Last updated on 23 June 2025
Castlery Ltd (Company Registration Number (CRN) 16110260) and our affiliates (hereinafter referred to as "We", "Us", "Our" or "Castlery" as the context permits) is committed to protecting your personal data.
This policy sets out the basis on which any personal data which we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our practices regarding your personal data and how we will treat it. At Castlery, we respect your privacy.
As a user of the internet, you know that e-commerce companies such as Castlery collect and use information relating to you. We also disclose your information and transfer your information to others from time to time.
We respect your rights to your personal data. This Privacy Policy serves to explain how we use, collect, disclose, transfer or otherwise manage your personal data. We are providing this Policy to you so that you can instruct us on how you want us to manage your personal data within your legal rights.
When you interact with us, we will be collecting data to achieve various objectives that we have described in detail in this Privacy Policy. However, the underlying principles behind these objectives are mainly to:
We respect and adopt the major privacy principles and frameworks around the world in designing our policies and processes as they apply to our management of your personal data. These principles and frameworks include the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
This Privacy Policy applies to all websites and domains owned by us, which we refer to as the Sites. It also applies to our interactions with you in person, as well as through the following Communication Platforms: e-mails, social media accounts, messaging and voice-over-IP platforms and services, chatbots, telephone calls, and any other form of communication media now available or becomes available anywhere in the world that we use to interact with you.
We only collect personal data that we need so that we can sell the products you love to you, provide you with the necessary after-sales support and fulfil legitimate business purposes. We comply with all relevant laws and regulations that apply to us and our interactions with you.
Below are the various ways we collect and process your personal data.
We may collect and use your contact details, date of birth, gender, login credentials and information relating to the product(s) you have expressed an interest in purchasing, or that you actually purchase, and the intended shipping addresses and addressees for your orders, for the following main purposes:
We collect and use the contact details, identification information, information required to purchase our products online, profile (including your date of birth and gender), role and preferences, login credentials, digital activity information and other information as may be relevant (e.g. information from publicly available sources) for the following main purposes (as applicable):
We collect and use your digital activity information for the following main purposes:
We also collect and use your contact details, login credentials, information included in your enquiries, comments and feedback that you may provide on online forums and surveys (including information from publicly available sources) or through any Communication Platform to:
We collect and use your contact details to:
We collect and use your contact details and other information as we reasonably determine to be relevant (including information from publicly available sources) to:
Our Sites and third parties that we authorise use cookies and other tracking technologies (such as pixels, web beacons, tags, session replay tools, embedded scripts, and SDKs) to collect Personal Data from you, as described in the “Personal Data We Collect” section above. We use this information to analyse how you use the Sites, personalise and improve your experience on our Sites, provide you with advertising, and measure and improve the effectiveness of our advertising campaigns.
By continuing to browse the Sites, you are agreeing to our and our authorised third parties' use of your cookies. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive.
We use the following cookies:
Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control and which are governed by these third parties’ privacy policies. These cookies are likely to be analytical/performance cookies or targeting cookies.
The third parties that administer services use technologies such as cookies, web server logs and web beacons to help us analyse how visitors use the website. The information collected through these means (including IP address) is disclosed to these service providers, who use the information to evaluate use of the website. These analytic services may use the data collected to contextualise and personalise the marketing materials of their own advertising network.
We may use the following third party web analytic services on the website:
Google Analytics is a web analysis service provided by Google Inc. ("Google"). Google's ability to use and share information collected by Google Analytics is in accordance with their policies: http://www.google.com/policies/privacy/partners/
You can prevent Google's collection and processing of data by using the Google Ads Settings page or downloading and installing their browser plug-in (https://tools.google.com/dlpage/gaoptout).
You may block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our Sites.
We collect and use your contact details, your employment and pay history, your references and information that are publicly available on professional social networks such as LinkedIn, to identify and contact potential job candidates and to consider the applications of candidates who apply for job openings through our Sites or other Communication Platforms.
We collect the contact details, identification information and CCTV footage of individuals who visit Castlery’s showrooms and offices to ensure the safety and security of Castlery staff, intellectual property and premises.
We promote and / or sell our products through our Sites as well as through third-party platforms. From time to time, we conduct marketing campaigns that are hosted on Communication Platforms that belong to our partners. We may also make available to you, through our Sites and other Communication Platforms, social media features that enable you to share information about Castlery or its products with your social networks, and to interact with us on various social media sites.
If you purchase or got to know of our products through third-party sites, access social media sites through us, or engage with our marketing campaigns that are hosted on our partners’ sites, you should be aware that we do not control any of those sites or their respective privacy practices.
We do not endorse or make any representations about those sites. Any personal data that you choose to provide to, or that is collected or shared by, those sites is not covered by this Privacy Policy. We encourage you to review the Privacy Policy of any site you interact with before allowing the collection and use of your personal data.
If you choose to join our mailing list, Castlery may provide you with information that complements our products and/or communications about our new products and offers. Our mailing list is an opt-in list and you do not have to join our mailing list to purchase our products.
In the event you no longer wish to receive communications from us, you can unsubscribe from such communications by following the opt-out or unsubscribe link and/or instructions included in each e-mail subscription communication.
In the event your opt-out or unsubscribe request has not been resolved in a timely manner, please contact the Castlery DPO (dpo@castlery.com) with details of your name, contact information, and description of the communications you no longer wish to receive from Castlery.
Please note that these options do not apply to communications relating to the administration of orders, contracts, support, product safety warnings, or other administrative and transactional notices, where the primary purpose of these communications is not promotional in nature.
We strive to maintain the accuracy of our records of your personal data. As required by the laws applicable to the relevant Castlery entity, we provide individuals with reasonable access to personal data that they provide to Castlery and the reasonable ability to review and correct it.
To protect your privacy and security, we will take reasonable steps to verify your identity, including requiring you to provide us with proof of your identity, before granting access to your personal data. To view and update the personal data you provided directly to Castlery, you can update your information with us:
We do not sell, rent or lease personal data to others except as described in this Privacy Policy.
We may share and/or disclose your personal data as follows:
Castlery may transfer your personal data as necessary within the Castlery group of companies and to other authorised third parties. The recipients may be located in countries which do not provide the same level of data protection as the country in which you are located. We will take steps to ensure there is adequate protection for the transfer of your personal data in compliance with the applicable data protection laws. Where required by local law, we will request your consent to transfer your personal data.
With respect to transfers to third parties located in countries that do not provide an adequate level of data protection, Castlery will take appropriate safeguards such as, signing UK International Data Transfer Addendum (UK Addendum) with the recipient, relying on their Privacy Shield certification, other approved codes of conduct or certification mechanisms or binding and enforceable commitments of the recipient.
We use reasonable and appropriate physical, technical and administrative procedures to safeguard the information we collect and process. All systems used to support our business are governed by our corporate cyber security policies. However, please note that no digital transmission of data can ever be guaranteed 100% secure, so we encourage you to take care when disclosing your personal data online and to use readily available tools, such as internet firewalls, secure e-mail and similar technologies, to protect yourself online.
We use Stripe to process our credit card payments and no credit card details are stored on our services. Stripe has been audited by a PCI-certified auditor, and is certified to PCI Service Provider Level 1. This is the most stringent level of certification available.
In case of an unauthorised security intrusion that materially affects you, we will notify you as soon as possible and will, within a reasonable time, report on our response actions.
We only keep personal data for the length of any contractual relationship and, to the extent permitted by applicable laws, after the end of that relationship for as long as necessary to perform purposes set out in this Privacy Policy, to protect Castlery from legal claims and to administer our business. We will delete your personal data from our systems and records, or take steps to anonymise the data when we no longer need it unless there is a legal or regulatory obligation that needs to be fulfilled. Please contact the Castlery DPO (dpo@castlery.com) for more information about our data retention policies.
Companies from the Castlery group may act as the appointed data controller for your personal data and for the processing of the same as described in this Privacy Policy. For more information on this, please contact the Castlery DPO (dpo@castlery.com).
The appointed Data Protection Office, or DPO can be contacted at dpo@castlery.com
We process your personal data on the following legal bases: Legitimate interest. We may process your personal data as required to pursue our legitimate business interests (provided this is not overridden by the interests or rights of relevant individuals). In particular, we may process your personal data to manage, develop and improve our products; support our customers and sales operations; protect our staff and assets; communicate information that supplements our products; and ensure compliance with the laws and regulations.
We may process your personal data to comply with applicable laws and regulations, establish or exercise our legal rights. This may include situations involving investigations or legal claims or for compliance or regulatory purposes.
We may process your personal data where you have provided your consent. In particular, we will rely on your consent where we cannot rely on an alternative legal basis or we are required by law to ask for your consent in the context of some of our sales and marketing activities, automatic data collection tools or surveys. At any time, you have a right to withdraw your consent by changing your communication choices, unsubscribing from Castlery communications or contacting the Castlery DPO (dpo@castlery.com).
You may have the following rights to:
These rights may be limited in some situations such as where Castlery can demonstrate that we have a legal requirement or legitimate interest to process your personal data.
If you would like to exercise your rights, please contact us by completing the support form available on this site or by writing to the Castlery DPO (dpo@castlery.com).
If you consider that the processing of your personal data infringes the GDPR, you have a right to lodge a complaint with a supervisory authority in the country where you live or work, or where you consider that data protection rules have been breached.
You may have additional rights under the data processing and/or data transfer agreements we have entered into with other parties. For instance, as a third-party beneficiary, where you believe your personal data has been transferred to a Castlery company located outside UK and processed by that company in breach of such data processing and/or data transfer agreements, you may have a right to:
We value your opinions. If you have any questions about our Privacy Policy, any concerns or complaints regarding our collection and use of your personal data or wish to report a possible breach of your privacy, please contact the Castlery DPO (dpo@castlery.com).
We will treat your requests and complaints confidentially. Our representative will contact you within a reasonable time after receiving your complaint to address your concerns and outline options regarding how they may be resolved. We will aim to ensure that your complaint is resolved in a timely and appropriate manner.
If we modify this Privacy Policy, we will publish a revised version with an updated revision date. The privacy link on the footer of every Castlery web page will then point to that new version.