Privacy Policy (UK GDPR & DPA 2018)
1. Introduction & Overview
ClickAura Ltd (“ClickAura”, “we”, “our”, or “us”) is a company registered in England and Wales, founded in Central Bedfordshire, United Kingdom.
We operate the website ClickAura.co.uk and act as the Data Controller for personal data processed through your interactions with our e-commerce platform. This policy outlines how we handle your personal information in strict adherence to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
We only collect personal information necessary to deliver exceptional shopping experiences and customer care:
- Identity Data: Full name, title, and contact preferences.
- Contact Details: Delivery address, billing address, email address, and telephone number (for Royal Mail & DPD tracked updates).
- Financial & Transaction Data: Payment card tokenisation (we do not store raw card numbers; payments are handled directly by PCI-DSS Tier 1 gateways such as Stripe and PayPal), order history, and refund records.
- Technical & Usage Data: IP address, browser type, operating system, pages visited, time spent, and referral URLs.
3. How & Why We Use Your Personal Data
Your personal data is utilised for specific, lawful purposes including:
- Processing, packing, and dispatching your orders from our UK fulfillment depots.
- Providing order tracking notifications via SMS and email.
- Administering warranty support as per manufacturer's warranty and return requests.
- Detecting, investigating, and preventing fraudulent transactions.
- Sending optional VIP newsletter promotions (only with your explicit opt-in consent).
4. Lawful Basis for Processing (UK GDPR)
Under Article 6 of the UK GDPR, our processing relies on the following lawful bases:
| Purpose | Data Categories | Lawful Basis |
|---|---|---|
| Order Fulfillment & Delivery | Identity, Contact, Payment Token | Contract Performance (necessary to deliver goods) |
| Warranty & Customer Support | Contact, Order Details | Contract & Legal Obligation |
| Fraud Prevention & Security | Technical Data, IP, Device Info | Legitimate Interest |
| Promotional Newsletters | Email, Marketing Preferences | Consent (freely given, revocable anytime) |
5. Data Sharing & Third-Party Service Providers
We collaborate strictly with trusted partners who maintain rigorous UK GDPR compliance:
- Couriers: Royal Mail Group Ltd and DPDgroup UK (name, shipping address, and telephone number for live SMS delivery tracking).
- Payment Gateways: Stripe Payments UK, PayPal (Europe), Apple Pay, and Google Pay.
- IT & Cloud Infrastructure: Secure servers located within the UK and European Economic Area (EEA).
6. Cookies & Tracking Technologies
We use essential cookies to manage your shopping basket and session state, and optional analytical cookies to understand how customers use our site. You can adjust your cookie settings at any time via your browser controls.
7. Data Retention Period
We retain transaction records for 6 years following your purchase to satisfy statutory UK accounting obligations (HMRC) and to support manufacturer warranty claims and customer care. Marketing information is deleted immediately upon unsubscribing.
8. Your Statutory Data Rights
Under the UK GDPR, you have full enforceable rights over your data:
- Right of Access: Request a copy of all personal data held about you (Subject Access Request).
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure: Request deletion of your data where no overriding legal obligation exists.
- Right to Restrict or Object: Object to processing for direct marketing at any time.
- Right to Data Portability: Receive your data in a structured, machine-readable format.