LEGENDLOOM — PRIVACY & COOKIE POLICY

Effective date: 6 September 2025

This Policy explains what data we collect, why we process it, and how you can exercise your rights. We comply with UK GDPR/GDPR and applicable e‑privacy rules.

1) Controller and contacts

Controller: LegendLoom Ltd (No. 15224498)
Registered office: 63–66 Hatton Garden, Fifth Floor, Suite 23, London, EC1N 8LE, United Kingdom
Email (privacy & data requests): team@legendloom.com
EU/EEA representative (if required): [not appointed / to be designated].
UK DPO/representative: [not appointed / to be designated].

2) Data we collect

  • Identity & contact: name/handle, email, country/region.

  • Transactions: purchases, subscriptions, amounts, currency, payment status (processed by payment provider).

  • Communications: support tickets, surveys, polls, votes.

  • Technical & cookie data: IP, device/browser type, events on site, cookie/SDK identifiers (see Cookie section).

  • Community platforms: your Discord handle and content you choose to share.

3) Purposes and legal bases

  • Contract (Art. 6(1)(b) GDPR/UK GDPR): order/subscription processing, digital delivery, support.

  • Consent (Art. 6(1)(a)): marketing emails, non‑essential analytics/marketing cookies, publishing testimonials. You may withdraw consent at any time.

  • Legitimate interests (Art. 6(1)(f)): security and fraud prevention, essential analytics for service improvement, and product development—balanced against your rights.

  • Legal obligations (Art. 6(1)(c)): tax and accounting, responses to authorities.

4) Marketing

We send marketing communications only with your prior opt‑in (e.g., double opt‑in for newsletters). You can unsubscribe at any time via the link in the email or by contacting us.

5) Cookies and trackers

What: cookies/identifiers stored on your device.
How we use:

  • Strictly necessary — site operation, cart/checkout, login.

  • Analytics (consent‑based) — understand usage and improve the service.

  • Marketing (consent‑based) — personalisation/retargeting.
    Your choice: on first visit, we display a banner that lets you Accept allReject all, or Manage preferences by category. You can change choices anytime via Cookie Settings (footer). Access to the site does not depend on accepting non‑essential cookies.

6) Children

We do not target children and do not knowingly collect data from children. If you believe a child provided data without appropriate consent, contact us and we will delete or anonymise it.

7) Automated decisions

We do not make decisions solely based on automated processing that produce legal or similarly significant effects. Non‑significant segmentation (e.g., newsletter groups) may occur.

8) Sharing data

We share data only as necessary and under appropriate contracts/confidentiality:

  • Payments: Stripe (payment processor).

  • Email & automations: MailerLite; Zapier.

  • Website/hosting: SITE123 (and/or other web providers used for our site).

  • Community: Discord.

  • Analytics/monitoring: [list if used, e.g., error tracking].
    An up‑to‑date list of processors is available on request and may change over time.

9) International transfers

Where we transfer personal data outside the UK/EEA, we use lawful mechanisms such as Standard Contractual Clauses (SCCs) or, where applicable to US recipients, the EU‑U.S./UK‑U.S. Data Privacy Framework participation of that recipient. We confirm the recipient’s status and apply additional safeguards where appropriate.

10) Retention

  • Orders & finance records: up to 6–7 years (statutory accounting).

  • Accounts & logs: for the life of the account and a reasonable period afterwards.

  • Marketing: until you unsubscribe or withdraw consent.

  • Cookies: per the lifetime indicated in the Cookie Settings table.

11) Your rights

You have rights of access, rectification, erasure, restriction, portability, objection (including to marketing), and withdrawal of consent. To exercise rights, contact team@legendloom.com. We will respond within 30 days (or explain if more time is needed for complex requests).

12) Security

We apply organisational and technical measures (e.g., encryption in transit, access controls, logging). No method is 100% secure.

13) Complaints and supervisory authorities

Please contact us first. If you are in the Netherlands, you may contact the Dutch DPA (Autoriteit Persoonsgegevens). If you are in the UK, you may contact the ICO (Information Commissioner’s Office). Links are provided on our Contact/Cookie pages.

14) Changes

We may update this Policy. Material changes will be announced on the site with a new effective date.

15) Contacts

Email: team@legendloom.com
Postal: 63–66 Hatton Garden, Fifth Floor, Suite 23, London, EC1N 8LE, United Kingdom


Annex A — Returns/defects (digital content)

If a file is corrupted or misdescribed, please try: (1) re‑download; (2) check instructions/versions; (3) contact support. If we cannot remedy, we may replace, reduce the price proportionately, or refund the affected item/period.