Privacy and Cookies Policy – Fonz Leather Styles Ltd.

1. Data Protection Policy Introduction

Fonz Leather Styles Ltd. [we] hold personal data about our employees, clients, suppliers, and other individuals for a variety of business purposes.

This policy defines how we protect personal data and ensures that customers and staff understand the rules governing its use.

Staff must consult the Communications Director before initiating any significant new data processing activity, such as setting up a competition or database with identifiable personal details, to ensure compliance with applicable laws.


2. Why Do We Collect Data?

2.1 Business Purposes

We use personal data for purposes such as sales, personnel, administration, finance, payroll, legal compliance, service operations, and business development.

These purposes include:

  • Order fulfilment and transaction recording

  • Maintaining confidentiality of commercially sensitive information and CCTV

  • Legal and regulatory compliance

  • Supporting investigations by regulatory bodies or in legal matters

  • Policy enforcement and issue resolution

  • Monitoring access, conduct, and performance

  • Staff training and development

  • Marketing and improving our services

  • Health and safety compliance

2.2 Personal Data

Personal data includes names, contact details, user IDs, job information, educational background, payroll data, identification numbers, and more.

2.3 Sensitive Personal Data

This includes data on ethnicity, criminal history, or similar. We do not collect sensitive personal data from customers, prospects, or suppliers.


3. Scope

This policy applies to all employees of Fonz Leather Styles Ltd. who handle personal data. It supplements our policies on internet, email, and other forms of data processing.

3.1 Responsibility

The Operations Manager of Fonz Leather Styles Ltd. is responsible for implementing and overseeing this policy.


4. Our Procedures

4.1 Fair and Lawful Processing

We only process personal data when the individual has consented or when we have a legitimate reason.

4.2 Operations Manager Responsibilities

  • Keeping leadership informed

  • Reviewing procedures

  • Coordinating staff training

  • Responding to data access and privacy requests

4.3 IT Manager Responsibilities

  • Ensuring systems meet security standards

  • Monitoring software integrity

  • Evaluating third-party data processors

4.4 Communications Director Responsibilities

  • Ensuring employee and customer data practices comply

  • Approving data protection disclaimers

  • Reviewing third-party processor contracts

4.5 Finance Director Responsibilities

  • Supporting data accuracy within payroll and sales

4.6 General Processing Principles

All data must be processed in our business interest while respecting individuals' privacy.

4.7 Processing Sensitive Data

We require explicit consent to process sensitive data unless legally required.

4.8 Accuracy and Relevance

We maintain accurate, up-to-date data and correct inaccuracies upon request.

4.9 Updating Data

Staff should report personal data changes to HR. Suppliers or customers must inform the Operations Manager.

4.10 Data Security

We ensure data is secure and include appropriate clauses in third-party contracts.

4.11 Storing Data

  • Paper files are stored securely

  • Unneeded documents are shredded

  • Digital data is encrypted and password-protected

  • Servers are secured and backed up

  • Cloud services must be IT-approved

  • Mobile devices with sensitive data must use encryption

4.12 Data Retention

We only retain data for as long as necessary for its purpose.

4.13 Transferring Data

All transfers must use secure protocols (e.g., HTTPS, SSH).

4.14 International Transfers

International data transfers require prior approval from the Communications Director.


5. Subject Access Requests

Under data protection laws, individuals may request access to their data. These requests must be referred to the Operations Manager.

5.1 Processing in Line with Rights

We do not send direct marketing unless there's an existing relationship or explicit consent. Individuals may opt out at any time.

5.2 Training

All staff will receive regular data protection training.


6. GDPR Provisions

6.1 Transparency

We provide clear information about data usage upon request.

6.2 Lawful Processing

All personal data use must be based on valid legal grounds.

6.3 Justification

We use Consent, Contract, Legal Obligation, or Legitimate Interest as the basis for processing.

6.4 Consent

Consent is actively obtained and may be revoked.

6.5 Criminal Record Checks

Only conducted when legally justified.

6.6 Data Portability

Data subjects can request structured copies of their data, or its transfer to another system.

6.7 Right to Be Forgotten

Data can be erased on request unless exemptions apply (e.g., ongoing contract obligations).

6.8 Privacy by Design

New IT projects must integrate privacy from the outset.

6.9 International Transfers

Require prior consent and oversight.

6.10 Data Audits

Regular audits are conducted to track and assess data practices.

6.11 Breach Reporting

All staff must report data breaches to the Operations Manager.

6.12 Monitoring

The Operations Manager monitors compliance with this policy.

6.13 Complaints

You may file complaints with the UK’s Information Commissioner’s Office:


7. Cookies

ashwoodleather.com uses cookies to enhance user experience and maintain functionality such as shopping carts.

We operate an implied consent policy, assuming you accept cookies unless you disable them via your browser.

If you'd like to learn more about managing cookies, visit:


Your Consent
By using ashwoodleather.com, you consent to our use of cookies unless you disable them.