BACKGROUND:
This Policy applies as between you, the User of this Website and Lighting Loft LTD, the owner and provider of this Website. This Policy applies to our use of any and all Data collected by us in relation to your use of the Website and any Services or Systems therein.

1. Important Information and Who We Are

1.1 Our website is not intended for children, and we do not knowingly collect data relating to children.

1.2 This Privacy Policy supplements our other policies (including our Terms of Use) and does not override them.

1.3 Lighting Loft LTD is the controller and responsible for your personal data (referred to as “we,” “us,” or “our”).

1.4 To assist you further in understanding this Privacy Policy, we have set out in Part 5 of Schedule 1 a glossary of terms used, examples of types of personal data we collect, how we use it, the lawful basis for processing such data, and further details of your rights.

1.5 We have appointed a data privacy manager (DPM). If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPM in writing:

1.6 By email to: legal@lightingloft.co.uk

1.7 By post to: Lighting Loft LTD, 14/2E Docklands Business Centre, 10-16 Tiller Road, London, E14 8PX

1.8 You have the right to make a complaint at any time to the ICO (www.ico.org.uk). However, we would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.

1.9 It is important that the data we hold about you is accurate and current. Please keep us informed of any changes to your personal data.

1.10 Our website may include links to third-party websites, plug-ins, and applications. By clicking on these links or enabling connections, you may allow third parties to collect or share your personal data. We have no control over third-party websites, plug-ins, or applications and are not responsible for their privacy policies. Please review their privacy policies to understand how they use your personal data.

2. The Data We Collect About You

2.1 We may collect, use, store, and transfer the types of personal data listed in Part 1 of Schedule 1.

2.2 We also collect, use, and share aggregated data. However, if we combine aggregated data with your personal data such that it can identify you, we treat it as personal data.

2.3 We do not collect special categories of personal data or any information about criminal convictions and offences.

2.4 If we are required by law or under a contract to collect your personal data and you fail to provide it, we may not be able to perform the contract with you, and we may have to cancel a product or service. We will notify you of this at the relevant time.

3. How Is Your Personal Data Collected?

We collect personal data in the following ways:

  • Direct Interactions: You may provide personal data when completing online forms, requesting products/services, subscribing to services, creating a user account, or otherwise corresponding with us (via post, phone, or email).
  • Automated Technologies: We automatically collect technical and usage personal data when you browse or interact with our website, using cookies, server logs, and similar technologies.
  • Publicly Available Sources: We may collect personal data from publicly available sources such as Companies House and the Electoral Register within the EU.
  • Third Parties: We may receive personal data from:
    • Analytics providers based outside the EU (e.g., Google);
    • Advertising networks based inside or outside the EU;
    • Search information providers inside or outside the EU;
    • Our suppliers, including payment providers, delivery services, website support, and maintenance providers.

4. How We Use Your Personal Data

4.1 We will only use your personal data when the law allows us to. Most commonly, we will use your personal data:

4.2 To perform a contract we are about to enter into or have entered into with you.

4.3 To comply with a legal obligation.

4.4 Where it is necessary to carry out our legitimate interests (or those of a third party), provided that your interests and fundamental rights do not override those interests.

4.5 Part 2 of Schedule 1 sets out the lawful basis we will rely on to process your personal data.

4.6 We generally only rely on consent for processing personal data related to email and SMS marketing communications. You have the right to withdraw your consent at any time by contacting us.

4.7 We may analyse your personal data to determine what products or services may interest you. You will only receive marketing communications from us if you have requested information or purchased services from us and have not opted out.

4.8 We do not share your personal data with third parties for their marketing purposes.

4.9 You can opt out of email marketing by clicking the unsubscribe button in the email or by contacting our DPM.

4.10 Even if you opt out of marketing, we may still use your personal data for other purposes where we have a lawful basis to do so.

5. Disclosures of Your Personal Data

5.1 We may share your personal data with third parties as set out in Part 4 of Schedule 1. All third parties must respect the security of your personal data and treat it in accordance with the law.

6. International Transfers

6.1 We do not transfer your personal data outside the European Economic Area (EEA).

7. Data Security

7.1 We have implemented security measures to protect your personal data from being accidentally lost, accessed, altered, or disclosed.

8. Data Retention

8.1 We retain personal data only as long as necessary for the purposes for which it was collected, including legal, accounting, and reporting obligations.

9. Your Legal Rights

9.1 You have rights under data protection law. To exercise any of your rights, please contact our DPM.

10. Changes to This Policy

10.1 Lighting Loft LTD reserves the right to update this Privacy Policy as necessary or required by law. Any changes will be immediately posted on the website, and continued use of the website indicates acceptance of the updated Policy.