Thorn Books Logo

Privacy & Cookie Policy

1. Introduction

Steve Farnsworth (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy & Cookie Policy explains how we collect, use, store and share your personal data, how cookies and similar technologies are used, and your rights under the UK GDPR, the EU GDPR as applicable, and the UK Privacy and Electronic Communications Regulations (PECR). We may update this policy from time to time; the version published on the website applies.

2. Data Controller

The data controller for the purposes of data protection laws is:

Steve Farnsworth
Email: info@thederwenttrilogy.com

3. What Personal Data We Collect and Why

We may collect the following personal data:

  • Contact information you provide (name, email address) when you subscribe to our newsletter or contact us.
  • Website usage data via Google Analytics 4 (GA4) such as anonymised IP address, device type, browser type, pages visited, time on site.
  • Transaction details if you purchase directly via this website or through our marketplace partners.

We use your personal data to deliver services, manage orders, analyse usage, comply with legal obligations, and send marketing communications where you have given consent.

4. Lawful Basis for Processing

  • Performance of a contract (purchases and fulfilment)
  • Legal obligation
  • Consent (marketing and non-essential cookies)
  • Legitimate interests (analytics, service improvement)

5. Cookies and Similar Technologies

We use cookies and similar technologies in accordance with UK PECR and the EU ePrivacy Directive. You can manage cookie preferences at any time through our cookie banner or browser settings.

  • Strictly necessary cookies enable core website functionality.
  • Analytics cookies (such as GA4) are used with your consent.

6. Data Sharing and Third Parties

We may share your personal data with payment processors, shipping partners, analytics providers (Google), and marketplace platforms (Amazon UK, Bannister Publications Ltd). Appropriate safeguards are in place to protect your data.

7. International Transfers

Your personal data may be transferred outside the UK/EEA (e.g., Google servers). Where this occurs, standard contractual clauses or equivalent safeguards are applied.

8. Data Retention

We keep your personal data only as long as necessary for the purposes collected or as required by law. Retention periods are reviewed regularly.

9. Your Rights

You have the following rights under UK and EU GDPR:

  • Access, rectification, erasure
  • Restriction or objection to processing
  • Data portability
  • Withdraw consent

To exercise your rights, please contact us at the email address above. You also have the right to lodge a complaint with the ICO or your local authority.

10. Marketing Communications

We will only send you marketing communications if you have given explicit consent or have an existing customer relationship. You can unsubscribe at any time.

11. Changes to This Policy

We may update this policy periodically. The most recent version will always be available on this page.