top of page

Privacy Policy

SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION?

We respect your privacy and are committed to protecting your personal data. We will not sell your data to third parties and will not contact you with unsolicited marketing messages.

When you purchase something from our store, as part of the buying and selling process, we collect personal information such as your name, address, email address, and payment information. This is processed on the legal basis of fulfilling our contractual obligations to you.

Additionally, when you browse our store, we automatically collect your internet protocol (IP) address, browser type, and operating system for the purposes of maintaining our website's functionality and security. This data is processed based on our legitimate interest in ensuring our site operates efficiently and securely.

If you opt into email marketing, we may, with your consent, send you emails about our store, new products, and other updates.

SECTION 2 - LEGAL BASIS FOR PROCESSING

Under GDPR, we process your personal data based on the following lawful grounds:

  • Performance of a contract: We collect and process personal data to fulfill orders, provide services, and manage your purchases.

  • Consent: When you opt-in for marketing communications, we rely on your explicit consent. You have the right to withdraw your consent at any time.

  • Legitimate interests: We may process your personal data for legitimate business purposes such as improving our services, preventing fraud, and enhancing security.

  • Legal obligation: We may need to process your data to comply with a legal obligation.

SECTION 3 - CONSENT

How do we obtain your consent?

When you provide personal information to complete a transaction, verify your payment method, place an order, or arrange delivery or returns, we imply that you consent to our collecting and using it for that specific purpose.

If we ask for your personal information for marketing purposes, we will explicitly request your consent, giving you the opportunity to opt-out.

SECTION 4 - YOUR RIGHTS UNDER GDPR

As a user in the European Economic Area (EEA), you have the following rights regarding your personal data:

  • Right of access: You have the right to request access to the personal data we hold about you.

  • Right of rectification: You may request correction of inaccurate or incomplete personal data.

  • Right to erasure (Right to be forgotten): You can ask us to delete your personal data where there is no longer a legitimate reason for holding it.

  • Right to restrict processing: You may request that we limit the processing of your personal data in certain circumstances.

  • Right to data portability: You have the right to request that we transfer your data to another service provider, where technically feasible.

  • Right to object: You can object to the processing of your personal data in some cases, such as for direct marketing purposes.

  • Right to withdraw consent: Where we rely on your consent for processing, you may withdraw that consent at any time.

You can exercise these rights by contacting us at info@flooddivert.co.uk or by mailing us at Flood Divert Ltd, Unit G7b, Elvington Industrial Estate, York, YO41 4AR, United Kingdom.

If you are not satisfied with how we handle your data, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the UK, or with your local data protection authority.

SECTION 5 - DATA RETENTION

We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention period may vary depending on the purpose of the data.

For example, we will retain transaction-related personal data for seven years to comply with tax and accounting regulations. For marketing communications, your data will be retained until you withdraw your consent.

SECTION 6 - DISCLOSURE OF PERSONAL DATA

We may disclose your personal data if required by law, or if you violate our Terms of Service. We may also disclose data to third-party service providers (as outlined below) in order to perform essential services, such as payment processing or shipping.

SECTION 7 - THIRD-PARTY SERVICES

We use third-party service providers to assist us in processing your orders and delivering our services. These third parties only have access to your personal data to the extent necessary to perform their functions and are obligated to protect your data.

We ensure that any third parties processing your data comply with GDPR, and where necessary, we have put in place Data Processing Agreements (DPAs) with these providers.

If any third-party provider is located outside the European Economic Area (EEA), we will ensure that your data is transferred in accordance with GDPR through mechanisms such as Standard Contractual Clauses (SCCs), which provide safeguards for data transfers.

SECTION 8 - SECURITY

We take the security of your personal data seriously. We implement industry best practices and follow GDPR guidelines to protect your data against unauthorized access, misuse, disclosure, or destruction.

Sensitive payment information is encrypted using secure socket layer technology (SSL) and stored using AES-256 encryption. While no system is completely secure, we follow all PCI-DSS requirements and implement additional security measures to protect your information.

SECTION 9 - INTERNATIONAL TRANSFERS

If your data is transferred outside the EEA, we will ensure it is protected by appropriate safeguards, such as SCCs, to ensure compliance with GDPR.

SECTION 10 - AGE OF CONSENT

By using this site, you confirm that you are at least the age of majority in your country of residence, or you have given us permission to allow any of your minor dependents to use this site.

SECTION 11 - CHANGES TO THIS PRIVACY POLICY

We reserve the right to update or modify this privacy policy at any time to comply with legal or regulatory changes, so please review it frequently. Any material changes will be posted on our website, and we will notify you of significant updates.

SECTION 12 - QUESTIONS AND CONTACT INFORMATION

For questions, or if you would like to: access, correct, amend, or delete any personal information we hold about you, register a complaint, or request more information, please contact our Privacy Compliance Officer at info@flooddivert.co.uk or by mail at:

Flood Divert Ltd
Unit G7b, Elvington Industrial Estate,
Elvington, York, YO41 4AR,
United Kingdom

bottom of page