GDPR POLICY

GDPR Privacy Policy for Toro!

At Toro!, we are committed to protecting the privacy and personal data of all visitors and customers interacting with our website, which is hosted on the Squarespace platform. This GDPR policy outlines how we collect, use, and safeguard your information in compliance with the General Data Protection Regulation (GDPR).

1. Data Controller

Toro! Designs
Contact Information:
Mr. Stephen Leadbetter, sleadbetter@torodesigns.co.uk

2. Personal Data We Collect

We may collect the following personal data from you:

  • Name

  • Email address

  • Phone number

  • Payment information (processed securely via Squarespace or third-party payment providers)

  • IP address and browsing behavior on our site (through cookies and analytics tools)

3. How We Use Your Personal Data

Your personal data will be used for the following purposes:

  • To provide and maintain our services

  • To process payments and orders

  • To communicate with you regarding your inquiries, orders, and feedback

  • To improve and personalize your experience on our website

  • To comply with legal obligations

4. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Your consent (e.g., accepting website terms)

  • Performance of a contract (e.g., fulfilling orders)

  • Legitimate interests (e.g., website analytics and security)

  • Compliance with legal obligations

5. Data Sharing and Transfers

  • We do not sell or rent your personal data to third parties.

  • Personal data may be shared with service providers such as Squarespace and payment processors for operational purposes. These providers are bound by confidentiality and data protection obligations.

  • Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place as required by GDPR.

6. Cookies and Tracking

Our website uses cookies and similar tracking technologies to enhance user experience and analyze site usage. For more information, please see our Cookie Policy. You can manage your cookie preferences through your browser settings.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy or as required by law.

8. Your Rights Under GDPR

You have the right to:

  • Access your personal data and obtain a copy

  • Correct inaccurate or incomplete data

  • Request erasure of your data under certain conditions

  • Object to or restrict processing of your data

  • Data portability

  • Withdraw consent at any time where processing is based on consent

  • Lodge a complaint with a supervisory authority

9. Security Measures

We implement appropriate technical and organizational measures to protect your data from unauthorized access, alteration, disclosure, or destruction.

10. Changes to This Policy

We may update this GDPR Privacy Policy periodically. Changes will be posted on this page with an updated revision date.

For any questions or requests regarding your personal data or this policy, please contact us at:
sleadbetter@torodesigns.co.uk

Effective Date: 3 July, 2025