At Elyah, I value your trust and am committed to protecting your personal data. This Privacy Policy explains how your information is collected, used and protected when you visit or make a purchase from this website.

Elyah is the data controller responsible for your personal data under UK data protection law.

If you have any questions, please contact: info@elyah.co.uk

Information I collect

Information you provide directly

When you interact with the website, I may collect:

  • Name

  • Email address

  • Billing and shipping address

  • Payment details (securely processed by third-party providers – I do not store this)

  • Order details

  • Messages sent via contact form or email

Information collected automatically:

When you browse the website, I may collect:

  • IP address

  • Device information

  • Browser type

  • Pages viewed

  • Time spent on the site

This helps me understand how visitors use the website and improve it over time.

Legal Basis for Processing (UK GDPR)

I process your personal data under the following legal bases:

  • Contract – to process and deliver your orders

  • Legal obligation – to comply with tax and accounting requirements

  • Legitimate interests – to operate and improve the business, prevent fraud, and analyse website use

  • Consent – where required (e.g. marketing or non-essential cookies)

How Your Information Is Used

Your data may be used to:

  • Process and deliver your orders

  • Communicate updates about your purchase

  • Respond to enquiries

  • Improve the website and user experience

  • Prevent fraud or misuse

  • Comply with legal obligations

  • I do not sell your personal data.

Sharing Your Information

I only share your information with trusted third parties who help me run the business.

A. Website Hosting (Hostinger)

My website is hosted by Hostinger International Ltd. They may process technical data (IP address, device info, server logs) to ensure the site runs securely and smoothly. Hostinger is GDPR‑compliant and processes data only on my behalf.

B. Service Providers

Your information may also be shared with:

  • Payment processors (e.g. Stripe)

  • Delivery couriers

  • Analytics tools (e.g., Google Analytics)

All third parties:

  • Process your data only on my instructions

  • Are required to comply with data protection laws

  • Only receive the information necessary for their role

International Data Transfers

Some third-party providers may process your data outside the UK.

Where this occurs, I ensure appropriate safeguards are in place (such as standard contractual clauses or equivalent protections) to keep your data secure and compliant with UK GDPR.

Cookies

Cookies are small data files stored on your device to help the website function and improve performance.

Cookies may be used to:

  • Enable core website functionality

  • Analyse website traffic and behaviour

  • Improve user experience

You can control or disable cookies through your browser settings.

Where required by law, a cookie consent banner is used to request your permission before non-essential cookies are placed.

Your Rights (UK GDPR)

You have the right to:

  • Access the personal data I hold about you

  • Request corrections to inaccurate information

  • Request deletion of your data (in certain circumstances)

  • Object to certain types of processing

  • Withdraw consent where applicable

  • Request a copy of your data

To exercise any of these rights, email me at info@elyah.co.uk

Complaints

If you are not satisfied with how your data is handled, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

Information Commissioner's Office

Data Retention

I only retain your personal data for as long as necessary:

  • Order data: typically 6 years (to comply with UK tax and legal obligations)

  • Enquiries: retained only as long as needed to respond and follow up

  • Analytics data: retained in line with provider policies

Once data is no longer required, it is safely deleted.

Security

I take appropriate technical and organisational measures to protect your data, including:

  • Secure hosting and encrypted connections (SSL)

  • Use of trusted third-party providers

  • Restricted access to personal data

However, no online system is completely secure, and I cannot guarantee absolute security.

Changes to This Policy

This Privacy Policy may be updated from time to time.

Any changes will be posted on this page with an updated date.

Contact

If you have questions about this policy or how your data is handled, please reach out:

Email: info@elyah.co.uk

Privacy Policy