web counter
0

0

Artisan Furniture circular black and white logo

0

0

Artisan Furniture circular black and white logo

Privacy Policy

1. Introduction

We value your privacy and are committed to protecting personal information. This Privacy Policy explains how Artisan Furniture processes personal data of EU-based B2B partners and end customers (delivery recipients), in line with the GDPR and national laws of the European Union.

This policy applies to our EU websites and affiliated platforms. It complements our Global Privacy Policy.

2. Who We Are

  • Global Vision Direct Ltd (UK) operates Artisan Furniture.
  • EU fulfilment and deliveries are managed through our German operations (Magdeburg centre) and Spain operations (Madrid centre).
  • Affiliated group company: Global Vision Direct Private Limited (India).
  • Person of Significant Control / UBO: Amit Basu.
  • Role allocation:
    • Controller for B2B partner data.
    • Processor for end-customer delivery data (acting under instructions from B2B partners).

3. Data We Collect

  • B2B partners: business contact details, login credentials, order history, payment details, support communications, technical usage logs.
  • End customers (delivery only): name, delivery address, postcode, phone, email (provided by resellers for shipping).
  • Technical data: IP address, device/browser type, cookies and analytics (where consented under ePrivacy).

We do not collect sensitive personal data or data directly from consumers.

4. Why We Use Data (Purposes)

We process personal data for:

  • Order fulfilment and delivery (manufacture, logistics, shipment).
  • B2B account management (inventory, ArtisanFlo, ERP, APIs).
  • Payments & invoicing (via secure payment providers).
  • Customer support (email, phone, chat, AI assistant “Flo”).
  • Legal & compliance (GDPR, accounting, tax, trade regulations).
  • Security & fraud prevention (monitoring, logs).
  • Website analytics (where consented).

End-customer data is used strictly for delivery purposes.

5. Legal Bases (GDPR)

  • Article 6(1)(b) Contract: processing necessary to perform a contract (B2B agreements, order fulfilment).
  • Article 6(1)(c) Legal obligation: accounting, tax, regulatory requirements.
  • Article 6(1)(f) Legitimate interests: B2B relationship management, fraud prevention, platform security.
  • Article 6(1)(a) Consent: marketing (B2B contacts only) and cookies/analytics.

6. Data Sharing & International Transfers

  • Intra-group transfers: EU data may be accessed by our UK parent and India affiliate for support/operations.
  • Third parties: couriers (UPS, DHL), payment processors (PayPal, iwocaPay), cloud hosting (AWS, Azure), communications (Twilio, SendGrid), approved developers.
  • Safeguards:
    • EU Standard Contractual Clauses (SCCs) for transfers outside the EU.
    • Supplementary measures (encryption, access controls).
    • Transfer Impact Assessments (TIAs) in line with Schrems II.

7. Cross-Navigation Between Websites

If an EU user signs up or visits from another region (e.g., UK), they may be automatically redirected to the EU website in a new tab. This ensures region-specific services.

8. Data Retention

  • B2B accounts & records: active + 7 years.
  • End-customer delivery data: retained only as long as required for delivery and statutory recordkeeping (max. 7 years).
  • Support queries: 3 years.

Cookie/analytics data: per Cookie Notice (6–26 months).

9. Security Measures

We use strict safeguards:

  • TLS encryption for all data transfers.
  • Data-at-rest encryption and secure cloud hosting.
  • Role-based access controls, MFA.
  • Vendor and sub-processor due diligence.
  • Incident response plan and periodic audits.

10. Your GDPR Rights

EU data subjects have the right to:

  • Access their data.
  • Rectify inaccuracies.
  • Erase data (“right to be forgotten”).
  • Restrict processing.
  • Object to processing (including marketing).
  • Data portability.
  • Withdraw consent at any time (without affecting prior processing).
  • Complain to their national Data Protection Authority (DPA).

Requests can be made via email (see Section 12).

11. Children’s Data

Our services are designed for businesses and are not directed at children. We do not knowingly process children’s data.

12. Contact

Global Vision Direct Ltd
T/A Artisan Furniture
5th Floor, Watson House
54–60 Baker Street
London W1U 7BU
United Kingdom

Email – [email protected]

Global Vision Direct Ltd acts as the data controller for all personal data processed across Artisan Furniture’s digital platforms, websites, sub domain Compliance and Policies Hub and services.

13. Changes

We may update this policy from time to time in line with law and operational changes. The updated policy will carry a new “Effective Date.”

Published January 2025 | Effective from January 2025 until Superseded or Amended