Privacy & Data Protection Policy

Last Updated: Oct 23, 2024

1. Introduction

This Privacy & Data Protection Policy explains how Framerverse ("we", "us", "our") collects, uses, and protects your personal data. As a sole proprietorship operated by [Your Name], we take your privacy seriously and handle all data processing internally with no third-party sharing except where absolutely necessary for business operations.

2. Data Controller Information

Data Controller: Chris Kellett Trading as: Framerverse Contact Email: chris@thunkd.co.uk Business Address: 11 Norgans Terrace, Pembroke, Pembrokeshire - SA71 4EX

3. Personal Data We Collect

3.1 Data Collected Automatically

  • IP address

  • Browser type and version

  • Operating system

  • Page visit timestamps

  • Basic analytics data

3.2 Data You Provide

  • Email address (for purchases and communications)

  • Name

  • Billing information

  • Purchase history

  • Communication records

  • Account preferences (if applicable)

3.3 Payment Data

  • We do not store complete payment card details

  • Payments are processed through secure third-party providers (e.g., Stripe/PayPal)

  • Only transaction references and last four digits of cards are stored for record-keeping

4. How We Use Your Data

4.1 Essential Processing

We process your data for:

  • Processing your purchases

  • Delivering digital products

  • Providing customer support

  • Sending transaction confirmations

  • Maintaining product records

  • Meeting legal obligations

4.2 Legal Basis for Processing

Our data processing is based on:

  • Contract fulfillment (processing purchases)

  • Legal obligations (tax records)

  • Legitimate business interests

  • Consent (for marketing communications)

5. Data Storage and Security

5.1 Storage Methods

  • All data is stored securely within the UK/EU

  • Digital records are encrypted

  • Access is restricted to the business owner only

  • Regular security updates and monitoring

5.2 Retention Periods

  • Purchase records: 7 years (legal requirement)

  • Communication records: 2 years

  • Marketing preferences: Until consent withdrawal

  • Inactive account data: 2 years

5.3 Security Measures

  • SSL encryption for all data transmission

  • Secure password protocols

  • Regular security assessments

  • Automated threat detection

  • Regular backups

  • Access logging and monitoring

6. Your Data Protection Rights

Under GDPR, you have the following rights:

6.1 Core Rights

  • Right to be informed

  • Right of access

  • Right to rectification

  • Right to erasure

  • Right to restrict processing

  • Right to data portability

  • Right to object

  • Rights related to automated decision making

6.2 Exercising Your Rights

To exercise these rights:

  1. Email [your email]

  2. Provide your name and email address

  3. Specify your request

  4. We'll respond within 30 days

7. Data Sharing and Transfers

7.1 Limited Sharing

We do not share your data with third parties except:

  • Payment processors (for transaction processing only)

  • Cloud storage providers (with appropriate safeguards)

  • Legal authorities (if legally required)

7.2 No Data Sales

  • We never sell your personal data

  • We never share data for marketing purposes

  • We never transfer data outside necessary business operations

7.3 Subprocessors

Essential service providers:

  • Payment gateway (Stripe/PayPal)

  • Cloud hosting (Framer)

  • Email service provider (Fasthosts)

8. Cookie Policy

8.1 Essential Cookies

We use only necessary cookies for:

  • Shopping cart functionality

  • Session management

  • Security purposes

8.2 Optional Cookies

  • We do not use tracking cookies

  • We do not use advertising cookies

  • We do not use third-party analytics cookies

9. Children's Privacy

  • We do not knowingly collect data from children under 16

  • If we discover we have such data, we will delete it

  • Parents can contact us about their children's data

10. Changes to This Policy

  • We may update this policy periodically

  • Changes will be posted on this page

  • Significant changes will be notified via email

  • Previous versions available upon request

11. Data Breaches

In the unlikely event of a data breach:

  1. We will notify affected users within 72 hours

  2. We will inform relevant authorities as required

  3. We will provide guidance on necessary actions

12. Contact Information

For privacy-related queries:

  • Email: [your email]

  • Response time: Within 2 business days

  • Urgent concerns: [phone number if applicable]

For formal requests:

  • Write to: [your business address]

  • Include: Full name, email, and specific request

  • Proof of identity may be required

13. Supervisory Authority

You have the right to lodge a complaint with the ICO: Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF

This policy demonstrates our commitment to protecting your personal data and complying with GDPR requirements.