Privacy policy

Your privacy is critically important to me.

Last Updated: 13 May 2026

This Privacy Policy explains how carmela.co.uk collects, uses, and protects personal data when you visit the website or contact us. We are based in the UK and process personal data in line with the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and other relevant privacy laws.


1. Who We Are

carmela.co.uk is a website providing information about Carmela and related services, content, or enquiries. This policy applies to visitors and people who contact us through the website.

carmela.co.uk is the data controller and is responsible for the personal data described in this policy.

You can contact us about privacy matters through our contact form.


2. What Data We Collect

2.1 Contact Form Submissions

When you contact us through the website, we may collect:

  • Name
  • Email address
  • Telephone number, if provided
  • Message content
  • Any other information you choose to include in your message

2.2 Website Analytics and Security

When you visit the website, we may collect technical and usage information, including:

  • IP address
  • User agent
  • Browser type and version
  • Operating system
  • Browser language
  • Country code or approximate location derived from technical data
  • Pages visited
  • Visiting URL and referral URL
  • Timestamp of visit or event
  • Device and usage information

This may be collected through:

  • Google Analytics, if enabled
  • Website hosting, security, and anti-spam tools
  • Cookie consent and website performance tools

3. How We Use Your Data

We use your information for:

  • Responding to messages sent through our contact form
  • Handling enquiries, bookings, support requests, or related follow-up
  • Improving our website, content, accessibility, and user experience
  • Understanding which pages and content are useful to visitors
  • Preventing spam, fraud, abuse, or unauthorised access
  • Maintaining the security and reliability of the website

We do not sell your personal information. We only share personal data with service providers where needed to run the website, measure performance, protect the site, respond to enquiries, or comply with legal requirements.


4. Cookies

We use cookies and similar technologies to:

  • Maintain site functionality
  • Remember preferences
  • Understand how visitors use the website
  • Improve website performance and content
  • Help protect the website from spam, fraud, and abuse

We may use Google Analytics to understand how visitors use the site. This may involve cookies or similar technologies, depending on your cookie choices. See our Cookie Policy for full details.

Non-essential cookies should only be used where you have given any required consent through the website’s cookie controls.


5. Legal Basis

We process personal data based on the following legal bases:

PurposeType of dataLawful basis
To reply to enquiriesName, email address, telephone number if provided, message contentLegitimate interests or steps taken at your request
To handle bookings, requests, or related follow-upName, contact details, message contentLegitimate interests, contract, or steps taken at your request
To run and protect the websiteTechnical and usage dataLegitimate interests
To understand website performanceTechnical and usage dataConsent where required by cookie rules, otherwise legitimate interests where applicable

Where we rely on consent, you can withdraw it at any time. Where we rely on legitimate interests, we only do so where we consider that our interests are not overridden by your rights and freedoms.


6. Your Rights

Under the UK GDPR, you have the right to:

  • Access your personal data
  • Correct inaccurate personal data
  • Request deletion of your personal data
  • Object to certain types of processing
  • Request restriction of processing
  • Request a copy of your data in a portable format, where applicable
  • Withdraw consent at any time where we rely on consent
  • Complain to the Information Commissioner’s Office if you are unhappy with how we handle your data

To exercise any of your rights, send us a message through the contact form.

You can also contact the Information Commissioner’s Office through ico.org.uk.


7. Data Retention

We retain personal data only for as long as necessary for the purpose collected.

  • Contact form messages are retained only as long as needed to respond to your enquiry and manage any related follow-up.
  • Records linked to bookings, services, or enquiries may be retained where needed for administration, legal, accounting, or dispute-resolution purposes.
  • Analytics data is anonymised or aggregated where possible and retained according to the settings used in Google Analytics.
  • Security logs may be retained for a limited period where needed to protect the website and investigate abuse or technical issues.

8. Third-Party Services and International Data Transfers

We use third-party service providers to operate the website, measure website performance, protect the site, and respond to enquiries. These may include:

  • Google Analytics, for website analytics, if enabled
  • Website hosting and infrastructure providers
  • Website security, anti-spam, cookie consent, and performance providers
  • Email or contact form delivery providers, where needed to receive and respond to enquiries

Some providers may process data outside the UK or European Economic Area. Where this happens, we rely on appropriate safeguards, such as adequacy regulations, International Data Transfer Agreements, Standard Contractual Clauses, or equivalent data protection measures.


9. Security

We use reasonable technical and organisational measures to protect your data, including HTTPS, access controls, security tools, and regular monitoring. No method of transmission online is completely secure, but we take reasonable steps to reduce the risk of unauthorised access, loss, misuse, or disclosure.

We limit access to personal data to people and service providers who need it for legitimate operational, technical, security, or legal reasons.


10. Third-Party Links

This website may include links to third-party websites, tools, plugins, applications, products, or other services. Clicking those links or using those services may allow third parties to collect or process data about you. We do not control these third-party websites and are not responsible for their privacy notices, policies, or practices.

We encourage you to read the privacy notices of any third-party websites you visit.


11. Changes to This Policy

We may update this policy from time to time. The latest version will always be posted on this page with the effective date shown at the top.


12. Questions

If you have any privacy concerns or questions about how we handle your data, send us a message through the contact form.