top of page

PRIVACY POLICY

PRIVACY POLICY

Privacy Policy
Hatopia https://www.hatopia.co.uk
Last Updated: 04 February 2026
 
Table of Contents

  1. Who We Are

  2. What This Policy Covers

  3. What Personal Data We Collect

  4. How We Collect Your Data

  5. Why We Process Your Data and Our Legal Basis

  6. Who We Share Your Data With

  7. International Data Transfers

  8. Cookies and Tracking Technologies

  9. How Long We Keep Your Data

  10. Your Rights Under UK GDPR

  11. How to Exercise Your Rights

  12. Data Security

  13. Automated Decision-Making and Profiling

  14. Children's Data

  15. Marketing Communications

  16. Third-Party Links

  17. Changes to This Privacy Policy

  18. How to Contact Us

  19. How to Complain

 
1. Who We Are
HATOPIA LIMITED, trading as Hatopia (“we” or “us”), is the data controller responsible for your personal data. This means we determine the purposes and means of processing your personal data and are responsible for looking after it properly.
Legal Name
HATOPIA LIMITED
Registered Address
85 Great Portland Street, First Floor, London, England, W1W 7LT
Website
https://www.hatopia.co.uk
Email
team@hatopia.co.uk 
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us using the details above.
 
2. What This Policy Covers
This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website at https://www.hatopia.co.uk, create an account, make a purchase, or otherwise interact with our business.
We are committed to protecting your privacy and handling your data in accordance with data protection laws in the UK including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
"Personal data" means any information that can identify you as an individual, either on its own or when combined with other information. This includes things like your name, email address, phone number, and postal address.
We encourage you to read this Privacy Policy carefully so that you understand how and why we use your personal data.
 
3. What Personal Data We Collect
We collect the following types of personal data:
3.1 Contact Information
This includes your name, email address, telephone number, and postal or delivery address.
3.2 Account Information
When you create an account on our website, we collect the details you provide during registration, such as your name, email address, and any password or login credentials you set up.
3.3 Transaction Information
When you make a purchase, we collect the details necessary to process your order, such as your billing address, delivery address, and details of the products you have ordered. We do not directly store your full payment card details — these are handled securely by our payment processing providers (see Section 6 below).
3.4 Communication Records
If you contact us via our website chat box, email, or other means, we keep a record of that correspondence.
3.5 Technical Data
When you visit our website, we may automatically collect limited technical data such as your IP address, browser type, and operating system. This information is collected to ensure our website functions correctly.
We do not collect any special category data (also known as sensitive personal data). This includes information about your race, ethnicity, religious beliefs, political opinions, health, sexual orientation, or trade union membership.
 
4. How We Collect Your Personal Data
We collect your personal data in the following ways:
4.1 Directly from you, when you:

  • Complete a contact form on our website;

  • Create an account with us;

  • Make a purchase from us; and/or

  • Correspond with us by email or other means.

4.2 Automatically, when you:

  • Visit our website (limited technical data and essential cookies — see Section 8 below).

We do not purchase personal data from third parties, and we do not collect personal data from publicly available sources.
 
5. Why We Process Your Personal Data and Our Legal Basis
Under UK GDPR, we must have a valid legal reason (known as a "lawful basis") for processing your personal data. We rely on the following lawful bases:
5.1 Performance of a Contract (Article 6(1)(b) UK GDPR)
We process your personal data where it is necessary to fulfil a contract with you, or to take steps at your request before entering into a contract. This includes:

  • Processing your orders and delivering products to you;

  • Providing customer support in relation to your orders;

  • Managing your account with us; and

  • Processing payments and refunds.

5.2 Legitimate Interests (Article 6(1)(f) UK GDPR)
We process your personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests include:

  • Improving our website, products, and services;

  • Preventing fraud and ensuring the security of our business and website; and

  • Sending you important service updates and notices related to your orders or account (these are not marketing communications).

Where we rely on legitimate interests, we have carried out a balancing test to ensure that your interests, rights, and freedoms do not override our legitimate interests. You have the right to object to processing based on legitimate interests (see Section 10).
5.3 Legal Obligation (Article 6(1)(c) UK GDPR)
We process your personal data where it is necessary to comply with a legal obligation to which we are subject. This includes:

  • Complying with tax and accounting requirements (such as maintaining transaction records for HMRC); and

  • Complying with any other applicable laws and regulations.

5.4 Consent (Article 6(1)(a) UK GDPR)
In certain circumstances, we process your personal data based on your explicit consent. This includes:

  • Sending you marketing emails, where you have opted in to receive them; and

  • Using non-essential cookies on our website, where you have given your consent (see Section 8 below).

Where we rely on consent, you have the right to withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it. To withdraw consent, please contact us at team@hatopia.co.uk .
 
6. Who We Share Your Personal Data With
We do not sell, rent, or trade your personal data to third parties.
We may share your personal data with the following categories of service providers (known as "data processors") who process data on our behalf and under our instructions:
6.1 Payment Processors
We use third-party payment processors (such as Stripe or PayPal) to handle payments securely. These providers process your payment information in accordance with the Payment Card Industry Data Security Standard (PCI-DSS) and their own privacy policies. We do not have access to your full payment card details.
6.2 Website Hosting and Platform Providers
Our website is hosted by a third-party provider who may process limited personal data as part of providing hosting services.
6.3 Professional Advisers
We may share your personal data with our accountants, legal advisers, or other professional advisers where necessary for them to provide advice to us.
6.4 Law Enforcement and Regulators
We may disclose your personal data where required by law, regulation, or court order, or to protect our legal rights.
All third-party processors we work with are required to process your data securely and in accordance with UK data protection law. We have appropriate contracts in place with our processors to ensure your data is protected.
 
7. International Data Transfers
We primarily operate in the United Kingdom. However, some of our third-party service providers (including payment processors) may process your personal data in countries outside the UK and the European Economic Area (EEA).
Where it is necessary to transfer customers’ personal data to any third party outside the UK, we only partner with third party service providers where appropriate safeguards are in place to protect our customers’ personal data, in accordance with UK GDPR. These safeguards include:

  • Adequacy decisions: The UK Government has determined that certain countries (including those within the European Union) provide an adequate level of data protection. 

  • Standard Contractual Clauses (SCCs): Where we transfer data to countries that do not have an adequacy decision, we use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as approved by the Information Commissioner's Office (ICO); or alternatively the EU Standard Contractual Clauses.

If you would like more information about the specific safeguards applied to transfers of your data, please contact us at team@hatopia.co.uk .
 
8. Cookies and Tracking Technologies
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work or function more efficiently, as well as to provide information to website owners.
8.1 Strictly Necessary Cookies
These cookies are essential for our website to function correctly. They enable core features such as login sessions, security, and shopping cart functionality. Because they are strictly necessary, these cookies do not require your consent and cannot be switched off. Without them, parts of our website — such as browsing products or completing a purchase — may not work properly.
8.2 Functionality Cookies
Functionality cookies allow our website to remember choices you make (such as your language preference or region) and provide enhanced, more personalised features. Depending on the type, these cookies may require your consent before being placed on your device.
8.3 Analytics and Advertising Cookies
We do not currently use performance or analytics cookies, and we do not use targeting or advertising cookies.
8.4 Cookie Consent
When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You can change your cookie preferences at any time.
8.5 Managing Cookies
You can manage and control cookies in several ways:

  • Cookie preference centre: Where available on our website, you can update your preferences at any time.

  • Browser settings: Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all cookies or to alert you when a cookie is being sent.

Please note that disabling strictly necessary cookies may affect the functionality of our website, including your ability to browse products or complete a purchase.
For more information about cookies and how to manage them, visit www.allaboutcookies.org.
 
9. How Long We Keep Your Personal Data
We will only retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
The retention periods we apply are as follows:
Type of Data
Retention Period
Reason
Active customer account data
For the duration of the customer relationship
To provide our services and manage your account
Inactive account data
Deleted after 2 years of inactivity
Data minimisation — we do not retain data we no longer need
Transaction and financial records
7 years from the date of the transaction
To comply with tax and accounting obligations (HMRC requirements)
Marketing consent and preferences
Until you withdraw consent, or after 2 years of no engagement
To respect your preferences and comply with PECR
Contact form enquiries
2 years from the date of the enquiry
To respond to your enquiry and for our records
At the end of the applicable retention period, your personal data will be securely deleted or anonymised so that it can no longer be associated with you.
 
10. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights in relation to your personal data:
10.1 Right of Access (Article 15 UK GDPR)
You have the right to request a copy of the personal data we hold about you. This is commonly known as a "Subject Access Request" (SAR). We will provide you with a copy of your data in a commonly used electronic format.
10.2 Right to Rectification (Article 16 UK GDPR)
You have the right to request that we correct any personal data we hold about you that is inaccurate or incomplete.
10.3 Right to Erasure (Article 17 UK GDPR)
You have the right to request that we delete your personal data, sometimes known as the "right to be forgotten." This right is not absolute and applies only in certain circumstances, for example where the data is no longer necessary for the purpose it was collected, or where you withdraw your consent. We may need to retain certain data to comply with legal obligations (such as tax records).
10.4 Right to Restriction of Processing (Article 18 UK GDPR)
You have the right to request that we restrict (i.e., limit) the processing of your personal data in certain circumstances, for example while we verify the accuracy of your data following a dispute, or where processing is unlawful but you do not wish us to delete it.
10.5 Right to Data Portability (Article 20 UK GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another data controller where technically feasible. This right applies only where our processing is based on your consent or the performance of a contract, and the processing is carried out by automated means.
10.6 Right to Object (Article 21 UK GDPR)
You have the right to object to the processing of your personal data where we are relying on legitimate interests as our lawful basis. Upon receiving an objection, we will stop processing your data for that purpose unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defence of legal claims.
You also have an absolute right to object to the processing of your data for direct marketing purposes at any time.
 
11. How to Exercise Your Rights
If you wish to exercise any of the rights set out in Section 10 above, please contact us:

What to expect:

  • We will aim to respond to your request within one calendar month of receiving it. If your request is particularly complex or we receive a large number of requests, we may extend this period by a further two months. We will inform you if this is the case and will keep you updated.

  • There is no fee for exercising your rights in most cases. However, if your request is clearly unfounded or excessive (particularly if it is repetitive), we reserve the right to charge a reasonable fee or refuse to act on the request.

  • We may need to verify your identity before processing your request to protect your data from unauthorised access. We will ask you to provide identification if we cannot verify your identity from the information we already hold.

 
12. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption: Data is encrypted in transit using SSL/TLS (Secure Sockets Layer/Transport Layer Security) technology, and at rest where appropriate.

  • Secure hosting: Our website and data are hosted on secure servers with appropriate security configurations.

  • Access controls: Access to personal data is restricted to authorised personnel on a need-to-know basis, with appropriate authentication measures in place.

  • Payment security: All payment transactions are processed through PCI-DSS compliant third-party providers. We do not store your full payment card details.

  • Regular reviews: We periodically review our security measures and practices to ensure they remain effective.

While we take all reasonable steps to protect your personal data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to maintaining a high standard of protection.
Data Breach Notification
We have put in place procedures to deal with any suspected personal data breach and will notify you and the ICO of a breach where we are legally required to do so..
 
13. Automated Decision-Making and Profiling
We do not use any form of automated decision-making or profiling in our processing of your personal data. All decisions that may affect you are made by real people.
 
14. Children's Data
Our products and services are not directed at children under the age of 16, and we do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data as soon as possible. If you believe we may have collected data from a child, please contact us immediately at team@hatopia.co.uk .
 
15. Marketing Communications
We do not currently send marketing communications. If this changes in the future, we will only send you marketing communications where you have given us your explicit consent to do so (opt-in), in accordance with PECR.
You will always have the option to unsubscribe from marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at team@hatopia.co.uk .
Please note that even if you opt out of marketing communications, we may still need to send you important service-related messages about your orders or account. These are not marketing communications and are sent on the basis of our contractual relationship with you or our legitimate interests.
 
16. Third-Party Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. When you leave our website, we encourage you to read the privacy policy of every website you visit.
 
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Any changes will be posted on this page with an updated "Last Updated" date.
Where changes are significant, we will make reasonable efforts to notify you by email or by placing a prominent notice on our website before the changes take effect.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data.
 
18. How to Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact us:
Email
team@hatopia.co.uk 
Post
4 Berrymede Road, W4 5JF London, United Kingdom
We aim to respond to all enquiries within a reasonable timeframe.
 
19. How to Complain
We take your privacy seriously and will always try to resolve any concerns you have. However, if you are not satisfied with how we have handled your personal data or responded to your request, please contact us so we can try to resolve the issue. You can find our complaints form here [LINK] or contact us by email at team@hatopia.co.uk.  We will send an acknowledgement within 30 days of receiving your complaint and will take appropriate steps to investigate the complaint. We aim to respond as quickly as possible. 
If, once you have received our response you are not happy with the outcome, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection.
Organisation
Information Commissioner's Office
Address
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone
0303 123 1113
Website
https://ico.org.uk
 
This Privacy Policy is effective as of 04 March 2026.
HATOPIA LIMITED is registered in England and Wales, Company Number 15261805.

PRIVACY POLICY

PRIVACY POLICY

bottom of page