Effective Date: 25/05/2025
Last Updated: 25/05/Thatch hair systems is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you visit our website Thatchhair.com in accordance with the General Data Protection Regulation (GDPR).
⸻
1. Data Controller
The data controller responsible for your personal data is:
Thatch hair systems
363 Brandlesholme Rd
Bury
BL8 1HS
Info@thatchhair.com
07960403043
⸻
2. What Data We Collect
We may collect and process the following categories of personal data:
• Identity Data: name, username, or similar identifier
• Contact Data: email address, telephone number, postal address
• Technical Data: IP address, browser type and version, time zone setting, location, browser plug-in types, operating system
• Usage Data: information about how you use our website, products, and services
• Marketing and Communications Data: your preferences in receiving marketing from us and your communication preferences
⸻
3. How We Collect Your Data
We use different methods to collect data from and about you, including:
• Direct interactions: You may provide personal data by filling in forms, signing up for newsletters, or contacting us directly.
• Automated technologies: As you interact with our Site, we may automatically collect Technical Data about your equipment, browsing actions, and patterns.
• Third parties or publicly available sources: We may receive personal data from analytics providers (e.g., Google Analytics), advertising networks, and search information providers.
⸻
4. How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we use your data:
• To provide and manage our services
• To improve our website and services
• To communicate with you (including marketing where consent is given)
• To comply with legal obligations
• To protect our legal rights
⸻
5. Legal Basis for Processing
We rely on the following legal bases under the GDPR:
• Consent – where you have given clear consent for us to process your data
• Contract – where processing is
A Privacy Policy itself is not a contract, so it is not legally binding in the traditional sense like a contract would be. However, it does carry legal significance, especially under laws like the GDPR and other data protection regulations.
Here’s how:
✅ Legally Required
Under the GDPR, any business or website that collects personal data from individuals in the EU/EEA is legally required to:
• Inform users clearly and transparently about how their data is collected, used, and stored.
• Disclose users’ rights regarding their personal data.
• Specify the legal basis for data processing.
Failing to have a proper Privacy Policy can result in serious fines.
✅ Enforceable by Regulators
If your business fails to follow its own privacy policy, regulatory bodies (like data protection authorities) can treat this as misleading or deceptive conduct, and you may be fined or ordered to stop data processing activities.
✅ Can Be Used in Legal Proceedings
If a dispute arises (e.g., a user believes their data rights were violated), the privacy policy can be used as evidence to show what your stated data practices were — or weren’t. So while it’s not a contract, it can still be legally relied upon in disputes.