Privacy & Cookie Policy for Neo Electric Bikes
Last Updated: 23 June 2025
Company Name: GNS Hardware Ltd
Trading As: Neo Electric Bikes
Website: www.neoelectricbikes.co.uk
1. Introduction & Scope
GNS Hardware Ltd (“we”, “us”, or “our”) operates Neo Electric Bikes and is committed to protecting your personal data in compliance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
- Other applicable UK and EU data protection laws
This policy governs all personal data collected:
- Through our website (www.neoelectricbikes.co.uk)
- Via email, phone, or live chat communications
- During the order and fulfilment process
- Through any third-party services integrated with our operations
2. Detailed Data Collection Methods
2.1 Direct Collection Points
- Create an account (name, email, password, contact details)
- Place an order (billing/shipping address, payment details, product preferences)
- Contact customer support (call recordings, email threads, live chat transcripts)
- Participate in marketing activities (competition entries, survey responses)
- Submit reviews or feedback (product opinions, service ratings)
- Apply for financing (credit checks through approved providers)
2.2 Automated Collection Technologies
- Google Analytics 4 (anonymized usage data)
- Facebook Pixel (conversion tracking)
- Server Logs: IP addresses, timestamps, browser/device characteristics
- Cookies: See Section 11
2.3 Third-Party Data Sources
- Payment processors (Stripe, PayPal)
- Delivery partners (DPD, DHL)
- Marketing platforms (Mailchimp)
- Review platforms (Trustpilot)
3. Categories of Personal Data Processed
Data Category | Examples | Legal Basis |
---|---|---|
Identity Data | Full name, date of birth (for finance) | Contractual necessity |
Contact Data | Email, phone, billing/delivery address | Contractual necessity |
Financial Data | Last 4 digits of payment cards | Legal obligation |
Transaction Data | Order history, returns, warranties | Legitimate interest |
Technical Data | IP address, browser type, device ID | Legitimate interest |
Usage Data | Clickstream, page interaction | Consent |
Marketing Data | Preferences, opt-ins/opt-outs | Consent |
4. Purposes & Lawful Bases for Processing
4.1 Contractual Necessity
- Processing and delivering your orders
- Managing your account and warranties
- Providing customer support services
4.2 Legal Obligations
- HMRC tax compliance (6 years)
- Fraud prevention and financial audits
- Product safety recalls and notifications
4.3 Legitimate Interests
- Improve website functionality and UX
- Prevent fraudulent transactions
- Personalize product recommendations
4.4 Consent-Based Processing
- Send marketing communications with opt-in
- Use non-essential cookies with permission
- Share data with third-party advertisers when consented
5. Data Sharing & Third-Party Processors
5.1 Essential Service Providers
Processor | Purpose | Data Shared | Safeguards |
---|---|---|---|
Stripe/PayPal | Payment processing | Transaction details | PCI DSS Compliance |
DPD/DHL | Order fulfilment | Delivery addresses | GDPR Data Processing Agreements |
Zendesk | Customer support | Contact details | EU Standard Contractual Clauses |
5.2 International Transfers
- We use UK-approved Standard Contractual Clauses
- Ensure recipients are Privacy Shield certified
- Conduct regular vendor compliance audits
6. Data Retention Schedule
Data Type | Retention Period | Rationale |
---|---|---|
Order records | 6 years | Legal/tax requirements |
Customer accounts | 3 years | Business relationship |
Marketing data | Until unsubscribed + 1 year | Preference management |
Call recordings | 12 months | Quality assurance |
Website logs | 90 days | Security monitoring |
7. Comprehensive Security Measures
7.1 Technical Protections
- TLS 1.3 encryption
- Role-based access with MFA
- WAF (Web Application Firewall)
- Quarterly penetration tests
7.2 Organizational Protections
- Annual staff training
- Employee confidentiality agreements
- Secure document disposal
8. Your Data Subject Rights
- Right to Access: Free copy of your personal data (within 30 days)
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion in specific cases
- Right to Restriction: Temporarily limit use of your data
- Right to Data Portability: Structured export of your data
- Right to Object: Opt-out of marketing or legitimate interest processing
To exercise rights:
📧 Email: privacy@neoelectricbikes.co.uk
📞 Phone: +44 203 916 5359