Data Protection & Privacy Notice


This Privacy Notice explains how Isle of Eriskay Spirits Company (“we”, “us”, “our”) collects, uses, stores, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


Address:

Isle of Eriskay Spirits Company

5a Balla

Isle of Eriskay

HS8 5JL


What Is Personal Data

Personal data is any information that can identify an individual, including (but not limited to) name, email address, telephone number, postal address, IP address, payment details, or online identifiers.


How We Collect Personal Data

We may collect personal data when you:

  • Purchase products from our website

  • Create an account or place an order

  • Contact us with an enquiry

  • Subscribe to marketing communications

  • Interact with our website (including cookies and analytics)

  • Leave reviews or comments


Purpose and Lawful Basis for Processing


We process personal data only where there is a lawful basis to do so, including:

  • Contractual necessity: to process orders, payments, deliveries, and customer support

  • Consent: for marketing communications where you have opted in

  • Legal obligation: to meet tax, accounting, and regulatory requirements (including alcohol sales)

  • Legitimate interests: to operate and improve our business, prevent fraud, and ensure website security


Your personal data will only be used for the purposes for which it was collected.


Marketing Communications


We will not send marketing communications without your consent.


If you have subscribed, you may receive information about products, events, or news related to Isle of Eriskay Spirits Company. You can unsubscribe at any time using the link in marketing emails or by contacting us directly.


Fraud Prevention

We may carry out checks to prevent fraud and protect our business. This may include processing personal data and, where legally required, sharing information with law enforcement or regulatory authorities.

How We Store and Protect Your Data

We:

  • Keep personal data accurate and up to date

  • Store data securely using appropriate technical and organisational measures

  • Limit access to personal data to authorised personnel only

  • Do not collect or retain excessive data


Data Retention


We retain personal data only for as long as necessary:

  • Customer orders and accounting records: up to 10 years (legal and tax requirements)

  • Inactive customer accounts: up to 6 months

  • Pending, failed, or cancelled orders: up to 6 months

  • Completed orders: up to 10 years

  • Website enquiries: up to 6 months

  • Comments or reviews: retained unless removal is requested


When data is no longer required, it is securely deleted.


Website Cookies & Analytics

We use cookies to:

  • Confirm age eligibility for alcohol-related content

  • Improve user experience

  • Prevent repetitive popups

  • Analyse website usage

We may use anonymised analytics tools to understand website traffic. IP addresses are anonymised, and no personal data is used to identify individual users.

You can manage cookie preferences through your browser settings.


E-Commerce & Payments

When you purchase from us, we may collect:

  • Name

  • Billing and shipping address

  • Email address

  • Telephone number

  • Payment details (processed securely by third-party payment providers)

  • Order history

Payment processing is handled by secure third-party providers (such as Stripe or PayPal). Only the data necessary to complete the transaction is shared with them. We do not store your card details.

Who Has Access to Your Data


Members of our team may access personal data where necessary to:

  • Process orders

  • Arrange deliveries

  • Handle refunds or complaints

  • Provide customer support


Access is limited to what is strictly required


Sharing Your Data


We do not sell or share your personal data with third parties for marketing purposes.

Data may only be shared:

  • With payment providers to process transactions

  • Where required by law or regulatory authorities


Your GDPR Rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure of your data (where applicable)

  • Withdraw consent at any time

  • Request restriction of processing

  • Request data portability

  • Lodge a complaint with the Information Commissioner’s Office (ICO)


Contact Us


To exercise your rights or raise a concern about how your data is used, please contact:


Isle of Eriskay Spirits Company

5a Balla

Isle of Eriskay

HS8 5JL

By using our website or services, you acknowledge that your personal data may be processed in accordance with this Privacy Notice