Privacy Policy
Last updated: 29 January 2026
This Privacy Policy explains how [Abbey Blinds Ltd] (“we”, “us”, “our”) collects, uses and protects your personal data when you use our website [blindsfactory.co.uk] (the “Website”), create an account, request samples, place an order, or contact us. We aim to be transparent and comply with applicable UK data protection laws.
1) Who we are (Data Controller)
Data Controller: [Abbey Blinds Ltd]
Registered address: [One Northgate Business Park, Aldridge, Walsall, West Midlands WS9 8TH]
Email: [privacy@blindsfactory.co.uk]
Telephone: [01922 496102] [ico.org.uk]
2) What information we collect
We collect personal data that you provide to us directly when you interact with the Website, create an account, request information, or place an order.
This may include:
- Identity & contact details: name, email address, telephone number(s).
- Order & delivery details: delivery address, order contents and preferences.
- Account details (if applicable): login credentials and account preferences.
- Customer communications: messages sent via forms, email, or phone (eg. queries about an order).
- Website usage data (cookies/tech data): information about how you use the Website via cookies and similar technologies.
Payments: We do not usually receive your full card details if you pay via a third-party payment provider (eg. PayPal); payment processing is handled by them and we receive confirmation of payment and associated transaction references.
3) How we use your information (purposes)
We use your information for purposes such as:
- Processing and fulfilling orders (including delivery, handling queries and customer service).
- Account administration (where you register an account).
- Record keeping and business administration, including maintaining order history and handling disputes.
- Marketing communications (only where you have opted in / where permitted), such as newsletters and offers.
- Website functionality and improvement, including remembering preferences and understanding how the Website is used (via cookies).
The ICO recommends being clear and specific about why you use personal data and what you do with it.
4) Our lawful bases (UK GDPR)
UK data protection law requires a lawful basis for processing. The ICO advises you to identify and document your lawful bases and explain them in your notice.
Typical lawful bases we rely on:
- Contract: to take steps you request and to process/fulfil your order (eg. delivery).
- Legitimate interests: for operational needs such as customer support, service improvement, fraud prevention, and maintaining business records (balanced against your rights).
- Consent: for optional marketing emails/newsletters and for non-essential cookies where required; consent must be a clear positive action, not just continued browsing.
- Legal obligation: where we must keep certain records (eg. tax/accounting).
5) Marketing preferences
If you opt in to receive our newsletter or promotions, we may send you information about our goods/services that we think you may find of interest.
You can opt out at any time by:
- using the unsubscribe link in our emails (if provided), or
- contacting us at [privacy@blindsfactory.co.uk], or
- updating your preferences in your account (if available).
Where consent is the lawful basis, the ICO expects you to tell people they can withdraw consent.
6) Who we share your information with
We do not sell, trade or rent your personal data.
However, we may share information with trusted third parties where necessary to provide our services, for example:
- Payment providers (eg. PayPal) to process payments.
- Delivery/courier companies to deliver your order (name, address, contact details as needed).
- IT and hosting providers who support our Website and systems.
We will only share what is necessary and expect service providers to protect your data appropriately. The ICO recommends telling people who you share information with.
7) How long we keep your information (retention)
We keep personal data only for as long as necessary for the purposes described above, including meeting legal, accounting, or reporting requirements. The ICO states you should explain how long you hold information before disposing of it securely.
Example retention wording (edit to match your business):
- Orders/invoices: [6 years] (typical for accounting/tax record-keeping in the UK—confirm for your circumstances).
- Marketing lists: until you unsubscribe or we refresh consent/engagement records.
- Customer support enquiries: [12–24 months] after resolution.
8) Your rights
Individuals have rights over their personal data, and the ICO expects privacy notices to include these rights and how to complain.
Depending on the circumstances, your rights may include:
- access to your data,
- correction of inaccurate data,
- deletion of data,
- restriction of processing,
- objection to processing,
- data portability, and
- the right to withdraw consent (where consent is used).
To exercise your rights, contact [privacy@blindsfactory.co.uk].
9) Complaints
If you have concerns, please contact us first so we can try to resolve the issue. The ICO expects you to explain how people can complain. [ico.org.uk]
You also have the right to complain to the Information Commissioner’s Office (ICO) (UK regulator).
Website: https://ico.org.uk/ [ico.org.uk]
10) Cookies and similar technologies
Cookies are small text files placed on your device to help the Website function and/or to understand usage.
The ICO states you must:
- tell people you set cookies,
- explain what cookies do and why, and
- obtain consent for cookies unless they are strictly necessary for a service the user requests.
10.1 Types of cookies we use (edit to match your site)
- Strictly necessary cookies: required for core functionality (eg. security, session management, basket/checkout). These do not require consent, but you should still inform users.
- Preferences cookies: remember choices and settings.
- Analytics cookies: help us understand how the Website is used (only set after consent where required)