Privacy & Cookie Policy for Neo Electric Bikes

Last Updated: 23 June 2025
Company Name: GNS Hardware Ltd
Trading As: Neo Electric Bikes
Website: www.neoelectricbikes.co.uk

1. Introduction & Scope

GNS Hardware Ltd (“we”, “us”, or “our”) operates Neo Electric Bikes and is committed to protecting your personal data in compliance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)
  • Other applicable UK and EU data protection laws

This policy governs all personal data collected:

  • Through our website (www.neoelectricbikes.co.uk)
  • Via email, phone, or live chat communications
  • During the order and fulfilment process
  • Through any third-party services integrated with our operations

2. Detailed Data Collection Methods

2.1 Direct Collection Points

  • Create an account (name, email, password, contact details)
  • Place an order (billing/shipping address, payment details, product preferences)
  • Contact customer support (call recordings, email threads, live chat transcripts)
  • Participate in marketing activities (competition entries, survey responses)
  • Submit reviews or feedback (product opinions, service ratings)
  • Apply for financing (credit checks through approved providers)

2.2 Automated Collection Technologies

  • Google Analytics 4 (anonymized usage data)
  • Facebook Pixel (conversion tracking)
  • Server Logs: IP addresses, timestamps, browser/device characteristics
  • Cookies: See Section 11

2.3 Third-Party Data Sources

  • Payment processors (Stripe, PayPal)
  • Delivery partners (DPD, DHL)
  • Marketing platforms (Mailchimp)
  • Review platforms (Trustpilot)

3. Categories of Personal Data Processed

Data Category Examples Legal Basis
Identity Data Full name, date of birth (for finance) Contractual necessity
Contact Data Email, phone, billing/delivery address Contractual necessity
Financial Data Last 4 digits of payment cards Legal obligation
Transaction Data Order history, returns, warranties Legitimate interest
Technical Data IP address, browser type, device ID Legitimate interest
Usage Data Clickstream, page interaction Consent
Marketing Data Preferences, opt-ins/opt-outs Consent

4. Purposes & Lawful Bases for Processing

4.1 Contractual Necessity

  • Processing and delivering your orders
  • Managing your account and warranties
  • Providing customer support services

4.2 Legal Obligations

  • HMRC tax compliance (6 years)
  • Fraud prevention and financial audits
  • Product safety recalls and notifications

4.3 Legitimate Interests

  • Improve website functionality and UX
  • Prevent fraudulent transactions
  • Personalize product recommendations

4.4 Consent-Based Processing

  • Send marketing communications with opt-in
  • Use non-essential cookies with permission
  • Share data with third-party advertisers when consented

5. Data Sharing & Third-Party Processors

5.1 Essential Service Providers

Processor Purpose Data Shared Safeguards
Stripe/PayPal Payment processing Transaction details PCI DSS Compliance
DPD/DHL Order fulfilment Delivery addresses GDPR Data Processing Agreements
Zendesk Customer support Contact details EU Standard Contractual Clauses

5.2 International Transfers

  • We use UK-approved Standard Contractual Clauses
  • Ensure recipients are Privacy Shield certified
  • Conduct regular vendor compliance audits

6. Data Retention Schedule

Data Type Retention Period Rationale
Order records 6 years Legal/tax requirements
Customer accounts 3 years Business relationship
Marketing data Until unsubscribed + 1 year Preference management
Call recordings 12 months Quality assurance
Website logs 90 days Security monitoring

7. Comprehensive Security Measures

7.1 Technical Protections

  • TLS 1.3 encryption
  • Role-based access with MFA
  • WAF (Web Application Firewall)
  • Quarterly penetration tests

7.2 Organizational Protections

  • Annual staff training
  • Employee confidentiality agreements
  • Secure document disposal

8. Your Data Subject Rights

  • Right to Access: Free copy of your personal data (within 30 days)
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion in specific cases
  • Right to Restriction: Temporarily limit use of your data
  • Right to Data Portability: Structured export of your data
  • Right to Object: Opt-out of marketing or legitimate interest processing

To exercise rights:
📧 Email: privacy@neoelectricbikes.co.uk
📞 Phone: +44 203 916 5359