Privacy Policy

Last Updated: 4th November 2023

1. Introduction

1.1 Important information and who we are

Welcome to Gabrielle Todd’s Privacy and Data Protection Policy (“Privacy Policy”). At www.gabrielletodd.com (“Gabrielle Todd”, “website”, “we”, “us” or “our”) we are committed to protecting and respecting your privacy and personal data in compliance with the law and guidelines of the EU General Data Protection Regulation (“GDPR”). This privacy policy will define the information that we collect from you and explains: how we collect your data, how we process/use this personal data to deliver our services and your privacy rights. It is important you read this policy, review it periodically and let us know if you have any questions. By using Gabrielle Todd, you acknowledge the collection and use of data by us as set out in this Privacy Policy; this will apply from your first visit to our website and your continued use of Gabrielle Todd shall constitute your acknowledgment of any modifications to this Privacy Policy.


1.2 Who is your data controller and data protection officer

Gabrielle Todd is your Data Controller and is responsible for your personal data. We have appointed a data protection officer (“DPO”) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights surrounding your personal data please contact the Data Protection Officer at elle@gabrielletodd.com. You have the right to contact the Information Commissioner’s Office (ICO); the UK’s supervisory authority for data protection issues (www.ico.org.uk). However, we would appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.


1.3 Changes to the privacy policy and your duty to inform us of changes

We keep our privacy policy under regular review and reserve the right to update this privacy policy at any time; we will inform you if we do so and update the “Last Updated” date of this policy. It is important that the personal data we hold about you is accurate and current. Therefore, please keep us informed if your personal data changes during your relationship with us.


1.4 Third party links

This website may contain links to other third-party websites, plug-ins and applications. Clicking on these links or enabling plug-in connections may allow third parties to collect or share data about you. This privacy policy only applies to our website, we do not control these third-parties and are not responsible for their privacy statements. If you click on a link to another website, we encourage you to read their privacy policy.

2. What personal data do we collect and the legal basis for this?

2.1 The types of personal data we collect

Personal data is any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We may collect, use, store and transfer different kinds of personal data about you that you voluntarily provide to us or that we otherwise collect or acquire about you. The extent of this personal data depends on your user type and how you use our website; subsequently, not all of the following types of data will necessarily be collected from you but this is the full scope of data that we collect:

If you register or otherwise sign up for our service, or send an enquiry to us:


If you sign up to our mailing list in order to receive email newsletters and updates:


If you make a payment to Gabrielle Todd for a product/service:


If you contact us or leave a review/reference:


Any other personal information we collect from you during the provision of our services which are necessary to administer your account with us or help us to deliver a better service:


2.2 The legal basis for collecting the above data

There are a number of lawful reasons under the GDPR that allow collection and processing of personal data. The main bases we rely on are (but see more on the specifics below under ‘How we use your personal data’ section.):


Contractual Obligations:


Legitimate Interest:


Legal Compliance:


Consent:


3. How do we collect your personal data?

3.1 Direct interactions

You may give us your personal data by registering for the service, creating an account, filling in forms or by corresponding with us by phone, email or otherwise. This includes personal data you provide when you:


3.2 Automated technologies or interactions

As you interact with our website and services, we will automatically collect Technical Data and Usage Data about your usage of the service and equipment you use including browsing actions and patterns. This information does not reveal your specific identity such as your name or contact information etc; however, it is required to maintain the security and operation of our website and for our internal analytics and reporting purposes to enable us to enhance, personalise and improve our services.

We collect this personal data by using cookies and other similar technologies. Where your data is collected through the use of non-essential cookies, we rely on consent to collect your personal data and for the onward processing purpose. Please see our Cookie Policy for more information.


3.3 Third parties or publicly available sources

We will receive personal data about you from various third parties including:

4. How do we use your personal data?

4.1 Our uses

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:


Generally, we do not rely on consent as a legal basis for processing your personal data although we will get your consent before sending direct marketing communications to you via email. You have the right to withdraw consent to marketing at any time by contacting us. 


Set out below are the ways we use your personal data, the type(s) of personal data used for these activities and the lawful basis for processing this data.

a) Register you for the service and creation of an account

b) Replying to any enquiries

c) Sending communication and marketing e.g. newsletters

d) Manage payments, fees and charges

e) Collect and recover money owed to us


a) Notifying you about changes to our terms and conditions or privacy/cookie policy

b) Notifying you about website changes and new services/features

c) Asking you to leave a review or take a survey

d) User support; including contacting us or leaving a review/reference




a) identifying where users are logging in from

b) identify which browsers’ users use

c) analysis of how users use our services





4.2 Marketing and content updates

You will receive marketing and new content communications from us if you have opted into and consent to receiving these communications. From time to time we may make suggestions and recommendations to you about goods or services that may be of interest to you.

You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us using the contact details below at any time.


4.3 Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact our Data Protection Officer. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent in compliance with the above rules and where this is required or permitted by law.

5. Your personal data & third parties

5.1 Storing your data

We generally store your personal data in the EU such that it is fully protected under the GDPR. However, some of the data that we collect may be transferred to and stored at a destination outside the European Economic Area (‘EEA’). We take all reasonable steps to ensure your data is treated securely and in accordance with this Privacy Policy. We use strict procedures and security features to prevent any unauthorised access to your data that we hold.


5.2 Securing your data

We implement a variety of security measures designed to protect and ensure the security of any personal data we process on our systems. Any personal data collected by us is contained behind secured networks and is only accessible by a limited number of employees who have special access rights to such systems and are bound by obligations of confidentiality. If and when we use subcontractors to store your data, we will not relinquish control of your personal data or expose it to security risks that would not have arisen had the data remained in our possession.

However, unfortunately no transmission of data over the internet is guaranteed to be completely secure. Although we do our best to protect your personal information, it may be possible for third parties not under the control of Gabrielle Todd to intercept or access transmissions or private communications unlawfully. While we strive to protect your personal data, we cannot ensure or warrant the security of any personal data you transmit to us. Any transmission of personal information to and from our website is at your own risk. You should only access the services within a secure environment. If you believe that your interaction with us is no longer secure, please contact us.


5.3 Retaining your data

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for. We may retain your personal data for a longer period than usual if permitted by law. In addition, a longer retention period may be required in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you. When we no longer have a legitimate business need to process your personal information, we will delete it.


5.4 Sharing your data

We only share your information with your consent, to comply with laws, to protect your rights or to fulfil business and contractual obligations. We will share your information in the following situations:


Compliance with laws:


Vital interests and legal rights:


Third party service providers:


Business transfers:


Third party advertisers:


Affiliates:


Business partners:


With your consent:


Other users:

6. Your rights

6.1 What are your privacy rights?

We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:


The right to access:


The right to rectification:


The right to erasure:


The right to restrict processing:


The right to object to processing:


The right to data portability:


The right to complain:


6.2 Requesting your data

If you would like to exercise any of your rights or request your data, please contact us at our email: elle@gabrielletodd.com. If you make a request, we have one month to respond to you. You may have to pay a fee to access your personal data (or to exercise any of the other rights). However, if your request is clearly unfounded, we could refuse to comply with your request. We will request specific information from you to help us confirm your identity and ensure you have the right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.


6.3 Opting out of marketing promotions

You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us using the contact details below at any time. Where you opt out of receiving these marketing messages, we will continue to retain personal data provided to us as a result of a product/service purchase, product/service experience or other transactions.

7. Terms and Conditions

Please see our full Terms and Conditions for our website which set out the terms, disclaimers, and limitations of liability governing your use of www.gabrielletodd.com.

8. Contact us

If you have any questions/concerns about this privacy policy or the information we hold on you, please do not hesitate to contact us by email to elle@gabrielletodd.com.