Privacy Policy
1. Introduction
Kheflaxxvorl ("we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website at https://kheflaxxvorl.world (the "Website") or place an order for our products.
This policy is provided in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR). By using our Website, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
- Business Name: Kheflaxxvorl
- Address: 7 Exchange Crescent, Edinburgh EH3 8AN, United Kingdom
- Email: support-center@kheflaxxvorl.world
- Website: https://kheflaxxvorl.world
3. What Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Information You Provide Directly
- Contact information: Full name, email address, and phone number (if provided voluntarily).
- Order information: Messages and enquiry details submitted through our order form.
- Consent records: Records of your consent to our Privacy Policy and data processing.
3.2 Information Collected Automatically
- Technical data: IP address, browser type and version, operating system, device type, and screen resolution.
- Usage data: Pages visited, time spent on pages, click patterns, referring URL, and date/time of access.
- Cookie data: Information collected through cookies and similar technologies (see our Cookie Policy).
4. Lawful Basis for Processing
We process your personal data on the following legal bases under Article 6 of the UK GDPR:
- Consent (Article 6(1)(a)): When you provide explicit consent, for example by submitting the order form with the consent checkbox selected, or by accepting optional cookies.
- Contractual necessity (Article 6(1)(b)): When processing is necessary to fulfil your order or respond to your enquiry.
- Legitimate interests (Article 6(1)(f)): For maintaining the security and performance of our Website, preventing fraud, and improving our services, provided these interests do not override your fundamental rights and freedoms.
- Legal obligation (Article 6(1)(c)): When we are required by law to retain or disclose certain information.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
- To process and respond to your orders and enquiries.
- To send order confirmations and delivery updates via email.
- To provide customer support and respond to your communications.
- To maintain the security and functionality of our Website.
- To analyse Website usage patterns and improve our services (using anonymised or aggregated data where possible).
- To comply with legal and regulatory obligations.
We will never sell, rent, or trade your personal data to third parties for their marketing purposes.
6. Data Sharing and Third Parties
We may share your personal data with the following categories of recipients, only to the extent necessary:
- Service providers: Hosting providers, email delivery services, and analytics platforms that process data on our behalf under appropriate data processing agreements.
- Legal and regulatory authorities: Where required by law, court order, or regulatory direction.
- Professional advisors: Lawyers, accountants, or auditors where necessary for legal or compliance purposes.
All third-party service providers are required to maintain the confidentiality and security of your personal data and are prohibited from using it for any purpose other than those specified in our agreements with them.
7. International Data Transfers
Your personal data is primarily processed and stored within the United Kingdom and the European Economic Area (EEA). If any data transfer occurs to a country outside the UK or EEA, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the Information Commissioner's Office (ICO), or transfers to countries that have received an adequacy decision.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Order and enquiry data: Retained for up to 24 months from the date of your last interaction, unless a longer retention period is required by law.
- Consent records: Retained for as long as the consent is valid, and for a reasonable period thereafter for compliance and audit purposes.
- Technical and usage data: Retained for up to 12 months in anonymised or aggregated form.
- Financial and tax records: Retained for up to 7 years as required by UK tax and accounting law.
After the applicable retention period expires, your personal data will be securely deleted or anonymised.
9. Your Rights Under UK GDPR
Under the UK GDPR and Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of access (Article 15): You have the right to request a copy of the personal data we hold about you.
- Right to rectification (Article 16): You can request correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17): You can request deletion of your personal data where there is no compelling reason for continued processing.
- Right to restrict processing (Article 18): You can request that we limit the processing of your personal data under certain circumstances.
- Right to data portability (Article 20): You can request to receive your personal data in a structured, commonly used, machine-readable format.
- Right to object (Article 21): You can object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: Where processing is based on consent, you can withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint: You have the right to file a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.
To exercise any of these rights, please contact us at support-center@kheflaxxvorl.world. We will respond to your request within one month of receipt, in accordance with UK GDPR requirements. In complex cases, this period may be extended by a further two months, and we will inform you accordingly.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- Encryption of data in transit using HTTPS/TLS protocols.
- Access control measures limiting data access to authorised personnel only.
- Regular security assessments and updates to our systems.
- Secure storage of data on servers with appropriate physical and technical safeguards.
While we take reasonable precautions to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but strive to use commercially acceptable means to protect your information.
11. Children's Privacy
Our Website and products are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will take immediate steps to delete such information.
12. Links to Third-Party Websites
Our Website may contain links to external websites that are not operated by us. We are not responsible for the privacy practices or content of those websites. We encourage you to review the privacy policies of any third-party sites you visit.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us at:
- Email: support-center@kheflaxxvorl.world
- Address: 7 Exchange Crescent, Edinburgh EH3 8AN, United Kingdom
You also have the right to lodge a complaint with the UK supervisory authority:
- Information Commissioner's Office (ICO)
- Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
- Website: https://ico.org.uk
- Helpline: 0303 123 1113