Privacy Policy

BRITTHERM LIMITED

Version: April 2026

This policy explains clearly and honestly how BritTherm Limited collects, uses and protects your personal data. It applies to all customers and visitors, whether you purchase through our website, by phone or email, or through a marketplace such as Amazon or eBay.

1. Who We Are and How to Contact Us

BritTherm Limited is the data controller responsible for your personal data.

  • Company name: BritTherm Limited
  • Company registration number: 11400625
  • Registered office: Unit G 14 Silverbox House, 56 Magnet Road, East Lane Business Park, Wembley, London, HA9 7FP
  • Data protection contact: info@brittherm.co.uk
  • Telephone: +44 (0)20 8904 4832
  • ICO registration number: ZC115745 — BritTherm Limited is registered as a data controller with the Information Commissioner's Office.

If you have any questions about how we use your personal data, or if you wish to exercise any of your rights, please contact us at info@brittherm.co.uk.

2. Important Information

2.1 This policy applies to personal data collected from individuals who: visit our website at www.brittherm.co.uk; purchase goods from us directly or through a marketplace such as Amazon or eBay; contact us by telephone, email or post; or register a product guarantee with us.

2.2 Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data relating to a child, please contact us immediately at info@brittherm.co.uk.

2.3 Where you purchase BritTherm products through third-party sellers, authorised stockists, distributors or online platforms including Amazon, BritTherm may receive limited personal data from those third parties solely for the purposes of warranty registration, customer support or order fulfilment. BritTherm does not control or process wider customer data held by those third parties.

2.4 We may update this policy from time to time to reflect changes in our data practices or the law. We will notify you of any material changes by posting a prominent notice on our website. The date at the top of this policy shows when it was last updated. We recommend you check this policy periodically.

3. What Personal Data We Collect

We collect and process the following categories of personal data:

Category What It Includes
Identity DataFirst name, last name, title, company name (for business customers)
Contact DataBilling address, delivery address, email address, telephone number
Transaction DataDetails of goods you have ordered or purchased, order history, invoices
Financial DataPayment method type only. Where you pay by card online, payment is processed securely by Stripe and card details are never stored by BritTherm. Where payment is made by bank transfer, only transaction reference data is retained.
Warranty Registration DataName, installation address, date of purchase and installation, pump part number, supplier name, invoice number
Technical DataIP address, browser type and version, device type, operating system, time zone, pages visited, referral source, session duration, cookie identifiers
Communications DataRecords of your enquiries, complaints, and correspondence with us
Marketing PreferencesYour preferences for receiving marketing from us and your unsubscribe history
Credit Data (B2B only)Information obtained from credit reference agencies for trade account applications
We do not collect any special category data, including information about race or ethnicity, religious beliefs, health, genetic or biometric data, political opinions, trade union membership, or sexual orientation. We do not collect information about criminal convictions or offences.

4. How We Collect Your Data

4.1 Directly From You

We collect data directly from you when you:

  • Place an order on our website, by phone or by email
  • Create an account on our website
  • Register a product guarantee online or by email
  • Contact us with an enquiry or complaint
  • Sign up to receive marketing communications
  • Apply for a trade account

4.2 Automatically

When you visit our website, we automatically collect Technical Data through cookies and similar technologies. Please refer to our Cookie Policy (managed through CookieYes) for full details of the cookies we use, their purposes, and how to manage your preferences.

4.3 From Third Parties

We may receive personal data from:

  • Amazon, eBay and other marketplaces — where you purchase our products through those platforms, they may share limited order and contact information with us for fulfilment and after-sales support purposes
  • Credit reference agencies — for trade account applications from business customers
  • Authorised distributors and stockists — where you have purchased a product through one of our trade partners and subsequently contact us for warranty or support purposes

5. How We Use Your Data and Our Lawful Basis

UK GDPR requires us to have a lawful basis for every use of your personal data. The table below sets out each processing activity, the data used, and the lawful basis we rely on.

Purpose / Processing Activity Data Used Lawful Basis
Process and fulfil your order, including dispatch and deliveryIdentity, Contact, TransactionContract performance
Process payment for your orderFinancial, TransactionContract performance
Send order confirmation, dispatch notification and delivery updatesIdentity, Contact, TransactionContract performance
Manage your website accountIdentity, ContactContract performance
Respond to your enquiries, questions and complaintsIdentity, Contact, CommunicationsLegitimate interests — to manage our customer relationships effectively
Administer and process product guarantee registrations and claimsIdentity, Contact, Warranty Registration, TransactionLegitimate interests — to administer our guarantee scheme and verify claims
Send essential service communications (e.g. warranty confirmations, safety notices, order updates)Identity, ContactContract performance / Legitimate interests
Send marketing communications to existing customers about similar products and servicesIdentity, Contact, Marketing PreferencesLegitimate interests — direct marketing to existing customers who have not opted out
Send marketing communications to customers who have opted inIdentity, Contact, Marketing PreferencesConsent
Improve and analyse website performance and user experienceTechnicalLegitimate interests — to maintain and improve our digital services
Prevent fraud, protect security and verify identityIdentity, Contact, Technical, TransactionLegitimate interests — to protect our business and customers
Conduct credit reference searches for trade account applicationsIdentity, Contact, Credit DataLegitimate interests — to assess creditworthiness for B2B trade accounts
Comply with legal and regulatory obligations (including HMRC, financial record-keeping)Identity, Contact, Transaction, FinancialLegal obligation
Transfer of business — sharing data with a prospective buyer or successorIdentity, Contact, TransactionLegitimate interests — in the context of a business sale or transfer
Where we rely on legitimate interests as our lawful basis, we have assessed that our interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests — see Section 9 for details.

6. Marketing

6.1 We may send you marketing communications about our products, services and promotions by email. We will only do so where: (a) you are an existing customer and we are marketing similar products or services and you have not opted out; or (b) you have given us your explicit consent to receive marketing.

6.2 We will never share your personal data with third parties for their own marketing purposes.

6.3 You can opt out of marketing communications at any time by: clicking the unsubscribe link in any email we send you; or emailing us at info@brittherm.co.uk. Opting out of marketing will not affect your receipt of essential service communications such as order confirmations, warranty information or safety notices.

6.4 Our marketing emails are sent via Mailchimp, which uses tracking pixels to record whether emails have been opened and which links have been clicked. This data is used to measure the effectiveness of our communications and improve what we send you. This tracking is disclosed in our Cookie Policy and you may opt out by contacting us at info@brittherm.co.uk.

7. How Long We Keep Your Data

We will only retain your personal data for as long as is necessary for the purposes set out in this policy. The table below sets out our specific retention periods.

Category of Data Retention Period Reason
Order and transaction records7 years from the date of the transactionHMRC statutory requirement for financial records
Customer account dataDuration of your account plus 6 years after closureLimitation Act 1980 — contractual claims period
Warranty registration dataDuration of the applicable guarantee period plus 2 yearsTo administer guarantee claims and defend potential disputes
Marketing contact dataUntil you unsubscribe, plus 12 monthsTo honour opt-out requests and maintain suppression lists
B2B trade account and credit dataDuration of the account plus 6 yearsContractual and credit management purposes
Enquiry and complaint records3 years from resolutionTo defend potential legal claims
Website analytics data13 months from collectionStandard analytics retention period
Data breach records (internal)5 years from the incidentICO regulatory requirement

In some circumstances we may retain data for longer, for example if we are involved in legal proceedings or if a complaint has been raised. We may also anonymise personal data for statistical purposes, in which case it is no longer personal data and may be retained indefinitely.

8. Who We Share Your Data With

8.1 Data Processors

We use the following third-party service providers who process personal data on our behalf under written agreements that comply with UK data protection law:

Processor Purpose Location Transfer Safeguard
Zoho CRM Customer relationship management and order administration European Union (EU data centre) Data stored within EU — no transfer outside UK/EEA
Mailchimp (Intuit Inc.) Email marketing and communications United States Standard Contractual Clauses (SCCs) under UK data protection law
CookieYes Cookie consent management European Union Data stored within EU — no transfer outside UK/EEA
Stripe / Bank Transfer Secure online card payment processing (Stripe) and direct bank transfer processing United States (Stripe) / United Kingdom (bank transfer) Card payments processed by Stripe (US, SCCs apply). Bank transfers processed directly — no card data stored by BritTherm.
Courier and logistics providers Delivery of goods to your address United Kingdom No transfer outside UK
Credit reference agencies (B2B only) Trade account creditworthiness assessment United Kingdom No transfer outside UK

8.2 Other Disclosures

8.2.1 We may share your data with law enforcement authorities, courts or regulatory bodies where required by law or where necessary to protect our legal rights.

8.2.2 If BritTherm is involved in a merger, acquisition or sale of assets, your personal data may be transferred to the relevant third party. We will notify you before your data is subject to a different privacy policy.

8.2.3 We do not sell your personal data to third parties under any circumstances.

9. International Data Transfers

9.1 Mailchimp, our email marketing provider, stores data on servers located in the United States. This constitutes a transfer of personal data outside the United Kingdom. We ensure this transfer is lawfully protected through Standard Contractual Clauses (SCCs) approved under UK data protection law, which provide equivalent safeguards to those available within the UK.

9.2 All other data processors we use store data within the United Kingdom or European Union. No other international transfers of your personal data take place.

9.3 You may request further information about the safeguards in place for international transfers by contacting us at info@brittherm.co.uk.

10. Data Security

10.1 We have implemented appropriate technical and organisational measures to protect your personal data from accidental loss, unauthorised access, alteration or disclosure. These include access controls, encryption, and regular security reviews.

10.2 Access to your personal data is limited to employees, contractors and service providers who have a legitimate business need to access it. All such persons are subject to a duty of confidentiality.

10.3 In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by UK GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

10.4 While we take all reasonable steps to protect your data, no internet transmission is completely secure. We cannot guarantee the security of data transmitted to us electronically and any such transmission is at your own risk.

11. Cookies

Our website uses cookies and similar technologies. Cookie consent on our website is managed through CookieYes, which allows you to accept, reject or customise your cookie preferences at any time.

Under the Privacy and Electronic Communications Regulations (PECR) as amended by the Data (Use and Access) Act 2025:

  • Strictly necessary cookies are placed automatically and do not require your consent.
  • Analytics cookies used solely to collect aggregate statistics about website performance are exempt from prior consent under the DUAA 2025 (in force from 5 February 2026), but you will be informed about them and can opt out.
  • Marketing and advertising cookies require your explicit prior consent.

For full details of the cookies we use, their purposes, retention periods and how to manage your preferences, please refer to our Cookie Policy, accessible via the cookie banner on our website.

12. Your Data Protection Rights

Under UK GDPR and the Data (Use and Access) Act 2025, you have the following rights in relation to your personal data. To exercise any of these rights, please contact us at info@brittherm.co.uk. We will respond within one month of receiving your request.

Your Right What It Means
Right to be informedThe right to be told how and why we use your personal data — this Privacy Policy fulfils that obligation.
Right of accessYou can request a copy of the personal data we hold about you (a Data Subject Access Request or DSAR). We will conduct a reasonable and proportionate search of our records.
Right to rectificationYou can ask us to correct inaccurate or incomplete personal data we hold about you.
Right to erasureYou can ask us to delete your personal data where there is no lawful reason for us to continue processing it. This right is not absolute and may be limited by our legal obligations.
Right to restrict processingYou can ask us to pause processing of your data in certain circumstances, for example while we verify the accuracy of data you have disputed.
Right to data portabilityWhere we process your data by automated means on the basis of contract or consent, you can ask us to provide your data in a structured, machine-readable format.
Right to objectYou can object to processing based on legitimate interests, including profiling. We must stop unless we can demonstrate compelling legitimate grounds. You also have an absolute right to object to direct marketing at any time.
Rights in relation to automated decision-makingWe do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. If this changes, we will update this policy and notify you.
Right to withdraw consentWhere we process your data on the basis of consent, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
You will not usually be charged for exercising your rights. However, if a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline to act. We will always explain our reasons if we cannot fulfil a request.

13. How to Make a Data Protection Complaint

BritTherm is committed to resolving data protection concerns promptly and fairly. If you have a concern about how we have handled your personal data, please follow the process below.

Step 1 — Contact Us Directly

In the first instance, please contact our data protection team:

  • Email: info@brittherm.co.uk
  • Post: BritTherm Limited, Unit G 14 Silverbox House, 56 Magnet Road, East Lane Business Park, Wembley, London, HA9 7FP

We will acknowledge your complaint within 30 days of receipt and will investigate your concern thoroughly. We will provide a full response without undue delay and keep you informed of our progress.

Step 2 — Escalate to the ICO

If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: www.ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Making a complaint to the ICO does not affect your right to take legal proceedings in the courts of England and Wales.

14. Credit Reference Searches (Business Customers Only)

This section applies to Business Customers applying for a trade account only. It does not apply to consumers purchasing through the website.

14.1 If you apply for a trade account with BritTherm, we may make enquiries with credit reference agencies. Those agencies may provide both public information (including electoral register data and county court judgements) and shared credit and fraud prevention data. A search footprint may be placed on your credit file which may be visible to other lenders.

14.2 We conduct these searches to verify the identity of your organisation and its representatives, to assess creditworthiness, to monitor and manage your trade account, and for debt collection and fraud prevention purposes.

14.3 Credit reference data is processed on the lawful basis of legitimate interests.

15. Third-Party Websites

Our website may contain links to third-party websites. This Privacy Policy does not apply to those websites. We are not responsible for the privacy practices of third parties and recommend that you read the privacy policy of any website you visit.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable law. Where changes are material — particularly where they affect how we use your data or the rights available to you — we will notify you by posting a prominent notice on our website before the changes take effect. The version date at the top of this document confirms when it was last reviewed.