Automated Decision-Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you.
To exercise any of these rights, please contact us at privacy@essentiaselectuk.com with your full name and sufficient information to identify your account. We will respond within one calendar month. We may need to verify your identity before fulfilling certain requests.
12. Children’s Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe that a child under 16 has provided us with their personal information without appropriate parental or guardian consent, please contact us immediately at privacy@essentiaselectuk.com, and we will take steps to delete such data promptly.
13. Third-Party Links
Our website may contain links to third-party websites, social media platforms, or online services that are operated independently and are not covered by this Privacy Policy. We are not responsible for the privacy practices of those third-party sites and encourage you to review their privacy policies before providing any personal data to them. The inclusion of a link on our website does not constitute an endorsement of that website or its privacy practices.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or how we handle personal data. When we make significant changes, we will update the “Last Updated” date at the top of this document and, where appropriate, notify you by email or by displaying a prominent notice on our website.
We encourage you to review this policy periodically to stay informed about how we are protecting your information. Your continued use of our website following any changes constitutes your acceptance of the updated policy.
15. How to Complain
If you are unhappy with how we have handled your personal data or responded to a rights request, you have the right to lodge a complaint with the UK’s supervisory authority for data protection:
Information Commissioner’s Office (ICO)
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please do contact us in the first instance at privacy@essentiaselectuk.com.
16. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing activities, please contact us:
- Email: privacy@essentiaselectuk.com
- Website: essentiaselectuk.com
- Subject line: “Data Protection Enquiry”
We aim to respond to all enquiries within 5 business days and to fulfil any formal rights requests within one calendar month