Privacy policy

Last updated: February 19, 2026

This policy explains how we collect, use and protect your information in accordance with UK GDPR and the Data Protection Act 2018.

At Aetheia, we respect your privacy and are committed to protecting your personal data.

Data Controller

The data controller is:

Aetheia

Email: hello@aetheia.co.uk

Registered Address: 22 Balmoral Close, Billericay, CM11 2LL

Information We Collect

We may collect:

  • Name
  • Email address
  • Billing and shipping address
  • Phone number
  • Payment information (processed securely via third-party providers)
  • Order history
  • Website usage data

How We Use Your Data

We use your information to:

  • Process and fulfil orders
  • Communicate about orders
  • Provide customer support
  • Send marketing emails (only with consent)
  • Improve our website and services

Lawful Basis for Processing

We process your data under:

  • Contractual necessity (to fulfil orders)
  • Legal obligation (tax/accounting)
  • Legitimate interests (improving services)
  • Consent (marketing communications)

Marketing

You will only receive marketing emails if:

  • You opt in, or
  • You have purchased and have not opted out (soft opt-in rule)

You can unsubscribe at any time.

Third-Party Services

We use trusted third-party providers including:

  • Shopify (e-commerce platform)
  • Payment processors
  • Shipping providers
  • Email marketing platforms
  • Analytics tools 

These providers process data in accordance with GDPR requirements.

Data Retention

We retain personal data only as long as necessary for:

  • Fulfilling orders
  • Legal compliance
  • Accounting purposes

Your Rights

Under UK GDPR, you have the right to:

  • Access your data
  • Correct inaccurate data
  • Request erasure
  • Restrict processing
  • Object to processing
  • Data portability

To exercise these rights, email: hello@aetheia.co.uk

You also have the right to complain to the Information Commissioner’s Office (ICO).

Data Security

We implement appropriate technical and organisational measures to protect your data.