PRIVACY POLICY – DATA PROCESSING FRAMEWORK
PURPOSE
This policy defines the processing of personal data within our international wine and spirits e-commerce operation, covering security controls applied specifically to payment transactions and contact records.
REGISTRATION DATA COLLECTION
Upon account establishment, we capture name, email address, and a hashed credential. Users may additionally store address books and preference profiles to expedite subsequent order placement.
PURCHASE DATA COLLECTION
Order execution requires processing of: line-item basket contents, billing particulars, delivery destination, jurisdictional tax and duty components, shipping tariffs, and consignment tracking identifiers. These are contractually necessary and support returns administration.
CARD PAYMENT PROCESSING
Payment card data is processed by our PCI-compliant gateway via TLS-encrypted interface. Our systems receive only a transaction outcome and a tokenised pan reference. Full PAN and CVV are not stored.
INFORMATION SECURITY PROTOCOLS
We deploy granular access controls, environmental segmentation, real-time monitoring, backup regimes, and patch cycles. Internal system access is restricted to function-specific roles and is subject to audit trail review.
DATA RECIPIENT CLASSES
Information may be disclosed to: logistics carriers (delivery execution), payment acquirers (transaction settlement), fraud screening platforms (risk modelling), and technical service providers (infrastructure and messaging) – limited to operational necessity.
COOKIE AND SESSION USAGE
Mandatory cookies maintain session state, basket persistence, and security posture. Optional cookies support analytics and personalisation, subject to user preference management where implemented.
RETENTION SCHEDULES
Transaction data is retained for statutory compliance and limitation periods governing contractual claims. Technical telemetry is retained for finite operational security windows.
INTERNATIONAL DATA FLOWS
Cross-border data processing occurs due to distributed hosting, carrier networks, and payment routing. We enforce contractual protections and minimise transferred data to essential fields.
DATA SUBJECT RIGHTS
Rights of access, rectification, restriction, objection, and erasure (where applicable) are recognised. Cookie management is available via browser controls or site preferences, where offered.