Privacy Policy
Last updated: [Insert Date]
- Introduction Echo Home Furniture ("we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website, purchase our products, or otherwise interact with us. It applies to individuals located in England and is prepared in line with applicable UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our services, you agree to the collection and use of information in accordance with this Privacy Policy.
- Who We Are Echo Home Furniture is a furniture retailer operating in England. We design, market, and sell home furniture and related products.
If you have any questions about this Privacy Policy or our data practices, you can contact us at: Email: [Insert Contact Email] Address: [Insert Physical Address in England]
- Personal Data We Collect We may collect and process the following categories of personal data:
3.1 Information you provide to us directly
- Identity data: name, title, date of birth (if required), and other similar identifiers.
- Contact data: billing address, delivery address, email address, telephone number.
- Account data: login details, password, and preferences when you create an online account.
- Purchase and transaction data: details of products you have purchased, order history, payment status (note: we do not store full payment card numbers; these are processed by secure payment providers).
- Communication data: information that you provide when you contact us (by email, phone, or through forms on our website), including queries, complaints, and feedback.
3.2 Information we collect automatically When you visit our website, we may automatically collect:
- Technical data: IP address, browser type and version, device identifiers, time zone setting, operating system and platform.
- Usage data: information about how you use our website, such as pages visited, time spent on pages, clickstream data, and referring/exit pages.
- Cookie data: information collected through cookies and similar technologies (see Section 9 for more details).
3.3 Information from third parties We may receive information about you from:
- Payment processors and financial institutions, relating to payment verification and fraud prevention.
- Delivery and logistics partners, relating to the delivery of your orders.
- Advertising and analytics partners, relating to how you interact with our adverts and website.
- How We Use Your Personal Data We use your personal data only when we have a lawful basis to do so. We may use your information for the following purposes:
4.1 To provide our products and services
- To process and fulfil your orders, including delivery and returns.
- To manage payments, fees, and charges.
- To create and manage your customer account.
4.2 To communicate with you
- To respond to your enquiries and customer service requests.
- To send you information about changes to our terms, conditions, or policies.
- To contact you about recalls, safety notices, or important information relating to our furniture products.
4.3 Marketing and promotions
- To send you marketing communications about our furniture products, special offers, promotions, events, and news that may be of interest to you, where you have given your consent or where we otherwise have a lawful basis.
- To personalise marketing content and recommendations based on your preferences and previous purchases. You can opt out of marketing communications at any time (see Section 8).
4.4 Website operation and improvement
- To operate, maintain, and improve our website, products, and services.
- To analyse how our website is used and to measure the effectiveness of our advertising.
- To ensure the security of our website, systems, and data.
4.5 Legal, compliance, and security
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations, regulatory requirements, and court orders.
- To establish, exercise, or defend legal claims.
-
Legal Bases for Processing We rely on the following legal bases under the UK GDPR to process your personal data:
- Performance of a contract: where processing is necessary to fulfil a contract with you or to take steps at your request before entering into a contract (for example, to process your order or provide customer support).
- Consent: where you have given clear consent for us to process your personal data for a specific purpose (for example, to receive marketing emails). You may withdraw your consent at any time.
- Legitimate interests: where processing is necessary for our legitimate business interests, and your interests and fundamental rights do not override those interests (for example, to improve our website or prevent fraud).
- Legal obligation: where processing is necessary to comply with laws or regulatory requirements.
-
How We Share Your Personal Data We may share your personal data with the following categories of recipients, only to the extent necessary for the purposes described above:
- Service providers: third-party vendors who provide services on our behalf, such as payment processing, order fulfilment, delivery and logistics, IT support, web hosting, email and SMS services, marketing, and analytics.
- Professional advisers: lawyers, accountants, auditors, and insurers who provide professional services to us.
- Authorities and regulators: law enforcement agencies, courts, regulatory bodies, and other public authorities where required by law or to protect our legal rights.
- Business partners: where we collaborate with other companies for specific promotions or services, provided this is lawful and, where necessary, based on your consent.
We require all third parties that process your personal data on our behalf to protect it and to treat it in accordance with the law. They may only process your personal data in accordance with our instructions and not for their own purposes, unless they are independently responsible for such processing.
- International Data Transfers
Where your personal data is transferred outside the UK or the European Economic Area (EEA), we will ensure that appropriate safeguards are in place to protect your data, in accordance with UK data protection law. This may include:
- Transferring data only to countries that have been deemed to provide an adequate level of data protection; or
- Using standard contractual clauses or other approved transfer mechanisms.
You may contact us for more information on the specific safeguards used for international transfers.
- Your Rights
Under the UK GDPR, you have certain rights regarding your personal data. These may include:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to have inaccurate or incomplete data corrected.
- Right to erasure: to request that we delete your personal data, in certain circumstances.
- Right to restriction: to request that we restrict the processing of your personal data, in certain circumstances.
- Right to data portability: to receive your personal data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Right to object: to object to our processing of your personal data where we are relying on legitimate interests or conducting direct marketing.
- Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time.
To exercise any of these rights, please contact us using the details provided in Section 2. We may need to request specific information from you to confirm your identity before responding.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you are unhappy with how we handle your personal data. Further information is available at www.ico.org.uk.
- Cookies and Similar Technologies
We use cookies and similar technologies on our website to:
- Enable essential website functions.
- Remember your preferences and improve your browsing experience.
- Analyse site usage and performance.
- Support advertising and marketing, including personalised adverts.
You can manage or disable cookies through your browser settings. However, disabling certain cookies may affect the functionality and performance of our website. For more information, please refer to our separate Cookie Policy (if available) or contact us using the details in Section 2.
- Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These measures include:
- Secure servers and access controls.
- Encryption and pseudonymisation where appropriate.
- Regular monitoring, testing, and review of our security practices.
Despite our efforts, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
- Data Retention
We will keep your personal data only for as long as is necessary for the purposes for which it was collected, including to:
- Provide the products and services you have requested.
- Fulfil our legal, accounting, and reporting obligations.
- Resolve disputes and enforce our agreements.
When we no longer need your personal data, we will securely delete or anonymise it in accordance with our data retention policies.
-
Children’s Privacy Our website and services are not intended for children under the age of 16, and we do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete such information as soon as reasonably possible.
-
Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
-
Contact Us If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact us at:
Echo Home Furniture Email: [Insert Contact Email] Address: [Insert Physical Address in England]
We will do our best to respond promptly and address your concerns.