Data Protection & UK GDPR

**Last updated: 10 September 2026** Woma Woma is committed to handling personal information responsibly, transparently and securely. This page explains our approach to data protection and the principles we follow when processing personal information. Woma Woma Ltd processes personal information in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where applicable to our activities in the European Economic Area, we also take account of the EU General Data Protection Regulation. Our use of electronic marketing, cookies and similar technologies is also managed in accordance with applicable privacy and electronic communications requirements. ## Our Data Protection Principles When we process personal information, we aim to ensure that it is: ### Used lawfully, fairly and transparently We explain what information we collect, why we need it and how it will be used. ### Collected for clear purposes We use personal information only for specified and legitimate business purposes and do not use it in ways that are incompatible with those purposes. ### Limited to what is necessary We seek to collect only the personal information reasonably required for the relevant purpose. ### Accurate and kept up to date We take reasonable steps to ensure that personal information is accurate and correct inaccurate information where appropriate. ### Retained only as long as necessary We do not keep personal information indefinitely and review retention based on operational, contractual, legal and regulatory requirements. ### Kept secure We use appropriate technical and organisational measures designed to protect information from unauthorised access, loss, misuse, alteration or disclosure. ## Lawful Processing Woma Woma only processes personal information where there is an appropriate lawful basis. Depending on the activity, this may include: - **Contract** — where processing is necessary to provide products or services, fulfil an order or take steps requested before entering into an agreement. - **Legal obligation** — where we need to process or retain information in order to comply with applicable law. - **Legitimate interests** — where processing is reasonably necessary for the operation, administration, improvement or protection of our business and those interests are not overridden by the rights and interests of the individual. - **Consent** — where an individual has freely chosen to allow a particular use of their information, including where consent is required for certain marketing or tracking technologies. Where processing is based on consent, that consent can be withdrawn at any time. ## Your Rights Data protection law gives individuals a number of rights over their personal information. Depending on the circumstances, these may include the right to: - Access personal information we hold about you. - Correct inaccurate or incomplete information. - Request deletion of personal information in certain circumstances. - Request restriction of processing. - Object to certain types of processing. - Request portability of certain personal information. - Withdraw consent where processing is based on consent. - Object to the use of personal information for direct marketing. Requests relating to personal information can be sent to: **beans@womawoma.co.uk** We will respond to valid requests in accordance with the timeframes and requirements established by applicable data protection law. ## Data Protection by Design We aim to consider privacy and data protection when introducing new systems, suppliers, processes and digital services rather than addressing these issues only after information has been collected. This includes considering: - What personal information is required. - Why it needs to be collected. - Who needs access to it. - How long it needs to be retained. - How it will be secured. - Whether third-party suppliers will process it. Where an activity may create a high risk to individuals, we will consider whether an appropriate data protection impact assessment or additional safeguards are required. ## Service Providers and Data Processors Woma Woma uses third-party providers to support areas such as: - Website operation. - E-commerce. - Payments. - Communications. - Logistics. - Analytics. - IT infrastructure. - Professional services. Where another organisation processes personal information on our behalf, we take appropriate steps to ensure that relevant data protection responsibilities and safeguards are addressed. Third-party providers are not permitted to use personal information supplied by Woma Woma for unrelated purposes simply because they have access to it. ## International Data Transfers Our suppliers and technology providers may operate internationally. Where personal information is transferred outside the United Kingdom, we use appropriate transfer mechanisms and safeguards where required by law. Where EU GDPR applies, we also consider the applicable requirements relating to transfers of personal information outside the European Economic Area. ## Cookies and Online Privacy We use cookies and similar technologies in accordance with applicable privacy and electronic communications requirements. Strictly necessary technologies may be used where required for the website to function. Where consent is legally required for analytics, marketing or other non-essential technologies, those technologies should not be activated until the appropriate consent has been obtained. Users can change their cookie preferences through the controls made available on our website. ## Direct Marketing We aim to communicate with customers and business contacts in a relevant and responsible way. Marketing communications are sent only where we have an appropriate legal basis and where the applicable electronic marketing requirements permit us to do so. Recipients can opt out of marketing communications at any time. ## Data Security We take reasonable technical and organisational precautions designed to protect personal information. Our approach may include: - Access controls. - Secure systems. - Appropriate supplier management. - Authentication measures. - Backups. - Other safeguards appropriate to the nature of the information being processed. We review our practices as our business, systems and risks evolve. ## Personal Data Breaches If a security incident involving personal information occurs, we assess the nature and potential impact of the incident and take appropriate steps to contain and investigate it. Where applicable law requires notification of a personal data breach to the Information Commissioner’s Office or affected individuals, we will make the required notifications within the applicable timeframe. ## Accountability Data protection is an ongoing responsibility rather than a one-time exercise. We periodically review: - The personal information we process. - How it is used. - The organisations that may have access to it. - Whether our practices remain appropriate. For detailed information about the personal information Woma Woma collects and uses, please see our **Privacy Policy**. ## Contact For questions about data protection or to exercise your data protection rights, contact: **Woma Woma Ltd** 5 Brayford Square London E1 0SG United Kingdom **Email:** beans@womawoma.co.uk If you remain concerned about how your personal information has been handled, you have the right to make a complaint to the UK Information Commissioner’s Office.