Legal information

Privacy policy

This policy describes the personal data we process when you use kcberry.co.uk, the purposes and lawful bases for that processing, how long we keep it, and the rights available to you under UK GDPR.

1. Data controller

The data controller is KCBERRY — Trade & Consulting, Ltd, publisher of kcberry.co.uk. Full details of the entity are given in our legal notice. For any question about your data, write to info@kcberry.com.

2. Data we collect

  • Quote request data — name, email address, phone number, postcode or town of the project, room type, approximate area in square metres, project description and any attachments (photos of the substrate).
  • Contact data — name, email address, phone number and the content of your message.
  • Order data — billing and delivery details, items ordered, amounts. As online sales are handled by our external shop, this data is collected by us only in connection with an accepted quote.
  • Newsletter sign-up data — email address and first name, when you sign up voluntarily.
  • Technical data — pages viewed, date and time, device and browser type, truncated IP address, only if you have accepted analytics cookies.

We do not collect any special category data within the meaning of UK GDPR, and we do not use profiling or automated decision-making producing legal effects on you. Please do not send us any information that is not necessary to assess your project.

3. Purposes and lawful bases

  • Responding to quote requests and enquiries — performance of a contract or steps taken at your request prior to entering into one (Article 6(1)(b) UK GDPR).
  • Processing and delivering an order, issuing the invoice — performance of the contract (Article 6(1)(b)).
  • Providing technical support, after-sales service and handling complaints — performance of the contract and our legitimate interest in the quality of our service (Article 6(1)(b) and 6(1)(f)).
  • Meeting our accounting and tax obligations — legal obligation (Article 6(1)(c)).
  • Measuring site traffic — your consent (Article 6(1)(a)), obtained via the cookie banner and revocable at any time.
  • Sending our marketing communications — your consent for prospects, legitimate interest for existing customers regarding similar products, with an unsubscribe option in every email.

4. Retention periods

  • Quote requests and unanswered enquiries: 3 years from the last contact.
  • Customer records and contractual documents: 5 years after the end of the business relationship.
  • Invoices and accounting records: 6 years, in line with UK tax record-keeping requirements.
  • Newsletter sign-ups: until you unsubscribe, then a maximum of 3 years of inactivity.
  • Analytics trackers and proof of consent: up to 13 months, see our cookie policy.

At the end of these periods, data is deleted or irreversibly anonymised.

5. Recipients and processors

Your data is accessible only to authorised members of our team, limited to what their role requires. We use processors acting on our instructions and bound by a contract compliant with Article 28 UK GDPR:

  • hosting of the site and the database;
  • sending transactional emails (quote confirmation, order confirmation, notifications);
  • sending our marketing communications;
  • site analytics, only with your consent;
  • couriers, for the delivery of pallets and parcels;
  • our accountant and, where relevant, legal advisers.

We may put your request in contact with a partner applicator: this only happens with your explicit agreement and is limited to the information needed to provide a quote. We never sell or rent your data.

6. Transfers outside the UK

Our data is hosted within the United Kingdom and the European Economic Area. Some technical providers may process data from third countries, including the United States. These transfers are governed by UK adequacy regulations or the International Data Transfer Agreement/Addendum, supplemented by technical measures such as encryption in transit and minimisation of the data transferred. A copy of the applicable safeguards is available on request.

7. Security

We implement measures appropriate to the risk: encrypted connections (HTTPS), role-based access control and authentication for administrator accounts, logging, regular backups and database access-control policies. In the event of a data breach likely to result in a high risk to your rights, we will inform the Information Commissioner's Office (ICO) and the individuals concerned within the timeframes required by UK GDPR.

8. Your rights

Under UK GDPR, you have the following rights:

  • right of access — confirmation that processing exists and a copy of your data;
  • right to rectification — correction of inaccurate or incomplete data;
  • right to erasure — deletion of your data, subject to our legal retention obligations;
  • right to object — object to processing based on our legitimate interest, and at any time to direct marketing;
  • right to restriction — pause the use of your data while a check is carried out;
  • right to data portability — receive, in a structured and machine-readable format, the data you provided to us;
  • right to withdraw consent at any time, where processing is based on it;
  • right to lodge a complaint — see section 9 below.

To exercise these rights, write to info@kcberry.com stating your request clearly. We respond within one month, extendable by a further two months for complex requests. Proof of identity may be requested where there is reasonable doubt about who is making the request.

9. Complaints to the ICO

If, after contacting us, you believe your rights have not been respected, you can lodge a complaint with the Information Commissioner's Office: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or online at ico.org.uk.

10. Updates to this policy

This policy may change as our services or the law evolve. The date of the last update appears at the bottom of this page; in the event of a substantial change, we will let you know via an appropriate channel.

Last updated: