Data Subject Rights & GDPR Compliance Policy
(Last updated: 12 May 2026)
Data Controller: Black Tulip Retail Ltd | ICO Registration No: ZC144582
Data Protection Contact: Sumit Joshan | customercare@blacktulipstudio.com
EU Representative (Art. 27 EU GDPR): Sumit Joshan | customercare@blacktulipstudio.com
This policy covers rights under UK GDPR (UK customers) and EU GDPR (EU/EEA customers).
Registered trade marks: 'Black Tulip' and 'Black Tulip Studio' are registered trade marks of Black Tulip Retail Ltd (UK IPO).
1. Legal Framework
Black Tulip Retail Ltd is committed to processing personal data lawfully and transparently in accordance with:
- The UK General Data Protection Regulation (UK GDPR), as retained in UK law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018 (DPA 2018)
- The EU General Data Protection Regulation (EU GDPR 2016/679), which applies to our processing of personal data of individuals in the European Union and EEA by virtue of Article 3(2) EU GDPR (we offer goods to EU data subjects and monitor their behaviour via cookies and advertising pixels)
- The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), as amended, governing our use of cookies and electronic marketing in the UK
- The EU ePrivacy Directive 2002/58/EC as implemented in relevant EU member states, governing our use of cookies and electronic marketing for EU/EEA customers
- Guidance issued by the Information Commissioner's Office (ICO) (UK) and the European Data Protection Board (EDPB) (EU)
Where we rely on legitimate interests (Article 6(1)(f) UK GDPR and EU GDPR), we have conducted and documented Legitimate Interests Assessments (LIAs) as required by ICO and EDPB guidance. LIAs balance our business interests against data subjects' rights and freedoms. Copies are available on request.
As we sell to EU/EEA customers and have no EU establishment, we have appointed an EU representative under Article 27 EU GDPR. Details are in our Privacy Policy and at the top of this document.
2. Your Rights as a Data Subject
UK GDPR and EU GDPR grant substantively identical rights. We honour these rights for all customers regardless of their country of residence. The applicable supervisory authority varies (see Section 8).
2.1 Right of Access (Article 15 UK GDPR / Article 15 EU GDPR)
You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data together with supplementary information about: the purposes of processing; the categories of data; the recipients; the retention period; and the existence of your other rights. This is a Subject Access Request (SAR).
We will respond within one calendar month of a valid request. Where requests are complex or numerous, we may extend by a further two months (three months total) and will notify you within the first month, as permitted by Article 12(3) UK GDPR / EU GDPR.
We will not charge a fee unless a request is manifestly unfounded or excessive (Article 12(5) UK GDPR / EU GDPR), in which case we may charge a reasonable fee or refuse.
2.2 Right to Rectification (Article 16 UK GDPR / Article 16 EU GDPR)
You have the right to ask us to correct personal data that is inaccurate or to complete data that is incomplete, having regard to the purpose of the processing. We will act within one calendar month.
2.3 Right to Erasure – 'Right to be Forgotten' (Article 17 UK GDPR / Article 17 EU GDPR)
You have the right to request deletion of your personal data where:
- The data is no longer necessary for the purpose for which it was collected
- You withdraw consent and there is no other lawful basis
- You object under Article 21 and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
This right is not absolute. We may refuse or limit erasure where we have a legal obligation to retain data – for example, financial records required by HMRC and the Companies Act 2006, which we must retain for six years. We will explain clearly if this is the case.
2.4 Right to Restriction of Processing (Article 18 UK GDPR / Article 18 EU GDPR)
You have the right to ask us to restrict processing in the following circumstances:
- You contest the accuracy of the data (restriction applies while we verify it)
- The processing is unlawful but you prefer restriction over erasure
- We no longer need the data but you require it for a legal claim
- You have objected under Article 21 and we are assessing whether our legitimate grounds override yours
Where processing is restricted, we will store but not otherwise process the data without your consent, except to establish, exercise, or defend legal claims.
2.5 Right to Data Portability (Article 20 UK GDPR / Article 20 EU GDPR)
Where we process your personal data by automated means on the basis of your consent or a contract, you have the right to receive that data in a structured, commonly used, machine-readable format (such as CSV), and to request direct transmission to another controller where technically feasible. This right covers data you have provided to us directly – it does not cover derived or inferred data.
2.6 Right to Object (Article 21 UK GDPR / Article 21 EU GDPR)
You have the right to object to processing based on legitimate interests (Article 6(1)(f)). We must cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for legal claims.
Where you object to direct marketing (including profiling for marketing purposes), we will cease processing immediately and unconditionally. There are no exceptions to this rule.
2.7 Rights Related to Automated Decision-Making (Article 22 UK GDPR / Article 22 EU GDPR)
We do not make decisions about you based solely on automated processing (with no human involvement) that produce legal or similarly significant effects. If this changes, we will update this policy and notify affected individuals in advance.
2.8 Right to Withdraw Consent
Where we rely on consent as our lawful basis, you may withdraw it at any time without affecting the lawfulness of prior processing:
- Email marketing: click 'Unsubscribe' in any marketing email, or email customercare@blacktulipstudio.com
- WhatsApp marketing: reply STOP to any marketing message, or email customercare@blacktulipstudio.com
- Non-essential cookies: click 'Cookie Settings' at the bottom of any page on our Site
3. How to Exercise Your Rights
Submit your request by any of the following methods:
- Email: customercare@blacktulipstudio.com (subject: 'Data Rights Request')
- Post: Data Protection Contact, Black Tulip Retail Ltd, 1st Floor Kirkland House, 11–15 Peterborough Road, Harrow, Middlesex, HA1 2AX
To process your request efficiently, please state which right(s) you are exercising and provide sufficient information to identify you (for example, the email address associated with your account). Where we have reasonable doubt about your identity, we may request additional verification before proceeding, as permitted by Article 12(6) UK GDPR / EU GDPR.
We will not charge a fee unless the request is manifestly unfounded or excessive. We will respond within one calendar month. If we cannot fulfil your request, we will explain why and inform you of your right to complain to the relevant supervisory authority.
4. Data Processing Agreements (Article 28 UK GDPR / Article 28 EU GDPR)
All third parties that process personal data on our behalf ('data processors') are engaged under written Data Processing Agreements (DPAs) as required by Article 28 UK GDPR and Article 28 EU GDPR. These processors may only process personal data on our documented instructions.
Our current processors include:
- Shopify Ltd – website platform and payment processing (DPA at https://www.shopify.com/legal/dpa)
- Klarna Bank AB (UK branch) – buy now/pay later payments (DPA via merchant agreement)
- WATI / Nametag Inc. – WhatsApp Business messaging (DPA via platform terms)
- instant.ai – email marketing (DPA via platform terms)
- Google LLC – Google Analytics 4 and Google Ads (DPA via Google's data processing terms)
- Meta Platforms Ireland Ltd – Meta Pixel and advertising (DPA via Meta Business Tools terms)
- Pinterest Europe Ltd – Pinterest advertising (DPA via Pinterest advertising terms)
- Microsoft Corporation – Microsoft Clarity (DPA via Microsoft's privacy terms)
- Royal Mail Group Ltd and DPD Group – delivery and logistics (DPA via carrier agreements)
5. Records of Processing Activities (Article 30 UK GDPR / Article 30 EU GDPR)
We maintain a written Record of Processing Activities (ROPA) as required by Article 30 UK GDPR and Article 30 EU GDPR. The ROPA records: the controller identity; purposes of each processing activity; categories of data subjects and data; recipients; third-country transfers and safeguards; and retention periods. The ROPA is available to the ICO and relevant EU supervisory authorities on request.
6. Privacy by Design and Data Minimisation (Article 25 UK GDPR / Article 25 EU GDPR)
In accordance with Article 25, we apply privacy by design and data minimisation: we collect only the data necessary for each specific purpose, consider data protection implications when introducing new products or systems, and implement appropriate technical and organisational measures from the outset.
7. Personal Data Breach Notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO (UK customers) and/or the relevant EU lead supervisory authority (EU/EEA customers) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by Article 33 UK GDPR and Article 33 EU GDPR.
Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will also notify those individuals directly without undue delay, as required by Article 34 UK GDPR and Article 34 EU GDPR.
8. Your Right to Complain to a Supervisory Authority
UK customers – Information Commissioner's Office (ICO)
Website: www.ico.org.uk | Tel: 0303 123 1113
Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
EU/EEA customers – your local Data Protection Authority (DPA)
Full list of EU supervisory authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en
You may complain to the authority in the member state where you live, work, or where the alleged infringement occurred.
We ask that you contact us first so we have the opportunity to resolve your concern.
9. Changes to This Policy
We may update this policy to reflect changes in law, regulatory guidance, or our practices. Material changes will be communicated to affected individuals by email before they take effect. The current version is always available on our Site.
10. Contact
- Email: customercare@blacktulipstudio.com (subject: 'Data Rights Request')
- Post: Black Tulip Retail Ltd, 1st Floor Kirkland House, 11–15 Peterborough Road, Harrow, Middlesex, HA1 2AX, United Kingdom
- EU Representative: Black Tulip Retail Ltd, 1st Floor Kirkland House, 11–15 Peterborough Road, Harrow, Middlesex, HA1 2AX, United Kingdom















