Privacy Notice

Privacy Notice — Printem Printing & Embroidery Limited

Version 1.1 — 9 September 2026
Last updated: 9 September 2026

This Privacy Notice explains how Printem handles personal data. If you have questions or want to object to any use described here, contact accounts@printem.co.uk.

1. Introduction and scope

This Privacy Notice explains how Printem Printing & Embroidery Limited (“Printem”, “we”, “us”, “our”) collects, uses and protects personal data when you:

  • visit or buy from our website at printem.co.uk (including our Shopify storefront and checkout);
  • order from us offline — by email, phone, post or in person;
  • apply for or operate a trade credit account;
  • supply artwork, proofs, name lists or End User fulfilment details; or
  • communicate with us about quotes, orders, accounts or marketing.

It covers both Trade Customers (businesses) and Consumers (individuals buying for personal use), and applies to online and offline dealings.

We process personal data under the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

This notice is not aimed at children. We do not knowingly collect personal data from anyone under 16.

Our Terms and Conditions of Sale are separate and are not a privacy notice (see Condition 22.1 of those Conditions). This Privacy Notice is the document referred to at printem.co.uk/privacy.

2. Who we are (data controller)

For website visitors, enquirers, customers, account contacts and suppliers, Printem is the data controller.

Legal name Printem Printing & Embroidery Limited
Company number 12644413
VAT number GB 508 4769 64
Registered / trading address Unit 11/12 Hall Farm, Sywell Aerodrome, Sywell, Northamptonshire, England NN6 0BN
Website printem.co.uk
Privacy / data protection requests accounts@printem.co.uk
Sales / orders sales@printem.co.uk
Accounts / credit / invoices accounts@printem.co.uk
General (director) ben@printem.co.uk

Please send all privacy requests (access, erasure, marketing opt-out, complaints about our handling of personal data) to accounts@printem.co.uk.

In some situations — for example where a Trade Customer gives us End User name lists or fulfilment addresses — we act as a processor (or sub-processor). See section 9.

3. How to complain (ICO)

You have the right to complain to the UK Information Commissioner’s Office (ICO) about how we handle your personal data.

We would prefer that you contact us first at accounts@printem.co.uk so we can try to resolve the matter.

4. What personal data we collect

Depending on how you deal with us, we may process:

Category Examples
Identity and contact Name, job title, company name, billing and delivery addresses, email, phone, customer / account reference
Trade account and credit Application details, Companies House / company identifiers, credit decisions, payment terms, guarantor or director details where relevant
Orders and transactions Quotes, order lines, proofs approvals, delivery instructions, invoices, returns, complaints
Payment / financial Payment status, bank transfer references, card payments handled by payment providers (we do not store full card numbers)
Artwork and production Artwork files, logos, digitised stitch files, screens/separations, proofs, colourways, and any personal data shown in designs (e.g. names on garments)
End User / fulfilment files Name lists, staff or wearer names, third-party delivery names and addresses supplied by a Trade Customer
Technical / website IP address, browser/device data, cookie identifiers, pages viewed, Shopify session and checkout data
Marketing preferences Opt-in / opt-out status, suppression records, consent evidence
Correspondence Emails, call notes, messages about quotes, orders, accounts or complaints

We do not collect special category data as a routine part of our decoration business. Please do not send us health, biometric or other special category data unless we have asked for it in writing for a specific lawful purpose.

5. How we collect personal data

We collect personal data:

  1. Directly from you — website forms, Shopify checkout, trade account applications, email, phone, post, site visits, artwork uploads and proofs.
  2. Automatically — essential Shopify cookies and, if you consent, analytics or similar technologies on printem.co.uk.
  3. From third parties, where appropriate:
    • Companies House and public company registers;
    • Creditsafe and other credit-reference agencies;
    • payment providers and banks (payment confirmation);
    • carriers such as DPD (delivery status);
    • Trade Customers who supply End User or fulfilment data for us to process on their instructions;
    • professional advisers (e.g. accountants) where relevant to our relationship with you.

6. Purposes and lawful bases

We only use personal data where we have a lawful basis under UK GDPR. The main mappings are:

Purpose Lawful basis
Providing quotes, taking and fulfilling orders (online and offline), proofs, manufacture, delivery, returns and customer service Contract (or steps before entering a contract)
Operating Shopify checkout and your customer account Contract / legitimate interests (running our online store)
Trade credit applications, credit decisions, account management and credit control Contract and/or legitimate interests (assessing and managing credit risk)
Keeping accounting, VAT, tax and Companies Act records Legal obligation
Fraud prevention, IT and network security, defending legal claims Legitimate interests
Business-to-business email or other marketing to corporate subscribers Legitimate interests (promoting our services to business contacts), with PECR opt-out
Email / SMS marketing to sole traders, partnerships treated as individual subscribers, or Consumers Consent or, where PECR allows, soft opt-in, plus a matching UK GDPR basis
Non-essential cookies, analytics and similar technologies Consent (PECR and UK GDPR)
Using customer artwork and name lists to decorate and fulfil an order Contract with the customer; where End User data is supplied by a Trade Customer, we process as processor on their instructions
Photos of branded work in our marketing Legitimate interests (show our work), with a written opt-out — see Condition 8.6 of our Terms
Sharing with carriers, payment providers, Shopify, outworkers, accountants or debt recovery as needed to run the business or recover sums due Contract, legitimate interests and/or legal obligation, as applicable

Legitimate interests. Where we rely on legitimate interests, we balance our interests against your rights. You can object — see section 16. Credit-reference data is not used for marketing.

7. Trade customers and consumers

We mainly supply Trade Customers (B2B), but Consumers may also buy from us online or offline.

  • If you buy as a Consumer, we still need your contact and order data to fulfil your purchase and meet our legal duties.
  • If you buy as a Trade Customer, we may also process account, credit and End User fulfilment data as described below.
  • Named individuals at a business (e.g. a buyer’s work email) are still personal data under UK GDPR.

For electronic marketing rules under PECR, see section 10.

8. Trade accounts and credit-reference checks

When you apply for a trade credit account, or we assess or recover credit, we may:

  • check information at Companies House (and similar public registers); and
  • carry out searches with credit-reference agencies, including Creditsafe, and other agencies where appropriate.

Checks may cover the business and, where relevant, directors, owners or guarantors, so we can assess creditworthiness, set payment terms, prevent fraud and manage risk. Until credit is approved, orders are usually accepted on a pro forma basis (as stated on our account application).

What we share. We may share Trade Customer identity and contact details, company identifiers, application information and payment-performance information with Creditsafe or another credit-reference agency, and with debt-recovery providers if sums are overdue — as described in Condition 21.3 of our Terms.

Lawful basis. Contract and/or legitimate interests (credit risk). This processing is not used for marketing.

Credit-reference agencies keep their own records and have their own privacy notices. Individuals may have rights to access information held by those agencies — see the ICO’s public guidance on credit: https://ico.org.uk/for-the-public/credit/.

Retention of credit files. We keep trade account and credit files (including decision rationale) for the life of the account plus 6 years after closure or decline.

9. Customer-supplied End User, artwork and name-list data (controller vs processor)

9.1 When Printem is the controller

We are the controller of personal data about our own customers, website visitors, enquirers, account contacts and suppliers (billing contacts, order history, credit files, marketing preferences, and so on).

9.2 When the Trade Customer is the controller and Printem is the processor

Where a Trade Customer provides End User names, addresses or other personal data for fulfilment (for example staff or wearer name lists for embroidery, or delivery contacts at a third site), then — aligning with Condition 22.2 of our Terms:

  • the Trade Customer is the controller;
  • Printem is the processor (or sub-processor) of that End User data.

The Trade Customer must have a lawful basis and any notices or consents needed to give us that data. We will:

  • process it only on the Trade Customer’s documented instructions (including the order and our Terms) to pack and deliver (including related decoration and fulfilment as instructed);
  • use appropriate technical and organisational measures;
  • not appoint a sub-processor other than carriers (e.g. DPD) and our usual outworkers without informing the Trade Customer;
  • assist with reasonable data-subject and breach requests; and
  • delete or return the data after the job unless the law requires storage, or the Trade Customer instructs longer storage under a processor arrangement / data-processing agreement (DPA).

A written DPA is available on request for Trade Customers who need one.

9.3 Artwork, proofs and Intermediates

We use artwork, proofs and related files only to produce and support your order (and related customer service). Separately, unless you opt out in writing, we may photograph and use images of finished decorated work in our marketing under Condition 8.6 of our Terms (licence to show the finished job; not ownership of your brand; credit/tags where reasonably practicable).

You confirm you have the right to supply the artwork and any personal data in it. Asking us to erase data does not cancel bespoke work already in progress and does not override invoices or tax records we must keep.

We may store Artwork and Intermediates for up to 12 months after the last related production (Condition 9.4); we may delete sooner. See section 14.

10. Marketing and PECR

We may send service messages about your orders or account (these are not marketing).

For marketing (offers, newsletters, new services):

  • Corporate subscribers (most limited companies and similar): PECR’s electronic-mail consent rule does not apply in the same way as for individuals, but we still need a UK GDPR lawful basis (usually legitimate interests), we identify ourselves as the sender, and we always provide a way to opt out.
  • Sole traders, some partnerships, and Consumers (individual subscribers): we rely on consent or, where the PECR soft opt-in conditions are met, soft opt-in, together with a matching UK GDPR basis.
  • If we are unsure whether an address is corporate or individual, we treat it carefully as an individual subscriber.
  • You can opt out at any time — use the unsubscribe link or email accounts@printem.co.uk. We will keep a minimal suppression record so we do not contact you again by mistake.
  • You have an absolute right to object to direct marketing (UK GDPR Article 21).
  • We do not sell, rent or trade mailing lists for others’ marketing.
  • Unless you opt out in writing, we may photograph and use images of your finished decorated work in our marketing (Condition 8.6). Email sales@printem.co.uk or accounts@printem.co.uk to opt out. We will give credit and/or social tags where reasonably practicable. Opt-out does not require us to recall materials already published in good faith.

11. Cookies and similar technologies

Our website is built on Shopify. Like most Shopify stores, we use:

  • Essential cookies — needed for the site, basket, checkout and security to work. These do not require consent.
  • Non-essential cookies / analytics — for example Shopify analytics and, if enabled, tools such as Google Analytics, to understand how the site is used. These are set only with your consent.

We will put a cookie banner on the site so you can accept, reject or manage non-essential cookies. Rejecting non-essential cookies will be as easy as accepting them. You can change your mind later via cookie settings on the site (once available).

Analytics retention is typically up to 14 months unless the tool is set shorter or you withdraw consent.

We may publish a short separate Cookie Policy if the banner and site settings need more detail. We will not invent specific advertising pixel names here; if we add marketing pixels later, we will update this notice and the banner.

12. Who we share personal data with

We share personal data only where needed, including with:

Recipient Why
Shopify Hosting the storefront, checkout, orders and related apps
Payment providers Taking and confirming card or other online payments (provider to be named in the live notice once confirmed — e.g. Shopify Payments or equivalent)
DPD and other carriers we nominate Delivery and tracking
Creditsafe and other credit-reference agencies Trade credit assessment and credit control
Companies House / public registers Company verification (look-ups; we do not “share” customer data with CH in the ordinary sense beyond using public data)
Accountants and professional advisers Bookkeeping, tax, audit and legal advice
Outworkers / subcontractors Digitising, print or embroidery capacity when we use them to fulfil your order
Debt-recovery providers Recovering overdue sums where needed
Insurers / brokers Claims or cover where relevant
Law enforcement or regulators Where the law requires or allows

We require processors to protect personal data appropriately and to use it only on our instructions (or, for End User data, on the Trade Customer’s instructions as reflected through us).

13. International transfers

Some providers — notably Shopify and certain payment or IT tools — may process personal data outside the United Kingdom (including in the United States).

Where personal data leaves the UK, we use UK-approved safeguards such as:

  • an adequacy decision where one applies; or
  • the UK International Data Transfer Agreement (IDTA); or
  • the EU Standard Contractual Clauses (SCCs) with the UK Addendum,

as appropriate to the provider.

We do not rely on the former EU–US Privacy Shield.

14. How long we keep personal data

Category Retention
Orders, invoices, accounting and tax records 6 years after the end of the relevant tax year / last transaction
Trade account and credit files (including Creditsafe decision rationale) Life of the account + 6 years after closure or decline
Artwork, digitised files, proofs / Intermediates Up to 12 months after last related production (may delete sooner); erasure does not override tax records or cancel bespoke work in progress
End User / name-list / fulfilment personal data supplied by a Trade Customer Delete or return promptly after fulfilment (target within 90 days of delivery), unless the Trade Customer instructs longer storage under a processor arrangement / DPA, or law requires retention
Marketing lists Until opt-out or objection; keep a suppression list; keep consent evidence while marketing continues and for about 2 years afterwards
Unconverted enquiries / quotes 2 years from last meaningful contact
Complaint / dispute files Until resolved + 6 years
Analytics cookies Per tool settings / while consented — typically up to 14 months unless shorter

We do not operate CCTV at our premises for the purposes of this notice.

15. Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse. Access to customer and account data is limited to people who need it for their role. Where a personal-data breach must be notified to the ICO or to individuals, we will do so as the law requires.

16. Your rights

Under UK GDPR you may have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data (the “right to be forgotten”), subject to legal retention duties;
  • restrict processing in certain cases;
  • data portability, where applicable;
  • object to processing based on legitimate interests, and to object absolutely to direct marketing;
  • withdraw consent where we rely on consent (withdrawal does not affect earlier lawful processing).

To exercise these rights, email accounts@printem.co.uk. We may need to verify your identity. We aim to respond within one month (or explain if we need longer, as UK GDPR allows).

These Conditions of Sale do not waive data-subject rights (Condition 22.3). Asking us to erase data does not cancel an order for bespoke goods already in production and does not require us to destroy invoices or other records we must keep for tax or legal reasons.

17. Changes to this notice

We may update this Privacy Notice from time to time. The “Last updated” date at the top will change when we do. Material changes will be highlighted on the website or, where appropriate, notified to account customers.

18. Contact us

Printem Printing & Embroidery Limited
Unit 11/12 Hall Farm, Sywell Aerodrome, Sywell, Northamptonshire, England NN6 0BN

Company number 12644413 · VAT GB 508 4769 64

Version 1.1 — 9 September 2026.