Privacy Policy
Last updated: 24 June 2026
Page title: Privacy Policy · Shopify slug: privacy-policy
ORVIAN ("we", "us", "our") is committed to handling your personal data with the utmost care and transparency. This Privacy Policy explains which personal data we gather, for what purposes, and how it is managed. The applicable legal frameworks are the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) and the Data Protection Act 2018.
1. Data Controller
The data controller within the meaning of the UK GDPR is the operator of orvian.com. For questions concerning this policy or the processing of your personal data, please write to us at contact@orvian.com. Full provider details are available on our Legal Notice page.
2. Types of Data We Process
When you place an order or get in touch with us, we handle the following categories of data:
- First and last name, together with email address
- Delivery and billing address
- Telephone number (optional — used solely for delivery status notifications)
- Payment details (managed securely by our payment partners — card data is never stored by us)
- Order and purchase history
- Technical data about your device and browsing activity (IP address, browser type, pages visited)
3. Purposes of Processing and Legal Bases
- Fulfilment of orders — name, address, email and payment particulars are necessary to carry out the purchase contract concluded with you (Art. 6(1)(b) UK GDPR).
- Buyer communications — order confirmations, despatch notifications and replies to service enquiries (Art. 6(1)(b) UK GDPR).
- Improvement of our offering — usage analytics enable us to refine our website on an ongoing basis (Art. 6(1)(f) UK GDPR — legitimate interest).
- Compliance with statutory obligations — business records are retained in line with applicable tax and commercial law (Art. 6(1)(c) UK GDPR).
4. Payment Processing
All transactions are handled by our payment partners (including Stripe, PayPal, Klarna and Viva Wallet), all of whom hold PCI DSS Level 1 certification. Card details are entered directly within their secure environments — the full card number, CVV and expiry date are at no stage accessible to or stored by ORVIAN.
5. Data Retention Period
Order-related data is retained for between 6 and 10 years in accordance with UK tax and accounting legislation (notably HMRC requirements and the Companies Act 2006). Marketing preferences are held until you opt out. Data no longer required for its original purpose is deleted or anonymised without delay.
6. Recipients of the Data
Personal data is shared with third parties only to the extent necessary to fulfil your order:
- Logistics providers (e.g. Royal Mail, DHL, DPD, Evri, UPS) for the delivery of goods
- Payment partners for the secure processing of transactions
- Email service providers for transactional correspondence
- Hosting companies for the technical operation of the website
- Accountants and legal advisers, where required to meet legal obligations
Data processing agreements in accordance with Art. 28 UK GDPR have been put in place with all our processors.
7. Data Transfers to Third Countries
Transfers of personal data to countries outside the United Kingdom or the European Economic Area (EEA) occur only where an adequacy decision is in force, or where suitable safeguards — such as Standard Contractual Clauses approved by the UK or EU Commission — are in place under Art. 45 ff. UK GDPR.
8. Cookies and Tracking
Our website makes use of cookies and similar technologies. Further details are provided in our Cookie Policy. Non-essential cookies may be declined or adjusted at any time via the cookie banner or your browser settings.
9. Your Rights as a Data Subject
You hold the following rights in relation to your personal data:
- Right of access (Art. 15 UK GDPR) — you may request details of the data we hold about you
- Right to rectification (Art. 16 UK GDPR) — inaccurate data may be corrected
- Right to erasure (Art. 17 UK GDPR) — subject to any applicable legal retention obligations
- Right to restriction of processing (Art. 18 UK GDPR)
- Right to data portability (Art. 20 UK GDPR)
- Right to object (Art. 21 UK GDPR) — to processing grounded in legitimate interest
- Right to withdraw consent at any time (Art. 7(3) UK GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 UK GDPR)
To exercise any of these rights, please send a brief message to contact@orvian.com.
10. Security of Your Data
We have implemented appropriate technical and organisational measures to guard your data against unauthorised access, loss and misuse. These include SSL/TLS encryption, secured server infrastructure, restricted access controls and regular security audits.
11. Automated Decision-Making
We do not engage in automated decision-making or profiling within the meaning of Art. 22 UK GDPR.
12. Right to Complain
If you believe that our processing of your personal data infringes the UK GDPR, you have the right to lodge a complaint with a data protection supervisory authority — in particular the Information Commissioner's Office (ICO) in the United Kingdom (www.ico.org.uk), or any competent authority in the EU member state of your habitual residence, place of work or the location of the alleged infringement.
13. Updates to This Policy
We may amend this Privacy Policy from time to time to reflect changes in legislation or in our business operations. The version currently in force is always available on this page.