Free UK shipping | Fully customised & printed | Certified sustainable materials | Delivery in 2-4 weeks
Privacy Policy
Last updated: February 2026
1. Data Controller
The data controller responsible for processing your personal data on this website is:
KAiLAR UG (haftungsbeschränkt)
Viererblock 18a
39326 Wolmirstedt
Germany
Managing Directors: Lea Rademacher, Ole Koslowski
Commercial Register: Amtsgericht Stendal, HRB 26608
VAT ID: DE322762389
We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your personal data when you visit our website or use our services, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
We may collect the following types of personal data:
2.1 Data you provide to us
- Contact information: Name, email address, phone number, and business address when you submit a quote request or contact us.
- Order information: Details about the products you order, including quantities, specifications, and design files you upload.
- Payment information: Bank details or payment references necessary for transaction processing.
- Newsletter subscription: Email address when you sign up for our newsletter.
2.2 Data collected automatically
- Server log data: IP address, browser type and version, operating system, referring URL, date and time of access, and pages visited.
- Cookie data: Information collected through cookies and similar technologies (see our Cookie Policy).
3. Legal Basis for Processing
We process your personal data based on the following legal grounds under UK GDPR:
- Contract performance (Art. 6(1)(b)): Processing necessary to fulfil your order, respond to enquiries, and provide our services.
- Consent (Art. 6(1)(a)): Where you have given consent, e.g. for newsletter subscriptions, analytics cookies, and marketing cookies.
- Legitimate interests (Art. 6(1)(f)): For website security, fraud prevention, improving our services, and ensuring proper website functionality.
- Legal obligation (Art. 6(1)(c)): Where processing is required to comply with tax, accounting, or other legal requirements.
4. How We Use Your Information
We use your personal data to:
- Process and fulfil your orders, including design review and production
- Respond to your enquiries and provide customer support
- Send you order confirmations, updates, and delivery notifications
- Send you marketing communications (only with your consent)
- Improve our website, products, and services
- Ensure website security and prevent fraud
- Comply with legal and regulatory obligations
5. Data Sharing and Third Parties
We do not sell your personal data. We may share your data with the following categories of recipients:
- Manufacturing partners: To produce your custom products (order details and design files only).
- Shipping providers: To deliver your products (name, address, and contact details).
- Payment processors: To process payments securely.
- Hosting and IT providers: Who maintain our website and email infrastructure.
- Legal authorities: When required by law or to protect our legal rights.
All third-party processors are contractually obligated to handle your data securely and only for the purposes we specify, in compliance with UK GDPR.
6. International Data Transfers
As our company is based in Germany and we work with partners in the EU, your data may be transferred to and processed in countries within the European Economic Area (EEA). The UK has an adequacy decision with the EU, meaning your data is afforded equivalent protection.
Where data is transferred outside the UK and EEA (e.g. to analytics providers with servers in the United States), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner’s Office (ICO), or adequacy decisions where applicable.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to operate our website and its features. Some cookies are strictly necessary for the website to function, while others require your consent and are used for analytics and marketing purposes.
You can manage your cookie preferences through our cookie consent banner at any time. For detailed information about the cookies we use and their purposes, please see our Cookie Policy.
You can also manage cookies through your browser settings:
8. Newsletter and Email Marketing
If you subscribe to our newsletter, we use your email address to send you updates about our products and services, based on your consent (Art. 6(1)(a) UK GDPR). You can unsubscribe at any time by clicking the unsubscribe link in any newsletter email or by contacting us. After unsubscribing, we will delete your email address from our mailing list.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Order data: For the duration of our business relationship plus any applicable statutory retention period (typically 6–10 years for tax and accounting purposes).
- Enquiry data: Deleted after your enquiry has been fully resolved, unless you become a customer.
- Newsletter data: Until you unsubscribe.
- Server logs: Deleted after 7 days.
10. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): Request deletion of your data where there is no compelling reason for continued processing.
- Right to restrict processing (Art. 18): Request that we limit how we use your data.
- Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the details in section 12 below. We will respond to your request within one month.
11. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113
12. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal data, please contact us:
KAiLAR UG (haftungsbeschränkt)
Email: hello@custom-rolling-papers.co.uk
Viererblock 18a, 39326 Wolmirstedt, Germany