Privacy Policy
Effective date: 12th July 2023
Last updated: 20th Jun 2026
1. About this Privacy Policy
Bayonson Co. Ltd respects your privacy and is committed to protecting your personal data. This Privacy Policy explains:
- what personal data we collect;
- where we obtain it;
- why and how we use it;
- the lawful bases on which we rely;
- who may receive it;
- how long we retain it;
- how we protect it; and
- the rights available to you.
This policy is intended to comply with the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, the EU General Data Protection Regulation and other applicable privacy and electronic-marketing laws.
This policy should be read together with any supplementary privacy notices that we provide when collecting personal data for a particular purpose.
2. Who Is Responsible for Your Personal Data?
Bayonson Co. Ltd, trading as Bayonson, is the controller responsible for the personal data described in this policy, except where we expressly state otherwise.
Registered office: [REGISTERED ADDRESS]Company registration number: [COMPANY NUMBER]
Data protection registration number: [ICO REGISTRATION NUMBER, IF APPLICABLE]
Privacy email: [PRIVACY EMAIL]
Telephone: [TELEPHONE NUMBER]
Data Protection Officer
[Choose and retain the appropriate statement.]
Option A: We have appointed a Data Protection Officer. You may contact the Data Protection Officer at: [DPO EMAIL].
Option B: We are not legally required to appoint a Data Protection Officer. Privacy enquiries are handled by our [PRIVACY LEAD/JOB TITLE], who may be contacted using the details above.
EU representative
If we are established outside the European Economic Area but offer services to, or monitor the behaviour of, individuals in the EEA, our EU representative is:
[EU REPRESENTATIVE NAME][EU REPRESENTATIVE ADDRESS]
[EU REPRESENTATIVE EMAIL]
[Delete this section if an EU representative is not required.]
3. Scope of This Policy
This policy applies when you:
- visit or interact with our website at [WEBSITE DOMAIN];
- download, install or use our mobile application;
- create or manage an account;
- purchase or subscribe to our services;
- communicate with our customer-support team;
- receive marketing communications from us;
- participate in a survey, promotion, event or trial;
- apply to become a supplier, partner or business customer; or
- otherwise interact with our products and services.
Where we process personal data solely on behalf of a business customer under its instructions, that customer may be the controller and we may act as its processor. In such cases, the customer's privacy notice will primarily govern the processing. Questions concerning that processing should normally be directed to the relevant customer.
4. Personal Data We Collect
“Personal data” means information relating to an identified or identifiable individual. Depending on how you use our services, we may collect the categories below.
4.1 Identity and account data
- full name;
- username or account identifier;
- date of birth or age range, where required;
- profile photograph or avatar;
- password in encrypted or hashed form;
- authentication tokens; and
- account preferences and settings.
4.2 Contact data
- email address;
- telephone number;
- billing or postal address; and
- communication preferences.
4.3 Transaction and subscription data
- products or services purchased;
- subscription type and status;
- purchase date and transaction reference;
- billing history;
- refund or cancellation information; and
- limited payment information supplied by our payment provider, such as payment status and the last four digits of a payment card.
Unless expressly stated otherwise, full payment-card details are collected and processed directly by our authorised payment provider and are not stored by us.
4.4 Device and technical data
- internet protocol address;
- device type and device identifier;
- operating system and version;
- browser type and version;
- mobile network information;
- app version;
- language and time-zone settings;
- cookie identifiers and advertising identifiers;
- login data;
- crash reports, diagnostic data and performance logs; and
- security and fraud-detection information.
4.5 Usage data
- features and pages viewed;
- buttons, links and functions used;
- search queries entered into the service;
- session dates, times and duration;
- referring website or campaign;
- interaction and navigation patterns; and
- service preferences and activity history.
4.6 Location data
We may collect approximate location derived from your IP address. We collect precise device location only where the relevant feature requires it and you have granted permission through your device or app settings.
4.7 Content and communications
- messages sent to customer support;
- feedback, reviews and survey responses;
- files, photographs, audio, video or documents you upload;
- comments, posts or other user-generated content;
- records of complaints and dispute correspondence; and
- telephone or video-call recordings where you have been appropriately informed.
4.8 Marketing and preference data
- marketing permissions;
- email and notification preferences;
- campaign engagement;
- interests inferred from use of our services; and
- records of consent, withdrawal and objections.
4.9 Business customer and supplier data
- job title;
- employer or organisation;
- business contact details;
- professional communications;
- contract and procurement information; and
- due-diligence information.
4.10 Special-category and criminal-offence data
We do not intentionally collect special-category personal data, such as information about health, ethnicity, religion, political opinions, trade-union membership, sexual orientation, biometric identification or genetic data, unless:
- the service expressly requires it;
- we have clearly explained why it is needed;
- an Article 6 lawful basis applies;
- an applicable Article 9 condition or UK legal condition applies; and
- appropriate safeguards are in place.
We do not intentionally collect criminal-conviction or offence data unless legally permitted and necessary for a stated purpose.
4.11 Aggregated and anonymised data
We may create aggregated or anonymised information for statistical, analytical and service-improvement purposes. Information that has been irreversibly anonymised so that no individual is identifiable is not personal data.
5. How We Collect Personal Data
We collect personal data:
- Directly from you, including when you register, place an order, upload content, contact us or complete a form.
- Automatically, through cookies, software development kits, server logs, app diagnostics and similar technologies.
- From authentication providers, where you sign in through services such as Apple, Google or another identity provider.
- From payment providers, which may confirm payment status, subscription details, refunds or fraud checks.
- From business customers, where an organisation creates or administers an account for you.
- From service partners, such as analytics, customer-support, hosting, fraud-prevention or marketing providers.
- From public sources, such as company websites, Companies House, professional directories or social-media profiles, where lawful.
If we obtain your personal data from another source, we will provide the information required by applicable law within the relevant period, unless an exemption applies.
6. How and Why We Use Personal Data
We process personal data only where we have an appropriate lawful basis. The table below describes common processing activities. Amend it so that it accurately reflects your service.
| Purpose | Data commonly used | Lawful basis |
|---|---|---|
| Creating and administering accounts, authenticating users and providing requested service features | Identity, contact, account, device and usage data | Performance of a contract; steps requested before entering a contract |
| Processing purchases, subscriptions, renewals, refunds and billing | Identity, contact, transaction and subscription data | Performance of a contract; compliance with legal obligations |
| Providing customer support and responding to enquiries, complaints and requests | Identity, contact, account, transaction and communication data | Performance of a contract; legitimate interests in supporting users and managing our relationship |
| Operating, maintaining, troubleshooting and improving the website, app and services | Device, technical, usage, account and communication data | Legitimate interests in operating and improving our services; consent where required for non-essential tracking |
| Protecting accounts, detecting security incidents, preventing fraud and enforcing our terms | Identity, account, transaction, device, technical and usage data | Legitimate interests in protecting users, systems and business operations; compliance with legal obligations |
| Personalising content, settings and recommendations | Account, preference, usage and device data | Legitimate interests in improving relevance; consent where required by law |
| Sending service notices, security alerts and essential account communications | Identity, contact, account and transaction data | Performance of a contract; legal obligations; legitimate interests in service administration and security |
| Sending newsletters, promotions and product updates | Identity, contact, preference and campaign-engagement data | Consent; or legitimate interests where direct-marketing rules permit |
| Measuring marketing effectiveness and non-essential analytics | Device, usage, cookie, advertising and campaign data | Consent where required; legitimate interests for limited measurement activities where legally permitted |
| Maintaining financial, tax, compliance and corporate records | Identity, contact, transaction, contract and communication data | Compliance with legal obligations; legitimate interests in managing and defending our business |
| Establishing, exercising or defending legal claims and responding to regulators or law-enforcement authorities | Any data relevant to the matter | Legal obligation; legitimate interests; establishment, exercise or defence of legal claims |
| Managing business customers, suppliers and commercial partners | Business contact, contract, communication and due-diligence data | Performance of a contract; legitimate interests in managing business relationships; legal obligations |
Legitimate interests
Where we rely on legitimate interests, we consider the purpose and necessity of the processing and balance our interests against your rights, interests and reasonable expectations. Our legitimate interests may include:
- operating and improving our services;
- protecting our systems, users and business;
- preventing fraud and misuse;
- understanding service performance;
- supporting customers;
- managing business relationships;
- recovering debts;
- enforcing agreements; and
- establishing or defending legal claims.
You may contact us to request further information about a legitimate-interest assessment relevant to your personal data.
Consent
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing conducted before consent was withdrawn.
Failure to provide personal data
Where personal data is required by law or under a contract and you do not provide it, we may be unable to create your account, process a payment, provide the relevant service or fulfil our contractual obligations.
Using data for a new purpose
We will use personal data only for the purposes for which it was collected unless we reasonably determine that another purpose is compatible with the original purpose. Where required, we will provide further information and identify the applicable lawful basis before beginning materially different processing.
7. Mobile-App Permissions and Device Features
Depending on the app features you choose to use, the app may request access to the following device functions:
| Permission or feature | Purpose | Control |
|---|---|---|
| Camera | To capture photographs, scan codes or support [INSERT RELEVANT FEATURE]. | You can allow or deny access through device settings. |
| Photo or media library | To upload, save or share images, video, audio or documents. | You can limit or withdraw access through device settings. |
| Microphone | To record audio, enable calls or support [INSERT RELEVANT FEATURE]. | You can allow or deny access through device settings. |
| Location | To provide location-based services such as [INSERT RELEVANT FEATURE]. | You can choose approximate or precise location and may withdraw permission through device settings. |
| Contacts | To help you find, invite or communicate with contacts where you actively select that feature. | Access requires device permission and may be withdrawn. |
| Notifications | To send service alerts, messages, reminders or marketing notifications, depending on your choices. | You can manage notification permissions through the app or device settings. |
| Biometric authentication | To enable device-based login using a fingerprint or facial authentication. | Biometric templates are normally controlled by your device provider and are not received by us. |
The app will request a permission only where the related feature requires it. Refusing or withdrawing permission may prevent that feature from working but should not affect unrelated functions.
9. Marketing Communications
We may send you information about our services where:
- you have expressly consented;
- applicable law permits us to contact an existing customer about similar services and an opt-out was provided; or
- another lawful basis and marketing rule permits the contact.
You may opt out at any time by:
- using the unsubscribe link in a marketing email;
- changing your account or app settings;
- disabling marketing push notifications on your device; or
- emailing [PRIVACY EMAIL].
Opting out of marketing will not stop essential service, transaction, security or legal communications.
11. International Transfers
Some recipients of personal data may be located outside the United Kingdom or European Economic Area. Those countries may not provide the same level of statutory data protection.
Where an international transfer is subject to the UK GDPR or EU GDPR, we will use an appropriate transfer mechanism, such as:
- a UK or EU adequacy decision applicable to the destination;
- the European Commission's Standard Contractual Clauses;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission's Standard Contractual Clauses;
- approved Binding Corporate Rules; or
- another legally permitted transfer mechanism.
Where required, we also assess the circumstances of the transfer and apply supplementary technical, organisational or contractual measures.
You may request further information about the safeguards relevant to your personal data by contacting us.
12. How Long We Retain Personal Data
We retain personal data only for as long as reasonably necessary for the relevant purpose, including to satisfy legal, accounting, tax, security and reporting requirements and to establish or defend legal claims.
Our retention decisions consider:
- the amount, nature and sensitivity of the data;
- the purposes for which it is processed;
- the duration of our relationship with you;
- the risk of harm from unauthorised use or disclosure;
- whether the purpose can be achieved by other means;
- applicable limitation periods; and
- statutory, regulatory, tax and contractual requirements.
| Record type | Indicative retention period |
|---|---|
| Active account information | For the duration of the account and up to [INSERT PERIOD] after closure. |
| Transaction, invoice and tax records | [INSERT PERIOD, commonly based on applicable statutory requirements]. |
| Customer-support records | [INSERT PERIOD] after the matter is closed. |
| Security and access logs | [INSERT PERIOD], unless needed for an investigation. |
| Cookie-consent records | [INSERT PERIOD] after the relevant choice or consent. |
| Marketing suppression records | Retained as necessary to respect your opt-out. |
| User-uploaded content | Until deleted by you, account closure or [INSERT APPLICABLE RULE], subject to backups and legal requirements. |
When retention is no longer necessary, we will securely erase, anonymise or isolate the relevant data from further use. Residual copies may remain in encrypted backups until they are overwritten in accordance with our backup schedule.
13. Data Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.
Measures may include:
- encryption in transit and, where appropriate, at rest;
- password hashing and secure authentication controls;
- role-based access restrictions and least-privilege access;
- multi-factor authentication for relevant systems;
- logging, monitoring and vulnerability management;
- secure software-development and change-management practices;
- employee confidentiality and data-protection training;
- supplier security and privacy assessments;
- business-continuity and backup procedures; and
- incident-response and breach-management processes.
No method of electronic transmission or storage is completely secure. You are responsible for keeping your account credentials confidential and for notifying us promptly if you suspect unauthorised account activity.
Where required by law, we will notify the relevant supervisory authority and affected individuals of a personal-data breach.
14. Your Data-Protection Rights
Subject to applicable law and any relevant exemptions, you may have the following rights:
- Right to be informed: to receive clear information about our processing.
- Right of access: to obtain confirmation of whether we process your data and receive a copy.
- Right to rectification: to correct inaccurate or incomplete personal data.
- Right to erasure: to request deletion in circumstances prescribed by law.
- Right to restrict processing: to request that use of your data be limited in certain circumstances.
- Right to data portability: to receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller.
- Right to object: to object to processing based on legitimate interests or a public task.
- Direct-marketing objection: to object at any time to processing for direct marketing, including related profiling.
- Rights concerning automated decisions: to request human intervention and contest certain decisions based solely on automated processing that have legal or similarly significant effects.
- Right to withdraw consent: where consent is the lawful basis.
- Right to complain: to lodge a complaint with an applicable data-protection supervisory authority.
How to exercise your rights
Submit a request by emailing [PRIVACY EMAIL] or writing to the address in section 2.
Please include:
- your name and relevant account email or identifier;
- the right you wish to exercise;
- a clear description of your request; and
- any information reasonably necessary to locate your data.
We may request information needed to verify your identity and protect personal data against unauthorised disclosure. We will not request more information than is reasonably necessary.
We normally respond without undue delay and within one month, although the period may be extended where permitted for complex or numerous requests. We will explain any lawful extension.
Rights requests are generally free. We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by law.
15. Automated Decision-Making and Profiling
[Select and retain the statement that applies.]
Option A: No significant automated decisions
We do not currently make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects concerning you.
Option B: Significant automated decisions are used
We use automated decision-making for [DESCRIBE THE DECISION AND PURPOSE]. The decision uses [DESCRIBE THE MAIN DATA AND LOGIC] and may result in [DESCRIBE THE POSSIBLE EFFECTS].
Our lawful basis is [INSERT LAWFUL BASIS]. Where required, you may request human intervention, express your point of view and contest the decision by contacting [PRIVACY EMAIL].
Delete the option that does not apply. Do not use Option A where fraud, credit, eligibility, moderation, pricing, employment or access decisions have significant effects and are made solely by automated means.
16. Children's Privacy
Our services are intended for individuals aged [INSERT MINIMUM AGE] or older. We do not knowingly collect personal data from children below that age without an appropriate lawful basis and, where required, authorisation from a person with parental responsibility.
If you believe that a child has provided personal data contrary to this policy, contact us at [PRIVACY EMAIL]. We will investigate and take appropriate action.
If the service is directed at children or likely to be accessed by them, this section must be replaced with a child-specific privacy notice addressing age assurance, parental involvement, child-appropriate language, profiling, default settings and applicable children's design standards.
17. Third-Party Services and Links
Our services may contain links to, integrate with or allow sign-in through third-party websites, apps, platforms or services. Those parties may independently collect and process personal data under their own privacy notices.
We are not responsible for the privacy practices of an independent third party. We encourage you to review its privacy information before providing personal data or enabling an integration.
App stores
When you download or purchase the app through an app store, the app-store operator may process information relating to your account, device, download and payment under its own terms and privacy policy.
18. Changes to This Privacy Policy
We may update this policy to reflect changes to our services, processing activities, technologies or legal obligations.
The current version will be published on this page and identified by the “Last updated” date. Where changes materially affect your rights or how we use personal data, we will provide additional notice where required, such as through the app, by email or by a prominent website notice.
We encourage you to review this policy periodically.
19. Questions and Complaints
Please contact us first if you have a question or concern about this policy or our use of personal data:
[FULL LEGAL COMPANY NAME][PRIVACY OR REGISTERED ADDRESS]
Email: [PRIVACY EMAIL]
Telephone: [TELEPHONE NUMBER]
United Kingdom
You may complain to the Information Commissioner's Office, the United Kingdom's data-protection supervisory authority:
Information Commissioner's OfficeWycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/
European Economic Area
If you are located in the EEA, you may lodge a complaint with the supervisory authority in the country where you live, work or believe an infringement occurred.
A list of European data-protection authorities is available from the European Data Protection Board: EDPB supervisory-authority directory .
Your right to complain to a supervisory authority is without prejudice to any other administrative or judicial remedy available to you.