1. General Information
1.1 Data Controller
DECSMN LTD
43 Crawford Avenue, Dartford. DA1 2GB
Email: privacy@decsmnltd.com
Company Number: 16551630
1.2 Purpose & Legal Basis for Processing
We process personal data to:
- Fulfil orders and warranties for vehicle parts.
- Manage trade accounts (B2B) and retail purchases (B2C).
- Comply with UK tax (HMRC) and anti-fraud laws.
- Improve our website and marketing (with consent where required).
Legal Bases:
- Contract (Art. 6(1)(b) GDPR): Processing orders, payments, and deliveries.
- Legal Obligation (Art. 6(1)(c) GDPR): VAT invoicing, fraud checks.
- Consent (Art. 6(1)(a) GDPR): Marketing emails, cookies.
- Legitimate Interest (Art. 6(1)(f) GDPR): Customer account management, fraud prevention.
1.3 Data Recipients
Your data may be shared with:
- Couriers (e.g., DPD, Royal Mail) for delivery.
- Payment processors (e.g., Stripe, PayPal).
- UK regulators (e.g., HMRC for tax audits).
- IT/cloud providers (e.g., Microsoft 365, UK-based hosting).
1.4 International Transfers
Data is stored primarily in the UK/EEA. If transferred outside the UK (e.g., US-based analytics tools), we use:
- UK GDPR-approved safeguards (e.g., Standard Contractual Clauses).
- Exceptions under Article 49 GDPR (e.g., explicit consent for marketing tools).
1.5 Data Retention
- Orders: 7 years (HMRC compliance).
- Marketing consents: Until withdrawn.
- Website logs: 12 months.
1.6 Your Rights (UK GDPR)
You may:
- Access, correct, or delete your data.
- Withdraw consent (e.g., unsubscribe from emails).
- Lodge complaints with the UK ICO (www.ico.org.uk).
1.7 Right to Object
Object to processing based on legitimate interests (e.g., direct marketing) by contacting us.
2. Processing Scenarios
2.1 Website Use
Cookies & Tracking:
- Essential cookies: No consent needed (e.g., shopping cart functionality).
- Analytics/marketing cookies: Require opt-in (via our Cookie Banner).
Tools We Use:
- Google Analytics: Anonymized traffic analysis.
- Hotjar: UX improvement (optional consent).
2.2 Customer Accounts & Orders
B2B Trade Accounts:
- Require business name, VAT number, and credit checks.
- Legal basis: Contract (Art. 6(1)(b)).
Retail Purchases:
- Consumer rights apply (e.g., 14-day returns for distance sales).
2.3 Marketing
- Email/SMS: Only with consent (opt-out anytime via link in messages).
- Postal marketing: Legitimate interest (opt-out via [email/address]).
2.4 Payment Processing
- Stripe/PayPal: Encrypted transactions; we never store full card details.
- Invoice terms (B2B): Credit checks may be performed.
2.5 Fraud Prevention
- Sanctions screening: Cross-checking names/addresses against UK/EU sanctions lists (legal obligation under UK financial regulations).
3. Data Security
- Encryption: SSL/TLS for all data transfers.
- Access controls: Staff training and limited data access.
- Breach response: Notify ICO within 72 hours if risk arises.
4. Contact & Complaints
Data Protection Officer:
DECSMN LTD
Email: dpo@decsmnltd.com
UK Representative:
[If required under UK GDPR, appoint a local representative.]
ICO Complaint:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
www.ico.org.uk