A plain-English summary of how Giftfluence collects, processes, and protects personal information under the UK General Data Protection Regulation. We don't sell it. We don't share it. We collect only what we need to ship a campaign.
This policy outlines the approach of Giftfluence ("the Company") to comply with the General Data Protection Regulation (GDPR) as applicable in the United Kingdom.
The Company has appointed a Data Protection Officer who is responsible for overseeing data protection activities and ensuring compliance with GDPR. The DPO can be contacted at the address provided in the Contact section below.
The Company may collect and process the following types of personal data:
The Company will only process personal data when there is a lawful basis for doing so, which may include:
Data subjects have the following rights under GDPR:
We do not knowingly collect or process personal data relating to children. Our website and services are not intended for individuals under the age of 18. If we learn that we have accidentally collected personal data from a child, we will delete it promptly.
The Company is committed to ensuring the security of personal data. This includes implementing appropriate technical and organisational measures to protect against unauthorised or unlawful processing, accidental loss, destruction, or damage.
In the event of a data breach, the Company will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
Personal data will be retained only for as long as necessary for the purposes it was collected. The Company has established specific retention periods for different types of data.
Where international transfers occur, they are carried out using approved safeguards such as the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs).
When using third-party processors to process personal data, the Company will ensure they provide sufficient guarantees regarding the security and protection of the data.
The Company will provide training to staff and contractors regarding GDPR compliance and data protection best practices.
This policy will be reviewed and, if necessary, updated annually or in response to changes in applicable data protection laws.
For any questions or concerns regarding this policy or the Company's data protection practices, please contact: