Data Protection Policy
Last reviewed: August 2026.
Purpose
This policy summarises the principles Ceramoda Limited applies when handling personal data in connection with its website and ordinary business enquiries.
Data protection principles
Personal data should be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; kept accurate; retained no longer than necessary; and protected with appropriate security.
Lawful processing
Before processing personal data, we consider the relevant lawful basis, which may include contractual necessity, steps taken before contract, legal obligation or legitimate interests. Consent is used where it is the appropriate basis and can be withdrawn where applicable.
Individual rights
Requests relating to access, correction, erasure, restriction, objection or portability should be sent to James@ceramoda.co.uk. We may need to verify identity before responding.
Retention and deletion
Records are retained according to their purpose and any applicable legal, tax, accounting or dispute-resolution need. Data that is no longer required should be securely deleted or anonymised where appropriate.
Security and breach management
Reasonable technical and organisational measures are used to protect information. Suspected personal-data breaches should be assessed promptly, contained where possible and reported to regulators or affected individuals when the law requires.
Processors
Where external processors are used, they should be selected with regard to data protection obligations and engaged under terms appropriate to the processing.
Automated decision-making
The standard website enquiry process does not use solely automated decision-making that produces legal or similarly significant effects.