top of page

Privacy & Safety

We are committed to safeguarding your privacy online and have developed this privacy policy to deal with issues which may concern you. Please read this policy to understand how your personal information will be treated. This policy may change from time to time so please check it periodically.

The details which you provide about yourself and any information which identifies you (such as your name, email address) (“personal information”) will be collected by us when you contact us, when you submit such information directly by filling in an online form, and when you browse, where cookies may be used.

Effective Date: 1 March 2026
Website: www.whileaways.com


Controller: While Aways

1. Who We Are
While Aways is the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Contact details:
While Aways
22 Crabtree Lane
Hemel Hempstead
Hertfordshire
HP3 9EG
Email: info@whileaways.com
If you have any questions about this Privacy Policy or wish to exercise your legal rights, please contact us using the details above.
You have the right to make a complaint to the Information Commissioner’s Office (ICO) at www.ico.org.uk. We would, however, appreciate the opportunity to resolve your concerns first.

2. Scope of This Policy
This Privacy Policy explains:
What personal data we collect
How we use it
The lawful basis for processing
Who we share it with
How long we retain it
Your legal rights
This policy applies when you:
Visit our website
Create an account
Purchase products
Contact us
Subscribe to marketing communications

3. The Personal Data We Collect
We collect personal data directly from you and automatically through your use of our website.


3.1 Data You Provide
We may collect:
Full name
Billing and delivery addresses
Email address
Telephone number
Order details
Payment details (processed securely via third-party payment providers)
Marketing preferences
Communications you send to us
We do not store full payment card details on our systems.

3.2 Data Collected Automatically
When you use our website, we may collect:
IP address
Device type
Browser type and version
Operating system
Time zone setting
Website usage data
Pages viewed and navigation paths
Referral source
This information is collected through cookies and similar technologies. Please refer to our Cookie Policy for further details.

4. Special Category Data
We do not intentionally collect special category personal data (e.g., health data, ethnicity, religious beliefs) through our e-commerce website.

5. Lawful Basis for Processing
Under Article 6 UK GDPR, we process personal data on the following lawful bases:


5.1 Performance of a Contract
Where processing is necessary to:
Process and fulfil orders
Deliver products
Process payments
Manage customer accounts


5.2 Legal Obligation
Where processing is necessary to:
Comply with tax and accounting obligations
Respond to lawful requests from authorities


5.3 Legitimate Interests
Where processing is necessary for:
Website administration
Fraud prevention
Improving our products and services
Customer service management
We ensure that our legitimate interests do not override your fundamental rights and freedoms.


5.4 Consent
We rely on consent only where required, including:
Sending marketing communications by email
Placing non-essential cookies
You may withdraw consent at any time.

6. Marketing Communications
We will send you marketing communications if:
You have opted in; or
You have purchased from us and have not opted out (in accordance with the Privacy and Electronic Communications Regulations 2003).
You can unsubscribe at any time by:
Clicking the unsubscribe link in emails; or
Contacting us at info@whileaways.com
We do not sell personal data to third parties.

7. Disclosure of Personal Data
We may share personal data with:
7.1 Service Providers (Processors)
Including:
Payment processors
Website hosting providers
Email marketing platforms
Delivery and courier services
IT and system administration providers
Analytics and advertising platforms
Professional advisers (legal, accounting, insurance)
These providers are contractually bound to process personal data only on our instructions and to maintain appropriate security.

7.2 Legal Authorities
We may disclose personal data where required by law or regulatory obligation.

7.3 Business Transfers
If we sell or restructure our business, personal data may be transferred to the new owner subject to the same safeguards.

8. International Transfers
Some service providers may process personal data outside the United Kingdom.
Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
UK-approved International Data Transfer Agreements (IDTAs);
Standard Contractual Clauses;
Transfers to countries with an adequacy decision issued by the UK government; or
UK Extension to the EU-US Data Privacy Framework (where applicable).

9. Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
Secure hosting infrastructure
Encryption (HTTPS)
Restricted access controls
Secure third-party payment processing
While we take reasonable precautions, no method of transmission over the internet is completely secure.

10. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected.
Transaction records are retained for 7 years to comply with UK tax legislation.
Marketing data is retained until you withdraw consent.
Website analytics data is retained in accordance with cookie settings.
Where appropriate, we anonymise data for statistical purposes.

11. Your Rights Under UK GDPR
You have the right to:
Request access to your personal data
Request correction of inaccurate data
Request erasure (in certain circumstances)
Request restriction of processing
Object to processing based on legitimate interests
Request data portability
Withdraw consent where processing is based on consent
To exercise your rights, contact: info@whileaways.com
We may request proof of identity before responding.
We aim to respond within one month.

12. Automated Decision-Making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

13. Children
Our website is not directed at children under 16.
 We do not knowingly collect personal data from children.

14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law or our practices. The latest version will always be available on our website.

 

By using our Site, you consent to the terms of this Privacy Policy.

bottom of page