Skip to content
White Bunny Creations

GDPR

White Bunny Creations Logo
Working The Magic!

 

UK GDPR Compliance Policy

Last updated: 1 June 2026

This policy outlines how White Bunny Creations © complies with the UK General Data Protection Regulation (UK GDPR) as retained in domestic law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018.

1. Data Controller

White Bunny Creations ©  is the Data Controller for personal data collected through our business activities. Our contact details are: contact@whitebunnycreations.co.uk

White Bunny Creations, Office 150067, P O Box 7169, Poole, Dorset, ENGLAND, UK. BH15 9EL.

2. The Six Principles of UK GDPR (Our Commitments)

  1. Lawfulness, fairness and transparency — We process personal data lawfully, fairly and in a transparent manner.
  2. Purpose limitation — We collect personal data for specified, explicit and legitimate purposes and do not process it in a manner incompatible with those purposes.
  3. Data minimisation — We only collect the minimum personal data necessary for the purposes stated.
  4. Accuracy — We take reasonable steps to ensure personal data is accurate and kept up to date.
  5. Storage limitation — We do not keep personal data for longer than necessary. See our retention schedule in the Privacy Policy.
  6. Integrity and confidentiality — We process personal data securely using appropriate technical and organisational measures.

3. Lawful Bases for Processing

We rely on the following lawful bases under UK GDPR Article 6:

  • Contract (Article 6(1)(b)): Processing necessary for fulfilment of sales contracts
  • Legitimate interests (Article 6(1)(f)): Analytics, fraud prevention, business management
  • Legal obligation (Article 6(1)(c)): Tax records, HMRC compliance
  • Consent (Article 6(1)(a)): Email marketing subscriptions

Where we process special category data (we do not currently do so), the additional conditions under Article 9 would apply.

4. Individual Rights Under UK GDPR

We have implemented processes to handle the following data subject rights within the required timeframes (generally one calendar month):

  • Right of access (Subject Access Request — SAR)
  • Right to rectification
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Rights related to automated decision-making and profiling

To exercise any right, email contact@whitebunnycreations.co.uk with “Data Subject Request” in the subject line.

5. Data Breach Procedure

In the event of a personal data breach, we will:

  • Contain the breach immediately upon discovery
  • Assess the risk to individuals and determine whether notification is required
  • Notify the ICO within 72 hours if the breach is likely to result in a risk to individuals’ rights and freedoms
  • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights
  • Document all breaches in our breach register, regardless of whether notification is required

6. Data Processors & Third Parties

We have Data Processing Agreements (or rely on established contracts/standard contractual clauses) with our key data processors including Mailerlite, Stripe, Google, Etsy, Amazon, Payhip, and Gumroad. A record of our data processing activities is maintained as required by UK GDPR Article 30.

7. International Transfers

Where personal data is transferred outside the UK, we ensure adequate safeguards are in place, including Standard Contractual Clauses, UK adequacy regulations, or other approved transfer mechanisms.

8. Privacy by Design

We build data protection into our products and services from the outset. New products, systems, or processes that involve personal data are assessed for privacy risk before implementation.

9. Contact the ICO

You have the right to complain to the Information Commissioner’s Office (ICO) at any time. Website: ico.org.uk | Helpline: 0303 123 1113