Last Updated: 30/01/2025
At Cornelli Sugarcraft, we are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the UK GDPR, Data Protection Act 2018, and PECR (Privacy and Electronic Communications Regulations).
1. Information We Collect
We may collect and process the following personal data:
- Identity Data: Name
- Contact Data: Billing and delivery address, email address, and telephone number
- Transaction Data: Details of payments, orders, and purchases made through our website
- Technical Data: IP address, browser type, time zone settings, device type, and usage data collected via cookies
- Usage Data: Information on how you interact with our website, including pages visited and actions taken
- Marketing & Communication Data: Preferences for receiving marketing communications
2. How We Collect Your Data
We collect personal data through the following methods:
- Direct Interactions: When you place an order, sign up for a class, request information, or contact us directly.
- Automated Technologies: Website analytics and cookies collect data about browsing patterns.
- Third Parties: Payment providers and analytics services (e.g., Google Analytics, Meta Pixel).
3. How We Use Your Data
We use your personal data to:
- Process orders and provide services (e.g., bespoke cakes, classes, workshops)
- Manage customer accounts and provide support
- Send marketing emails (only if you have opted in)
- Improve our website and services through analytics and customer feedback
- Ensure security and fraud prevention
We will only use your personal data when the law allows us to. The most common legal bases for processing your data are:
- Performance of a Contract: When processing your orders or bookings.
- Legitimate Interests: Improving our services and understanding customer needs.
- Consent: When sending marketing communications (which you can opt out of anytime).
4. Marketing & Communication
If you opt in to receive updates, we may send you occasional emails about new workshops, products, and offers. You can unsubscribe anytime via the link in our emails or by contacting us directly.
We do not sell or share your data with third-party advertisers.
5. Sharing Your Data
We only share your data when necessary, including:
- Payment Processing: Secure third-party providers (e.g., Stripe, PayPal).
- Website Analytics: Google Analytics and Meta Pixel (for tracking user interactions).
- Legal Obligations: If required by law, we may share data with regulatory authorities.
We do not sell, rent, or trade your data with third parties.
6. Cookies & Tracking Technologies
Our website uses cookies to enhance user experience and improve functionality. You can manage or disable cookies via your browser settings. See our Cookies Policy for full details.
7. Data Retention
We only keep personal data for as long as necessary:
- Order records: Retained for tax/legal purposes for up to 6 years.
- Marketing data: Retained until you opt out.
- Account information: Retained while your account is active.
When no longer needed, data is securely deleted or anonymized.
8. Your GDPR Rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion (“Right to be Forgotten”)
- Object to processing (e.g., for marketing purposes)
- Restrict processing under certain conditions
- Request data portability
To exercise your rights, contact us at [Insert Contact Email]. We respond within 30 days.
9. Data Security
We use encryption, secure payment gateways, and access controls to protect your personal data. However, no method is 100% secure, and we recommend keeping your login details private.
10. Changes to This Policy
We may update this Privacy Policy as needed. Any significant changes will be highlighted on our website.
11. Contact Us
If you have questions about this Privacy Policy or your personal data, please contact us at debbie@cornelli.co.uk
For complaints, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at www.ico.org.uk.