1. Who we are
Tech Gallery is the trading name of TECH GALLERY LIMITED (“we”, “us”, “our”), a private company limited by shares registered in England and Wales under company number 16993942, with its registered office at 137 Grosvenor Road, London, England, SW1V 3JY.
We are the data controller for the personal data described in this policy. That means we decide why and how your personal data is processed. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
For any question about this policy, or to exercise your rights, email info@gallerytech.org or write to us at the registered office address above.
2. Scope of this policy
This policy applies when you:
- visit or browse gallerytech.org;
- place an order, or ask us for a quotation;
- contact us by email or through any form on the site;
- subscribe to our updates or take part in a promotion; or
- deal with us as a supplier, trade customer or business contact.
It does not apply to third-party websites we link to, which have their own privacy policies — see section 14.
3. Personal data we collect
We only collect what we actually need. Depending on how you interact with us, that may include:
3.1 Information you give us
- Identity and contact data — name, delivery and billing address, email address and, if you provide one, a telephone number for the courier.
- Order data — the products you buy, order value, order number, gift messages and any delivery instructions you leave.
- Payment data — we do not receive or store your full card number. Payments are handled by regulated payment providers; we receive only a transaction reference, the result, the amount and, in some cases, the card type and last four digits.
- Correspondence — the content of emails and messages you send us, including photographs you attach to support a return or a fault report.
- Account data — where we offer accounts, your login email and a securely hashed password. We never store passwords in readable form.
- Trade data — for schools, clubs and businesses: organisation name, purchase order references, billing contact and VAT number where relevant.
3.2 Information collected automatically
- Technical data — IP address, browser type and version, device type, operating system, language and time zone settings.
- Usage data — pages viewed, referring page, time spent, and interactions such as adding an item to a basket.
- Cookie data — identifiers stored on your device. Non-essential cookies are only set with your consent. See the Cookie Policy.
3.3 Information from other sources
- Delivery partners, who confirm tracking status and delivery outcomes.
- Payment providers and fraud prevention services, who confirm whether a payment succeeded or was declined.
- Publicly available sources, such as Companies House, for trade account checks.
4. How and why we use it
We must have a lawful basis for every use of your personal data. The table below sets out what we do and why we are allowed to do it.
| What we do | Data used | Lawful basis |
|---|---|---|
| Process and deliver your order, including packing, dispatch and tracking | Identity, contact, order, payment | Performance of a contract with you |
| Handle returns, cancellations, refunds, repairs and replacements | Identity, contact, order, correspondence | Performance of a contract; legal obligation (consumer law) |
| Answer your questions and provide customer support | Contact, correspondence, order | Legitimate interests — running a responsive shop; performance of a contract |
| Detect and prevent fraud and misuse of the site | Technical, order, payment | Legitimate interests — protecting the business and our customers; legal obligation |
| Keep accounting, tax and VAT records | Identity, contact, order, payment | Legal obligation (Companies Act 2006, tax legislation) |
| Issue product safety notices and recall information | Identity, contact, order | Legal obligation; vital interests where a safety risk is serious |
| Send marketing emails about products and offers | Identity, contact, order | Consent, or legitimate interests under the soft opt-in for existing customers (PECR) |
| Measure how the website is used and improve it | Technical, usage, cookie | Consent (for analytics cookies) |
| Establish, exercise or defend legal claims | Any of the above, as relevant | Legitimate interests — protecting our legal position; legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and concluded that they are not. You can object to processing based on legitimate interests at any time — see section 11.
5. Cookies and similar technologies
We use a small number of cookies. Strictly necessary cookies — those that keep your basket working, keep you signed in and protect the checkout — are set automatically because the site cannot function without them. Analytics and any preference cookies are set only after you consent, and you can withdraw that consent at any time.
Full details, including how to control cookies in your browser, are in our Cookie Policy.
6. Marketing communications
We will only send you marketing email where you have opted in, or where you have previously bought a similar product from us and did not opt out at the time (the “soft opt-in” permitted by PECR). We do not sell, rent or trade your contact details to other organisations for their own marketing.
Every marketing email contains a one-click unsubscribe link, and you can also opt out at any time by emailing info@gallerytech.org. Opting out of marketing does not stop service messages — order confirmations, dispatch notices, refund confirmations and safety notices — which we must send to fulfil the contract or comply with the law.
7. Who we share data with
We share personal data only where it is necessary, and only with recipients who are bound to protect it:
- Delivery and logistics partners — to deliver your parcel and handle returns.
- Payment providers and acquirers — to take payment, issue refunds and prevent fraud.
- Technology suppliers — website hosting, email, order management, analytics and customer support tools, acting as our processors under written contracts.
- Professional advisers — accountants, auditors, insurers and lawyers, where they need the information to advise us.
- Suppliers and manufacturers — where a warranty claim, spare part or recall requires it, limited to the minimum needed.
- Public authorities — including HM Revenue & Customs, Trading Standards and law enforcement, where we are legally required to disclose.
- Purchasers of the business — if the company or its assets are sold or reorganised, subject to the same protections continuing to apply.
Our processors act only on our documented instructions. They may not use your data for their own purposes.
8. International transfers
We aim to keep personal data within the United Kingdom or the European Economic Area. Some of our suppliers operate globally, so data may be transferred outside the UK. Where that happens, we make sure an appropriate safeguard recognised by UK data protection law is in place — normally UK adequacy regulations for the destination country, or the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.
You can ask us for details of the safeguards applied to any specific transfer by contacting info@gallerytech.org.
9. How long we keep data
We keep personal data only for as long as we need it for the purposes described in this policy, then delete it or anonymise it. Our normal retention periods are:
| Record | Retention period | Reason |
|---|---|---|
| Order, invoice and payment records | 7 years from the end of the relevant financial year | Tax and accounting requirements |
| Customer account details | Until you close the account, plus 12 months | To reinstate an account closed in error |
| Customer support correspondence | 3 years from the last contact | Handling follow-up queries and disputes |
| Warranty, fault and safety records | 10 years from supply | Product safety traceability and liability periods |
| Marketing preferences and consent records | Until withdrawn, plus 3 years | Evidence that consent was validly obtained |
| Website analytics data | Up to 26 months | Year-on-year comparison, then deletion |
| Server and security logs | Up to 12 months | Security monitoring and fraud prevention |
Where a legal claim is live or reasonably anticipated, we may keep relevant records for longer until the matter is resolved.
10. Keeping data secure
We take appropriate technical and organisational measures to protect personal data, including:
- encryption in transit using HTTPS across the whole website;
- outsourcing card processing to PCI DSS compliant payment providers, so card numbers never reach our systems;
- access controls, so staff only see the data needed for their role;
- multi-factor authentication on administrative accounts;
- regular software updates and backups; and
- written contracts with all processors requiring equivalent protection.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and will tell you directly where the risk is high.
11. Your rights
Under the UK GDPR you have the right to:
- Be informed about how your data is used — this policy is part of meeting that duty.
- Access a copy of the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data where we no longer have a good reason to keep it.
- Restrict processing in certain circumstances, for example while accuracy is disputed.
- Data portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Object to processing based on legitimate interests, and to direct marketing at any time — an objection to marketing is always absolute.
- Withdraw consent at any time where we rely on consent, without affecting processing carried out before withdrawal.
To exercise any right, email info@gallerytech.org. We will respond within one month. That period can be extended by up to two further months for complex requests, and we will tell you if that applies. Exercising your rights is free; we may charge a reasonable fee, or refuse, only if a request is manifestly unfounded or excessive. We may ask for proof of identity before disclosing personal data.
12. Children’s privacy
We sell toys and games, so many of our products are intended for children — but the website and shop are intended for adults. Our services are not directed at children, and we do not knowingly collect personal data from anyone under 16. Orders must be placed by someone aged 18 or over.
If you believe a child has provided us with personal data, contact info@gallerytech.org and we will delete it promptly.
13. Automated decisions
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling for that purpose. Payment providers may apply automated fraud screening to a transaction; if a payment is declined on that basis you can contact us and we will look at it manually.
14. Third-party websites
This site may link to manufacturer pages, rulebooks, review sites and social media. We are not responsible for the privacy practices of those sites. Please read their own privacy notices before providing personal data to them.
15. Changes to this policy
We review this policy regularly and will update it when our processing changes or the law does. The date at the top of the page always shows when it was last revised. Where a change materially affects how we use your personal data, we will tell you directly — for example by email — before it takes effect.
16. Contact and complaints
Contact us about anything in this policy at:
- Email: info@gallerytech.org
- Post: Data Protection, TECH GALLERY LIMITED, 137 Grosvenor Road, London, England, SW1V 3JY
We would like the chance to resolve any concern first. However, you have the right to complain at any time to the UK supervisory authority for data protection:
- Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline: 0303 123 1113 — ico.org.uk