Privacy Policy
Last updated: 1 January 2025
1. Data Controller
Creartio LTD ("we", "us", "our") is the data controller responsible for your personal data. We are registered in England and Wales and our registered address is Basement, 56 Theobalds Rd, London WC1X 8SF, United Kingdom.
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at: info@creartio.com
2. What Data We Collect
We may collect and process the following categories of personal data:
- Identity Data: first name, last name, title.
- Contact Data: billing address, delivery address, email address, telephone number.
- Transaction Data: details about payments and purchases made through our Website.
- Technical Data: IP address, browser type and version, time zone setting, operating system, and platform.
- Usage Data: information about how you use our Website, products, and services.
- Marketing Data: your preferences in receiving marketing from us and your communication preferences.
3. How We Collect Your Data
We collect data through:
- Direct interactions: when you create an account, place an order, subscribe to our newsletter, or contact us.
- Automated technologies: as you navigate our Website, we may automatically collect Technical and Usage Data using cookies, server logs, and similar technologies.
- Third parties: we may receive data from analytics providers, payment service providers, and delivery partners.
4. Legal Basis for Processing
We process your personal data on the following legal bases under the UK General Data Protection Regulation (UK GDPR):
- Contract: processing is necessary to perform a contract with you (e.g., to fulfil your order).
- Legitimate interests: processing is necessary for our legitimate business interests (e.g., improving our Website, preventing fraud), provided these are not overridden by your rights.
- Consent: where you have given clear consent for us to process your personal data for a specific purpose (e.g., marketing emails).
- Legal obligation: processing is necessary to comply with a legal obligation (e.g., tax and accounting requirements).
5. How We Use Your Data
We use your personal data to:
- Process and fulfil your orders, including delivery and payment;
- Manage your account and provide customer support;
- Send you order confirmations, dispatch notifications, and delivery updates;
- Send marketing communications where you have opted in;
- Improve our Website, products, and services;
- Detect and prevent fraud;
- Comply with legal and regulatory obligations.
6. Cookies
Our Website uses cookies to distinguish you from other users and to provide a better browsing experience. Cookies are small text files placed on your device. We use the following types of cookies:
- Strictly necessary cookies: required for the Website to function (e.g., session cookies, shopping cart).
- Analytics cookies: help us understand how visitors use the Website (e.g., Google Analytics).
- Functional cookies: remember your preferences and settings.
- Marketing cookies: used to deliver relevant advertisements and track campaign performance.
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of the Website.
7. Third-Party Sharing
We may share your personal data with the following categories of third parties:
- Payment processors: to process your transactions securely (e.g., Stripe).
- Delivery partners: to fulfil and deliver your orders.
- Analytics providers: to help us analyse Website usage (e.g., Google Analytics).
- Marketing platforms: where you have consented to receive marketing communications.
- Legal and regulatory authorities: where required by law or to protect our legal rights.
We do not sell your personal data to third parties.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Typically:
- Order and transaction data: 7 years (for tax and accounting purposes).
- Account data: for as long as your account remains active, plus 2 years.
- Marketing data: until you unsubscribe or withdraw consent.
- Technical and usage data: up to 26 months.
9. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data ("right to be forgotten").
- Right to restrict processing: request that we limit how we use your data.
- Right to data portability: request a copy of your data in a structured, commonly used, machine-readable format.
- Right to object: object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at info@creartio.com. We will respond to your request within one month.
10. Data Protection Officer
For any data protection enquiries or concerns, please contact our Data Protection Officer at:
Email: info@creartio.com
Creartio LTD, Basement, 56 Theobalds Rd, London WC1X 8SF
11. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
Telephone: 0303 123 1113
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.
This document was last updated on March 12, 2026.