HomePrivacy Policy
Legal

Privacy Policy

Last updated: 14 June 2026

Obsidian Research ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect information about you when you visit obsidianresearch.co.uk or place an order with us. We operate in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. What Data We Collect

When you use our website or place an order, we may collect the following categories of personal data:

  • Identity data — full name
  • Contact data — email address, postal address
  • Order data — products purchased, order history, SKU references
  • Payment data — processed securely via our payment provider; we do not store card details
  • Technical data — IP address, browser type, device information, pages visited
  • Communications data — messages sent via our contact form
  • Compliance data — age confirmation and research-use declaration

2. How We Use Your Data

We use your personal data only for the purposes for which it was collected:

  • To process and fulfil your orders, including dispatch and delivery
  • To send order confirmations, dispatch notifications, and CoA documentation
  • To respond to enquiries submitted via our contact form
  • To verify age and research-use compliance as required by our terms
  • To improve our website and user experience via anonymised analytics
  • To comply with our legal obligations under UK law

We do not use your data for unsolicited marketing without your explicit consent.

3. Legal Basis for Processing

We process your personal data under the following lawful bases:

  • Contract — processing is necessary to fulfil your order
  • Legal obligation — we are required to verify age and research-use compliance
  • Legitimate interests — improving our website and preventing fraud
  • Consent — where you have explicitly opted in (e.g. marketing communications)

4. Data Sharing

We do not sell, rent, or trade your personal data. We may share your data with trusted third parties only where necessary:

  • Payment processors — to securely handle card transactions
  • Delivery and logistics providers — to dispatch and track your order
  • IT and hosting providers — to operate and maintain our website securely
  • Legal and regulatory authorities — where required by law

All third-party processors are contractually bound to handle your data in compliance with UK GDPR.

5. Data Retention

We retain your personal data only for as long as necessary:

  • Order records — retained for 7 years to comply with UK tax and accounting obligations
  • Contact form enquiries — retained for 12 months, then securely deleted
  • Technical/analytics data — anonymised and retained for up to 24 months
  • Compliance records (age/research verification) — retained for the duration required by applicable regulations

6. Cookies

Our website uses cookies to ensure it functions correctly and to understand how visitors use the site. Cookies we use include:

  • Essential cookies — required for the website to operate (e.g. session management)
  • Analytics cookies — anonymised data to help us understand site usage

You can control cookie settings through your browser. Disabling certain cookies may affect website functionality.

7. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of the data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your data where no legal obligation requires retention
  • Right to restrict processing — request we limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — where processing is based on consent, you may withdraw at any time

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted data transmission (HTTPS), access controls, and regular security reviews.

No method of transmission over the internet is 100% secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.

9. Contact & Data Controller

Obsidian Research is the data controller for personal data collected through this website.

For any privacy-related queries, requests, or complaints:

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The date at the top of this page indicates when it was last revised. Continued use of our website after any changes constitutes acceptance of the updated policy.