top of page

PRIVACY
POLICY

Here at Iris Charles, we deeply respect your privacy and are determined to protect your personal data. The purpose of this privacy notice is to inform you as to how we look after your personal data when you visit our website and when you place a purchase order. We’ll also tell you about your privacy rights and how data protection law protects you.

What information we collect, use, and why

We collect or use the following information to provide services and goods, including delivery:

              Names and contact details

              Addresses

              Purchase or account history

              Payment details (including card or bank information for transfers and direct debits)

              Website user information (including user journeys and cookie tracking)

              Information relating to compliments or complaints

We collect or use the following information for service updates or marketing purposes:

               Names and contact details

               Addresses

               Purchase or viewing history

               IP addresses

               Website and app user journey information

 

We collect or use the following information to comply with legal requirements:

               Name

               Contact information

               Financial transaction information

We collect or use the following personal information for dealing with queries, complaints or claims:

               Names and contact details

               Purchase or service history

               Customer or client accounts and records       

               Financial transaction information

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are in brief set out below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

               Your right of access - You have the right to ask us for copies of your personal information. You can request other                                   information such as details about where we get personal information from and who we share personal information with.                   There are some exemptions which means you may not receive all the information you ask for. You can read more about                       this right here.

               Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or                   incomplete. You can read more about this right here.

               Your right to erasure - You have the right to ask us to delete your personal information. You can read more about this                           right here.

               Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information.                       You can read more about this right here.

               Your right to object to processing - You have the right to object to the processing of your personal data. You can read                           more about this right here.

               Your right to data portability - You have the right to ask that we transfer the personal information you gave us to                                 another organisation, or to you. You can read more about this right here.

               Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent                    at any time. You can read more about this right here.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide services and goods are:

               Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights                   may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

               Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data                 protection rights may apply except the right to object.

               Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection                     rights may apply, except the right to erasure, the right to object and the right to data portability.

 Our lawful bases for collecting or using personal information for service updates or marketing purposes are:

               Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights                   may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

               Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone                         else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to                       portability. Our legitimate interest is the interest of our business in conducting and managing our business to enable us to                 give you the best service/product and the most secure experience. We make sure we consider and balance any potential                   impact on you (both positive and negative) and your rights before we process your personal data for our legitimate                             interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless                 we have your consent or are otherwise required or permitted to by law).

 

Our lawful bases for collecting or using personal information for legal requirements are:

               Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights                   may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

               Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data                 protection rights may apply except the right to object.

               Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection                     rights may apply, except the right to erasure, the right to object and the right to data portability.

               Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

               Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights                   may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Where we get personal information from

Directly from you. You provide us with your personal information when making an order, accessing our Website or signing up for marketing or service updates. 

How long we keep information

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

 

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

 

Details of retention periods for different aspects of your personal data are available in our retention policy which you can request from us by email at irischarles@irischarles.co.uk.

In some circumstances you can ask us to delete your data: see Your legal rights below for further information.

In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

Who we share information with

               Internal Third Parties such as employees and contractors of Iris Charles Limited.

               External Third Parties Service such as delivery providers like Royal Mail

               Providers such as Wix who provide IT and system administration services and the hosting of this website.

               Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers who                           provide consultancy, banking, legal, insurance and accounting services.

               HM Revenue & Customs, regulators and other authorities acting as processors or joint controllers based in the United                         Kingdom who require reporting of processing activities in certain circumstances.

               Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we                         may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may                use your personal data in the same way as set out in this privacy notice but we will always let you know in advance.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Others we share personal information with

               Publicly on our website, social media or other marketing and information media

               Suppliers and service providers

Sharing information outside the UK

Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.

We share your personal data within wix.com. This will involve transferring your data outside the UK.

Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by implementing safeguards:

Please contact us here if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details here

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:           

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint

Last updated

Our Privacy Policy was last updated on 31 October 2024.

© Iris Charles 2025 All Rights Reserved.

Website lovingly designed by Rachael Does Design

  • Whatsapp number
  • Instagram
  • Facebook

​​Iris Charles is a trading name of Iris Charles Limited registered under Company number 15839188.

bottom of page