Privacy Policy
BRITTHERM LIMITED
Version: April 2026
1. Who We Are and How to Contact Us
BritTherm Limited is the data controller responsible for your personal data.
- Company name: BritTherm Limited
- Company registration number: 11400625
- Registered office: Unit G 14 Silverbox House, 56 Magnet Road, East Lane Business Park, Wembley, London, HA9 7FP
- Data protection contact: info@brittherm.co.uk
- Telephone: +44 (0)20 8904 4832
- ICO registration number: ZC115745 — BritTherm Limited is registered as a data controller with the Information Commissioner's Office.
If you have any questions about how we use your personal data, or if you wish to exercise any of your rights, please contact us at info@brittherm.co.uk.
2. Important Information
2.1 This policy applies to personal data collected from individuals who: visit our website at www.brittherm.co.uk; purchase goods from us directly or through a marketplace such as Amazon or eBay; contact us by telephone, email or post; or register a product guarantee with us.
2.2 Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data relating to a child, please contact us immediately at info@brittherm.co.uk.
2.3 Where you purchase BritTherm products through third-party sellers, authorised stockists, distributors or online platforms including Amazon, BritTherm may receive limited personal data from those third parties solely for the purposes of warranty registration, customer support or order fulfilment. BritTherm does not control or process wider customer data held by those third parties.
2.4 We may update this policy from time to time to reflect changes in our data practices or the law. We will notify you of any material changes by posting a prominent notice on our website. The date at the top of this policy shows when it was last updated. We recommend you check this policy periodically.
3. What Personal Data We Collect
We collect and process the following categories of personal data:
| Category | What It Includes |
|---|---|
| Identity Data | First name, last name, title, company name (for business customers) |
| Contact Data | Billing address, delivery address, email address, telephone number |
| Transaction Data | Details of goods you have ordered or purchased, order history, invoices |
| Financial Data | Payment method type only. Where you pay by card online, payment is processed securely by Stripe and card details are never stored by BritTherm. Where payment is made by bank transfer, only transaction reference data is retained. |
| Warranty Registration Data | Name, installation address, date of purchase and installation, pump part number, supplier name, invoice number |
| Technical Data | IP address, browser type and version, device type, operating system, time zone, pages visited, referral source, session duration, cookie identifiers |
| Communications Data | Records of your enquiries, complaints, and correspondence with us |
| Marketing Preferences | Your preferences for receiving marketing from us and your unsubscribe history |
| Credit Data (B2B only) | Information obtained from credit reference agencies for trade account applications |
4. How We Collect Your Data
4.1 Directly From You
We collect data directly from you when you:
- Place an order on our website, by phone or by email
- Create an account on our website
- Register a product guarantee online or by email
- Contact us with an enquiry or complaint
- Sign up to receive marketing communications
- Apply for a trade account
4.2 Automatically
When you visit our website, we automatically collect Technical Data through cookies and similar technologies. Please refer to our Cookie Policy (managed through CookieYes) for full details of the cookies we use, their purposes, and how to manage your preferences.
4.3 From Third Parties
We may receive personal data from:
- Amazon, eBay and other marketplaces — where you purchase our products through those platforms, they may share limited order and contact information with us for fulfilment and after-sales support purposes
- Credit reference agencies — for trade account applications from business customers
- Authorised distributors and stockists — where you have purchased a product through one of our trade partners and subsequently contact us for warranty or support purposes
5. How We Use Your Data and Our Lawful Basis
UK GDPR requires us to have a lawful basis for every use of your personal data. The table below sets out each processing activity, the data used, and the lawful basis we rely on.
| Purpose / Processing Activity | Data Used | Lawful Basis |
|---|---|---|
| Process and fulfil your order, including dispatch and delivery | Identity, Contact, Transaction | Contract performance |
| Process payment for your order | Financial, Transaction | Contract performance |
| Send order confirmation, dispatch notification and delivery updates | Identity, Contact, Transaction | Contract performance |
| Manage your website account | Identity, Contact | Contract performance |
| Respond to your enquiries, questions and complaints | Identity, Contact, Communications | Legitimate interests — to manage our customer relationships effectively |
| Administer and process product guarantee registrations and claims | Identity, Contact, Warranty Registration, Transaction | Legitimate interests — to administer our guarantee scheme and verify claims |
| Send essential service communications (e.g. warranty confirmations, safety notices, order updates) | Identity, Contact | Contract performance / Legitimate interests |
| Send marketing communications to existing customers about similar products and services | Identity, Contact, Marketing Preferences | Legitimate interests — direct marketing to existing customers who have not opted out |
| Send marketing communications to customers who have opted in | Identity, Contact, Marketing Preferences | Consent |
| Improve and analyse website performance and user experience | Technical | Legitimate interests — to maintain and improve our digital services |
| Prevent fraud, protect security and verify identity | Identity, Contact, Technical, Transaction | Legitimate interests — to protect our business and customers |
| Conduct credit reference searches for trade account applications | Identity, Contact, Credit Data | Legitimate interests — to assess creditworthiness for B2B trade accounts |
| Comply with legal and regulatory obligations (including HMRC, financial record-keeping) | Identity, Contact, Transaction, Financial | Legal obligation |
| Transfer of business — sharing data with a prospective buyer or successor | Identity, Contact, Transaction | Legitimate interests — in the context of a business sale or transfer |
6. Marketing
6.1 We may send you marketing communications about our products, services and promotions by email. We will only do so where: (a) you are an existing customer and we are marketing similar products or services and you have not opted out; or (b) you have given us your explicit consent to receive marketing.
6.2 We will never share your personal data with third parties for their own marketing purposes.
6.3 You can opt out of marketing communications at any time by: clicking the unsubscribe link in any email we send you; or emailing us at info@brittherm.co.uk. Opting out of marketing will not affect your receipt of essential service communications such as order confirmations, warranty information or safety notices.
6.4 Our marketing emails are sent via Mailchimp, which uses tracking pixels to record whether emails have been opened and which links have been clicked. This data is used to measure the effectiveness of our communications and improve what we send you. This tracking is disclosed in our Cookie Policy and you may opt out by contacting us at info@brittherm.co.uk.
7. How Long We Keep Your Data
We will only retain your personal data for as long as is necessary for the purposes set out in this policy. The table below sets out our specific retention periods.
| Category of Data | Retention Period | Reason |
|---|---|---|
| Order and transaction records | 7 years from the date of the transaction | HMRC statutory requirement for financial records |
| Customer account data | Duration of your account plus 6 years after closure | Limitation Act 1980 — contractual claims period |
| Warranty registration data | Duration of the applicable guarantee period plus 2 years | To administer guarantee claims and defend potential disputes |
| Marketing contact data | Until you unsubscribe, plus 12 months | To honour opt-out requests and maintain suppression lists |
| B2B trade account and credit data | Duration of the account plus 6 years | Contractual and credit management purposes |
| Enquiry and complaint records | 3 years from resolution | To defend potential legal claims |
| Website analytics data | 13 months from collection | Standard analytics retention period |
| Data breach records (internal) | 5 years from the incident | ICO regulatory requirement |
In some circumstances we may retain data for longer, for example if we are involved in legal proceedings or if a complaint has been raised. We may also anonymise personal data for statistical purposes, in which case it is no longer personal data and may be retained indefinitely.
8. Who We Share Your Data With
8.1 Data Processors
We use the following third-party service providers who process personal data on our behalf under written agreements that comply with UK data protection law:
| Processor | Purpose | Location | Transfer Safeguard |
|---|---|---|---|
| Zoho CRM | Customer relationship management and order administration | European Union (EU data centre) | Data stored within EU — no transfer outside UK/EEA |
| Mailchimp (Intuit Inc.) | Email marketing and communications | United States | Standard Contractual Clauses (SCCs) under UK data protection law |
| CookieYes | Cookie consent management | European Union | Data stored within EU — no transfer outside UK/EEA |
| Stripe / Bank Transfer | Secure online card payment processing (Stripe) and direct bank transfer processing | United States (Stripe) / United Kingdom (bank transfer) | Card payments processed by Stripe (US, SCCs apply). Bank transfers processed directly — no card data stored by BritTherm. |
| Courier and logistics providers | Delivery of goods to your address | United Kingdom | No transfer outside UK |
| Credit reference agencies (B2B only) | Trade account creditworthiness assessment | United Kingdom | No transfer outside UK |
8.2 Other Disclosures
8.2.1 We may share your data with law enforcement authorities, courts or regulatory bodies where required by law or where necessary to protect our legal rights.
8.2.2 If BritTherm is involved in a merger, acquisition or sale of assets, your personal data may be transferred to the relevant third party. We will notify you before your data is subject to a different privacy policy.
8.2.3 We do not sell your personal data to third parties under any circumstances.
9. International Data Transfers
9.1 Mailchimp, our email marketing provider, stores data on servers located in the United States. This constitutes a transfer of personal data outside the United Kingdom. We ensure this transfer is lawfully protected through Standard Contractual Clauses (SCCs) approved under UK data protection law, which provide equivalent safeguards to those available within the UK.
9.2 All other data processors we use store data within the United Kingdom or European Union. No other international transfers of your personal data take place.
9.3 You may request further information about the safeguards in place for international transfers by contacting us at info@brittherm.co.uk.
10. Data Security
10.1 We have implemented appropriate technical and organisational measures to protect your personal data from accidental loss, unauthorised access, alteration or disclosure. These include access controls, encryption, and regular security reviews.
10.2 Access to your personal data is limited to employees, contractors and service providers who have a legitimate business need to access it. All such persons are subject to a duty of confidentiality.
10.3 In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by UK GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
10.4 While we take all reasonable steps to protect your data, no internet transmission is completely secure. We cannot guarantee the security of data transmitted to us electronically and any such transmission is at your own risk.
11. Cookies
Our website uses cookies and similar technologies. Cookie consent on our website is managed through CookieYes, which allows you to accept, reject or customise your cookie preferences at any time.
Under the Privacy and Electronic Communications Regulations (PECR) as amended by the Data (Use and Access) Act 2025:
- Strictly necessary cookies are placed automatically and do not require your consent.
- Analytics cookies used solely to collect aggregate statistics about website performance are exempt from prior consent under the DUAA 2025 (in force from 5 February 2026), but you will be informed about them and can opt out.
- Marketing and advertising cookies require your explicit prior consent.
For full details of the cookies we use, their purposes, retention periods and how to manage your preferences, please refer to our Cookie Policy, accessible via the cookie banner on our website.
12. Your Data Protection Rights
Under UK GDPR and the Data (Use and Access) Act 2025, you have the following rights in relation to your personal data. To exercise any of these rights, please contact us at info@brittherm.co.uk. We will respond within one month of receiving your request.
| Your Right | What It Means |
|---|---|
| Right to be informed | The right to be told how and why we use your personal data — this Privacy Policy fulfils that obligation. |
| Right of access | You can request a copy of the personal data we hold about you (a Data Subject Access Request or DSAR). We will conduct a reasonable and proportionate search of our records. |
| Right to rectification | You can ask us to correct inaccurate or incomplete personal data we hold about you. |
| Right to erasure | You can ask us to delete your personal data where there is no lawful reason for us to continue processing it. This right is not absolute and may be limited by our legal obligations. |
| Right to restrict processing | You can ask us to pause processing of your data in certain circumstances, for example while we verify the accuracy of data you have disputed. |
| Right to data portability | Where we process your data by automated means on the basis of contract or consent, you can ask us to provide your data in a structured, machine-readable format. |
| Right to object | You can object to processing based on legitimate interests, including profiling. We must stop unless we can demonstrate compelling legitimate grounds. You also have an absolute right to object to direct marketing at any time. |
| Rights in relation to automated decision-making | We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. If this changes, we will update this policy and notify you. |
| Right to withdraw consent | Where we process your data on the basis of consent, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. |
13. How to Make a Data Protection Complaint
BritTherm is committed to resolving data protection concerns promptly and fairly. If you have a concern about how we have handled your personal data, please follow the process below.
Step 1 — Contact Us Directly
In the first instance, please contact our data protection team:
- Email: info@brittherm.co.uk
- Post: BritTherm Limited, Unit G 14 Silverbox House, 56 Magnet Road, East Lane Business Park, Wembley, London, HA9 7FP
We will acknowledge your complaint within 30 days of receipt and will investigate your concern thoroughly. We will provide a full response without undue delay and keep you informed of our progress.
Step 2 — Escalate to the ICO
If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: www.ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Making a complaint to the ICO does not affect your right to take legal proceedings in the courts of England and Wales.
14. Credit Reference Searches (Business Customers Only)
14.1 If you apply for a trade account with BritTherm, we may make enquiries with credit reference agencies. Those agencies may provide both public information (including electoral register data and county court judgements) and shared credit and fraud prevention data. A search footprint may be placed on your credit file which may be visible to other lenders.
14.2 We conduct these searches to verify the identity of your organisation and its representatives, to assess creditworthiness, to monitor and manage your trade account, and for debt collection and fraud prevention purposes.
14.3 Credit reference data is processed on the lawful basis of legitimate interests.
15. Third-Party Websites
Our website may contain links to third-party websites. This Privacy Policy does not apply to those websites. We are not responsible for the privacy practices of third parties and recommend that you read the privacy policy of any website you visit.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable law. Where changes are material — particularly where they affect how we use your data or the rights available to you — we will notify you by posting a prominent notice on our website before the changes take effect. The version date at the top of this document confirms when it was last reviewed.