Privacy Policy

Effective date: 12th July 2023
Last updated: 20th Jun 2026

Privacy summary: This Privacy Policy explains how Bayonson Co. Ltd collects, uses, discloses, stores and protects personal data when you use our websites, mobile applications, products, platforms and related services.

1. About this Privacy Policy

Bayonson Co. Ltd respects your privacy and is committed to protecting your personal data. This Privacy Policy explains:

This policy is intended to comply with the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, the EU General Data Protection Regulation and other applicable privacy and electronic-marketing laws.

This policy should be read together with any supplementary privacy notices that we provide when collecting personal data for a particular purpose.

2. Who Is Responsible for Your Personal Data?

Bayonson Co. Ltd, trading as Bayonson, is the controller responsible for the personal data described in this policy, except where we expressly state otherwise.

Registered office: [REGISTERED ADDRESS]
Company registration number: [COMPANY NUMBER]
Data protection registration number: [ICO REGISTRATION NUMBER, IF APPLICABLE]
Privacy email: [PRIVACY EMAIL]
Telephone: [TELEPHONE NUMBER]

Data Protection Officer

[Choose and retain the appropriate statement.]

Option A: We have appointed a Data Protection Officer. You may contact the Data Protection Officer at: [DPO EMAIL].

Option B: We are not legally required to appoint a Data Protection Officer. Privacy enquiries are handled by our [PRIVACY LEAD/JOB TITLE], who may be contacted using the details above.

EU representative

If we are established outside the European Economic Area but offer services to, or monitor the behaviour of, individuals in the EEA, our EU representative is:

[EU REPRESENTATIVE NAME]
[EU REPRESENTATIVE ADDRESS]
[EU REPRESENTATIVE EMAIL]

[Delete this section if an EU representative is not required.]

3. Scope of This Policy

This policy applies when you:

Where we process personal data solely on behalf of a business customer under its instructions, that customer may be the controller and we may act as its processor. In such cases, the customer's privacy notice will primarily govern the processing. Questions concerning that processing should normally be directed to the relevant customer.

4. Personal Data We Collect

“Personal data” means information relating to an identified or identifiable individual. Depending on how you use our services, we may collect the categories below.

4.1 Identity and account data

4.2 Contact data

4.3 Transaction and subscription data

Unless expressly stated otherwise, full payment-card details are collected and processed directly by our authorised payment provider and are not stored by us.

4.4 Device and technical data

4.5 Usage data

4.6 Location data

We may collect approximate location derived from your IP address. We collect precise device location only where the relevant feature requires it and you have granted permission through your device or app settings.

4.7 Content and communications

4.8 Marketing and preference data

4.9 Business customer and supplier data

4.10 Special-category and criminal-offence data

We do not intentionally collect special-category personal data, such as information about health, ethnicity, religion, political opinions, trade-union membership, sexual orientation, biometric identification or genetic data, unless:

We do not intentionally collect criminal-conviction or offence data unless legally permitted and necessary for a stated purpose.

Do not submit sensitive personal data through the service unless we have specifically requested it.

4.11 Aggregated and anonymised data

We may create aggregated or anonymised information for statistical, analytical and service-improvement purposes. Information that has been irreversibly anonymised so that no individual is identifiable is not personal data.

5. How We Collect Personal Data

We collect personal data:

If we obtain your personal data from another source, we will provide the information required by applicable law within the relevant period, unless an exemption applies.

6. How and Why We Use Personal Data

We process personal data only where we have an appropriate lawful basis. The table below describes common processing activities. Amend it so that it accurately reflects your service.

Purpose Data commonly used Lawful basis
Creating and administering accounts, authenticating users and providing requested service features Identity, contact, account, device and usage data Performance of a contract; steps requested before entering a contract
Processing purchases, subscriptions, renewals, refunds and billing Identity, contact, transaction and subscription data Performance of a contract; compliance with legal obligations
Providing customer support and responding to enquiries, complaints and requests Identity, contact, account, transaction and communication data Performance of a contract; legitimate interests in supporting users and managing our relationship
Operating, maintaining, troubleshooting and improving the website, app and services Device, technical, usage, account and communication data Legitimate interests in operating and improving our services; consent where required for non-essential tracking
Protecting accounts, detecting security incidents, preventing fraud and enforcing our terms Identity, account, transaction, device, technical and usage data Legitimate interests in protecting users, systems and business operations; compliance with legal obligations
Personalising content, settings and recommendations Account, preference, usage and device data Legitimate interests in improving relevance; consent where required by law
Sending service notices, security alerts and essential account communications Identity, contact, account and transaction data Performance of a contract; legal obligations; legitimate interests in service administration and security
Sending newsletters, promotions and product updates Identity, contact, preference and campaign-engagement data Consent; or legitimate interests where direct-marketing rules permit
Measuring marketing effectiveness and non-essential analytics Device, usage, cookie, advertising and campaign data Consent where required; legitimate interests for limited measurement activities where legally permitted
Maintaining financial, tax, compliance and corporate records Identity, contact, transaction, contract and communication data Compliance with legal obligations; legitimate interests in managing and defending our business
Establishing, exercising or defending legal claims and responding to regulators or law-enforcement authorities Any data relevant to the matter Legal obligation; legitimate interests; establishment, exercise or defence of legal claims
Managing business customers, suppliers and commercial partners Business contact, contract, communication and due-diligence data Performance of a contract; legitimate interests in managing business relationships; legal obligations

Legitimate interests

Where we rely on legitimate interests, we consider the purpose and necessity of the processing and balance our interests against your rights, interests and reasonable expectations. Our legitimate interests may include:

You may contact us to request further information about a legitimate-interest assessment relevant to your personal data.

Consent

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing conducted before consent was withdrawn.

Failure to provide personal data

Where personal data is required by law or under a contract and you do not provide it, we may be unable to create your account, process a payment, provide the relevant service or fulfil our contractual obligations.

Using data for a new purpose

We will use personal data only for the purposes for which it was collected unless we reasonably determine that another purpose is compatible with the original purpose. Where required, we will provide further information and identify the applicable lawful basis before beginning materially different processing.

7. Mobile-App Permissions and Device Features

Depending on the app features you choose to use, the app may request access to the following device functions:

Permission or feature Purpose Control
Camera To capture photographs, scan codes or support [INSERT RELEVANT FEATURE]. You can allow or deny access through device settings.
Photo or media library To upload, save or share images, video, audio or documents. You can limit or withdraw access through device settings.
Microphone To record audio, enable calls or support [INSERT RELEVANT FEATURE]. You can allow or deny access through device settings.
Location To provide location-based services such as [INSERT RELEVANT FEATURE]. You can choose approximate or precise location and may withdraw permission through device settings.
Contacts To help you find, invite or communicate with contacts where you actively select that feature. Access requires device permission and may be withdrawn.
Notifications To send service alerts, messages, reminders or marketing notifications, depending on your choices. You can manage notification permissions through the app or device settings.
Biometric authentication To enable device-based login using a fingerprint or facial authentication. Biometric templates are normally controlled by your device provider and are not received by us.

The app will request a permission only where the related feature requires it. Refusing or withdrawing permission may prevent that feature from working but should not affect unrelated functions.

8. Cookies and Similar Technologies

Our website and app may use cookies, pixels, local storage, software development kits, device identifiers and similar technologies.

These technologies may be categorised as:

We will request consent before placing or accessing non-essential cookies or comparable technologies where applicable law requires it. You can change your choices through our cookie settings.

Further information, including the providers, purposes and lifespans of individual technologies, is available in our Cookie Policy.

9. Marketing Communications

We may send you information about our services where:

You may opt out at any time by:

Opting out of marketing will not stop essential service, transaction, security or legal communications.

10. How We Share Personal Data

We do not sell personal data. We may disclose it to the following recipients where necessary and lawful:

Service providers acting as processors are required by contract to process personal data only on documented instructions, protect it appropriately, maintain confidentiality and assist us with applicable data-protection obligations.

A current list of material service providers or subprocessors is available at: [SUBPROCESSOR PAGE URL].

11. International Transfers

Some recipients of personal data may be located outside the United Kingdom or European Economic Area. Those countries may not provide the same level of statutory data protection.

Where an international transfer is subject to the UK GDPR or EU GDPR, we will use an appropriate transfer mechanism, such as:

Where required, we also assess the circumstances of the transfer and apply supplementary technical, organisational or contractual measures.

You may request further information about the safeguards relevant to your personal data by contacting us.

12. How Long We Retain Personal Data

We retain personal data only for as long as reasonably necessary for the relevant purpose, including to satisfy legal, accounting, tax, security and reporting requirements and to establish or defend legal claims.

Our retention decisions consider:

Record type Indicative retention period
Active account information For the duration of the account and up to [INSERT PERIOD] after closure.
Transaction, invoice and tax records [INSERT PERIOD, commonly based on applicable statutory requirements].
Customer-support records [INSERT PERIOD] after the matter is closed.
Security and access logs [INSERT PERIOD], unless needed for an investigation.
Cookie-consent records [INSERT PERIOD] after the relevant choice or consent.
Marketing suppression records Retained as necessary to respect your opt-out.
User-uploaded content Until deleted by you, account closure or [INSERT APPLICABLE RULE], subject to backups and legal requirements.

When retention is no longer necessary, we will securely erase, anonymise or isolate the relevant data from further use. Residual copies may remain in encrypted backups until they are overwritten in accordance with our backup schedule.

13. Data Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.

Measures may include:

No method of electronic transmission or storage is completely secure. You are responsible for keeping your account credentials confidential and for notifying us promptly if you suspect unauthorised account activity.

Where required by law, we will notify the relevant supervisory authority and affected individuals of a personal-data breach.

14. Your Data-Protection Rights

Subject to applicable law and any relevant exemptions, you may have the following rights:

How to exercise your rights

Submit a request by emailing [PRIVACY EMAIL] or writing to the address in section 2.

Please include:

We may request information needed to verify your identity and protect personal data against unauthorised disclosure. We will not request more information than is reasonably necessary.

We normally respond without undue delay and within one month, although the period may be extended where permitted for complex or numerous requests. We will explain any lawful extension.

Rights requests are generally free. We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by law.

15. Automated Decision-Making and Profiling

[Select and retain the statement that applies.]

Option A: No significant automated decisions

We do not currently make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects concerning you.

Option B: Significant automated decisions are used

We use automated decision-making for [DESCRIBE THE DECISION AND PURPOSE]. The decision uses [DESCRIBE THE MAIN DATA AND LOGIC] and may result in [DESCRIBE THE POSSIBLE EFFECTS].

Our lawful basis is [INSERT LAWFUL BASIS]. Where required, you may request human intervention, express your point of view and contest the decision by contacting [PRIVACY EMAIL].

Delete the option that does not apply. Do not use Option A where fraud, credit, eligibility, moderation, pricing, employment or access decisions have significant effects and are made solely by automated means.

16. Children's Privacy

Our services are intended for individuals aged [INSERT MINIMUM AGE] or older. We do not knowingly collect personal data from children below that age without an appropriate lawful basis and, where required, authorisation from a person with parental responsibility.

If you believe that a child has provided personal data contrary to this policy, contact us at [PRIVACY EMAIL]. We will investigate and take appropriate action.

If the service is directed at children or likely to be accessed by them, this section must be replaced with a child-specific privacy notice addressing age assurance, parental involvement, child-appropriate language, profiling, default settings and applicable children's design standards.

17. Third-Party Services and Links

Our services may contain links to, integrate with or allow sign-in through third-party websites, apps, platforms or services. Those parties may independently collect and process personal data under their own privacy notices.

We are not responsible for the privacy practices of an independent third party. We encourage you to review its privacy information before providing personal data or enabling an integration.

App stores

When you download or purchase the app through an app store, the app-store operator may process information relating to your account, device, download and payment under its own terms and privacy policy.

18. Changes to This Privacy Policy

We may update this policy to reflect changes to our services, processing activities, technologies or legal obligations.

The current version will be published on this page and identified by the “Last updated” date. Where changes materially affect your rights or how we use personal data, we will provide additional notice where required, such as through the app, by email or by a prominent website notice.

We encourage you to review this policy periodically.

19. Questions and Complaints

Please contact us first if you have a question or concern about this policy or our use of personal data:

[FULL LEGAL COMPANY NAME]
[PRIVACY OR REGISTERED ADDRESS]
Email: [PRIVACY EMAIL]
Telephone: [TELEPHONE NUMBER]

United Kingdom

You may complain to the Information Commissioner's Office, the United Kingdom's data-protection supervisory authority:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/

European Economic Area

If you are located in the EEA, you may lodge a complaint with the supervisory authority in the country where you live, work or believe an infringement occurred.

A list of European data-protection authorities is available from the European Data Protection Board: EDPB supervisory-authority directory .

Your right to complain to a supervisory authority is without prejudice to any other administrative or judicial remedy available to you.