Aura Indigo – Privacy Policy
Last updated: 8 August 2026
This policy explains how Aura Indigo collects, uses and protects your personal data when you visit www.auraindigo.co.uk, buy from us, contact us, or apply to work with us. It also explains your rights under UK data protection law (the UK GDPR and the Data Protection Act 2018).
## 1. Who we are
Aura Indigo is the controller of your personal data. That means we decide how and why it is used.
- Controller – Aura Indigo, Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom
- Email –help@auraindigo.uk
- Phone – 07983 211245
\[If registered with the ICO, add your ICO registration number here. Most businesses processing personal data must pay the ICO data protection fee – check at ico.org.uk/registration.\]
## 2. The personal data we collect
- Identity and contact data – your name, email address, phone number, and account login details
- Order data – billing and delivery address, items purchased, order history, and returns
- Payment data – payments are handled by our payment provider \[e.g. Stripe / PayPal / Shopify Payments\]; we do not store your full card details – we see only confirmation of payment and, where needed, partial card information for refunds
- Correspondence – what you tell us when you email, call or message us
- Technical and usage data – IP address, browser type and version, device type, operating system, time zone, and how you navigate our website, collected via cookies and similar technologies (see section 5)
- Marketing preferences – your preferences for receiving marketing from us
- Job applicant and staff data – if you apply to work with us or work for us, the information you provide for recruitment and HR purposes
We do not knowingly collect special category data (such as health or religious information) and ask that you do not send it to us.
## 3. How and why we use your data
UK GDPR requires us to have a lawful basis for everything we do with your personal data. These are set out below.
- Processing and delivering your order, taking payment, and handling returns or refunds. Lawful basis: Performance of a contract with you. Data used: identity, contact, order, payment.
- Managing your account and responding to enquiries. Lawful basis: Performance of a contract; legitimate interests (customer service). Data used: identity, contact, order.
- Sending order confirmations, dispatch updates and service messages. Lawful basis: Performance of a contract. Data used: identity, contact, order.
- Sending marketing emails about our products and offers. Lawful basis: Consent (or the “soft opt-in” for existing customers, with an unsubscribe option in every message). Data used: identity, contact, marketing preferences.
- Online advertising and remarketing. Lawful basis: Consent. Data used: technical, usage (via advertising cookies).
- Website analytics and improving our Service. Lawful basis: Consent (for analytics cookies); legitimate interests (aggregated, essential analytics). Data used: technical, usage.
- Keeping our website and customers secure, and preventing fraud. Lawful basis: Legitimate interests (security and fraud prevention). Data used: identity, technical, order.
- Keeping accounting and tax records. Lawful basis: Legal obligation. Data used: identity, order, payment.
- Recruitment and HR administration. Lawful basis: Legitimate interests; legal obligation; performance of a contract. Data used: applicant/staff data.
Where we rely on legitimate interests, we have balanced those interests against your rights and will not use your data where the impact on you outweighs our interest. You can ask us for details of these assessments.
## 4. Marketing
We only send you marketing emails if you have opted in, or if you are an existing customer and we are telling you about similar products (the “soft opt-in”), in which case you were given the chance to opt out when we collected your details. Every marketing email contains an unsubscribe link, and you can also opt out at any time by emailing us. Opting out does not affect service messages such as order confirmations.
## 5. Cookies
We use cookies and similar technologies on our website. Strictly necessary cookies (for example, those that keep your basket working or keep you logged in) are set without consent because the site cannot function without them. All other cookies – including analytics and advertising/remarketing cookies – are set only if you consent through our cookie banner. You can change or withdraw your cookie choices at any time via \[link to cookie settings\] and can also block cookies in your browser settings, though this may affect site functionality.
The cookies we use are: \[list your cookies here, e.g. Google Analytics, Meta Pixel, with names, purposes and durations – your cookie banner tool can usually generate this list\].
## 6. Who we share your data with
We do not sell your personal data. We share it only with:
- service providers who process data on our behalf under written contracts, including our website/e-commerce platform \[e.g. Shopify\], payment provider \[e.g. Stripe / PayPal\], delivery couriers \[e.g. Royal Mail / Evri\], email provider, and marketing/analytics tools \[list them\]
- professional advisers such as accountants, lawyers and insurers, where necessary
- HMRC, regulators and law enforcement, where we are legally required to do so
- a buyer or prospective buyer if we sell or restructure our business – the new owner may use your data only in the ways set out in this policy
## 7. International transfers
Some of our service providers store or process data outside the UK. Where they do, we make sure an equivalent level of protection applies, either because the destination country has a UK adequacy decision, or through approved safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. You can contact us for details of the safeguards used.
## 8. How long we keep your data
We keep personal data only for as long as we need it for the purposes described above, then delete or anonymise it. Our standard retention periods are:
- Order and transaction records – 6 years from the end of the tax year, to meet HMRC requirements
- Customer account data – While your account is active, then \[e.g. 2 years\] after your last order or login
- Marketing list data – Until you unsubscribe or \[e.g. 2 years\] of inactivity
- Customer service correspondence – \[e.g. 2 years\] from resolution of your query
- Unsuccessful job applicant data – \[e.g. 6 months\] after the recruitment process ends
- Website analytics data – \[e.g. 14 months\], as configured in our analytics tool
## 9. Your rights
Under UK GDPR you have the right to:
- Access – ask for a copy of the personal data we hold about you
- Rectification – ask us to correct inaccurate or incomplete data
- Erasure – ask us to delete your data (the “right to be forgotten”)
- Restriction – ask us to limit how we use your data in certain circumstances
- Portability – receive the data you gave us in a machine-readable format, or have it sent to another provider
- Objection – object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent – withdraw any consent you have given, at any time, without affecting processing already carried out
- Automated decisions – not be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions)
To exercise any of these rights, email us at help@auraindigo.uk. We will respond within one month (extendable by two further months for complex requests, in which case we will tell you). Exercising your rights is free of charge, though we may ask you to verify your identity first.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator: ico.org.uk, or 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to resolve your concern first, so please contact us before going to the ICO if you can.
## 10. Security
We use appropriate technical and organisational measures to protect your personal data, including encryption of our website traffic (HTTPS), access controls limiting who can see customer data, and reputable third-party providers for payments and hosting. If a personal data breach occurs that risks your rights and freedoms, we will notify the ICO within 72 hours and, where the risk is high, we will tell you directly.
## 11. Children
Our Service is not aimed at children, and we do not knowingly collect personal data from anyone under 13, the age at which children in the UK can consent to online services in their own right. If you believe a child has provided us with personal data, please contact us and we will delete it.
## 12. Third-party links
Our website may link to other websites we do not control. This policy applies only to our Service; other sites have their own privacy policies, which we encourage you to read.
## 13. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new “last updated” date, and if the changes significantly affect you we will notify you (for example by email) before they take effect.