We do all we can to respect, limit and protect your Personal Data. By using our Services, you agree to be bound by this Privacy Policy. This policy was updated on 22 May 2018.

1. Introduction

A Shade Above Ltd (hereinafter “A Shade Above”, “we”, “us” and “our”) is a bespoke, handmade lampshade specialist working with interior and lighting designers, hoteliers and architects worldwide. A Shade Above is a company limited by guarantee (Registered in England and Wales: 3966726). Our registered address is Regency House, North Street, Portslade, Brighton and Hove BN41 1ES UK.

Our products and services (hereinafter “Services”) are available to anyone via Our Website (hereinafter “Our Website”), located or directly at our workshop. This Privacy Policy, together with any other referenced documents herein, explains what Personal Data we collect, how we collect it and why, how we use this data, the conditions under which we may disclose it to others and what choices our customers (hereinafter “Customers”, “you”, “your”), meaning any person who has made a contractual agreement with us, used Our Website or who has registered and holds an account on Our Website, have.

For the purposes of this policy and in respect of your personal data (hereinafter “Personal Data”) A Shade Above may act as either a data controller (hereinafter “Controller”), that is, the entity that decides how and why Personal Data is processed, or, a data processor (hereinafter “Processor”, “Third Party Service Provider”), meaning, any person, other than employees of the Controller, entity or entity’s website, that processes Personal Data on behalf of the Controller, depending on the circumstances. Data “process”, “processing” or “processed” means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

2. What is personal data

Personal Data is information that can be used directly or indirectly to identify you. Personal data also includes anonymous information that is linked to information that can be used to directly or indirectly identify you. Personal Data does not include information that has been irreversibly anonymised or aggregated so that it can no longer enable us, whether in combination with other information or otherwise, to identify you.

3. Why we collect personal data

Our legal grounds for collecting your Personal Data is because either you provided your express consent (written, verbal or online) to the processing of your Personal Data, it is necessary for our contractual relationship (“contractual necessity”), the processing is necessary for us to comply with our legal or regulatory obligations or we have a legitimate interest in carrying out the processing for the purpose of managing, operating or promoting our business.

4. Personal data we collect

We collect the minimum amount of data we need to be able to deliver our Services to you in the best possible way, to maintain Our Website, to protect the privacy of all our Customers, to keep you informed, to process transactions for you and respond to correspondence. We do not gather sensitive Personal Data about you without your prior, informed, consent. We may collect Personal Data either directly from you, automatically from your devices that interact with our Services, or from Third Party Service Provider sources as described below.

● Your name, email addresses, telephone numbers, postal, delivery and contact addresses;
● Gender, date of birth, language and title;
● Payment type or method, username and encrypted password;
● Any consents, communications and feedback;
● Personal interests;
● Work-related information such as company name and contact details;
● Gift purchase information such as the recipient’s name, delivery addresses, telephone numbers and email addresses; and
● Other personal information collected on the basis of your prior, express, voluntary consent (including public social media profiles and website content).

● Your user account identity (username, name, email address) and registration date;
● Your browser, operating system, device model, IP-address, time of access and duration of access;
● Location data such as GPS coordinates or similar measures;
● Web pages through which Our Website were accessed, the pages browsed by you, any other activities you undertook during your visit to Our Website such as interactions, clicked referral links and search key words you used;
● Cookies and other identification tags;
● Your participation in our promotions, surveys or competitions; and
● Other information collected based on your consent.

● Information on orders, deliveries, payment methods, billing and delivery addresses and other information related to any business you may do with A Shade Above;
● Any communication we have with you;

Note that when using any of our paid Services, you may be asked for financial details such as credit or debit card information for payment processing purposes. Any Personal Data collected during payment processing is held on Third Party Service Provider’s separate secure servers and is subject to that Third Party Service Provider’s terms and privacy policy. We do not store any credit or debit card information on our servers. Refer to Section 11 regarding “Exclusions”.

● If you have connected to any A Shade Above website, service or social media channel using your social media profile(s), we may collect the public information available on your social media profile(s);
● We may collect information from public registers maintained by authorities, if such registers are available in your country; and
● Updated delivery and contact information from delivery agents.

5. Cookies and similar technologies

Our Website use cookies and similar technologies to provide, protect, and improve our Services, such as by personalising content, offering and measuring advertisements, understanding user behaviour, and providing a safer experience. You can remove or reject cookies using your browser or device settings, but in some cases doing so may affect your ability to use our Services. Please read our separate Cookies Policy for more information and how to refuse cookies.

6. How we use your personal data

We use the private information we have collected for the following purposes:

As is our legal obligation we will notify you by email about any changes to our terms of service and other legal policies or documentation.

We may process your Personal Data for the purposes of detecting, investigating and preventing unlawful or fraudulent activities. We may provide your information to law enforcement authorities based on their request or on a legal basis defined in any applicable law for prevention and investigation of fraud and other unlawful activities. We may disclose your Personal Data to any party in response to an order from a court of competent jurisdiction.

If you have ordered and paid Services from us, we may collect your Personal Data for the purposes of processing your order(s) and to fulfil any contractual obligations we have with you. Payment details are not stored in our systems. Instead, payment data is provided by you directly to Third Party Service Providers. Refer to Section 11 regarding “Exclusions”.

We will retain your Private Data in order to respond effectively to your correspondence with us (written or verbal). If you are a business or have subscribed to any of our marketing and communication channels, we will keep you informed of A Shade Above news, information published on Our Website and offer you the most relevant Services. Such marketing and communications may be carried out via mail, telephone, electronic messages (emails and other electronic messages), digital online displays, web-based notifications and search engine marketing.

We may need to identify you for the purposes of ensuring your privacy and the privacy of all our Customers is protected. We may also identify you to provide you with better, more personalised and customised Services. For example, Our Website use “cookies”to enhance your experience when browsing. Refer to Section 5 regarding “Cookies”.

We use anonymised data to help us maintain and develop Our Website, troubleshoot problems, research general user interests, to keep Our Website safe and secure and to monitor actual or suspected fraudulent activity. This information is delivered to us by Third Party Service Providers in an aggregated format. Data in an aggregated format cannot be used to identify you and is not considered Personal Data. Refer to Section 11 regarding “Exclusions”.

We may process Personal Data to allow you to participate in interactive features of our Services, ensure any content you publish on Our Website is presented effectively, measure the effectiveness of our Services, improve our existing Services and to develop new ones. If you choose to participate in any of our consumer surveys, panels or questionnaires we may connect any feedback and communication received from you with your account. Such activities are aimed at ascertaining a meaningful analysis of our customers’ preferences, expectations and opinions. The processing of Personal Data collected through such research, panels and surveys is governed by this Privacy Policy.

7. Retention period

We take every reasonable step to ensure that your Personal Data is processed for the minimum period necessary and solely for the purposes set out in this Privacy Policy.

Your Personal Data is stored for as long as it is absolutely necessary to deliver our contracted Services.

We may retain your data for a longer period if we are legally required to do so in compliance with applicable law including the resolution of legal claims and disputes, to establish, exercise or defend our legal rights and any other additional periods required or permitted under applicable law. Remember to update your information if any material changes occur.

If you have created an account on Our Website, your Personal Data will be retained until such time as you either terminate the account and request that your data be deleted.

8. Disclosure

There are certain controlled circumstances in which we may disclose, transfer or share your information with certain Third Party Service Providers without further notice to you and in accordance with applicable law. Your data is adequately protected if transferred internationally.

We do not, and will never, procure, sell, lease or rent your Personal Data.

We do not use any Personal Data for automated decision making or profiling nor is such data subject to automated decision making or profiling.

We may disclose your Personal Data if required to do so by law in order to, for example, respond to a subpoena or request from law enforcement, a court or a government agency, including in response to public authorities to meet national security or law enforcement requirements, or in the belief that such action is necessary to (a) comply with a legal obligation, (b) protect or defend our rights, interests or property or that of third parties, (c) prevent or investigate possible wrongdoing in connection with our Services, (d) act in urgent circumstances to protect the personal safety of our Customers or the public, or (e) protect against legal liability.

In the event of any sale, consolidation or reorganisation of our businesses (for example mergers and acquisitions), we may disclose your Personal Data to prospective or actual purchasers or their advisers, where appropriate.

We may pass limited information to some Third Party Service Providers who we have engaged for the purpose of providing you with our Services and any other contractual obligations we have established with you. Such disclosures may include transferring your Personal Data to payment processors, companies that facilitate your orders, delivery companies and customer service teams. We also share information with analytics providers that assist us in the improvement and optimisation of Our Website. This analysis data is aggregated and does not identify you. We have verified that these Third Party Service Providers are GDPR compliant and are certified under the EU-US Privacy Shield Framework where these organisations are based outside of the European Union.

9. Safeguarding

We take security very seriously and have created and implemented both technical and organisational safety measures, systems and processes to protect your Personal Data. Such security measures are designed to protect your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of processing, in accordance with applicable law. A copy of our internal Data Security Policy is available on request.

All personnel authorised to access and process Personal Data are trusted and accredited or are authorised personnel of Third Party Service Providers operating on our behalf. All A Shade Above personnel who are granted access to your Personal Data are required to keep such data strictly confidential.

All Private Data is stored on encrypted, password protected, servers. We use best practice concerning devices such as computers, laptops and mobiles, online accounts, website hosting servers as well as physical access and storage.

We hold only the data that is absolutely necessary to deliver our Services.

Unfortunately, the transmission of information via the internet is never completely secure. We therefore cannot guarantee the security of your data transmitted to our site and any such transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. Additionally, the data that we collect from you may be transferred to, and stored, at a destination outside the European Economic Area (“EEA”). It may also be processed by personnel operating outside the EEA who work for one of our Third Party Service Providers. Third party personnel may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support Services. By submitting your Personal Data, you agree to this transfer, storing and/or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.

Website account holders are required to hold a secure password in order to access and make use of some Services. As an account holder on Our Website or authorized Third Party Service Providers, your password/s are additionally encrypted and therefore strictly private to you alone. You are responsible for keeping your password/s confidential and we ask you not to share them with anyone.

10. Your rights

You have certain rights concerning the information we hold about you, as defined under the General Data Protection Regulation (hereinafter “GDPR”). If you have contracted business with us, subscribed to any of our communication Services and/or registered an account on Our Website, you have full access to your private information with, as is your right, the ability to opt in, view, update, correct, take copy of and delete forever your private information. If you would like to request copy, submit a query, request to be deleted or have any difficulty in accessing and/or managing your options please contact us by email in the first instance. Note that there is a small fee for some of these services and we will respond within 40 days.

You may choose not to provide your Personal Data to us. Note that some features of our Services may not be fully available to you if you choose not to provide us with your Personal Data. For example, we may not be able to process your orders without the necessary details.

By choosing to contract business with us, subscribe to any of our marketing and communication Services and register an account on Our Website you will be given prior informed opportunity to provide the minimum Personal Data required and consent to our retention of same.

You have the right to request access to your Personal Data, together with information regarding the nature, processing and disclosure of that data, at any time. We hope to ensure that the Personal Data we possess is accurate at all times and therefore we encourage you to update us should any changes have occurred. As a registered and logged in account holder on Our Website or authorised Third Party Service Providers websites, you can view and manage the information held on your account at any time. If you have opted in to any of our marketing and communications Services you will find the links to update your information at the bottom of every communication you have previously received or displayed prominently on the relevant website.

You may request a copy of any data we hold about you. Expect our response within and up to 40 days of the date of your request. Upon request, we will provide you with an electronic file containing the Personal Data we hold on record about you.

You may at any time decide to withdraw your consent to the processing of your Personal Data and request erasure. If your consent is withdrawn, we will update our database promptly, however, it does not prevent us from processing your Personal Data based on other legal premises, such as fulfilling your orders and storing your order data as required by applicable law. Please note that withdrawal of consent does not affect the lawfulness of any processing performed prior to the date on which we receive notice of such withdrawal. We include an unsubscribe link in all electronic marketing messages we send to you and options to cancel your account on Our Website.

You may have the right to object, on legitimate grounds, to the processing of your Personal Data. Should you believe that our processing of your Personal Data is inaccurate or illegal, we are not processing your data in accordance with the processing purpose or you want to oppose the processing, please contact us by email. We will investigate your request promptly before deciding what action to take. Should you believe that our processing of your Personal Data infringes your legal rights, you may lodge a claim with your local supervisory authority – National Data Protection Authorities

11. Exclusions

Our Services are not directed at persons under the age of 18 years. Therefore, we do not seek to collect Personal Data of children. If you learn that a person under the age of 18 years has provided us with Personal Data without consent, please contact us by email.

This Privacy Policy does not apply to any Personal Data that you provide to another website user or visitor to Our Website or other Customers through any of our Services or through any other means, including information posted by you to any public areas of Our Website. As copyright owner of all the content you create on Our Website, you may include for publication any private information you wish and do so at your own risk. We take all necessary steps to protect the Personal Data collected from loss, misuse, unauthorised use, access, inadvertent disclosure, alteration and destruction. However, no network, server, database, internet or e-mail transmission is ever fully secure or error free. Therefore, you should take special care in deciding what information you choose to publish on Our Website.

This Privacy Policy applies only to our Services and does not apply to Third Party Service Providers or third party websites. Certain elements of Our Website in particular, contain features, interactive user activities such as social sharing buttons and/or links to other websites not operated or controlled by us. In providing such features, activities and links to these third party websites does not imply that we endorse or have reviewed these websites and therefore we cannot be held liable for any privacy policies or terms and conditions concerning the data privacy of such third parties. We suggest that you contact these websites directly for information about their privacy policies.

12. Changes to this privacy policy

We may update this Privacy Policy from time to time. Any changes we make will be published here, on Our Website, so please ensure you visit this page occasionally to stay informed.

13. Contact

If for any reason you feel that your private information is not secure, you wish to raise a complaint or you have any questions regarding this Privacy Policy and our privacy practices please contact us by email. For more information about Private Data and GDPR please visit the Information Commissioner’s Office website.