Privacy policy
Effective date: 14th June 2026 | 12pm [GST Time]
This Privacy Policy explains how Doelara collects, uses, stores, and shares personal data, and explains the rights available to individuals under applicable data protection law. ICO guidance states that a privacy notice should identify contact details, the types of personal data collected, where data comes from, why it is used, the lawful basis relied on, who it is shared with, how long it is kept, and the individual rights and complaint routes available.
1. Who controls the data
Doelara is the controller of personal data collected through its website and customer interactions, except where another party is clearly identified.
Contact details for privacy queries should be listed in the Contact Information page, including a valid contact email.
2. Personal data collected
Doelara may collect and process the following categories of personal data:
-
identity and contact data, such as name, email address, billing address, shipping address, and telephone number;
-
transaction data, such as products purchased, order values, payment status, and refund history;
-
account and communications data, such as customer service messages, reviews, survey responses, and correspondence records;
-
technical data, such as IP address, browser type, device identifiers, cookies, and website usage data; and
-
marketing preference data, including consent records and communication choices.
3. How data is collected
Personal data may be collected when an individual places an order, creates an account, signs up to marketing, contacts support, browses the website, interacts with cookies, enters a promotion, or otherwise communicates with Doelara.
In limited cases, data may also be received from payment providers, delivery partners, analytics providers, advertising partners, fraud-screening tools, or other third parties involved in operating the store.
4. Purposes of processing and lawful bases
Doelara may process personal data to:
-
fulfil orders, take payment, deliver purchases, and provide customer service;
-
manage refunds, returns, disputes, and fraud-prevention checks;
-
maintain business records, tax records, and legal compliance obligations;
-
improve website performance, store operations, and customer experience;
-
send service communications relating to orders, accounts, and policy updates; and
-
send marketing communications where consent has been given or another lawful basis applies.
Lawful bases may include performance of a contract, compliance with legal obligations, legitimate interests, and consent where required.
5. Sharing data
Doelara may share personal data with service providers and partners where reasonably necessary to operate the business, including payment processors, website and ecommerce platform providers, hosting providers, fraud-prevention providers, delivery partners, customer support tools, analytics providers, advertising partners, and professional advisers.
Personal data may also be disclosed where required to comply with legal obligations, enforce rights, detect fraud, or protect the business, customers, or the public.
6. International transfers
Where personal data is transferred outside the UK, Doelara will take steps intended to ensure that an appropriate level of protection applies in accordance with applicable data protection law.
7. Data retention
Personal data will be retained only for as long as reasonably necessary for the purposes for which it was collected, including legal, tax, accounting, dispute-handling, and fraud-prevention purposes.
Retention periods may vary depending on the nature of the data and the reason for processing.
8. Individual rights
Individuals may have rights including the right to access personal data, request correction, request erasure, object to certain processing, request restriction, request transfer where applicable, and withdraw consent where consent is relied on. ICO guidance also says the privacy notice should explain the right to complain and, where relevant, the right to withdraw consent.
Complaints may be raised with the UK Information Commissioner’s Office if concerns cannot be resolved directly.
9. Cookies and similar technologies
Doelara may use cookies and similar technologies to support site functionality, security, analytics, personalisation, and marketing. Where required, non-essential cookies will be used only with valid consent.
10. Data security
Doelara uses reasonable technical and organisational measures intended to help protect personal data from unauthorised access, loss, misuse, or alteration. No method of transmission or storage can be guaranteed to be completely secure.
11. Children’s data
Doelara’s website and products are not directed to children unless expressly stated. Where children’s data is processed, additional care should be taken to ensure transparency and fairness in line with applicable guidance.
12. Privacy policy updates
This Privacy Policy may be updated from time to time. The latest version published on the website will apply from its effective date.