Privacy Policy

At Holywell Tools, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what information we collect about you, how we use it, who we share it with, and your rights under UK data protection law.

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

  • Holywell Tools Ltd
  • Company Number: 08619606
  • VAT Number: GB 213080948
  • Address: Unit 10 Cornwall Business Centre, Cornwall Road, Wigston, Leicester, LE18 4XH
  • Email: info@holywelltools.com
  • Phone: 0116 288 1110

If you have any questions about how we handle your data, please contact us using the details above.

2. What Personal Data We Collect

When you place an order:

  • Full name
  • Billing and delivery address
  • Email address
  • Phone number
  • Payment information (processed securely via our payment provider β€” we do not store card details)
  • Order history and transaction details

When you create an account:

  • Username and password (stored in encrypted form)
  • Saved addresses and preferences

When you use our website:

  • IP address and browser type
  • Pages visited and time spent on site
  • Referring website or search terms
  • Cookie and tracking data (see Section 7)

When you contact us:

  • Your name and contact details
  • The content of your message or enquiry

3. How We Use Your Personal Data

We use your personal data for the following purposes:

To fulfil your order (Contractual necessity):

  • Processing and dispatching your purchase
  • Sending order confirmations, shipping updates, and receipts
  • Handling returns, refunds, and warranty claims
  • Responding to customer service enquiries

To comply with legal obligations:

  • Maintaining financial and tax records
  • Fraud prevention and detection
  • Compliance with court orders or regulatory requirements

For our legitimate business interests:

  • Improving our website and product range based on usage patterns
  • Analysing sales data and customer trends
  • Preventing abuse of our services

With your consent:

  • Sending you marketing emails about new products, offers, and promotions
  • Placing non-essential cookies on your device

You may withdraw your consent at any time by unsubscribing from marketing emails or adjusting your cookie preferences.

4. Who We Share Your Data With

We do not sell your personal data. We only share it with trusted third parties where necessary to operate our business:

  • Payment processors (e.g. Stripe, PayPal) β€” to securely handle your payment
  • Delivery and logistics providers (e.g. Royal Mail, DPD, Evri) β€” to fulfil your order
  • Email service providers β€” to send transactional and marketing emails
  • Website hosting and ecommerce platform providers (e.g. WooCommerce/WordPress) β€” to operate our website
  • Analytics providers (e.g. Google Analytics) β€” to understand how our site is used
  • Accountancy software and financial services β€” to maintain our business records

All third parties are required to handle your data securely and in accordance with UK data protection law. We only share the minimum data necessary for each purpose.

We may also disclose your data to law enforcement or regulatory bodies if required by law.

5. International Data Transfers

Some of our third-party service providers may process your data outside the UK or European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO), to protect your data to UK GDPR standards.

6. How Long We Keep Your Data

We retain your personal data only for as long as necessary for the purposes set out in this policy:

  • Order and transaction records: 7 years (required for HMRC tax compliance)
  • Customer account data: For the duration of your account, plus 2 years after last activity
  • Marketing preferences: Until you unsubscribe or withdraw consent
  • Website analytics data: Up to 26 months
  • Customer service correspondence: 3 years

After these periods, your data is securely deleted or anonymised.

7. Cookies

Our website uses cookies β€” small text files stored on your device β€” to make the site work properly and to improve your experience.

Strictly necessary cookies:

These are required for the website to function (e.g. keeping items in your basket, maintaining your login session). These cannot be disabled.

Analytics cookies:

These help us understand how visitors use our site (e.g. Google Analytics). They collect anonymised data about pages visited and time spent on site. These are only placed with your consent.

Marketing cookies:

These may be used to show you relevant adverts on other websites (e.g. Facebook Pixel). These are only placed with your consent.

You can manage your cookie preferences at any time via the cookie banner on our website, or through your browser settings. Please note that disabling certain cookies may affect how the website functions.

For more information about cookies, visit www.allaboutcookies.org.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access β€” you can request a copy of the personal data we hold about you
  • Right to rectification β€” you can ask us to correct inaccurate or incomplete data
  • Right to erasure ('right to be forgotten') β€” you can request that we delete your data, subject to certain legal exceptions
  • Right to restrict processing β€” you can ask us to limit how we use your data
  • Right to data portability β€” you can request your data in a structured, machine-readable format
  • Right to object β€” you can object to processing based on legitimate interests or for direct marketing
  • Rights related to automated decision-making β€” we do not make solely automated decisions that have a significant effect on you

To exercise any of these rights, please contact us at info@holywelltools.com. We will respond within one month. We may need to verify your identity before processing your request.

You will not normally be charged a fee to exercise these rights, unless a request is manifestly unfounded or excessive.

9. Data Security

We take data security seriously and have implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include SSL/TLS encryption for data in transit, secure access controls, and regular security reviews.

In the event of a data breach that is likely to affect your rights and freedoms, we will notify you and the ICO in accordance with our legal obligations.

10. Third-Party Links

Our website may contain links to third-party websites (e.g. manufacturer sites, social media). We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies before providing any personal data.

11. Children's Privacy

Our website is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us and we will delete it promptly.

12. Right to Complain

If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with the UK's supervisory authority:

  • Information Commissioner's Office (ICO)
  • Website: www.ico.org.uk
  • Helpline: 0303 123 1113

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The latest version will always be available on our website, with the date it was last updated. We encourage you to review this policy periodically.

Holywell Tools Ltd β€” Registered in England and Wales. Company No: 08619606. VAT No: GB 213080948.