GPDR Privacy and Data Policy

POWERFUL SIGNATURE; ('We' and 'The Business') is subjected to the GDPR Governance applicable to businesses less then 250 staff and subjected to the UK Data Protection Act. POWERFUL SIGNATURE, Rob van Nigtevecht is a sole trader.

PRIVACY & COOKIE POLICY

We are deeply committed to protecting your personal data and ensuring a transparent, secure shopping experience. We do not participate in behavioural tracking networks, ad targeting, or data profiling. 

1. WE DO NOT USE TRACKING OR MARKETING COOKIES

This website does not use Google Analytics, Meta Pixels, heatmaps, or any other third-party tracking services. Because we do not track your behaviour across the web or collect marketing data, you will not encounter intrusive cookie consent pop-ups on our store. 

1. STRICTLY NECESSARY COOKIES WE USE

To provide a functional e-commerce environment, We use a minimal set of Strictly Necessary cookies. These cookies are legally exempt from consent requirements because our website cannot physically operate without them: 

* Shopping Session Cookies: Local, temporary cookies that remember what items are in your shopping cart as you browse from page to page. These expire automatically when you close your browser.
* Security & Infrastructure Cookies: Handled via Cloudflare to protect our server against automated bot attacks, malicious scripts, and DDoS threats.

2. WHAT DATA WE COLLECT AND WHY

When you interact with our shop, We only process personal information under the legal bases of Contractual Necessity (to fulfil your order) and Legitimate Interest (to keep our website secure): 

* Order Placement: We collect your name, email address, physical delivery address, and phone number exclusively to process your payment, generate invoices, and ship your physical products.
* Customer Accounts: If you choose to register an account, we securely store your profile information to streamline your future checkouts.
* Server Logs: Our infrastructure temporarily logs incoming IP addresses solely for security monitoring, fraud prevention, and server performance diagnostics.

3. THIRD-PARTY DATA SHARING

Your data is private. We process your information entirely within our own secure database. We never sell, rent, trade, or share your personal data with external marketing companies, data brokers, or unessential third-party providers. Your delivery information is shared strictly with our chosen postal/shipping couriers solely to complete your delivery.

4. Do not Track
Do not track is a function that allows visitors to opt out from being tracked by websites for any purpose including the use of analytics services, advertising networks and social platforms. Do not track options are available in a number of browsers, check your browser for the settings.
Anonymous browsing visitors cannot be traced back to a person. Users who are logged in are tracked only within the site for performance reasons and site usage statistics. We do not use ID tracking; we do use DNS checking for email verifications.
If you have disabled all cookies in your browser, we will still collect some general data about your browsing (e.g., a record as a visitor to our website, pages visited), but it will be less accurate.

4. SHOPPING SESSION COOKIES
Local, temporary cookies used to keep you securely logged into your customer account and remember your shopping cart items as you browse. For your security, these cookies automatically expire when you close your web browser, or will automatically time out after 2.3 days of total inactivity.

5. YOUR RIGHTS

Regardless of where you reside, you have the right to request access to the personal data we hold about you, request corrections to inaccurate information, or request the complete deletion of your customer account records (subject to local tax and accounting laws for past orders). If you have any questions, please contact us directly at info@powerfulsugnature.co.uk

Content Delivery Network (CDN) and Web Security

1. Description of Data Processing

Our website uses network services provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) to optimize page load speeds, maintain high availability, and protect our store against malicious online attacks, distributed denial-of-service (DDoS) events, and automated spam bots.When a user visits our website, their web browser requests assets through Cloudflare's network infrastructure. During this transit process, technical connection data—including your IP address, HTTP request metadata, device operating system, browser type, and timestamps—is automatically processed by Cloudflare.

2. Legal Basis for Processing

This processing is carried out in accordance with Article 6(1)(f) of the UK GDPR (Legitimate Interests). We have a critical, legitimate business interest in ensuring that our e-commerce platform loads reliably on mobile and desktop networks, remains protected against security threats, and offers a safe, uncompromised checkout experience for our customers.

3. Data Processor Relationship and Safeguards

Cloudflare acts strictly as a Data Processor on our behalf. We hold a formal Cloudflare Data Processing Addendum (DPA) incorporating approved UK International Data Transfer Agreements (IDTA) and Standard Contractual Clauses (SCCs). Furthermore, Cloudflare, Inc. is certified under the UK Extension to the EU-U.S. Data Privacy Framework, ensuring that any international data transfers maintain equivalent protections to those guaranteed inside the United Kingdom.

4. Data Retention and Privacy Options

Technical request logs and connection parameters are minimized and processed close to the user's location wherever possible. These logs are automatically retained only for short-term operational and diagnostic safety evaluation windows. For more specific details on how your routing signatures are managed, you may consult the official Cloudflare Privacy Policy.

5. What Data We Collect and Why
When you interact with our shop, we only process personal information under the legal bases of Contractual Necessity, to fulfil your order, and Legitimate Interest, (to keep our website secure.

Fulfilment & Delivery Logistics

Postal Services.
We use your full name, delivery address, postcode, county, and nation. This data is required solely to arrange packing and ship your physical products.

Contact Details
Your email address and phone number, which we use to send order confirmations and coordinate delivery updates.

Transaction History
The specific products purchased and their total financial value. This data is securely archived inside our database for internal bookkeeping and local tax accounting requirements.

Third-Party Data Sharing &  Secure Payments

Your data is private.
We process your information entirely within our own secure database. We never sell, rent, trade, or share your personal data with external marketing companies or data brokers.

No Financial Data Stored
This website does not capture, process, or store your bank details, credit card numbers, or financial credentials.

Secure Payment via Square
All financial transactions are handled securely off-site. We use SquareUp (Square) to generate your secure order invoice based strictly on your email address. Your payment is processed entirely on Square's encrypted infrastructure.

Data and Certificates
Product certificates are part of product guarantee and provenance. The certificate contain information to verify if the pen and certificate are genuine. This is also used for servicing and on the website linked to the purchase detail. Old fountain pen certificates, issued before 2020 containing personal information, will be destroyed after 5 years. Certificates using NFTs contain no personal information and are kept for servicing purposes linked to the purchase details.

Data Retention Policy
Retention Policy
The following policy is in place regarding data retention and removal

- An unused account created by the customer will be anonymised after 1 year. However, we must retain sales data related to the products that contains customer information.
- Customers who initiate an online order but do not complete it will have their order cancelled after 30 days.
- Accounts of customers who placed an online order and registered on The Business website are retained as sales data.
- Customers with an account can delete their account at any time via the "Edit" section in the Customer Account menu.
Customers who placed an order as a guest on The Business website have no account; only purchase details are retained for tax purposes.
- Customers with blocked accounts will be contacted after 7 days, at The Business's discretion, before the account is removed.
- Data related to fraudulent activities will be retained to protect the business for future checks or where required by law.
An account cannot be deleted if there is a legal enforcement order placed on it by a Government Authority, but it will be deleted within 14 days once the data is no longer required to remain available.

Complaint handling

Which kinds of personal data does the website process?
The business processes the personal data submitted by website visitors to create the final email invoice, which will be sent from the payment provider’s system. When filing a complaint, you must properly identify yourself to us The Business. This must include the billing and shipping name(s), address(es), email address used on the website, and, where applicable, phone number(s), as well as the order details where applicable, the content of the allegations (insofar as the latter qualify as personal data).
 

Who may receive my personal data?
The case file containing your personal data is only accessible by the shop owner who is also the website administrator.

What are my rights?
You are entitled to access the personal data we hold about you and to have it rectified where necessary. You can access this in your personal account. In certain cases, you also have the right to have your data erased or to object; you can raise a request via the contact page. Please note that payment processing is handled by payment providers. We only use registration details for contact and delivery purposes. Contact details are also used to create and send invoices via the payment providers as mentioned on the checkout.
To exercise any of these rights, please contact the Business using our prepared page when you are a registered user. We will reply to confirm receipt within 3 days and complete the process within three months. Please note that in some cases restrictions under Article 20 of the Regulation may apply.

How long we keep you data
The Business keeps log files—including your personal data such as name, address, and contact details—for up to 2 years for support related to the Makers Guarantee, or longer for legal purposes where needed, but will remove them within 14 days when no longer needed. However, purchase details cannot be deleted, they are required for tax purposes.

What happens if I request my data to be removed?
After deleting all your details, which is your name, address(es), email address(es), phone number(s), anything in the data which identifies you, it will no longer be possible for The Business to contact you. The only reference left is a case number as reference of the completion of a deletion request.

Who can I contact?
You can contact The Business via the website contact page.

Changes of this document
We reserve the right to update or revise this additional GDPR at any time without notice. Please check the GDPR periodically for changes. The revised content will be effective immediately as soon as they are posted on the Website.