Privacy policy

Version dated 31 July 2026

This Privacy Policy explains how Shake Party processes personal data when you visit shakeparty.de, use the online store, submit enquiries, place orders or make bookings, communicate with us, or receive our services.

1. Controller

The controller responsible for processing personal data within the meaning of Article 4(7) of the EU General Data Protection Regulation (hereinafter “GDPR”) is:

Shake Party
Alona Yanchenko
Holunderweg 9
65510 Idstein
Germany

Telephone: +49 178 3111805
Email: shakeparty.de@gmail.com

You can contact us using the details above with any questions about data protection or to exercise your rights.

2. Categories of data, sources and legal bases

Depending on how you interact with us, we may process the following categories of personal data:

  • identity and contact data, such as your name, address, email address and telephone number;
  • order, booking and event data, such as the selected service, date, time, venue, number and age group of participants, individual requests and programme language;
  • customer account, shopping cart, delivery, payment, cancellation and refund data;
  • the content of messages, chats, reviews and files submitted to us;
  • technical data, such as your IP address and information about your browser, device, operating system, pages visited and interaction with the website;
  • data concerning consent, privacy preferences and opt-outs;
  • photographs and videos, if the recording or their use has been agreed separately.

As a rule, we obtain data directly from you. Data may also be provided by a person placing an order for a child, guest, gift recipient or other participant, as well as by Shopify and payment, communication, analytics and advertising services within the scope of the features and settings you have selected. If you provide us with another person’s data, submit only the information that is necessary, ensure that you have a lawful basis for doing so and make this Privacy Policy available to that person.

Depending on the purpose, processing is carried out on the following legal bases:

  • Article 6(1)(a) GDPR — consent;
  • Article 6(1)(b) GDPR — steps taken prior to entering into a contract and performance of a contract;
  • Article 6(1)(c) GDPR — compliance with a legal obligation;
  • Article 6(1)(f) GDPR — our legitimate interests or those of a third party, provided that the rights and interests of the data subject do not override those interests.

Where processing is based on consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.

3. Shopify platform

The website and online store operate on the Shopify platform. The platform provider for merchants in Europe is Shopify International Limited, Ireland.

To operate the storefront, shopping cart, checkout, customer accounts and order processing, and to provide security, fraud prevention and technical support, Shopify processes visitor and customer data primarily as our processor under a data processing agreement. For certain expressly designated services of its own, such as Shop, Shop Pay, and certain security and fraud-prevention features, Shopify may act as an independent controller.

If Shopify Network Intelligence or associated Enhanced Services are enabled for the store, Shopify may, as an independent controller, use interaction and transaction information from participating stores for analytics, service personalisation and advertising. Where required by law, such processing must be based on consent. Information about Shopify’s processing, available settings and how to object is provided in the Shopify Consumer Privacy Policy and through Shopify Privacy Controls.

Shopify is an international group of companies. Intra-group transfers may rely, in particular, on the adequacy decision for Canada and Shopify’s binding corporate rules; the appropriate safeguards described in Section 18 apply to other recipients.

4. Technical data, server logs and website security

When you access the website, the servers and security systems may automatically process your IP address, the date and time of access, the requested page or file, the referring page address, browser type and version, operating system, device type, language settings, approximate region, server response codes, error information and security events.

This processing is necessary to deliver content, localise the store, ensure the stable and secure operation of the website, detect errors, prevent misuse and protect against attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the reliable operation of the website and the protection of our systems, customers and visitors.

Logs are deleted or anonymised when they are no longer required for the relevant technical or security purpose, unless longer retention is necessary to investigate a specific incident, comply with a legal obligation or establish, exercise or defend legal claims.

5. Orders, bookings, customer accounts and performance of contracts

When you request a quote, place an order or book an event, we may process:

  • the customer’s first and last name;
  • the postal, billing, delivery or event address;
  • telephone number and email address;
  • the selected service, product, programme or character;
  • the date, time, duration and venue of the event;
  • the number and age group of participants;
  • the name and age of the child or other person receiving a greeting, where this is necessary for the programme;
  • the preferred language, individual requests and agreed terms;
  • order, payment, delivery, refund and cancellation data, as well as correspondence;
  • information necessary to produce a personalised product or provide digital content.

Processing is carried out to prepare a quote, check date availability, enter into and perform a contract, organise an event, deliver goods, issue documents, accept payments, and handle cancellations, rescheduling, complaints and refunds. The legal basis is Article 6(1)(b) GDPR.

Invoice, payment and business documentation is also processed on the basis of Article 6(1)(c) GDPR in order to meet tax, accounting and commercial obligations. Data necessary to establish, exercise or defend legal claims is processed on the basis of Article 6(1)(f) GDPR; our legitimate interest is to protect and exercise our rights.

When a customer account is created, Shopify processes registration and identification data, order history and login data in order to provide and protect the account. The legal basis is Article 6(1)(b) GDPR and, for security measures, Article 6(1)(f) GDPR.

Mandatory fields are marked as such. Without the data required for the relevant contract, we will be unable to prepare a quote, accept a booking, process an order, deliver goods or provide a service.

6. Online booking via Cowlendar

We use the Cowlendar Appointment Booking app, provided by PENIDA, 14 Rue Charles-V, 75004 Paris, France, to select dates and times and manage online bookings.

When you use the booking feature, your name, contact details, selected service, date and time, time zone, event address or venue, notes, IP address and browser and device information may be processed. The purpose is to prepare and fulfil the booking; the legal basis is Article 6(1)(b) GDPR. If calendar synchronisation is enabled, the booking data required for this purpose may be transferred to the connected calendar service.

Further information: Cowlendar Privacy Policy.

7. Contact form, email, telephone, chat and spam protection

When you contact us via the contact form, by email or by telephone, we process the information you provide, including in particular your name, email address, telephone number, message content, files submitted, date of contact and related technical data.

The contact form is processed within Shopify’s infrastructure, and the chat feature is provided through Shopify Inbox. The chat may request your first name, last name, email address, order number and other information required to respond. Artificial intelligence features may assist in drafting responses or retrieving order information. Messages and attachments are accessible to Shake Party and are processed by Shopify to provide, secure and, in accordance with Shopify’s policy, improve these features. We do not use the chat to make decisions that produce legal or similarly significant effects.

We use Google services for email. Messages, addresses, attachments and technical metadata may be processed by Google Ireland Limited, Ireland, as well as affiliated companies and service providers. Further information: Google Privacy Policy.

If your communication concerns a prospective or existing contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, the legal basis is Article 6(1)(f) GDPR; our legitimate interest is to handle enquiries, communicate with visitors and customers and document business correspondence.

If you contact us by telephone, your telephone number, the time and duration of the call and the information you provide may be processed. We do not record calls without giving separate prior notice and having an appropriate legal basis.

To protect forms against spam and automated attacks, Shopify may use hCaptcha, provided by Intuition Machines, Inc., USA. This may involve processing the IP address, browser and device characteristics and information about interaction with the form. Any storage of information on, or access to information already stored on, the end user’s terminal equipment that is strictly necessary for this purpose is permitted under Section 25(2) TDDDG; the subsequent processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to protect the website and its forms against misuse. Further information: hCaptcha Privacy Policy.

8. WhatsApp, Telegram and video communication

If you contact us on your own initiative via WhatsApp or Telegram, we process your telephone number or username, profile name, message content, files sent and related correspondence data.

For messages relating to a quote, order or booking, the legal basis is Article 6(1)(b) GDPR. For other business enquiries, the legal basis is Article 6(1)(f) GDPR; our legitimate interest is convenient and efficient communication through the channel you have selected.

WhatsApp is provided in the European Region by WhatsApp Ireland Limited. Telegram is provided by Telegram Messenger Inc. These providers independently process registration and technical data and communications metadata in accordance with their own policies. Processing may also take place outside the European Economic Area.

If video communication via WhatsApp, Zoom, Skype or another selected service has been separately agreed for a remote programme, the relevant provider processes connection, account and device data, as well as transmitted content, under its own policy. This processing is necessary to perform the selected service pursuant to Article 6(1)(b) GDPR. The use of messaging services and any particular video communication service is voluntary; where possible, another channel can be agreed. Do not send special categories of personal data through these services unless this has been separately deemed necessary and agreed.

9. Reviews and Ali Reviews

The Ali Reviews app may be used to display and manage reviews. When the widget loads, the provider may receive the IP address, browser and device information and the page visited. If you submit a review, the stated name or pseudonym, email address, rating, text, photograph or video, order details and data necessary to prevent misuse may also be processed.

The publication of a review submitted voluntarily is based on your consent under Article 6(1)(a) GDPR. Authenticity checks, moderation and protection against misuse are based on Article 6(1)(f) GDPR; our legitimate interest is the reliable and secure display of reviews. Consent to continued publication may be withdrawn with effect for the future.

Further information: Ali Reviews Privacy Policy.

10. Email newsletters and promotional messages

When you subscribe to an email newsletter using the Shopify form, we process your email address, subscription details, the date and time when consent was given and confirmed, and the technical data required to document consent and prevent misuse. Shopify email services may be used to send messages.

The legal basis is consent pursuant to Article 6(1)(a) GDPR in conjunction with Section 7 UWG. Where email subscription confirmation is used, the confirmation data is used to verify that the subscription is valid. The narrow exception permitting the advertising of our own similar services to existing customers applies only if all requirements of Section 7(3) UWG are met.

You may withdraw your consent at any time by using the unsubscribe link in each promotional email or by contacting shakeparty.de@gmail.com. After you opt out, the address will no longer be used for the relevant mailing. Minimum records of consent and opt-out may be retained where necessary to demonstrate compliance with the law and prevent further mailings.

11. Payments

The payment methods displayed during checkout are available when you place an order. These may currently include Shopify Payments, Shop Pay, PayPal, Klarna, Apple Pay, Google Pay and payment by Visa, Mastercard, Maestro, American Express or UnionPay cards.

When you select a payment method, the necessary data is transferred to the relevant payment provider, bank and card scheme. Depending on the method, your name, billing and delivery address, email address, telephone number, amount, currency, order and transaction identifiers, payment status, technical data and fraud-prevention information may be processed. Full card details are generally entered in the payment provider’s secure environment and are not disclosed to us in full.

Processing necessary to pay for an order is based on Article 6(1)(b) GDPR. Processing required to comply with accounting, tax, identification and other legal obligations is based on Article 6(1)(c) GDPR. Security and fraud-prevention checks may be based on Article 6(1)(f) GDPR or carried out by the provider under its own responsibility.

PayPal and Klarna may perform their own identity, creditworthiness and risk checks and make decisions under their own responsibility. The scope of processing depends on the payment method selected.

12. Cookies and consent management

The website uses cookies and comparable technologies to store information on or read information from a terminal device. We use Pandectes GDPR Cookie Consent to manage user choices. The service displays the cookie banner and preferences, records the user’s choices and helps communicate them to connected services. A consent identifier, selected categories, date and time, IP address or limited technical information and the settings version may be processed for documentation purposes.

Technically necessary technologies are used only to the extent strictly necessary to transmit a communication or provide a feature expressly requested by you, such as the shopping cart, checkout, account login, language selection, security or storage of consent preferences. The storage of information on, or access to information already stored on, your terminal equipment is permitted under Section 25(2) TDDDG; depending on the relevant feature, the subsequent processing of personal data is based on Article 6(1)(b) or (f) GDPR.

Analytics, marketing and other non-essential technologies require consent under Section 25(1) TDDDG; the subsequent processing of personal data is based on Article 6(1)(a) GDPR. Records demonstrating the user’s choice are stored on the basis of Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR.

Category and services Examples of technologies Purpose
Essential: Shopify, Pandectes, hCaptcha, booking features Session and security cookies; shopping cart, localisation, login and consent-choice data Store operation, security, checkout and storage of selected preferences
Analytics: Shopify Analytics, Google Analytics 4 _shopify_y, _shopify_s, _ga, _ga_* and comparable identifiers Statistics on visits, website use, shopping carts, orders and performance
Marketing: Google Ads, Meta, TikTok, Pinterest, Elevar _fbp, _pin_unauth, _ttp, _tt_enable_cookie and comparable identifiers and events Conversion measurement, advertising attribution, audience creation and advertising personalisation
External media: YouTube Player, device and interaction data and, where applicable, Google/YouTube cookies Playback of embedded video

The current names, providers, purposes and lifetimes of individual cookies are displayed in the cookie preferences. You can accept or reject non-essential categories with equal ease, and you may change or withdraw your choices at any time with effect for the future:

Open cookie preferences

You can also delete individual cookies in your browser. Blocking essential cookies may prevent the shopping cart, login, language selection, booking, checkout or other requested features from functioning properly.

Further information about the consent-management provider: Pandectes Privacy Policy.

13. Analytics and advertising technologies

Once the relevant consent has been given, the IP address and approximate region, cookie, browser, device and advertising identifiers, pages, products and services viewed, referral source and campaign, shopping-cart and checkout actions, purchases, amount, currency, order identifier and interaction characteristics may be processed. For enhanced conversion matching, certain providers may receive contact identifiers in hashed form if the relevant feature is enabled and the consent required for that transfer has been obtained.

The storage of information on, or access to information already stored on, your terminal equipment is based on consent under Section 25(1) TDDDG; the subsequent processing of personal data is based on Article 6(1)(a) GDPR. Consent can be withdrawn through the cookie preferences.

13.1 Shopify Analytics

Shopify provides statistics on visits, traffic sources, store use, shopping carts, checkout and purchases. Essential operational metrics may be processed to operate and secure the store; non-essential analytics is based on consent.

13.2 Google Tag Manager, Google Analytics 4 and Google Ads

Google Tag Manager is used to manage connected tags. The container itself is used to organise them; the legal basis and activation rules are determined by the relevant feature. Google Analytics 4 is used to analyse website traffic and use, while Google Ads is used to measure advertising conversions, conduct remarketing and assess campaigns. The enhanced conversions feature may transmit hashed contact data to Google to match an event if the feature is enabled and the required consent has been obtained.

The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC and service providers in the USA and other third countries. Depending on the user’s login status and settings, Google may associate information with the user’s Google account.

Further information: Google Privacy Policy.

13.3 Elevar

Elevar is used to organise browser-side and server-side transmission of online-store events to connected analytics and advertising services. Elevar may process technical identifiers and information about the session, page views, shopping cart, checkout, purchase and traffic source. Server-side transmission does not remove the requirement for consent; events are transmitted to analytics and advertising recipients only within the scope of valid consent and for the corresponding purpose.

Further information: Elevar Privacy Policy.

13.4 Meta Pixel and Meta Conversions API

Meta Pixel and the server-side Meta Conversions API are used to measure advertising results on Facebook and Instagram, match conversions and create advertising audiences. Events transmitted may include information about the page visited, product, shopping cart, checkout and purchase, browser and device identifiers, IP address and, where configured accordingly, hashed contact identifiers.

The recipient is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. With regard to the collection and transmission of certain data through Meta Business Tools, the parties may be joint controllers to the extent provided in Meta’s terms; Meta carries out subsequent processing under its own responsibility. Data may be transferred to Meta affiliates and service providers outside the European Economic Area.

Further information: Meta Privacy Policy.

13.5 TikTok Pixel

TikTok Pixel is used to measure actions taken after viewing or clicking a TikTok advertisement, assess campaign performance and create advertising audiences. Identifiers, IP address, browser and device information, page URL and metadata, the advertising campaign, and page-view, shopping-cart, checkout and purchase events may be transmitted.

The provider for users in the European Economic Area is TikTok Technology Limited, Ireland. Data may be processed by TikTok affiliates and service providers in third countries.

Further information: TikTok Privacy Policy.

13.6 Pinterest Tag

Pinterest Tag is used to measure the effectiveness of Pinterest advertising, match conversions and create target audiences. Identifiers, IP address, browser and device information, URL, referral source and page-view, shopping-cart, checkout and purchase events may be processed.

The recipient is Pinterest Europe Ltd., Ireland. Pinterest may also process data through affiliates and service providers outside the European Economic Area.

Further information: Pinterest Privacy Policy.

14. Embedded YouTube videos

YouTube videos provided by Google Ireland Limited, Ireland, and Google LLC, USA, are embedded on certain pages. When the player is loaded or used, the IP address, page URL, browser and device information, video-interaction data and Google/YouTube identifiers may be transmitted. If the user is signed in to a Google account, the visit and viewing activity may be associated with that account.

The storage of information on, or access to information already stored on, your terminal equipment and the loading of the non-essential external player are based on consent under Section 25(1) TDDDG; the subsequent processing is based on Article 6(1)(a) GDPR. Consent can be changed or withdrawn through the cookie preferences.

Further information: Google/YouTube Privacy Policy.

15. Links to social networks

The website contains ordinary links to our pages on services including Facebook, Instagram, YouTube, TikTok, X, Pinterest and Tumblr. If only an ordinary link is displayed, the relevant social network does not receive data merely because the link appears on the page. Transmission begins when you follow the link to the external website. The provider then receives, in particular, your IP address, browser and device information and, depending on the settings, the address of the referring page. If the user is signed in to an account on the platform, the visit may be associated with that account.

Once you follow the link, the privacy policy and settings of the relevant platform apply. We do not control subsequent data processing by these providers.

16. Children’s data, health information, photographs and video recordings

Our party services are intended for children; however, independent ordering, creation of a customer account and entry into a contract through the website are intended for adults.

We process a child’s name, age, preferences and other information only to the extent provided by a parent, legal guardian or other authorised adult and necessary to prepare and carry out the programme. The legal basis is performance of the contract with the customer under Article 6(1)(b) GDPR or our legitimate interest in properly organising the event under Article 6(1)(f) GDPR.

Do not submit health information, allergies, diagnoses or other special categories of personal data through the general form or an ordinary messaging service. If such information is genuinely necessary for the safe delivery of a particular programme, we will request it separately, limit its scope and state the specific legal basis. Depending on the circumstances, the legal basis may be separate explicit consent under Article 9(2)(a) GDPR or, in the exceptional case of an immediate threat to vital interests, Article 9(2)(c) GDPR. We do not use images for biometric identification.

Photography or video recording carried out by us for the website, social media or advertising is not based solely on the fact that a booking has been made. Separate consent is obtained from the relevant individual or legal guardian for the publication of identifiable images of adults and, in particular, minors, pursuant to Article 6(1)(a) GDPR and, where applicable, Section 22 KUG.

If photography or video recording is a separately commissioned service, the processing necessary to create and deliver the materials to the customer is based on Article 6(1)(b) GDPR. Use of those materials in our advertising requires a separate legal basis.

Consent may be withdrawn with effect for the future. Following withdrawal, we will discontinue further use and, to the extent within our control and required by law, remove the material from our own channels. It may be impossible to remove all copies already distributed by third parties, cached by search engines or published outside our control.

17. Recipients of data

Depending on the specific order, website feature and channel selected, recipients of data may include:

  • Shopify, its affiliates and subprocessors;
  • providers of hosting, technical support, security, consent management, forms, chat, booking, reviews, email, calendar, analytics, advertising and external media;
  • banks, payment providers, card schemes and accelerated-checkout providers;
  • entertainers, hosts, photographers, videographers and other contractors engaged for a particular event;
  • production partners, courier and transport services where this is necessary to produce or deliver an order;
  • tax advisers, accountants, lawyers, insurance companies and other professional advisers;
  • public authorities, courts and other authorised persons where disclosure is required by law or necessary to protect legal claims.

Each recipient receives only the data required for its task. Where a provider acts as a processor, the relationship is governed by an agreement pursuant to Article 28 GDPR. Event contractors receive only the organisational and safety information they require.

18. Transfers of data outside the European Economic Area

Some providers are located outside the European Economic Area or use affiliates, servers and subprocessors there. This may apply, in particular, to Shopify, Google, Meta, TikTok, Pinterest, Telegram, Elevar, hCaptcha and certain payment or technical providers.

Transfers are made only where a basis under Chapter V GDPR is available. Depending on the recipient, this may be a European Commission adequacy decision, including the EU–US Data Privacy Framework only for a recipient whose certification is current and valid, binding corporate rules, the European Commission’s standard contractual clauses with any necessary supplementary measures, or another basis permitted by law. For TikTok and other recipients not covered by an adequacy decision, the relevant provider’s standard contractual clauses are used in particular.

You may request information about the applicable safeguards or a copy of them by emailing shakeparty.de@gmail.com. A copy may be provided with such redactions as are necessary to protect trade secrets, security and the rights of third parties.

19. Retention periods

We retain personal data no longer than necessary for the relevant purpose, unless longer retention is required or permitted by law.

  • Enquiries that do not result in a contract are generally deleted no later than 12 months after the final response, unless there is a need for longer retention.
  • Contract, order, payment and accounting data is stored while the contract is being performed and thereafter in accordance with applicable commercial and tax retention periods. Depending on the type of document, those periods may be 6, 8 or 10 years.
  • Customer account data is retained until the account is deleted or the relevant feature is discontinued; mandatory order records are retained for the statutory period regardless of account deletion.
  • Data may be retained until the applicable limitation period expires where it is necessary to establish, exercise or defend legal claims.
  • Newsletter data is used until consent is withdrawn. Minimum records necessary to demonstrate consent and honour an opt-out may be retained for longer within the applicable period.
  • Cookie consent information is retained for as long as necessary to apply and demonstrate the user’s choice; the specific cookie lifetimes are stated in the cookie preferences.
  • Retention periods for analytics and advertising data depend on the settings of the relevant service and are shown in the cookie preferences or the provider’s policy.
  • Reviews are retained until they are deleted, consent is withdrawn or the purpose of publication ends, unless further retention is required to protect against misuse or legal claims.
  • Photographs and video recordings are retained until the agreed service has been performed, the stated purpose ends or consent is withdrawn, unless there is another legal basis.

At the end of the retention period, data is deleted or anonymised. Backups may be retained until their scheduled overwrite and are not used for other purposes.

20. Your rights

Where the statutory requirements are met, you have the right to:

  • obtain access to the data being processed pursuant to Article 15 GDPR;
  • request rectification of inaccurate data or completion of incomplete data pursuant to Article 16 GDPR;
  • request erasure of data pursuant to Article 17 GDPR;
  • request restriction of processing pursuant to Article 18 GDPR;
  • receive the data you have provided in a structured, commonly used and machine-readable format and, where applicable, transmit it to another controller pursuant to Article 20 GDPR;
  • object to processing pursuant to Article 21 GDPR;
  • withdraw consent previously given with effect for the future pursuant to Article 7(3) GDPR;
  • lodge a complaint with a competent supervisory authority pursuant to Article 77 GDPR.

You may submit a request to shakeparty.de@gmail.com. To protect personal data, we may request the information reasonably necessary to verify the requester’s identity.

The supervisory authority competent for our place of business is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7
65185 Wiesbaden
Germany
Telephone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: datenschutz.hessen.de

You also have the right to contact any other competent supervisory authority, in particular the authority for your habitual residence, place of work or the place of the alleged infringement.

21. Specific right to object

Where processing is based on Article 6(1)(f) GDPR, you have the right to object to it at any time on grounds relating to your particular situation. Following an objection, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.

Where personal data is processed for direct marketing purposes, you have the right to object to such processing at any time without stating specific reasons. Once we receive your objection, the data will no longer be used for direct marketing.

22. Automated decision-making

Shake Party does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

Following consent, analytics and advertising providers may create interest profiles to measure or personalise advertising. Shake Party does not use these profiles to make legally significant decisions about a customer. Payment providers may independently use automated payment, creditworthiness and fraud checks; information about such procedures and the related rights is provided in the relevant provider’s policy.

23. Security measures

We implement reasonable technical and organisational measures appropriate to the nature of the data and the level of risk. These include, in particular, encryption in transit, access controls, secure accounts, system updates, backups, data minimisation and provider checks.

Data transmission over the internet cannot be protected against every risk with absolute certainty. We cannot guarantee absolute security, but we take measures to prevent accidental or unlawful loss, alteration, disclosure and unauthorised access.

24. Changes to this Privacy Policy

We may update this Privacy Policy if the website, connected services, processing practices or applicable law change. The current version is published on this page together with its date.

If a change requires renewed consent or a separate notice, we will meet that requirement. Amending the text of this Privacy Policy does not in itself retroactively create a new legal basis for processing already carried out.