Legal

Privacy Notice

Effective date:
2026-07-31
Last updated:
2026-08-02
Version:
1.1

Change log: Legal entity updated to DIVAFASHION LTD (company no. 16932732).

This notice explains how personal data is handled for this project. Controller: DIVAFASHION LTD (company no. 16932732), registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Privacy contact: divafashionsltd@gmail.com.

Payments

Stripe processes payment and payment-method data through its own hosted checkout. This website never receives, stores or transmits card or bank details. Stripe acts as an independent controller for its own fraud-prevention and regulatory purposes.

Data this website collects

  • Contact form: name, email, message and optional phone. Purpose: responding to enquiries. Provisional lawful basis: legitimate interests (a Legitimate Interests Assessment is to be confirmed by the controller). Retention: deleted within 12 months of the matter closing unless a legal, accounting, fraud or dispute reason requires longer.
  • Update subscription: email, preferred language, consent timestamp, consent-wording version and unsubscribe status. Purpose: project and launch updates. Lawful basis: consent. Retention: until consent is withdrawn, plus a minimal suppression record.
  • Public acknowledgement (optional, default anonymous): chosen display name only, never the contribution amount. Lawful basis: consent, withdrawable at any time.

Recipients and processors

Stripe (payment processing). An email service provider and a contact-form storage provider will be named here once selected — marked [EMAIL SERVICE PROVIDER] and [CONTACT FORM STORAGE PROVIDER] until then. No advertising networks, data brokers or profiling services receive your data.

International transfers

Stripe and other providers may process personal data outside the United Kingdom. Transfers rely on UK adequacy regulations where available, otherwise the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. This section will be updated when the remaining providers are confirmed.

Security

Reasonable technical and organisational measures are used, including encryption in transit, restricted administrative access and secrets held only in server-side environment variables. No system can be guaranteed to be absolutely secure, and no such guarantee is given.

Your rights

  • Access, rectification and erasure
  • Restriction of processing and objection to processing
  • Withdrawal of consent at any time, without affecting prior processing
  • The right to complain to the UK Information Commissioner's Office (ICO)

Regulatory registration

The controller will complete the ICO self-assessment and register and pay the data-protection fee unless a documented exemption applies.

Contribute Now