Privacy Policy
Updated: 12.12.2024
Arcana Living Ltd (“Arcana Living Ltd”, “we”, “our” or “us”) has created its website www.arcanaliving.com which we offer our variable products and Products and/or Services through (hereby collectively referred to as the "Website”).
This Privacy Policy governs those that will access and use our Website or will engage with us directly or indirectly as a customer of Arcana Living Ltd (“Customer”) which means you will use our Website to buy our products and/or Products and/or Services. Our Privacy Policy also governs those that we provide our products and/or services to generally (“Products and/or Services”), or those that are general visitors to the Website (“you” or “your”) for the purpose of this Privacy Policy.
Overview
At Arcana Living Ltd, we take privacy very seriously. We have prepared this Privacy Policy (“Privacy Policy'') to ensure that we communicate to you, in the clearest way possible, how we treat your personal information.
We are committed to ensuring that your personal information remains confidential and secure in accordance with applicable Data Protection Legislation.
This policy sets out how we look after your personal data if you are:
- A visitor to our Website;
- A Customer;
- Supplier or business contact of Arcana Living Ltd;
- A client wishing to receive our Products and/or Services;
- Any third-party organisation that uses Arcana Living Ltd;
This Privacy Policy (together with any applicable terms and conditions of purchase, website terms of use, and any other documents or terms incorporated by reference) describe the types of information that we collect from you through the use of the Website, or through our business generally, and how that information may be used or disclosed by us and the safeguards we use to protect it. The personal information that we collect is used for providing and improving our Products and/or Services. We will not use or share your information with anyone except as described in this Privacy Policy.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
We may update this notice from time to time, and you can find our latest version on our Website or by asking us for a copy.
Who is Arcana Living Ltd?
Arcana Living Ltd, is a company registered in England and Wales. Our company registration number is 14399047 and our registered office is at The Barn Meadow Court, Faygate Lane, RH12 4SJ.
This Privacy Policy applies to any personal data we collect through our business and within the Website to enable us to deliver our Products and/or Services.
If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact us at care@arcanaliving.com
We will only process personal information about you in accordance with the UK Data Protection Legislation which for the purposes of this Privacy Policy shall mean: all applicable data protection and privacy legislation in force from time to time in the UK including without limitation the UK GDPR; the Data Protection Act 2018 (and regulations made thereunder) and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended; and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of personal data (including, without limitation, the privacy of electronic communications); and the guidance and codes of practice issued by the Commissioner or other relevant regulatory authority and which are applicable to a party (“Data Protection Legislation”).
1. Collection of Information and how we use it.
- We will collect any information that you provide to us when you:
- Input forms on the Website or via us directly;
- place a purchase in person, over the phone or by email;
- register to purchase our Products and/or Services;
- make an enquiry, provide feedback or make a complaint to us over the phone, by email or via the Website;
- submit correspondence to us by post, email or via the Website;
- ‘follow’, ‘like’, post to or interact with any of our social media accounts including but not limited to Instagram, Facebook, Twitter, Snapchat, LinkedIn;
- Interact with us as a Customer or a potential customer.
- Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together depending on your relationship with us (for instance, whether you are a Customer benefitting from our Products and/or Services, a general Website visitor, a business contact of ours, or a supplier) as follows:
- Identity Data: includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.Financial Information: details of bank account / credit and debit card details for billing and payment information relating to our Products and/or Services.
- Contact Data: your email address, telephone number and postal address.
- Technical Log Data includes internet protocol (IP) address, device ID’s, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, geolocation data, social media preferences, operating system and platform and other technology on the devices you use to access the Website.
- Usage Data includes information about how you use the Website, and our Products and/or Services.
- Cookies Data like many websites, we may use some "cookies" to enhance your experience and gather information about the visitors and number of visits to the Website. Please refer to our Cookie Policy on our Website about cookies, how we use them and what kind.
- Analytics includes third-party analytics to Customers of our Products and/or Services (such as Google Analytics) to evaluate your use of the Website, compile reports on activity, collect demographic data, analyse performance metrics, and collect and evaluate other information relating to our Website and internet usage. These third parties use cookies and other technologies to help analyse and provide us with the data. By accessing and using the Website, you consent to the processing of data about you by these analytics providers in the manner and for the purposes set out in this Privacy Policy.
You can withhold your personal data from us, but we may not be able to provide our Products and/or Services to you if you do so.
We may collect your personal data from different sources:
- We collect all the types of data listed above directly from you when you interact with us. This includes when you register or use the Website.
- We collect Technical Data automatically when you interact with the Website, by using cookies and other similar technologies.
- We have no automatic deletion period for personal information. The nature of our business is such that our Customers have no limits or restrictions to their requirements so personal information which is infrequently or never used may still be See below our section on data retention.
2. Information we collect about you.
- Non-Personal information is used to help us monitor and improve our service, for example by showing how many people are visiting our Website and which pages are most or least Individual user patterns are not monitored.
- We (or third-party data processors, agents and sub-contractors acting on our behalf) may collect, store and use your personal information by way of different methods to collect data from and about you including through:
Direct interactions. This is information (including Identity, Contact and Financial Data) you consent to giving us about you when you fill in forms and sections through the Website or send to us directly, or by corresponding with us (for example, by email, by social media, What’s App or chat). It includes information you provide when you purchase any of our Products and/or Services, visit or use the Website, or when you create an account with us, and finally when you report a problem with our Products and/or Services, or with Arcana Living Ltd. If you contact us, we will keep a record of that correspondence.
Information we collect about you and your device, either automated or otherwise. Each time you visit or use the Website, we will automatically collect personal data including Technical Log Data. We collect this data using cookies and other similar technologies including server logs. We may also receive technical data about you if you visit other websites employing our cookies. We may also collect Technical Log Data if you contact us and use our Products and/or Services generally through Arcana Living Ltd.
Financial information. We will collect information related to bookings and attendances. We will also collect information relating to payments to you such as bank details or other related transaction information.
We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions, which include strict confidentiality and contractual terms.
Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you purchase our Products and/or Services and create an account, you are responsible for keeping your account credentials safe.
Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or Products and/or Services. This may include using your personal information to better tailor the Products and/or Services and advertising on our Website and other websites.
Testimonials and customer feedback collection. If you share a testimonial or review about your experience using our Website or purchasing our Products and/or Services, it will be shared or otherwise used on the Website.
We will only use your personal data when the law allows us to. Most commonly we will use your personal data in the following circumstances:
- Where you have consented before the processing.
- Where we need to perform a contract, we are about to enter into, or have entered into with you.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation.
- We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
When we are acting as a data controller, we will use your personal data for the purposes set out in the table below.
The law sets out several different reasons for which we can collect and use your data. The legal grounds on which we collect and use your data are also set out in the table below. Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground, we are relying on to process your personal data where more than one ground has been set out in the table below.
Purpose for using your data |
Legal ground for using your data for this purpose
|
To allow you to access your order / account created through the Website or through us directly, and to register an account with us.
To enable us to manage our business and our commercial relationships with our strategic partners and to enable you to benefit from our Products and/or Services. This may include sharing your information with our third-party payment providers, our fulfilment centre partners, website hosts and developers.
To manage any account with us and to enable us to deliver our Products and/or Services, including placing orders, managing and making payments. |
Necessary for our legitimate interests (to allow those with an account to use it) / Performance of a contract with us. To comply with a legal obligation.
Necessary on the basis of us performing our contract with you and for our legitimate interests in promoting our Website.
Necessary for our legitimate interests (to respond to support calls as our Customers would expect) / Performance of a contract. |
|
|
To provide support to you when you contact us.
|
Necessary for our legitimate interests (to respond to support calls as our users would expect) / Performance of a contract. |
To manage our relationship with you, which will include notifying you about changes to our Privacy Policy, revised Terms and Conditions and any key correspondence with you.
|
Processing is necessary for compliance with a legal obligation to which we are subject to the Data Protection Legislation.
Necessary for our legitimate interests (to provide important updates to our users)/ Performance of a contract.
|
To administer and protect our business and the Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).
|
Necessary for our legitimate interests (to protect our business, and Website; to keep our Products and/or Services updated). |
To deliver relevant system, Website and website content and advertisement and promotional activity to measure or understand the effectiveness of the business.
|
Necessary for our legitimate interests (to study how Customers use our products/Products and/or Services, to develop them, to grow our business and to inform our marketing strategy).
|
To use data analytics to improve our Website, Products and/or Services, marketing, customer relationships and experiences.
|
Necessary for our legitimate interests (to continuously improve our Products and/or Services for our Customers and users). |
Marketing our Products and/or Services to existing and former Customers. To enable us to keep you informed of news, events and Products and/or Services that may be of interest |
For our legitimate interests, i.e. to promote our business to existing and former Customers, or on the basis of consent where we have requested it. See ‘Marketing’ below for further information.
|
To create anonymous aggregated data, as set out below. |
Necessary for our legitimate interests (to provide additional benefits and functionality to our Customers and users without disclosing personal data). |
|
|
|
|
To comply with policies, applicable laws and regulatory obligations.
Social media interactions. To enable us to interact with users on social media. |
To comply with a legal obligation and on the basis of our legitimate interests to operate a safe and lawful business.
On the basis of our legitimate interests in promoting our brand. |
- As outlined above, from time to time we may use your personal data to pursue legitimate interests of our own or those of third parties.
- Who do we share your information with?
- We may need to share your personal data when using your personal data as set out in the table above. We may share your personal data with the following third parties:
- Our professional advisers, including lawyers, auditors and insurers and any other third parties that may be necessary such as authorities, regulatory or other government agencies which may be required.
- Any organisation that we use to provide third party payment Products and/or Services on our behalf who invoice and take payments in relation to any orders placed or any subscription payments.
- Service providers who we work with to deliver our Products and/or Services, who may act as processors and provide the following Products and/or Services (including, but not limited to) web development, hosting Products and/or Services, IT and system administration, marketing Products and/or Services, social media plug in Products and/or Services, payment Products and/or Services.
- Our fulfillment centres that we work with including Gillards, Trident Works, Marsh Lane, Temple Cloud, Bristol BS39 5AZ.
- Regulators and Government bodies.
- Payment processing and recovery services. Your information will be used in order to process payments in the event of a purchase, refund, or other similar request.
- Subcontractors and consultants who we may engage to provide our Products and/or Services to you.
- Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Privacy Policy.
Where any of your personal data is required for such a purpose, we will take all reasonable steps to ensure that your personal data will be handled safely, securely, and in accordance with your rights, our obligations, and the obligations of the third party under the Data Protection Legislation. This type of external data processing is always subject to contractual assurances that personal data will be kept securely and used only in accordance with our specific directions.
We will not misuse your personal data for any other purpose other than as set out in this Privacy Policy.
- International Transfers
-
Subject to us complying with Data Protection Legislation and ensuring appropriate safeguards are in place, we may transfer your personal data to third parties providing Products and/or Services to us who are based outside of the UK without obtaining your specific written consent. This may include parties providing IT administration Products and/or Services and hosting Products and/or Services and other organisations which have products or Products and/or Services that are essential in the delivery of our Products and/or Services; and finally, organisations providing assistance with managing our marketing databases.
- Whenever we transfer your personal data outside of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- the personal data is transferred to or processed in a territory which is subject to adequacy regulations under the Data Protection Legislation that the territory provides adequate protection for the privacy rights of individuals such as the EEA; or
- we participate in a valid cross-border transfer mechanism under Data Protection Legislation, so that we can ensure that appropriate safeguards are in place to ensure an adequate level of protection with respect to the privacy rights of individuals as required under the Data Protection Legislation;
- we enter into an internation data transfer agreement; or
-
the transfer otherwise complies with Data Protection Legislation.
- Retention Periods
- We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
- For more details of our specific retention periods, please contact us.
- Data Security
- Data security is of great importance to us, and to protect your data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure data collected through the Website and through our business.
- We have implemented significant security measures to maintain a high level of security.
-
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
- Notwithstanding the security measures that we take, it is important to note that the transmission of data via the internet may not be completely secure and that you are advised to take suitable precautions when transmitting to us data via the internet and you take the risk that any sending of that data turns out to be not secure despite our efforts.
- If we give you a password upon registration and use of the Website, you must keep it confidential. Please don't share it.
- Your rights to the information we hold about you.
- Under certain circumstances, you have rights under the Data Protection Legislation in relation to your personal data. These rights are set out below. If you wish to exercise any of the rights set out below, please contact us.
- You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
- Right of access – you have the right to request a copy of the personal data that we hold about you and to check that we are lawfully processing it.
- Right of rectification – you have a right to request that we correct personal data that we hold about you that is inaccurate or incomplete.
- Right to be forgotten / erasure – in certain circumstances you can ask for the data we hold about you to be erased from our records i.e., when there is no good reason for us continuing to process it.
- Right to restriction of processing – where certain conditions apply, you have a right to restrict or suspend the processing, for example if you want us to establish its accuracy or the reason for processing it.
- Right of portability – you have the right to have the data we hold about you transferred to another organisation.
- Right to object – you have the right to object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms.
There are some exceptions to the above rights.
- Right to withdraw consent. In the limited circumstances where you have provided your consent to the collection, processing and transfer of the personal data referred to above, you may withdraw that consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent, or to processing carried out on other legal grounds. If you withdraw your consent, we may not be able to provide certain products or Products and/or Services to you. We will advise you if this is the case at the time you withdraw your consent.
- All the above requests will be forwarded to the relevant party should there be a third party involved in the processing of your personal data.
- Privacy of Children
- We acknowledge that some of our Products and/or Services are aimed at children. However, children under the age of 18 years of age are prohibited from using our Website directly. For the purposes of our Products and/or Services, we may from time to time collect personal information from children below the age of 16, including names, ages, to enable us to deliver our Products and/or Services where we offer personalization and to analyse and improve our Products and/or Services for the future.
- By sending us any information to us, registering to use our Products and/or Services, or asking us to email you, the parent and guardian who is the Customer as referred to in this Privacy Policy, shall confirm that we have your consent to process your personal information and that of any children supplied by you.
- Like sensitive personal data, we have to implement additional measures to safeguard the privacy and security of children's personal data. This Privacy Policy covers those measures, but you can always request further information from us.
- Marketing
-
We will use your personal data to send you updates (by email, text message, telephone or post) about our products, including exclusive offers, promotions or new products.
- We have a legitimate interest in using your personal data for marketing purposes (see above ‘How and why we use your personal data’). This means we do not need your consent to send you marketing information. If we change our marketing approach in the future so that consent is needed, we will ask for this separately and clearly.
- You have the right to opt out of receiving marketing communications at any time by: contacting us at care@arcanaliving.com
- Complaints to the Information Commissioner’s Office
- You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance by emailing us at ria@wearearcana.com.
- Changes to this Privacy Policy
- We may from time to time make changes to this Privacy Policy. We will post changes to our Website or notify you of any material changes by email
Contact
- If you have any queries or concerns, then please in the first instance contact care@arcanaliving.com
-
You have the right to access or exercise any other statutory right by contacting us at care@arcanaliving.com
- At any time you have the right to bring a complaint to the Information Commissioner’s Office (https://ico.org.uk)