Privacy Policy
This policy explains what personal data we collect, why we collect it, how we protect it, and your rights under UK data protection law. Awareverse is committed to handling your data with care and transparency.
🏢 Who We Are
Awareverse is a UK sole trader business providing peer-led support, sensory products, digital resources, and safeguarding awareness services for neurodivergent families and vulnerable individuals.
📦 What Data We Collect
Order and Purchase Data
- Items purchased, order value, and timestamps
- Delivery name and address (physical orders only)
- Payment confirmation from our processor — we never store full card details
- Order history and transaction records
Contact and Account Data
- Name or alias provided when creating an account or contacting us
- Email address
- Support communications and our responses
Website Analytics Data
- Usage data, pages visited, and session information — only if you consent to analytics cookies
- Device type and browser information for technical optimisation
Safeguarding and Peer Support Data
Important: When someone contacts Awareverse through our safeguarding or peer support channels, we collect and handle this data differently to all other data.
- Any name or alias provided — real names are never required
- Broad area or location provided — used only to route referrals correctly
- The nature of the concern — which may include sensitive personal data relating to harm or abuse
- Contact method provided — which may be an anonymous email address
- Any coded communication received through the Awareverse coded system
- Records of referrals made to statutory services on your behalf
- Records of any consent given for Awareverse to advocate on your behalf
⚖️ How We Use Your Data and Our Legal Basis
| Purpose | Legal Basis |
|---|---|
| Processing and fulfilling orders | Contract performance |
| Providing peer support and safeguarding signposting | Legitimate interests / Vital interests where life is at risk |
| Making safeguarding referrals to statutory agencies | Legal obligation and Vital interests |
| Fraud prevention and website security | Legitimate interests |
| Responding to enquiries and support requests | Legitimate interests |
| Marketing communications | Consent — opt-in only, withdraw any time |
| Analytics and website improvement | Consent — via cookie preferences |
| Tax, accounting and legal compliance | Legal obligation |
🔒 Safeguarding Data — Special Handling
Data received through safeguarding and peer support channels is subject to additional protections and specific rules:
Confidentiality is not absolute in safeguarding. If information received indicates that a child or vulnerable adult is at risk of significant harm, Awareverse has a responsibility to share that information with the appropriate statutory service — regardless of whether the person has asked us to keep it confidential. We will always tell you what we are doing and why.
- Safeguarding records are stored separately from all other Awareverse data
- Access is restricted to the Designated Safeguarding Lead only
- Records are retained for a minimum of seven years in line with safeguarding best practice
- Data is never used for any commercial purpose
- Referrals to statutory agencies share only the minimum information necessary
- Anonymous or partial disclosures are still logged and referred where appropriate
🤝 Who We Share Data With
We only share data when necessary to provide our services or meet legal obligations:
- Payment processors — for secure transaction processing
- Delivery partners — for physical order fulfilment
- Email service providers — for order confirmations and support
- Website hosting providers — for technical service provision
- Analytics providers — only if you consent to tracking cookies
- Statutory safeguarding agencies — local authority children's services, adult safeguarding teams, NSPCC, or police where a safeguarding concern requires referral
- Emergency services — where there is immediate risk to life
We never sell your data. We never share data for advertising or marketing purposes without your explicit consent.
🗓️ How Long We Keep Your Data
| Data Type | Retention Period |
|---|---|
| Order records | 7 years — tax and accounting requirements |
| Support communications | 3 years from resolution |
| Safeguarding records | Minimum 7 years from date of concern |
| Marketing consent records | Until you withdraw consent |
| Analytics data | As configured in analytics tools |
| Account data | Until account deletion is requested |
🛡️ Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion, subject to legal retention requirements
- Restriction — limit how we process your data in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Object — oppose processing based on legitimate interests
- Withdraw consent — for any consent-based processing at any time
Please note: Safeguarding records may be exempt from some of these rights where disclosure would prejudice the prevention or detection of crime or the apprehension of offenders, or where it would place a child or vulnerable adult at risk.
To exercise any of your rights, contact us at legal@awareverse.co.uk. We will respond within 30 days as required by UK GDPR.
🔐 Security
We use technical and organisational measures appropriate to the risk level of the data we hold, including encrypted storage, secure hosting, access controls, and separate storage for sensitive safeguarding data. No method of transmission or storage is completely secure, but we take all reasonable steps to protect your information.
🌍 International Transfers
Some of our service providers may be based outside the UK. Where this occurs, we ensure adequate safeguards are in place including standard contractual clauses or adequacy decisions recognised by the UK Information Commissioner's Office.
👶 Children's Privacy
Awareverse serves neurodivergent families including children. We do not knowingly collect personal data directly from children under 13 without parental or guardian consent for general platform use. Our safeguarding function may receive contacts from children — this data is handled under our Safeguarding Policy and peer support framework with additional protections in place. If you are a parent or guardian and are concerned about data relating to your child, please contact safeguarding@awareverse.co.uk.
🍪 Cookies
Our use of cookies is covered in our separate Cookie Policy. You can manage your cookie preferences at any time through our cookie settings.
📝 Changes to This Policy
We may update this policy periodically. Material changes will be notified via email or a prominent notice on the website. The date at the top of this page always reflects the most recent update.
📬 Contact and Complaints
You also have the right to complain to the Information Commissioner's Office (ICO) at any time if you are unhappy with how we handle your personal data.