Legal
Privacy Policy
How Haperture Ltd handles personal data under UK GDPR.
Haperture is a trading name of Concept by Hannah Ltd, a company registered in England and Wales. Concept by Hannah Ltd is the data controller for personal information collected through haperture.com. This page explains what we collect, why, and who else touches it.
What we collect
- Order information — name, delivery address, email, phone number (optional). Required to fulfil an order and issue a VAT invoice.
- Payment information — processed entirely by Revolut Business. We never see or store your card details.
- Enquiry information — whatever you include in a contact or bespoke-print form.
- Newsletter subscription — email address and the fact that you subscribed. Nothing else.
- Technical data — standard server logs, Vercel Speed Insights (anonymous, cookieless), and our own basic traffic analytics (cookieless).
We do not set tracking cookies. We do not sell or share data with advertisers.
Who else processes your data
Under UK GDPR, the following are our data processors:
- Vercel Inc. — hosting, edge network, server logs. Data processing terms.
- Supabase Inc. — order, enquiry, and customer database. Hosted in the EU region.
- Revolut Ltd — payment processing. Separate controller for card data.
- Resend Inc. — transactional email delivery.
- Klaviyo Inc. — marketing email and newsletter subscriptions.
- Cloudflare Inc. — Turnstile verification on the contact form (bot prevention).
- getAddress.io (or Loqate) — UK postcode autocomplete at checkout.
Each processor operates under its own privacy notice and UK GDPR obligations.
How long we keep it
- Order records and VAT invoices — six years, per HMRC statutory minimum.
- Enquiry messages — two years, then deleted unless converted to an order.
- Newsletter subscription — until you unsubscribe. Every newsletter includes a one-click unsubscribe link.
- Server logs — 30 days, then rotated.
Your rights
Under UK GDPR you have the right to access, correct, export, and delete your personal data. To exercise any of these, use the contact form and tell us which right you'd like to exercise. We respond within one month, per statutory requirement.
If you believe we are not handling your data correctly, you can complain to the Information Commissioner's Office.
Changes
We will update this page when we change processors or materially change what we collect. The "last updated" date above reflects the latest change. No pop-ups, no overlays, no forced consent flow — just the current text.