Privacy Policy

This Privacy Policy describes how www.vellabio.co.uk (the “Site” or “we”) collects, uses, processes and discloses your Personal Information when you visit or make a purchase from the Site. We, and the entities we sponsor, have security measures in place to protect the loss, misuse, and alteration of the information under our control, to comply with GDPR and other laws. While we make every effort to ensure the integrity and security of our network and systems, we cannot guarantee that our security measures will prevent third-party “hackers” from illegally obtaining this information.

It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide when we are collecting or processing personal data about you so you are fully aware of how and why we are using your data.

Who We Are

The Site is owned and run by Kenneth Green Associates Limited (KGA). For data protection law, the controller is KGA of Hill House, Monument Hill, Weybridge, Surrey, KT13 8RX, United Kingdom and we are responsible for your personal data

Contact

After reviewing this policy, if you have additional questions, want more information about our privacy practices, or would like to make a complaint, please contact us by e-mail at enquiries@vellabio.co.uk.

Collecting Personal Information

When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information about an identifiable individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.

  • Device information
    • Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.
    • Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
    • Disclosure for a business purpose: shared with our processor Shopify.
    • Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
  • Order information
    • Purpose of collection: to provide products or services to you to fulfil our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services. For those customers who register an account, some of this information will be stored for you to access once logged in.
    • Source of collection: collected from you.
    • Disclosure for a business purpose: shared with our processor Shopify, warehouse BDM, payment processors Paytriot, and internal ordering systems including Navision.
    • Personal Information collected: name, billing address, shipping address, payment information (including credit/debit card numbers, Apple Pay accounts, email address, and phone number.
  • Customer support information
    • Purpose of collection: to provide customer support.
    • Source of collection: collected from you.
    • Disclosure for a business purpose: Internal teams at KGA
    • Personal Information collected: Name, email address, payment information, order information past and present, phone number.
  • Email subscription information
    • Only relevant if you agree to receive email marketing from ‘Vellabio’
    • Purpose of collection: to send you marketing emails. These will include, but are not limited to, promotions, information on new products, brand news, category news and articles.
    • Source of collection: collected from you.
    • Disclosure for a business purpose: your data will be hosted in Shopify when you opt-in to email marketing. KGA will use the Shopify Email app to build, send and analyse email campaigns delivered to customers who have subscribed.
    • Personal Information: name, email address, address, gender, birthday, preferences.

Minors

The Site is not intended for individuals under the age of 18. We do not intentionally collect Personal Information from children. If you are the parent or guardian and believe your child has provided us with Personal Information, please contact us at the address above to request deletion.

Placing orders for others

If you complete an order for someone else, such as a gift order sent directly to a recipient, you may be asked to provide information about the recipient, such as name, address, email address and phone number. We have no control over the third parties’ use of any Personal Information you provide when placing such an order. Please exercise care when doing so. If you order products directly from the Site we will use the Personal Information you provide only to process that order. We do not share this with outside parties except to the extent necessary to complete that order.

Sharing Personal Information

We share your Personal Information with service providers to help us provide our services and fulfil our contracts with you, as described above. For example:

  • We use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
  • We may share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
  • If consented by yourselves, we may share your Personal Information with our customer database processor to send you marketing related emails and track the performance of these campaigns.

Behavioural Advertising

As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:

For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at https://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising by:

Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: https://optout.aboutads.info/.

Using Personal Information

We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfilment of your order, and keeping you up to date on new products, services, and offers.

Lawful basis

Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your personal information under the following lawful bases:

  • Your consent;
  • The performance of the contract between you and the Site;
  • Compliance with our legal obligations;
  • To protect your vital interests;
  • To perform a task carried out in the public interest;
  • For our legitimate interests, which do not override your fundamental rights and freedoms.

Retention

When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. Some information will need to be retained for compliance with our legal obligations. For more information on your right of erasure, please see the ‘Your legal rights’ section below.

Automatic decision-making

If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.

We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.

Services that include elements of automated decision-making include:

  • Temporary blacklist of IP addresses associated with repeated failed transactions. This blacklist persists for a small number of hours.
  • Temporary blacklist of credit cards associated with blacklisted IP addresses. This blacklist persists for a small number of days.

Your legal rights

GDPR

If you are a resident of the UK or EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the details provided under “Contact” above.

Your Personal Information will be accessible by KGA but hosted in and processed by Shopify. It will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper. This also relates to UK GDPR and the UK Data Protection Act. https://help.shopify.com/en/manual/your-account/privacy/GDPR.

In order to deliver your product KGA and its chosen partners will need to utilise your personal data. KGA and its chosen partners take the required measures to ensure data is protected and processed in a way compliant with UK GDPR and the UK Data Protection Act.

Cookies

A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.

The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.

You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.

Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as: www.allaboutcookies.org.

Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please follow the instructions in the “Behavioural Advertising” section above.

Do Not Track

Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

Changes

We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

Complaints

As noted above, if you would like to make a complaint, please contact us by e-mail or by mail using the details provided under “Contact” above.

If you are not satisfied with our response to your complaint, you have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance as detailed above. 

Last updated: November 2022

Your Bag