Legal
Privacy Policy
Effective date: 1 September 2026
1. Introduction and Scope
1.1 This Privacy Policy (“Policy”) sets out how Vivian De Vere (“we”, “us”, “our” or the “Controller”) collects, uses, discloses, retains and otherwise processes personal data in connection with our advertising, marketing, brand promotion and related commercial activities conducted across digital platforms and channels, including but not limited to Facebook, Instagram, WhatsApp, Pinterest, Twitter/X, Threads, YouTube, TikTok, and services operated by Meta Platforms, Inc. and Google LLC (collectively, the “Platforms”).
1.2 This Policy applies to all personal data processed by us for the purposes of direct marketing, advertising, audience development, commercial partner eligibility assessments, fraud prevention and reporting, and associated analytics, whether collected directly from individuals (“Data Subjects”) or obtained via the Platforms, third-party partners, or publicly available sources.
1.3 By interacting with our content, advertisements, landing pages, contact forms, or by otherwise providing personal data to us, Data Subjects acknowledge that their data will be processed in accordance with this Policy and applicable law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (as amended), and the Data (Use and Access) Act 2025 (“DUAA”).
2. Controller and Contact Details
2.1 The data controller responsible for your personal data is Vivian De Vere.
2.2 For all privacy-related queries, requests, or complaints, please use our online contact form available on our website. We do not publish direct email addresses or telephone numbers for privacy and security reasons.
2.3 We do not currently appoint a Data Protection Officer (“DPO”). Where required by law, we will update this Policy to reflect the appointment of a DPO and provide appropriate contact details.
3. Personal Data We Process
3.1 We may process the following categories of personal data:
- Identity and contact data: name, postal address, email address, telephone number (where provided via contact form or lead generation).
- Profile and interaction data: social media handles, platform user IDs, follower/following status, content interactions (likes, comments, shares, saves), click-throughs, watch time, story views, and other engagement metrics.
- Device and technical data: IP address, device type, operating system, browser type, advertising IDs (e.g., IDFA, GAID), cookie identifiers, pixel data, SDK data, and approximate or precise location data derived from IP or device settings.
- Analytics and inferred data: audience segments, interests, behavioural patterns, campaign performance metrics, and derived insights used for targeting and optimisation.
- Commercial partner data: where assessing eligibility for partnerships, we may process reputational and financial criteria information (e.g., business name, trading history, public filings, creditworthiness indicators) obtained from commercial partners or public sources.
3.2 We do not knowingly collect special category data (e.g., race, health, religion) unless explicitly provided by a Data Subject and processed under a separate lawful basis.
4. Purposes of Processing and Lawful Bases
4.1 We process personal data for the following purposes:
- Advertising and marketing: to deliver, target, measure, and optimise paid and organic advertising campaigns across the Platforms; to build audience segments; to retarget website visitors and engagers; and to evaluate campaign performance.
- Direct marketing communications: to send promotional emails, newsletters, event invitations, and partnership offers where consent has been obtained or where legitimate interests apply (subject to PECR compliance and the absolute right to object).
- Commercial partner eligibility assessments: to assess potential commercial partners against reputational and financial criteria for collaboration, sponsorship, or co-marketing opportunities.
- Fraud prevention and crime reporting: to detect, investigate, and report suspected fraud, criminal activity, or breaches of terms to relevant authorities where we have a legal obligation or legitimate interest to do so.
- Analytics and business intelligence: to analyse audience behaviour, content performance, and market trends to inform strategy and investment decisions.
4.2 Our lawful bases under Article 6 UK GDPR include:
- Consent (Article 6(1)(a)): where Data Subjects have explicitly consented to specific processing (e.g., email marketing opt-in).
- Legitimate interests (Article 6(1)(f)) and recognised legitimate interests (Article 6(1)(ea) as introduced by DUAA): for direct marketing, intra-group or partner sharing for administrative purposes, network and information security, and analytics, provided such processing is necessary and not overridden by Data Subjects’ rights and freedoms.
- Legal obligation (Article 6(1)(c)): where processing is necessary to comply with applicable law (e.g., fraud reporting, tax, or regulatory requirements).
4.3 Where we rely on legitimate interests, we conduct a balancing test to ensure our interests are not outweighed by Data Subjects’ rights and freedoms. Data Subjects have the right to object to processing based on legitimate interests, including direct marketing, at any time.
5. Data Sharing and Disclosures
5.1 We may share personal data with the following categories of recipients:
- Platform providers: Meta Platforms, Inc., Google LLC, and other Platform operators for the purposes of ad delivery, measurement, audience building, and analytics under their respective terms and data policies.
- Commercial partners and sponsors: where Data Subjects have consented or where we have a legitimate interest, we may share data with brands, agencies, event organisers, and other partners for marketing, sponsorship, or collaboration purposes.
- Service providers: third-party vendors who process data on our behalf (e.g., CRM, email marketing, analytics, cloud hosting) under written data processing agreements compliant with UK GDPR.
- Authorities and regulators: where required by law or where we suspect fraud, criminal activity, or threats to safety, we may disclose data to law enforcement, regulatory bodies, or courts.
5.2 Sale or licensing of data: We reserve the right to sell, license, rent, or otherwise disclose personal data to third parties for direct marketing purposes, subject to applicable law and the requirements of the UK GDPR and PECR. Where data is sold or shared for direct marketing, we will inform Data Subjects and provide an opportunity to opt out.
5.3 We do not sell financial products or services. Any reference to “financial criteria” in this Policy relates solely to assessing the reputational and financial stability of commercial partners, not to offering financial products to consumers.
6. International Transfers
6.1 Personal data may be transferred to, and processed in, countries outside the United Kingdom and the European Economic Area, including the United States, where Platform providers and service providers are located.
6.2 Where transfers occur, we ensure appropriate safeguards are in place, such as:
- Transfers to countries with UK adequacy regulations; or
- Use of UK International Data Transfer Agreements (IDTAs) or approved contractual clauses; or
- Reliance on recognised derogations under UK GDPR where applicable.
7. Data Retention
7.1 We retain personal data only for as long as necessary to fulfil the purposes set out in this Policy, or as required by applicable law.
7.2 Specific retention periods include:
- Marketing and analytics data: retained until Data Subject opts out or objects, or for a period justified by our legitimate interests (e.g., campaign lifecycle, audience modelling).
- Legal and compliance data: retained for the duration required by law (e.g., tax, fraud, or regulatory records).
- Commercial partner data: retained for the duration of the partnership and for a reasonable period thereafter for dispute resolution or compliance.
7.3 Upon expiry of the retention period, data is securely deleted or anonymised in accordance with our data minimisation and security policies.
8. Children’s Data
8.1 Our content and services are intended for adults only. We do not knowingly collect personal data from children under the age of 16, except for aggregated, anonymised metrics that do not identify individuals.
8.2 Where we become aware that personal data of a child under 16 has been collected without parental consent (where required), we will take steps to delete such data promptly, unless retention is required by law or for legitimate safety/fraud prevention purposes in anonymised form.
8.3 In accordance with Article 8 UK GDPR, where we offer information society services directly to children and rely on consent, only children aged 13 or over may provide their own consent; for children under 13, parental consent is required.
9. Data Subject Rights
9.1 Under UK GDPR, Data Subjects have the following rights:
- Right of access: to request a copy of their personal data.
- Right to rectification: to correct inaccurate or incomplete data.
- Right to erasure: to request deletion of data in certain circumstances.
- Right to restrict processing: to limit how we use their data.
- Right to data portability: to receive their data in a structured, commonly used format.
- Right to object: to object to processing based on legitimate interests, including direct marketing (an absolute right).
- Rights related to automated decision-making and profiling: not applicable here, as we do not engage in solely automated decision-making with legal or significant effects; any assessments are subject to human review.
9.2 To exercise these rights, Data Subjects should use our online contact form. We will respond within one month, as required by law.
10. Opt-Out and Marketing Preferences
10.1 Data Subjects may opt out of direct marketing communications at any time by:
- Clicking the “unsubscribe” link in any marketing email; or
- Using our online contact form to request opt-out.
10.2 Upon opt-out, we will cease processing the Data Subject’s personal data for direct marketing purposes, unless required by law for fraud prevention or compliance.
11. Security
11.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption, access controls, and staff training.
11.2 In the event of a personal data breach likely to result in a high risk to Data Subjects, we will notify the Information Commissioner’s Office (“ICO”) and affected individuals where required by law.
12. Changes to This Policy
12.1 We may update this Policy from time to time to reflect changes in law, technology, or our practices. The “Effective date” at the top of this Policy will indicate the most recent revision.
12.2 Material changes will be communicated via our website or other appropriate channels.
13. Complaints and Supervisory Authority
13.1 Data Subjects have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. Contact details:
- Website: www.ico.org.uk
- Helpline: 0300 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.
13.2 We encourage Data Subjects to contact us first via our online contact form to resolve any concerns promptly.
14. Governing Law and Jurisdiction
14.1 This Policy and our data processing practices are governed by the laws of England and Wales and the UK GDPR. Where applicable, EU GDPR may also apply to processing related to EEA Data Subjects.
14.2 Any disputes arising from this Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales, without prejudice to Data Subjects’ rights to seek remedies from supervisory authorities.
For questions or removal requests, please use the enquiry form on The Edit page.