Privacy policy
Privacy Policy
Last updated: 26 November 2024
1. Introduction
1.1 We are Maloa Ltd, a company registered in England and Wales under company number 16035805 with our registered office at 110 Brooker Road, Waltham Abbey, England, EN9 1JH (we, us or our). We are the controller responsible for your personal data.
1.2 We comply with Data Protection Laws, which means the General Data Protection Regulation (EU) (2016/679) (GDPR), and any applicable laws, regulations, and other legal requirements relating to (a) privacy, data security, and protection of personal data; and (b) the processing of any personal data, which may include, but are not limited to, the EU law retained version of the GDPR (UK GDPR), the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). We also strive to comply with other state-specific privacy laws as they apply, including the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), and the Utah Consumer Privacy Act (UCPA).
1.3 We are registered with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues. Our registration number is ZB816094. If you have any concerns about data protection, please contact us first at info@maloa.co.uk.
1.4 We respect your privacy and are committed to protecting your personal data. This policy explains how we collect and process your data when you:
- Visit our website at https://maloa.co.uk/
- Make a purchase
- Contact us
- Engage with us in any other way
2. The Data We May Collect About You
2.1 Personal data means any information that can identify an individual. We may collect:
- Identity Data: Name, title, date of birth, gender
- Contact Data: Address, email, phone number
- Financial Data: Payment and bank details
- Transaction Data: Purchase details
- Technical Data: IP address, browser, device info
- Profile Data: Orders, preferences, feedback
- Usage Data: Website interaction data
- Marketing Data: Communication preferences
- Aggregated Data: Statistical data (non-identifiable)
3. How Is Your Personal Data Collected
We collect data through:
- 3.1 Direct interactions: Forms, purchases, emails, social media
- 3.2 Automated technologies: Cookies, server logs, tracking tools
- 3.3 Public sources: Google, Companies House, electoral register
4. How We Use Your Personal Data
We use your data only when legally permitted:
- 4.1 Contract: To fulfil orders or services
- 4.2 Legitimate Interests: Business improvement and operations
- 4.3 Legal Obligation: Compliance with law
- 4.4 Consent: Marketing and newsletters
5. Purposes for Which We Will Use Your Personal Data
We use your data for purposes including:
- Processing orders and payments
- Managing customer relationships
- Improving website performance
- Marketing communications (with consent)
- Legal and regulatory compliance
| Purpose / Use | Type of Data | Lawful Basis for Processing (Including Basis of Legitimate Interest) |
|---|---|---|
| To enable you to submit an enquiry to us, whether via email, through our website or via social media, including but not limited to our Instagram or Facebook | Identity Contact |
Contract Legitimate interests (to enable us to respond to your enquiries) |
| To enable you to make a purchase on our website, including: (a) Manage shipping and refunds, (b) Manage payments, fees, and charges (c) Collect and recover money owed to us |
Identity Contact Financial Transaction Marketing and Communications |
Contract Legitimate interests (to enable us to recover debts due to us) |
| To manage our relationship with you which will include: (a) Notifying you about changes to our terms or conditions or this privacy and cookies policy (b) Dealing with your requests, complaints, and queries |
Identity Contact Profile Marketing and Communications |
Contract Legal Obligation Legitimate interests (to keep our records updated and manage our relationship with you) |
| To enable you to register for our mailing list/email marketing | Identity Contact Marketing and Communications |
Contract Consent Legitimate interests (to provide you with the newsletter/email marketing and present you with information, or services we consider you will be interested in) |
| To administer and protect our business and our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | Identity Contact Technical |
Legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring) Legal Obligation |
| To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you | Identity Contact Profile Usage Marketing and Communications Technical |
Legitimate interests (to study how customers use our services, to develop them, to grow our business and to inform our marketing strategy) |
| To use data analytics to improve our website, services, marketing, customer relationships and experiences | Technical Usage |
Legitimate interests (to define types of customers for our services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
| To make suggestions and recommendations to you about goods or services that may be of interest to you | Identity Contact Technical Usage Profile Marketing and Communications |
Legitimate interests (to develop our products/services and grow our business) |
6. Direct Marketing
6.1 You will receive marketing communications from us if you have requested information from us or purchased goods or services from us and you have not opted out of receiving the marketing.
6.2 We may also analyse your Identity Data, Contact Data, Technical Data, Usage Data and Profile Data to form a view which products, services and offers may be of interest to you so that we can then send you relevant marketing communications.
7. Third Party Marketing
We will get your express consent before we share your personal data with any third party for their own direct marketing purposes.
8. Opting Out of Marketing
8.1 You can ask to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us at info@maloa.co.uk.
8.2 If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.
9. Cookies
9.1 Our website uses cookies to distinguish you from other users of our website and improve your browsing experience.
9.2 A cookie is a small file of letters and numbers stored on your browser or device if you agree.
9.3 We use the following cookies:
- Strictly necessary cookies: Required for website functionality.
- Analytical cookies: Help us understand website usage.
- Functionality cookies: Remember your preferences.
- Targeting cookies: Deliver relevant advertisements.
9.4 Third parties such as Google Analytics may also use cookies to analyse traffic and usage data.
9.5 You can block cookies via your browser settings, but some parts of the website may not function properly.
10. Disclosures of Your Personal Data
10.1 We may share your personal data with staff, courier services, business partners, legal authorities, and fraud prevention agencies.
10.2 We use third-party services including:
- Payment processors
- Order fulfilment providers
- Courier services
- Analytics providers
- Email services
- IT infrastructure providers
10.3 All third parties must respect the security of your data and process it only as instructed.
11. Data Security
11.1 We implement appropriate security measures to protect your data.
11.2 In case of a data breach, we will notify you where legally required.
11.3 You are responsible for keeping your password confidential.
11.4 Internet data transmission is not completely secure.
12. International Transfer
12.1 We may transfer your data outside the UK/EEA with appropriate safeguards.
12.2 Contact us for details about data transfer protections.
13. Data Retention
13.1 We retain your data only as long as necessary.
13.3 Legal requirements may require retention up to six years.
14. Your Legal Rights
You have rights including access, correction, deletion, objection, and data portability.
To exercise your rights, contact info@maloa.co.uk.
15. Privacy Rights (US States)
Residents of California and other US states have rights including access, deletion, and non-discrimination.
16. Third Party Links
We are not responsible for privacy practices of external websites.
17. Policy Changes
17.1 This policy was last updated on 26 November 2024.
17.2 Please keep your personal data up to date.