A jurisdiction-aware privacy notice generated for a small EU/UK cross-border business.
Illustrative sample — no real personal dataNorthbridge Tea Co. Ltd. (14 Camden High Street, London, NW1 0JH, United Kingdom) is the data controller of your personal data.
What we collect: name, email, phone, postal address, account credentials, payment information, usage data, device info, cookies & analytics ids.
Why: to deliver the product or service the user signed up for; to comply with a legal obligation (e.g., tax, kyc); to keep our service secure and prevent fraud; to understand how people use our service (basic analytics); to send marketing emails / push notifications; to run non-essential cookies (advertising, third-party analytics).
Who else sees it: Stripe (payments), Mailchimp (email), AWS (hosting), Google Analytics. Some recipients are outside the EU/UK; we use SCC as the safeguard.
How long: For as long as you have an account, then up to 6 years after closure to meet UK tax and accounting obligations.
Your rights: access, rectification, erasure, restriction, portability, objection, withdraw consent, complain to a supervisory authority (lead: UK ICO).
Contact: privacy@northbridgetea.example.
Last updated: 2026-06-15
This Privacy Policy explains how Northbridge Tea Co. Ltd. ("we", "us") collects and uses your personal data in connection with our website https://www.northbridgetea.example and services. This policy applies in the EU/EEA under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and in the United Kingdom under the UK GDPR and the Data Protection Act 2018. Where the two differ, we apply the stricter standard.
Northbridge Tea Co. Ltd., registered at 14 Camden High Street, London, NW1 0JH, United Kingdom. We have not appointed a statutory Data Protection Officer; for any privacy enquiry contact privacy@northbridgetea.example.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| To deliver the product or service the user signed up for | Art. 6(1)(b) — contract performance |
| To comply with a legal obligation (e.g., tax, KYC) | Art. 6(1)(c) — legal obligation |
| To keep our service secure and prevent fraud | Art. 6(1)(f) — legitimate interests (security) |
| To understand how people use our service (basic analytics) | Art. 6(1)(f) — legitimate interests (analytics) |
| To send marketing emails / push notifications | Art. 6(1)(a) — consent (with opt-out) |
| To run non-essential cookies (advertising, third-party analytics) | Art. 6(1)(a) — consent (cookie banner) |
Our service is not directed to children under 16 and we do not knowingly collect their personal data.
Some recipients are outside the EU/UK. We rely on SCC as the safeguard under Chapter V GDPR.
For as long as you have an account, then up to 6 years after closure to meet UK tax and accounting obligations.
To exercise: privacy@northbridgetea.example. We respond within one month (Art. 12(3)).
You may complain to a DPA. Lead: UK ICO.
We may update this policy. The "Last updated" date reflects the latest revision.
Northbridge Tea Co. Ltd., 14 Camden High Street, London, NW1 0JH, United Kingdom — privacy@northbridgetea.example.
We use essential cookies to run the site. With your permission, we'd also like to use analytics and marketing cookies.
[Accept all] [Reject non-essential] [Customise]