Privacy Policy

Harrold & Lloyd – Privacy Policy

Effective Date: 17/12/2025
Company: Harrold & Lloyd Ltd
Contact: contact@harroldandlloyd.com

Harrold & Lloyd Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data responsibly and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you interact with our website, place an order, or communicate with us.


1. Information We Collect

We may collect and process the following categories of personal data:

  • Identity and contact details (name, email address, telephone number, billing and delivery address)
  • Transaction information (order details and payment confirmations – payment card details are processed securely by third-party providers and are not stored by us)
  • Technical data (IP address, browser type, device information, operating system)
  • Usage data (how you interact with our website, pages viewed, navigation behaviour)
  • Marketing preferences and communication choices
  • Communications you send to us by email, website form, or other channels

2. How We Collect Your Data

We collect personal data when you:

  • Place an order or make an enquiry
  • Subscribe to marketing communications
  • Contact us via email, website forms, or social media
  • Browse our website, including through the use of cookies and analytics tools

3. Lawful Bases for Processing

We process personal data only where we have a lawful basis under UK GDPR, including:

  • Contract – to fulfil orders, process payments, arrange delivery, and provide customer support
  • Legal obligation – to comply with accounting, tax, consumer protection, and regulatory requirements
  • Legitimate interests – to operate and improve our business, secure our website, prevent fraud, and communicate with existing customers about similar products or services
  • Consent – where you have explicitly opted in, such as receiving newsletters or marketing communications

You may withdraw your consent at any time.


4. Marketing Communications

We may contact existing customers with information about products or services similar to those previously purchased, where permitted by law.

Marketing communications are only sent where you have consented or where a lawful soft opt-in applies. You may unsubscribe at any time using the link provided in our emails or by contacting us directly.

We do not sell or trade your personal data.


5. Cookies & Analytics

Our website uses cookies to:

  • Ensure proper site functionality
  • Analyse website performance and usage
  • Improve user experience

Cookies may collect technical and usage data but do not personally identify you on their own. You can manage or disable cookies through your browser settings.


6. Third-Party Service Providers

We may use trusted third-party service providers to support:

  • Website hosting and e-commerce functionality
  • Payment processing
  • Customer communications
  • Website analytics
  • Order fulfilment and delivery

These providers process personal data only on our instructions and are contractually required to protect your data and comply with applicable data protection laws.


7. International Data Transfers

Where personal data is transferred outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses
  • Equivalent data protection measures
  • Limited data sharing strictly necessary for service delivery

8. Data Retention

We retain personal data only for as long as necessary to:

  • Fulfil contractual obligations
  • Comply with legal, accounting, and tax requirements
  • Resolve disputes and enforce our agreements

When data is no longer required, it is securely deleted or anonymised.


9. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Secure servers and SSL encryption
  • Restricted internal access
  • Reputable third-party platforms with robust security standards

While no system can guarantee absolute security, we take reasonable steps to safeguard your information.


10. Your Data Protection Rights

Under UK GDPR, you have the right to:

  • Request access to your personal data
  • Request correction of inaccurate data
  • Request deletion of your data (where legally permissible)
  • Object to or restrict processing
  • Withdraw consent at any time
  • Lodge a complaint with the Information Commissioner’s Office (ICO)

To protect your privacy, we may request verification of identity before responding to a data request.


11. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page and, where appropriate, notified to you.


13. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact:

Email: contact@harroldandlloyd.com