OUR PRIVACY POLICY

The points below are in place to help protect customer data and ensure compliance with data protection laws introduced on 25th May 2018. These are based on key GDPR principles and are covered in more detail by the ICO (Information Commissioner’s Office) at www.ico.org.uk.


1. FAIR AND LAWFUL USE

We only retain the following information, and only where consent has been given (e.g. newsletter sign-up):
a. Name
b. Address
c. Telephone number
d. Email address


2. WHY DATA IS COLLECTED

This data is used for:
a. Contacting you via email (with unsubscribe option) regarding news and offers
b. Internal business use only — we never share your data with third parties


3. DATA ADEQUACY & MINIMISATION

We do not proactively contact customers to verify data accuracy, as this may be intrusive.


4. DATA ACCURACY & SECURITY

a. Customer data listed above is retained indefinitely unless removal is requested
b. Card details are encrypted for online payments — we do not have access to them
c. Phone payment details are destroyed immediately after transaction authorisation


5. DATA RETENTION

Customer data is stored in one of the following ways:
a. Electronically via email correspondence
b. Securely stored in a non-networked storage system


6. RIGHTS OF INDIVIDUALS

We ensure GDPR compliance and protect customer data accordingly. Our processes are reviewed annually.


7. DATA ACCESS REQUESTS

Customers may request access to their personal data in writing. Requests will be fulfilled within 60 days and must relate only to the individual making the request.

Requests should be sent to:
Tim Duke
TIM DUKE ORIGINALS


8. POLICY UPDATES

We reserve the right to amend this policy in line with audit findings and updates to GDPR regulations.