Privacy Policy

Privacy Policy

This Privacy Policy explains how personal data is collected, used and protected when using the website www.mysculpd.com, operated under the trade name SCULPD™.

1. Data Controller

The data controller is:

Trade name: SCULPD™ Status: Sole trader (Autónomo – Spain) Registered address: 5 Plaza Mayor, 29700 Vélez-Málaga, España Contact email: contact@mysculpd.com

2. Personal Data We Collect

When you use our website and place orders, we may collect the following data:

Identity: first name, surname. Contact details: email address, postal address, phone number. Order and payment information. IP address and browsing data (browser type, operating system, pages visited, access times). Correspondence history with our customer service team.

Bank details are never stored by SCULPD. They are processed securely by certified payment providers only.

3. Why We Collect Your Data

Personal data is collected for the following purposes:

Processing and managing orders. Delivering products and providing tracking information. Managing payments and invoicing. Customer service and follow-up on enquiries. Sending transactional emails (order confirmation, dispatch notification). Improving user experience and website performance. Complying with legal and regulatory obligations.

4. Legal Basis for Processing

Data processing is based on:

Performance of a contract (UK GDPR, Article 6(1)(b)): processing orders and delivery. Consent (UK GDPR, Article 6(1)(a)): newsletters, non-essential cookies, marketing communications. Legitimate interest (UK GDPR, Article 6(1)(f)): website improvement, fraud prevention. Legal obligation (UK GDPR, Article 6(1)(c)): tax and accounting requirements.

5. Who We Share Your Data With

Personal data may be shared with the following categories of service providers, where necessary for the proper operation of the business:

E-commerce platform: Shopify Inc. (Canada). Payment providers: Stripe, PayPal. Delivery and logistics providers. Analytics tools: Google Analytics. Email services: Shopify Email.

These service providers are contractually required to maintain the confidentiality of your data and comply with applicable data protection regulations. Data is not shared with any other third parties unless required by law.

6. International Data Transfers

Certain data may be transferred outside the United Kingdom, particularly via Shopify (Canada) or certain technical service providers (USA). These transfers are safeguarded by appropriate measures in accordance with UK GDPR Article 46, including International Data Transfer Agreements (IDTAs) and supplementary security measures approved by the Information Commissioner's Office (ICO).

7. How Long We Keep Your Data

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected:

Order data: 6 years (in line with HMRC record-keeping requirements). Customer account data: duration of the business relationship, plus 3 years after the last contact. Marketing data: until consent is withdrawn. Cookies and browsing data: maximum 13 months.

8. Your Rights

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights:

Right of access (Article 15). Right to rectification (Article 16). Right to erasure (Article 17). Right to restriction of processing (Article 18). Right to object (Article 21). Right to data portability (Article 20). Right to withdraw consent (Article 7(3)).

To exercise any of these rights, please contact us at: contact@mysculpd.com. We will respond within 30 days.

9. Cookies

Our website uses cookies to:

Ensure the proper functioning of the website (strictly necessary cookies). Measure visitor numbers and analyse user behaviour (analytics cookies). Improve user experience (functional cookies).

You can manage or reject non-essential cookies via the consent banner on your first visit or at any time through your browser settings. Strictly necessary cookies cannot be disabled as they are required for the website to function.

10. Data Security

SCULPD implements appropriate technical and organisational measures in accordance with UK GDPR Article 32 to protect personal data against unauthorised access, loss, alteration or disclosure. These include SSL encryption for all data transfers and the use of certified payment providers.

11. Complaints

If you believe your rights have not been upheld, you have the right to lodge a complaint with the relevant supervisory authority:

For the United Kingdom: Information Commissioner's Office (ICO) — https://ico.org.uk For Spain: Agencia Española de Protección de Datos (AEPD) — https://www.aepd.es

12. Changes to This Privacy Policy

SCULPD reserves the right to update this Privacy Policy at any time. The current version is always available on our website. Where significant changes are made, we will notify you in an appropriate manner.