1. Data Controller Information

Reinier Verplancke acts as Data Controller under UK GDPR regulations.
Address: 1726 Dormont Ln, Orlando, FL 32804, USA
Email: contact@reinierverplancke.shop
ICO Registration Reference: [Your ICO Number if applicable]

2. Personal Data Collection

We collect and process:
- Identity Data: Full name, title
- Contact Data: Billing/delivery addresses, email, phone number
- Transaction Data: Payment details (via PCI-compliant gateways), order history
- Technical Data: IP addresses, browser types, device information
- Marketing Data: Communication preferences

3. Lawful Basis for Processing

- Contractual Necessity: Processing required to fulfill orders
- Legal Obligation: Compliance with UK tax and customs regulations
- Legitimate Interests: Fraud prevention, service improvement
- Consent: For marketing communications (explicit opt-in required)

4. Data Sharing & Transfers

We share data with:
- Payment processors (Stripe/PayPal) for transaction completion
- Courier services (Royal Mail/DHL) for delivery fulfillment
- HMRC for tax compliance purposes
- Data may be transferred outside UK to US under GDPR adequacy decisions

5. Data Security Measures

- SSL encryption on all data transmissions
- Payment data tokenization via PCI-DSS Level 1 providers
- Regular security vulnerability assessments
- Role-based access control systems

6. Data Retention Periods

- Order records: 6 years (UK tax law requirement)
- Customer correspondence: 3 years from last contact
- Marketing data: Until consent withdrawal
- Technical logs: 12 months

7. Your Legal Rights

Under UK GDPR and Data Protection Act 2018, you may:
- Request access to your personal data (Subject Access Request)
- Rectify inaccurate or incomplete information
- Erase data where no legal basis for processing remains
- Restrict processing during disputes
- Object to direct marketing processing
- Lodge complaints with the Information Commissioner's Office