Pandora’s Keepsakes
www.pandoras-keepsakes.co.uk
Last updated: April 2026

1. Who I am

Pandora’s Keepsakes creates handcrafted memorial and keepsake jewellery from ashes, hair, breastmilk, flowers, and other cherished materials.
I am based in Carmarthenshire, Wales, and I work with families across the UK.

2. The purpose of this policy

This policy explains how I collect, use, store, and protect your personal information when you visit my website, contact me, or place an order.

3. What personal data I collect

I may collect:

• Your name
• Your email address
• Your postal address
• Your phone number (if provided)
• Order details
• Photos you choose to send
• Messages you send through my website, email, or social media
• Technical data such as IP address, browser type, and cookies


Important:
Ashes, hair, breastmilk, flowers, and other physical materials are not personal data under GDPR.
However, the communications around them (names, addresses, order notes, photos) are.

4. How I collect your data

• Through website forms
• Through email
• Through social media messages
• Through Etsy (if you order there)
• Through analytics tools (if you consent to cookies)


5. Why I collect your data (lawful bases)

I process your data under the following lawful bases:

Contract

To create and deliver your jewellery, answer questions, and manage your order.

Recognised Legitimate Interests (2026 UK GDPR update)

For:

• Internal administration
• Preventing fraud
• Responding to enquiries
• Basic website analytics (if consented)


Consent

For:

• Email marketing (if you sign up)
• Non‑essential cookies
• Optional photo sharing or testimonials


You can withdraw consent at any time.

6. How I use your data

• To respond to your messages
• To prepare and deliver your order
• To keep records for tax and accounting
• To improve my website
• To send updates (only if you opted in)


I do not sell or share your data with advertisers.

7. Special materials (ashes, hair, breastmilk, flowers)

These materials are handled with care, dignity, and confidentiality.
They are stored securely and returned or respectfully disposed of according to your instructions.
No personal data is extracted from them.

8. Who I share your data with

Only when necessary:

• Webador (website hosting)
• Email provider
• Payment processors (e.g., Etsy, PayPal)
• Delivery companies (Royal Mail, couriers)
• Analytics tools (only if you consent to cookies)


All providers meet UK GDPR requirements.

9. How long I keep your data

• Order records: 6 years (legal requirement)
• Emails and messages: up to 2 years
• Photos you send: deleted after order completion, unless you consent to reuse
• Website analytics: as per cookie settings


10. Your rights

You have the right to:

• Access your data
• Correct your data
• Request deletion
• Restrict processing
• Object to processing
• Withdraw consent
• Make a complaint to the ICO


11. Subject Access Requests (SARs)

You can request your data at any time.
I may ask for clarification if needed (“stop‑the‑clock” rule).
I respond within one month.

12. Contact

Email: pandoraskeepsakes@outlook.com
Website: www.pandoras-keepsakes.co.uk