Privacy Policy

Sensory Education Ltd · Last updated 8 September 2026

This Privacy Policy explains how Sensory Education Ltd (“Sensory Education”, “we”, “us” or “our”) collects, uses, discloses, retains and otherwise processes personal data when you visit our website, communicate with us, create an account, place or receive an order, use our services, interact with our advertising or otherwise deal with us.

This notice is intended to provide the information required by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable electronic communications law. It should be read with our Terms and Conditions, Cookie Policy and any specific notice shown when information is collected.

1. Who we are and how to contact us

Sensory Education Ltd is the controller of personal data covered by this Policy, except where another controller is identified at the point of collection.

Sensory Education Ltd
Unit W1, Westpoint Business Park
Aldridge
Walsall
WS9 8DT

Email: customercare@sensoryeducation.co.uk

Please mark privacy enquiries “Data Protection”. We may require evidence reasonably necessary to verify identity and authority before acting on a request.

2. Scope and responsibility

This Policy applies to personal data processed through sensoryeducation.co.uk, associated customer accounts, support channels, order fulfilment, marketing, fraud prevention and business administration. Third-party websites, platforms and services have their own privacy practices. We are not responsible for their independent processing merely because we link to or integrate with them.

If you give us personal data about another person, including a recipient, parent, pupil, employee, colleague or authorised contact, you confirm that you are permitted to provide it and, where required, have made this Policy available to them.

3. Personal data we collect

Depending on how you interact with us, we may collect and derive:

  • Identity and contact data: name, title, organisation, job role, delivery and billing addresses, email address, telephone number and account identifiers.
  • Transaction and payment data: orders, products, amounts, discounts, refunds, invoices, purchase orders, payment status, limited card details such as card type and last four digits, chargeback information and fraud-screening results. Full card details are generally processed by payment providers rather than stored by us.
  • Account and preference data: credentials, saved details, wish lists, communication choices, interests, account activity and customer-service history.
  • Technical and usage data: IP address, device and browser information, identifiers, cookie and pixel data, approximate location, referral source, pages, searches, clicks, basket activity, session events, diagnostic logs and interaction with messages or adverts.
  • Communications and content: emails, chats, forms, reviews, survey responses, telephone or other support records, images, documents and information supplied in claims or disputes.
  • Delivery and verification data: tracking events, delivery instructions, proof-of-delivery information, photographs, parcel weights, signatures where used and information used to investigate loss, damage or non-receipt.
  • Business and due-diligence data: organisation details, authorised buyers, credit status, references, public-register information, sanctions or fraud indicators and correspondence concerning debts or legal claims.
  • Inferences: likely preferences, product interests, customer segments, risk indicators and predictions produced from the data above.

Please do not send unnecessary special-category data. Our products may be used by people with disabilities or health needs, but a product purchase does not necessarily reveal health information. If you voluntarily provide health, disability or other sensitive information, we will process it only where necessary and where a lawful condition applies, including explicit consent, legal claims or substantial public interest as permitted by law.

4. How we obtain personal data

We obtain data directly from you and from people ordering for or communicating about you. We may also receive it from Shopify and other commerce providers; payment, identity and fraud-prevention providers; couriers, warehouses, suppliers and returns providers; schools, NHS bodies, charities, employers and purchasing organisations; customer-service and communications platforms; advertising, analytics and social-media partners; credit-reference, debt-recovery and professional advisers; public registers and publicly available sources; and parties involved in corporate transactions or disputes.

5. How we use personal data and our lawful bases

Purpose Typical data Lawful basis
Provide the website, accounts, quotes, orders, delivery, returns, refunds, warranties and customer support. Identity, contact, account, transaction, communications and delivery data. Contract; steps requested before contract; legitimate interests in operating and supporting our business; legal obligation.
Take and reconcile payments; manage invoices, credit accounts, rebates, chargebacks and debt recovery. Identity, contact, transaction, payment, business and communications data. Contract; legitimate interests in receiving payment, managing credit and protecting revenue; legal obligation; legal claims.
Prevent, detect and investigate fraud, misuse, security incidents, false claims, prohibited activity and breaches of our terms. All relevant categories, including technical identifiers, delivery evidence and risk inferences. Legitimate interests in protecting customers, systems, property and legal rights; legal obligation; establishment, exercise or defence of legal claims.
Personalise the service, recommend products, remember choices, measure engagement and improve our website, products, operations and customer experience. Account, transaction, preference, technical, usage and inferred data. Legitimate interests in improving and developing our business; consent where required for cookies or similar technologies.
Advertise, market and promote our products; measure campaigns; build or use audiences; suppress existing customers from unsuitable campaigns. Contact, transaction, preference, technical, usage and inferred data. Consent where required; otherwise legitimate interests, including permitted marketing to existing customers, subject to the right to object or opt out.
Request, moderate, publish and analyse reviews, feedback, surveys and user-submitted content. Identity, communications, content, transaction and technical data. Consent where requested; contract; legitimate interests in obtaining feedback, protecting authenticity and promoting our business.
Comply with tax, accounting, product-safety, consumer, law-enforcement and regulatory duties; respond to lawful requests. Any data reasonably required. Legal obligation; public task where applicable; legitimate interests in compliance and accountability; legal claims.
Operate, secure, analyse, reorganise, sell or finance our business and manage suppliers, advisers, insurance and disputes. Any relevant data, minimised where reasonably possible. Legitimate interests in business administration, resilience, transactions and legal rights; legal obligation; legal claims.

Where we rely on legitimate interests, we consider the purpose, necessity and impact on individuals. You may object as explained below, but an objection is not absolute where we have compelling grounds or need the data for legal claims.

Where processing is necessary to contract with you, failure to provide required information may mean we cannot open an account, accept an order, deliver goods, investigate a claim or provide the requested service.

6. Cookies, analytics and advertising technologies

We and authorised partners may use cookies, pixels, tags, software development kits, local storage and similar technologies to keep the website working, secure sessions, remember preferences, analyse use, attribute sales, personalise content and advertising, and measure campaigns across devices and services.

Where UK law requires consent for non-essential technologies, we seek it through our consent controls. You may withdraw or change that choice through the cookie settings available on the website. Necessary technologies may operate without consent where permitted because they are required to provide a service you requested, maintain security or perform another exempt function.

Blocking technologies may affect site functions. Browser “do not track” signals are not necessarily standardised; we respond to legally recognised preference signals where and to the extent required.

7. Marketing communications

We may send marketing where you consent or where law permits us to market similar products or services to an existing customer. Business contact details may also be used for relevant business marketing where permitted. We may tailor messages using purchase history, browsing activity, engagement and inferred interests.

You can unsubscribe using the link in a marketing message or contact us. We may retain limited suppression information so that we can respect the opt-out. Opting out of marketing does not stop service, safety, account, order, debt or legal communications.

8. Automated processing and fraud controls

We and our providers may use automated tools to score transactions, detect fraud, prioritise security checks, select payment options, personalise content or advertising, and identify unusual account, order, delivery, return or claim activity. Inputs may include identity, transaction, device, location, payment, account-history and behavioural signals.

An automated assessment may result in additional verification, delayed processing, limitation of payment methods, manual review, refusal or cancellation where permitted by our contract and applicable law. Where a decision produces legal or similarly significant effects and Article 22 UK GDPR applies, you may request human intervention, express your view and contest the decision.

9. Sharing personal data

We may disclose personal data, to the extent reasonably necessary, to:

  • Shopify and providers of hosting, ecommerce, customer accounts, communications, reviews, analytics, advertising, security, IT and business software;
  • payment processors, banks, card schemes, lenders, credit-reference, identity-verification and fraud-prevention organisations;
  • warehouses, suppliers, manufacturers, couriers, customs agents, delivery, installation, returns and claims providers;
  • professional advisers, auditors, insurers, debt-recovery agencies, courts, dispute-resolution bodies and law-enforcement, regulatory, tax or public authorities;
  • schools, NHS bodies, charities, employers, framework operators, buying groups and other organisations involved in an order or account;
  • advertising and social-media partners where permitted by law and consistent with your cookie or marketing choices; and
  • prospective or actual purchasers, investors, lenders, sellers, group companies or advisers in connection with a merger, acquisition, restructuring, financing, insolvency, sale of assets or other corporate transaction.

Recipients may act as our processors, independent controllers or joint controllers depending on the service and legal context. We require processors to protect data and act only on documented instructions, subject to lawful exceptions.

We do not disclose personal data merely in exchange for money as an isolated commodity. Some advertising disclosures may nevertheless be described as “sale”, “sharing” or targeted advertising under non-UK laws. Where such laws apply, relevant rights will be honoured.

10. International transfers

We operate a UK business but use global technology, commerce, cloud, payment, analytics, communications, support and logistics providers. Personal data may therefore be accessed, stored or processed outside the United Kingdom, including in the United States and other countries whose laws may differ from UK law.

Where UK transfer restrictions apply, we use one or more lawful safeguards, including UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, another approved mechanism, or a permitted statutory derogation. We may implement supplementary contractual, organisational or technical measures where appropriate.

You may contact us for further information about the relevant safeguard. We may provide a summary or redact commercially sensitive, confidential or third-party information where lawful.

11. Data retention

We keep personal data for as long as reasonably necessary for the purposes described, including to provide services, maintain business and tax records, enforce contracts, prevent fraud, resolve disputes and meet legal, regulatory, insurance and accounting requirements.

Retention varies according to the data, relationship, risk and limitation periods. In general, core order, invoice and accounting records may be retained for at least six years after the relevant transaction or relationship, and longer where reasonably required for an active dispute, legal hold, product-safety issue, fraud prevention, warranty or other lawful purpose. Technical, marketing and support data may be retained for shorter or longer periods according to operational need, consent status, risk and provider settings.

We may delete, anonymise or aggregate data when no longer required. Backups and archived copies may persist until securely overwritten in the ordinary course.

12. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. No system, transmission or storage method is completely secure, and we cannot guarantee absolute security. You are responsible for keeping account credentials confidential and notifying us promptly of suspected compromise.

13. Your UK data-protection rights

Subject to legal conditions and exemptions, you may have rights to:

  • request access to personal data and supplementary information;
  • request correction of inaccurate or incomplete data;
  • request erasure;
  • request restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • withdraw consent without affecting earlier lawful processing;
  • request safeguards concerning qualifying automated decisions; and
  • complain to a supervisory authority.

These rights are not absolute. We may refuse or limit a request where the law permits, including where data is required for legal obligations, freedom of expression, fraud prevention or the establishment, exercise or defence of legal claims. We may ask for information to verify identity, clarify scope or confirm authority. Requests are ordinarily free, but a reasonable fee may be charged or a request refused where it is manifestly unfounded or excessive, as permitted by law.

To exercise a right, email customercare@sensoryeducation.co.uk. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint/. We would welcome the opportunity to address concerns first.

14. Children’s privacy

We sell products for children, but the website and purchasing services are directed to adults, parents, carers, professionals and organisations. Children should not create accounts, place orders or send personal data without appropriate adult involvement. We do not knowingly use a child’s personal data for behavioural advertising where prohibited.

If you believe a child has provided data contrary to this Policy, contact us. We may take reasonable steps to verify parental responsibility or authority before responding to a request concerning a child.

15. Public content and reviews

Information you choose to publish in a review, question or other public contribution may be visible, copied or used by others. Do not publish personal data about another person or information you do not wish to be public. We may moderate, verify, edit or remove content in accordance with our terms, legitimate interests and legal duties.

16. Changes to this Policy

We may update this Policy to reflect changes in law, technology, providers, products or business operations. The current version will be posted on this page with its effective date. Where required by law, we will provide additional notice or seek consent. Continued use does not override any consent requirement imposed by law.

17. General

If any part of this Policy is found invalid or unenforceable, the remaining provisions continue to apply. This Policy does not create contractual rights beyond those required by applicable law. Nothing in it restricts rights that cannot lawfully be excluded.

Privacy request: Include your name, relevant order or account details and a clear description of the request. Do not send full payment-card details, passwords or unnecessary sensitive information.