Privacy Policy

Last Updated: 17 October 2023

Heffernan's Hemp Ltd ("we," "us," or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, www.heffernanshemp.com (the “Website”), and purchase our products.

We are the data controller for the data we process, and we are fully committed to complying with our legal obligations under the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

What Data We Collect and Our Lawful Basis for Processing

We collect various types of personal data to provide and improve our service to you. Below, we outline the categories of data we collect and the legal reasons we have for doing so.

Category of DataExamplesLawful Basis for Processing
Identity & Contact DataName, billing address, delivery address, email address, phone number.Performance of a contract with you.
Transaction DataDetails about payments to and from you, order history, products you have purchased.Performance of a contract with you.
Financial DataWe do not store your full payment card details. Payments are processed by secure third-party payment gateways (e.g., Stripe, PayPal).Performance of a contract and legitimate interests (fraud prevention).
Technical & Usage DataIP address, browser type and version, time zone setting, operating system, pages visited, time spent on pages.Legitimate interests (to improve our website, services, and marketing).
Marketing & Communications DataYour preferences in receiving marketing from us and your communication preferences.Consent.

How We Use and Share Your Data

How We Use Your Data

  • To process and deliver your order.
  • To manage payments, fees, and charges.
  • To manage our relationship with you, including sending you order updates and service communications.
  • To send you marketing communications (where you have consented).
  • To improve our website, products, and services through data analysis.
  • To comply with our legal and regulatory obligations.

Who We Share Your Data With

We do not sell your personal data. We only share it with trusted third parties where necessary to provide our services, as outlined below:

  • Payment Processors: Such as Stripe and PayPal, to securely process your payments.
  • Delivery Companies: Such as Royal Mail, DPD, or other couriers, to deliver your order.
  • Marketing Platforms: Such as Klaviyo or Mailchimp, to send you newsletters and marketing emails if you have opted-in.
  • Analytics Providers: Such as Google Analytics, to help us understand how our website is used.
  • IT & System Administration Providers: To help us maintain our website and services.
  • Professional Advisers: Including lawyers, bankers, auditors, and insurers who provide services to us.

Your Rights, Data Security, and International Transfers

Your Rights Under GDPR

You have rights over your personal data. These include the right to:

  • Access: Request a copy of the data we hold about you.
  • Rectification: Correct any inaccurate or incomplete data.
  • Erasure: Request that we delete your data.
  • Restrict Processing: Limit how we use your data.
  • Data Portability: Receive your data in a machine-readable format.
  • Object: Object to us processing your data (e.g., for direct marketing).
  • Withdraw Consent: Withdraw your consent at any time where we are relying on it to process your data.

To exercise any of these rights, please contact us at info@heffernanshemp.com. We will respond to your request within one month.

International Transfers

Some of our third-party service providers are based outside the UK and European Economic Area (EEA). When we transfer your data to them, we ensure it is protected by using lawful transfer mechanisms, such as an Adequacy Decision or by implementing Standard Contractual Clauses (SCCs) or the UK's International Data Transfer Agreement (IDTA).

Data Security

We have implemented appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way. These measures include SSL encryption for data in transit and access controls to our systems.

Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. By law, we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.

Cookies, Complaints, and Contact

Cookies

Our website uses cookies to distinguish you from other users. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. We use essential cookies to make the site work and will only use optional analytics or marketing cookies with your explicit consent. For detailed information on the cookies we use and the purposes for which we use them, please see our Cookie Policy.

Contact Us and Your Right to Complain

If you have any questions about this privacy policy or wish to exercise your rights, please contact us:

Data Protection Officer
Heffernans Hemp Ltd
86-90 Paul Street, London, EC2A 4NE
Email: info@heffernanshemp.com

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.

Changes to This Policy

We may update this policy from time to time. Any changes will be posted on this page, and the “Last Updated” date will be revised. We encourage you to review this policy periodically.