Privacy policy

PRIVACY POLICY

Last revised: January 12, 2026

Introduction

Welcome to the privacy policy of Minel Cosmetic Limited trading as Atelier Rebul UK.

Minel Cosmetic Limited (referred to as "we", "us" or "our" in this privacy policy). respects your privacy and is committed to protecting your personal data.

This privacy policy explains:

  • what personal data we collect;
  • how and why we collect, use, store and share it;
  • your rights; and
  • how to contact us and Information Commissioner's Office (ICO).

Please read this policy carefully. Please keep a copy for your records. This policy forms part of our Terms and Conditions.

We collect, use and are responsible for certain personal data about you. When we do so we are subject to UK data protection law, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and any UK law that updates these rules. If you are based in the EU or another country, local law may also apply.

This policy covers personal data collected through:

  • our website https://atelierrebul.co.uk/;
  • our physical retail stores in the United Kingdom;
  • loyalty programmes;
  • customer service interactions;
  • marketing channels, including SMS and email; and
  • in-store customer registrations via QR code.

This website and our services are not intended for individuals under the age of 18. We do not knowingly collect personal data relating to children. If we become aware that personal data relating to a child under the age of 18 has been collected inadvertently, we will take reasonable steps to delete that data without undue delay.

This policy uses numbered sections so you can navigate specific areas.

  1. Important information and who we are
  2. The data we collect about you
  3. How your personal data is collected
  4. How we use your personal data
  5. Disclosures of your personal data
  6. International transfers
  7. Data security
  8. Data retention
  9. Your legal rights
  10. Important information and who we are

Purpose of this privacy policy

This privacy policy aims to give you information on how we collect and process your personal data, including any data you provide when you create an account, make a purchase, join our loyalty programme, subscribe to our marketing, or contact us.

It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data.

Controller

MINEL COSMETIC LIMITED, a company registered in England and Wales under company number 14227395 t/as ATELIER REBUL UK, is the controller responsible for your personal data and this website.

For certain processing activities, we and an affiliated group company in Turkey jointly determine the purposes and essential means of processing. For those activities, we and the below group company act as joint controllers under Article 26 UK GDPR.

Joint controllers

We act as joint controllers under Article 26 UK GDPR with:

REBUL JCR Kozmetik Pazarlama Anonim Şirketi

Company number: 796080-0,

Registered office: Huzur Mahallesi Sude Sokak No:5, 34396 Maslak/Sarıyer, Istanbul, Turkey

(referred to in this policy as Rebul JCR).

Joint controller activities include:

• group-wide loyalty programme management, including loyalty IDs, rewards and customer profiles;

• customer relationship management across online and physical channels;

• business intelligence, analytics and reporting;

• marketing strategy, segmentation and campaign analysis;

• QR-based in-store customer registration and linking in-store and online transactions;

  customer relationship management (for example, handling complaints, returns and aftersales support where stores and the website both hold information about the same customer)

This means that, for those activities, we and REBUL JCR jointly decide why your data is used and how it is used. We and REBUL JCR are jointly responsible for keeping your personal data safe for the activities listed above and for meeting data protection law. Both joint controllers also be held legally responsible if something goes wrong in accordance with their respective responsibilities under the Article 26 arrangement

Minel Cosmetic Limited remains the primary contact point for UK data subjects and the ICO. Data subjects may exercise their rights against either joint controller. We will handle your requests to access, correct, delete or object to the use of your personal data, and will answer questions about how your data is shared. You can contact us using the details in "How to contact us" below.

Essence of the Article 26 joint controller arrangement

a. We act as the primary contact point in the UK for the purposes of transparency obligations under Articles 13 and 14 UK GDPR, for handling data subject rights requests, and for engagement with the Information Commissioner’s Office (ICO).

b. Rebul JCR cooperates with us and provides necessary assistance in relation to personal data processed or accessed in Turkey, including implementing and responding to data subject rights requests where relevant.

c. Data subjects may exercise their rights under the UK GDPR against either joint controller.

Contact details (How to Contact us)

You can contact us and our data protection manager by post or email if you have any questions about this privacy policy or the information we hold about you, to exercise a right under data protection law or to make a complaint.

Our contact details are shown below:

Full name of legal entity: Minel Cosmetic Limited t/a Atelier Rebul UK

Email address: contact@atelierrebul.co.uk

Postal address: 8 Clock House Parade, North Circular Road, London, England, N13 6BG

How to make a complaint

Please contact us if you have any query or concern about our use of your information. We hope we will be able to resolve any issues you may have.

You also have the right to make a complaint at any time to your local data privacy supervisory authority. ICO is the UK supervisory authority for data protection issues (www.ico.org.uk). If you are based outside the UK, you may also have the right to submit a complaint to the relevant supervisory authority in your jurisdiction. A list of EU supervisory authorities is available here: https://edpb.europa.eu/about-edpb/about-edpb/members_en.

We would, however, appreciate the chance to deal with your concerns in the first instance.

Third-party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

Changes to this privacy policy

We may change this privacy notice from time to time. Please ensure that you regularly check this privacy policy for any changes that may affect you. The Last Revised date is written on the top.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

  1. The data we collect about you

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

  • Identity Data includes name, surname, title, billing name, delivery or recipient name, date of birth, gender, marital status, occupation and employment status where applicable, loyalty ID, internal CRM identifiers (including customer ID, loyalty membership ID and CRM profile ID), account ID, customer account details, and CCTV footage and related metadata (including store location, camera reference, date and time).
  • Contact Data includes billing address, delivery address, email address, mobile and landline telephone numbers, communication preferences and consent status, including opt-in and opt-out timestamps and consent source (for example QR code, checkout or cookie banner).
  • Financial Data includes payment method details, partial card number (last four digits only). We do not store full card numbers or CVV codes. Our PCI-DSS compliant payment providers (for example Shopify Payments, Klarna, PayPal or card acquirers) process card details securely.
  • Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us like orders, returns, refunds, purchases, refund reason codes, loyalty points, receipts, internal transaction references, delivery and logistics data (such as courier name, tracking number and delivery status events), and the identity of the returner where relevant.
  • Technical Data includes Internet protocol (IP) address, cookies, login data, login identifiers (such as Apple ID, Google ID, PayPal or Klarna ID), browser type and version, time zone setting and location, browser plug-in types and versions, session IDs, consent status, consent source and timestamp, consent source (cookie banner, checkout, QR form), operating system and platform, device type, device identifiers, and other technology on the devices you use to access our website, information about how you use our website and services, including clickstream data, pages viewed, response times, download errors, browsing patterns, length of visits, page interaction information (such as scrolling, clicks and mouse-overs) and how you contact customer service.
  • Profile Data includes loyalty and CRM profile information, segmentation and engagement history, account opening date, purchases or orders made by you, your interests, preferences, feedback and survey responses. Account credentials are stored in an encrypted or hashed form and are not stored in plain text.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and our affiliated group companies, your marketing consent and communication preferences, e-mail and SMS opt-in status, opt-out timestamps, campaign IDs, open and click metrics, review submissions, QR campaign participation records, and interaction metrics associated with digital advertising and influencer campaigns.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate Usage Data to calculate the percentage of users accessing a specific website feature.

We do not intentionally collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods). In this case, we may have to cancel a product you have with us but we will notify you if this is the case at the time.

  1. How your personal data is collected

We use different methods to collect data from and about you including through:

  • Direct interactions. You give data to us directly when you:
  • browse or interact with our website;
  • create an account;
  • make a purchase in-store or online;
  • join our loyalty programme in-store or online including at the point of invoicing in physical retail stores;
  • register for loyalty membership via QR code in stores,  ;
  • apply for our products or services;
  • subscribe to our newsletter, SMS list, service updates or other publications;
  • request marketing to be sent to you;
  • take part in a competition, promotion, prize draw or survey;
  • leave a review or post a comment;
  • contact us through a form on the website, by email, by telephone, by post, through live chat, or in-store; or
  • ask for support with delivery, returns, refunds or complaints.
  • Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies and login identifiers (such as Apple ID or Google ID where used), and analytics events generated through platforms such as Shopify, Klaviyo, Google Analytics and advertising integrations. Please see our cookie policy https://atelierrebul.co.uk/policies/cookie-policy for further details.
  • Third parties. We will receive personal data about you from various third parties including
    • Shopify (website hosting, checkout, fraud prevention, account management, order management);
    • Klaviyo (email and SMS marketing, marketing analytics);
    • Google Analytics (website analytics and performance);
    • Meta, TikTok, Pinterest, YouTube (social media, ad targeting, tracking of ad performance);
    • Judge.me (product reviews);
    • Mappy Store Locator (store finder);
    • delivery and logistics partners such as DHL and Yodel (delivery status, delivery address validation);
    • payment service providers and finance/tax partners such as Xero (via Certax) to handle invoicing, tax and reconciliation;
    • Group systems (Odoo and loyalty databases), including the Turkey-based Odoo system which acts as the central CRM, consent management and loyalty platform for group-wide marketing and customer relationship management.
    • Suppliers, vendors, influencers and other business contacts who provide personal data in the course of a business relationship with us.
  1. How we use your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances (these are called lawful bases):

  • Where we need to perform the contract we are about to enter into or have entered into with you.
  • Where it is necessary for our legitimate interests (or those of a third party) such as running and improving our website, preventing fraud, and understanding our customers provided that your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal obligation for example tax, fraud prevention, product safety and record-keeping.

Generally, we do not rely on consent as a legal basis for processing your personal data although we will get your consent before sending third party direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.

Purposes for which we will use your personal data

We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.

Purpose/Activity

Type of data

Lawful basis for processing including basis of legitimate interest

To provide products and services to you and to send you essential information about the products

(a) Identity

(b) Contact

(c) Transaction

(d) Financial

Performance of a contract with you or

to take steps at your request before entering into a contract

To register you as a new customer or loyalty member

(a) Identity

(b) Contact

Performance of a contract with you

To process and deliver your order including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(a) Identity

(b) Contact

(c) Financial

(d) Transaction

(e) Marketing and Communications

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to recover debts due to us and to prevent fraud in orders and returns)

To provide customer support (including returns, refunds, complaints, aftersales)

(a) Identity

(b) Contact

(c) Profile

(d) Transaction


(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to resolve issues efficiently and improve our service)

To identify and authenticate you during registration and login, protect access to accounts, and send one-time passwords or security verification

(a) Identity

(b) Contact

(c) Technical

(d) Profile

(a) To take steps at your request before entering into a contract / performance of a contract with you

(b) Necessary for our legitimate interests (to prevent unlawful access to our systems and customer accounts)

(c) Necessary to comply with our legal and regulatory obligations in relation to security and fraud prevention

To manage our relationship with you which includes:

(a) Notifying you about changes to our terms or privacy policy

(b) Asking you to leave a review or take a survey

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To enable you to partake in a prize draw, competition or complete a survey

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) 

(a) Identity

(b) Contact

(c) Technical

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation

To deliver website content, measure site performance and fix technical issues (for example page speed, checkout errors, broken links)

(a) Technical

(b) Usage

(c) Profile

Necessary for our legitimate interests (to keep our website usable, reliable and secure, to maintain our services and to improve how the website works)

To deliver targeted advertising and marketing content to you, and to measure or understand the effectiveness of the advertising we serve to you (including social media ads, retargeting, custom audiences, lookalike audiences, and marketing cookies / pixels)

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(f) Technical

Consent (for marketing cookies, tracking pixels, targeted / behavioural advertising and for direct marketing where consent is required under PECR)

You can withdraw consent at any time. Please see under “marketing” for details.


To send you direct marketing emails, SMS or push messages about our products, offers, loyalty rewards and events

(a) Identity

(b) Contact

(c) Marketing and Communications

(d) Transaction / purchase history (to decide what to send you)

(a) Legitimate interests (to promote similar products and offers to existing customers, where allowed by law and you have not opted out)

(b) Consent (for certain email, SMS or electronic marketing where consent is required under PECR, including marketing to non-customers)

You can opt out or withdraw consent at any time.

Please see under “marketing” for details.

To make suggestions and recommendations to you about goods or services that may be of interest to you (including personalised offers and loyalty benefits)

(a) Identity

(b) Contact

(c) Technical

(d) Usage

(e) Profile

(f) Marketing and Communications

Necessary for our legitimate interests (to develop our products and services and grow our business by offering relevant products and loyalty benefits)

To use analytics to understand how customers browse, shop and interact with the website, our stores and our marketing, and to improve our website, products, services, customer experience and marketing strategy

(a) Technical

(b) Usage

(c) Profile

(a) Necessary for our legitimate interests (to understand customer behaviour, keep our website updated and relevant, develop our business and inform our marketing strategy)

(b) Consent, where analytics relies on non-essential cookies or similar tracking technologies

To prevent, detect and investigate fraud, misuse and security incidents (for example suspicious orders, abnormal returns behaviour, account takeover attempts, bot traffic)

(a) Identity

(b) Contact

(c) Technical

(d) Transaction

(a) Necessary for our legitimate interests (to protect our business, customers and systems from fraud, abuse and unlawful activity)

(b) Necessary to comply with legal obligations (for example to assist law enforcement and comply with fraud and tax rules)

To run loyalty, apply loyalty benefits across our stores and website, and prepare group-level stock control, reporting and customer analytics

(a) Identity

(b) Contact

(c) Transaction

(d) Profile

Necessary for our legitimate interests (to operate our loyalty programme, understand buying trends, manage stock and run the business efficiently across physical stores and online channels)

To comply with tax, accounting, legal and regulatory requirements, and to respond to lawful requests from regulators or law enforcement

(a) Identity

(b) Contact

(c) Transaction

(d) Financial

(e) Technical (where relevant to a legal request)

Legal obligation

To consolidate customer data across online and physical channels and maintain a single CRM and loyalty profile

(a) Identity

(b) Contact

(c) Transaction

(d) Profile

(e) Marketing and Communications

Necessary for our legitimate interests (to manage customer relationships, maintain accurate records, and operate our business efficiently across channels)

To produce business intelligence, management reports and group-level sales, loyalty and performance analytics

(a) Transaction

(b) Profile

(c) Usage

(d) Technical

Necessary for our legitimate interests (to analyse performance, improve operations, plan stock and assess business trends)

To comply with data protection, consent management, audit, record-keeping and regulatory accountability requirements, including handling data subject rights requests

(a) Identity

(b) Contact

(c) Technical

Legal obligation

Necessary for our legitimate interests (to demonstrate compliance and manage regulatory risk)

To collect customer personal data in UK physical stores via QR codes, transfer that data to Turkey, create or update CRM and loyalty profiles, and use the data for digital marketing communications

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(e) Technical (QR source, consent source and timestamp)

(a) Consent (for electronic marketing to new contacts collected via QR codes, as required under PECR, recorded separately for each channel such as email and SMS)

(b) Performance of a contract (where the customer joins a loyalty programme at the point of QR registration)

(c) Necessary for our legitimate interests (to manage customer relationships, consolidate in-store and online customer data, and operate a group-wide CRM and loyalty programme), provided that those interests are not overridden by the customer’s rights and freedoms

Marketing

We strive to give you clear choices about how your personal data is used for marketing and advertising. You will receive marketing communications from us only if you have purchased from us, subscribed to our updates, or requested information and you have not opted out.

We may use your Identity, Contact, Technical, Usage, and Profile data to form a view of what you may want, need, or find interesting. This allows us to send you information about our products, services, promotions, events, loyalty offers, and other updates that are most relevant to you.

We may contact you by email, SMS, post, or other electronic means.

We rely on legitimate interest to send you marketing communications to existing customers only, where the law allows us to do so and where the conditions of the PECR “soft opt-in” exemption are met.

All email and SMS marketing activities comply with the Privacy and Electronic Communications Regulations (PECR), which require your prior consent for such communications unless an existing customer relationship allows us to rely on the “soft opt-in” exception.

Where consent is required under PECR, for example for certain SMS or email marketing, we will ask for it clearly and separately.

Email and SMS marketing to new contacts collected via QR codes requires explicit, separate consent for each channel and can be withdrawn at any time. Where you register in-store via QR code, we collect the following personal data: first name, last name, mobile phone number, date of birth and email address.

Personal data processed for marketing purposes, including data collected via in-store QR registrations, website interactions, customer accounts and campaign activity may be transferred to and processed in Turkey by our joint controller REBUL JCR Kozmetik Pazarlama Anonim Şirketi for CRM, loyalty management and digital marketing purposes, in accordance with the safeguards described in the “International transfers” section of this policy.

You have the right to opt out of marketing communications at any time by:

  • clicking the unsubscribe link in our emails,
  • replying STOP to SMS messages,
  • updating your marketing preferences through your online account, or
  • contacting us using the details in this policy.

Where you opt out of marketing, this will not affect service messages that we must send to you (such as order confirmations, delivery updates, returns, or product recall notices).

We may ask you to confirm or update your marketing preferences if you request further products or services in the future, or if there are changes in the law, regulation, or our business structure.

We will always treat your personal data with respect.

We will never sell your personal data to any third party for marketing purposes.

We will only share your data with third parties for their own marketing if you have given us your express opt-in consent.

You can withdraw consent for marketing or cookies at any time. Withdrawing consent will not affect the lawfulness of any processing carried out before withdrawal.

Automated decisions that may affect you

We use automated tools to help detect and prevent suspected fraud in online orders and to protect customer accounts. These tools assess factors such as device details, IP address and transaction history. If our systems identify a high risk of fraud, we may delay or refuse an order. You can request a human review of any decision made in this way.

Cookies

We use cookies and similar tracking technologies.

Non-essential cookies, such as analytics and advertising cookies, will only run with your consent. You can set your browser to refuse some or all cookies, or to alert you when websites set cookies. If you disable or refuse cookies, some parts of our website may not function properly. For more information, please see our Cookie Policy https://atelierrebul.co.uk/policies/cookie-policy.

Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

  1. Disclosures of your personal data (Who we share your personal data with)

We may share your personal data with the parties set out below for the purposes set out in the table above.

  • Intra-group Parties

For certain processing activities, Minel Cosmetic Limited and REBUL JCR Kozmetik Pazarlama Anonim Şirketi act as joint controllers under Article 26 UK GDPR, as described in section 1 of this policy.

Our group company REBUL JCR Kozmetik Pazarlama Anonim Şirketi, located in Turkey, may access personal data strictly for group-wide loyalty programme management, customer relationship management, customer analytics, business intelligence and reporting, in accordance with the joint controller arrangement.

Certain technical and IT support services are provided by our group company Canfiltech Bilişim ve Tasarım Hizmetleri Anonim Şirketi, located in Turkey, which acts solely as a data processor to REBUL JCR Kozmetik Pazarlama Anonim Şirketi and does not use personal data for its own purposes and does not determine the purposes or means of processing.

Minel Cosmetic Limited remains your main contact for all privacy matters.

  • External Third Parties

Shopify – e-commerce platform, website hosting, order management and customer accounts.

Odoo – customer relationship management, loyalty programme administration and consent management.

Klaviyo – email/SMS marketing.

Google Analytics – website analytics.

Meta, TikTok, Pinterest, YouTube – social media advertising.

Judge.me – product reviews.

Mappy Store Locator – store location services.

DHL and Yodel – deliveries.

Xero (via Certax) – accounting.

Payment processors and card acquirers

IT and security providers.

Our insurers.

Professional advisers and auditors as required by law.

We may share personal data with potential buyers, investors, funders or merger partners. If a change happens in our business, the new owner may use your personal data in the same way as set out in this policy.

We may disclose and exchange information with law enforcement agencies, regulators, tax authorities and other authorities when we are legally required to do so.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

  1. International transfers

We are based in the United Kingdom. Your personal data is usually stored in the UK or the European Economic Area (EEA).

Some of our service providers and group companies are located outside the UK or the EEA. This means your personal data may be transferred to a country whose data protection laws are different from UK law.

Transfers within our group

Some of your personal data is shared with our joint controller group company REBUL JCR Kozmetik Pazarlama Anonim Şirketi in Turkey and our other group companies:

We share data for loyalty management, central stock control, customer relationship management, customer analytics, business intelligence, IT support and group reporting. Such access may involve live access to systems hosted in the UK or EEA. All access is logged, restricted to authorised roles and subject to contractual and technical safeguards.

Turkey does not currently have a UK adequacy decision. Because of this, we only transfer personal data to Turkey where we have put in place appropriate safeguards under UK data protection law. These safeguards include:

  • the UK International Data Transfer Agreement (IDTA) (or the UK Addendum to the EU Standard Contractual Clauses, where relevant), signed between Minel Cosmetic Limited and REBUL JCR Kozmetik Pazarlama Anonim Şirketi.; and
  • a data transfer risk assessment, which considers the laws and practices of the destination country and the nature of the data.

These safeguards are intended to make sure that your personal data remains protected and that you have enforceable rights and effective legal remedies.

Transfers to our service providers

Some of our external providers (for example, ecommerce platform, marketing automation platform, analytics and advertising partners, payment processors, and delivery / logistics partners) may store or access personal data from outside the UK or the EEA.

Where the United Kingdom has decided that a country provides an adequate level of protection (an "adequacy decision"), we rely on that decision.

If there is no UK adequacy decision for the relevant country, we only transfer personal data where we have put in place appropriate safeguards recognised under UK data protection law. These usually include the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

Your rights in relation to international transfers

You can contact us using the details in "How to contact us" to:

  • ask which countries your personal data is transferred to;
  • ask which safeguard we use for that transfer; and
  • request a copy of the key terms of the relevant safeguard.

Your rights under data protection law (for example access, correction, deletion, objection, and complaint to the ICO) continue to apply to personal data that is transferred internationally as described above.

  1. Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

  1. Data retention

How long will you use my personal data for?

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements..

In practice, we apply the following retention periods:

• Customer account, transaction, loyalty and CRM data is retained for 5 years from the date of your last transaction or last meaningful interaction with us, whichever is later. Each new transaction or meaningful interaction triggers a new 5-year retention period subject to periodic necessity and proportionality reviews. Where a customer relationship becomes inactive, personal data will not be retained for longer than 6 years from the date of the last meaningful interaction, unless a longer retention period is required to comply with legal or regulatory obligations or to establish, exercise or defend legal claims.

• Marketing data, including email and SMS consent records, is retained for up to 5 years from the last interaction or until you withdraw your consent or opt out, whichever occurs first.

• Order, payment and invoicing records are retained for 6 years to comply with tax and accounting obligations.

• Customer service records, including complaints, returns and enquiries, are retained for 6 years from the date of the last interaction, in line with applicable limitation periods and to establish, exercise or defend legal claims.

• CCTV footage collected in our stores is retained for a short, limited period, unless it is required for security investigations, incident management or legal proceedings. (CCTV operates in our physical retail stores for security and safety purposes. Clear and visible CCTV signage and a short-form privacy notice are displayed at store entrances and within monitored areas, directing individuals to this privacy policy for further information.)

These periods are reviewed regularly.

In some circumstances you can ask us to delete your data: see your legal rights below for further information.

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

  1. Your legal rights

You have following rights under data protection laws in relation to your personal data which you can exercise at any time

Access

Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

Rectification

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Erasure (also known as the right to be forgotten)

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Restriction of processing

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

If you want us to establish the data's accuracy.

Where our use of the data is unlawful but you do not want us to erase it.

Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.

You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Data portability

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

To object

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Not to be subject to automated individual decision making

The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you

If you wish to exercise any of the rights set out above, please contact us at contact@atelierrebul.co.uk.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.