GDPR Statement
Last updated: 26 July 2026
This statement is maintained by WOW Scent Ltd to explain how we handle personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It complements our Privacy Policy.
Data controller
WOW Scent Ltd, 9, SK17 7TH, United Kingdom, is the data controller for personal data collected through wowscent.co.uk. Contact: hello@wowscent.co.uk.
Lawful bases we rely on
- Contract — to process and deliver the orders you place with us.
- Consent — for marketing emails (double opt-in) and for storing non-essential preferences.
- Legitimate interests — to keep the site running securely, prevent fraud, and improve the customer experience.
- Legal obligation — to keep tax and accounting records required by UK law.
Your rights under UK GDPR
You have the right to:
- Be informed about how your data is used (this statement and our Privacy Policy).
- Access a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Ask us to erase your data ("right to be forgotten") where the law allows.
- Restrict or object to certain processing, including direct marketing.
- Receive your data in a portable format.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to solely automated decisions with legal effect — we do not carry out such profiling.
Exercising your rights
For newsletter data, you can view or delete your subscription data yourself. For any other request, email hello@wowscent.co.uk with the subject "GDPR request". We will respond within one calendar month and may ask you to confirm your identity before releasing data.
Data we process
We process only what we need to run the shop and (where applicable) our ambassador programme: contact details, delivery address, order history, marketing preferences, and — for ambassador applicants — the identity document you upload for age and age verification. Payment card details are handled directly by Stripe and never reach our servers.
Sharing and subprocessors
We share personal data only with the providers that help us operate: Stripe for payments, our hosting and database provider, our transactional email provider, and the shipping carrier fulfilling your order. Each is bound by their own data protection terms. We do not sell personal data.
International transfers
Our providers may process data outside the UK. Where they do, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the safeguards each provider publishes.
Retention
Order and accounting records are kept for six years to meet HMRC requirements. Newsletter records are kept until you unsubscribe. Ambassador verification documents are kept only for as long as needed to verify eligibility and to meet any legal obligation, then deleted.
Security
The site runs over HTTPS. Customer accounts and ambassador logins are protected by password authentication with hashed credentials, and ambassador verification uploads are stored in a private bucket accessed only through short-lived signed links by authorised admins.
Breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner's Office within 72 hours and contact affected individuals where required.
Complaints
If you're unhappy with how we've handled your data, please contact us first so we can put it right. You can also complain to the UK Information Commissioner's Office at ico.org.uk.