Your data at HOLY
Protecting your personal data is a genuine concern for us. On the following pages we explain, as clearly as possible, what data we process when you visit our website and its sub-pages, as well as our social media profiles, and for what purpose.
Technology keeps developing, our services change, and the law does not stand still either. For these and similar reasons, it may become necessary to amend this privacy policy. We therefore reserve the right to change it at any time with effect for the future, and we ask you to check back regularly for the current version, which you can always find here.
Personal data is any data that can be related to a specific natural person, e.g. your name or your IP address.
The controller within the meaning of Art. 4(7) of the UK General Data Protection Regulation (“UK GDPR”) is HOLY Softdrinks Ltd (“HOLY”), Broadway 50, London, United Kingdom, email: hello@holy.uk. We are legally represented by Daniel Jon Macken.
Our data protection officer is heyData GmbH (“heyData”), Schützenstraße 5, 10117 Berlin, Germany, www.heydata.eu, email: datenschutz@heydata.eu.
The following principles apply to all processing activities described in this statement. Details on specific processing activities can be found in the respective sections below.
The following may serve as the legal basis for data processing:
- Art. 6(1)(a) UK GDPR (Consent): for processing for which we obtain your consent.
- Art. 6(1)(b) UK GDPR (Contract): where processing is necessary for the performance of a contract or for pre-contractual steps (e.g. when purchasing a product or making enquiries about our products/services).
- Art. 6(1)(c) UK GDPR (Legal obligation): where the processing is necessary for us to comply with a legal obligation, e.g. under tax law.
- Art. 6(1)(f) UK GDPR (Legitimate interests): e.g. for cookies that are necessary for the technical operation of our website.
Where we transfer data to service providers or other third parties outside the UK, we ensure an adequate level of protection as follows:
- UK adequacy regulations, where available (e.g. for the EU/EEA, Canada and Israel).
- USA: UK adequacy regulations, where the service provider is additionally certified under the UK Extension to the EU-US Data Privacy Framework.
- International Data Transfer Agreement (IDTA) / UK Addendum to the EU Standard Contractual Clauses in all other cases, i.e. where we do not indicate otherwise. These form part of our contract with the relevant third party. Many providers have given additional contractual guarantees (e.g. regarding encryption or notification obligations in the event of governmental access requests).
Unless expressly stated otherwise, we delete the data we hold as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent deletion. Where data continues to be required for other, legally permitted purposes, we restrict processing; the data is blocked and not processed for other purposes. This applies, for example, to data we must retain for commercial or tax law reasons.
Customers, prospective customers or other third parties only need to provide us with the personal data that is necessary for the establishment, performance and termination of a business relationship or other relationship, or which we are legally obliged to collect. Without this data, we will generally be unable to conclude a contract or provide a service, or will be unable to continue performing an existing contract or other relationship. Mandatory information is marked as such.
For the purpose of establishing and performing a business relationship or other relationship, we generally do not use fully automated decision-making within the meaning of Art. 22 UK GDPR. Should we use such processes in individual cases, we will inform you separately where legally required.
As a data subject, you have the following rights against us regarding your personal data:
- Right of access (Art. 15 UK GDPR): You may request confirmation as to whether and which personal data of yours we process. You also have a right to further information, e.g. on the purposes of processing or the intended retention period. Your right of access may be restricted by law in certain circumstances.
- Right to rectification (Art. 16 UK GDPR): If the data processed is inaccurate or incomplete, you have a right to rectification and/or completion. We will carry out the rectification without undue delay.
- Right to restriction of processing (Art. 18 UK GDPR): In certain circumstances, you may request the restriction of processing, thereby preventing further processing of your data for the time being, in particular while we review another right you wish to exercise (e.g. erasure).
- Right to erasure (Art. 17 UK GDPR): You can request that we erase your data. This is possible where the data is no longer necessary, has been unlawfully processed, or where consent has been withdrawn. The statutory exemptions to the duty to erase apply, in particular under the Data Protection Act 2018 (“DPA 2018”). If erasure is not possible following your request, we will inform you of the reason.
- Right to data portability (Art. 20 UK GDPR): You have the right to receive the data concerning you in a structured, commonly used and machine-readable format, where processing is based on consent or a contract and is carried out by automated means. You may also request that we transmit the data directly to another controller.
- Right to withdraw consent: You have the right to withdraw any data protection consent you have given at any time. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.
- Right to complain directly to us: Since 19 June 2026, in addition to your right to complain directly to the ICO, you also have a statutory right to raise a data protection complaint directly with us under section 164A of the DPA 2018 (introduced by the Data (Use and Access) Act 2025) if you consider that we have infringed the UK GDPR in processing your personal data. We will acknowledge your complaint within 30 days and, without undue delay, take appropriate steps to investigate it and keep you informed of progress and the outcome. This internal complaints procedure does not replace or limit your right to contact the ICO directly at any time – that right remains fully available to you. You can submit a complaint informally, e.g. by email, to the contact details set out in Section 1.
- Right to complain to a supervisory authority: You have the right to complain to a data protection supervisory authority about the processing of your data. The supervisory authority responsible for the UK is the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom, telephone: +44 303 123 1113, www.ico.org.uk. You may exercise this right regardless of whether you have first raised a complaint with us.
You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data which is based on Art. 6(1)(e) or (f) UK GDPR; this also applies to profiling within the meaning of Art. 4(4) UK GDPR based on that provision. The right to object cannot be exercised in certain cases, e.g. where we are legally obliged to carry out the processing or where the processing serves to establish, exercise or defend legal claims.
Our website stores information on your device (e.g. cookies) or accesses information already stored there (e.g. IP addresses). This storage and access take place on the following basis:
- Where strictly necessary to provide a service expressly requested by you (e.g. chatbot, IT security): Regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”).
- Otherwise: your consent under Regulation 6(1) PECR.
Any subsequent data processing takes place in accordance with the following sections on the basis of the UK GDPR.
When the website is used purely for information purposes, we collect the personal data that your browser transmits to our server in order to ensure stability and security (Art. 6(1)(f) UK GDPR):
- IP address
- Date and time of the request
- Time zone difference from GMT
- Content of the request (specific page)
- Access status/HTTP status code
- Amount of data transferred
- Referring website
- Browser
- Operating system and its interface
- Language and version of the browser software
This data is stored in log files and deleted after 14 days at the latest.
For the hosting of our website and for the fast and secure delivery of content, we use the services and content delivery network (CDN) of Shopify. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. The provider processes the personal data transmitted via the website (e.g. content, usage, meta/communication or contact data). The CDN uses a distributed server infrastructure to optimise the loading times of our website and to ensure smooth operation even during high traffic peaks.
We have a legitimate interest in providing a functional, secure and fast website (Art. 6(1)(f) UK GDPR). Insofar as data is processed by Shopify outside the UK (in particular in the EEA), the transfer takes place on the basis of UK adequacy regulations and/or the International Data Transfer Agreement (IDTA)/UK Addendum to the EU Standard Contractual Clauses.
Further information: https://www.shopify.com/legal/privacy.
You can open a customer account on our website. We process the data requested in this context to perform the usage contract relating to the account (Art. 6(1)(b) UK GDPR).
In your customer account, we centrally manage the data required for your orders and your participation in our rewards programme. This includes in particular your master data (e.g. name, email, delivery and billing address), your order and purchase history, and your rewards status (coins, level, redeemed rewards). The purpose is the convenient management of your orders and benefits, without you having to re-enter your data with every purchase. The legal basis is performance of the usage contract for the account (Art. 6(1)(b) UK GDPR).
We offer goods via our website. In the course of the order, we process name, address, email, telephone number (optional) and payment data to perform the contract concluded with you (Art. 6(1)(b) UK GDPR).
Fulfilment / logistics:
We pass on the data mentioned above to the following provider, insofar as this is necessary in connection with your order (Art. 6(1)(b) UK GDPR):
Hive Technologies GmbH, Karl-Liebknecht-Str. 14, 10178 Berlin, Germany (“HIVE”): a service provider for order processing and logistics (e.g. storage, picking, shipping). The provider processes contact data (e.g. name, address), content data (e.g. ordered items) and meta/communication data in the EU.
To offer our customers a seamless shopping experience and to manage our customer database efficiently (e.g. to avoid duplicate records and to correctly attribute purchase history), we automatically consolidate personal data from our various sales channels. If you purchase goods via external marketplaces (such as TikTok Shop), we match the data provided there (full name and telephone number) against existing customer profiles in our core system (Shopify). Where there is a match, the external purchase history is linked to your existing HOLY customer profile.
The legal basis for this matching, for internal data maintenance and to ensure a consistent customer history, is our legitimate interest under Art. 6(1)(f) UK GDPR. Our legitimate interest lies in the efficient management of our customer relationships and the accuracy and cleansing of our data.
We use external payment service providers to process payments. Depending on the payment method you select during checkout, we transmit the data required to process the payment (e.g. name, address, bank or credit card details, invoice amount) to the relevant payment provider. Payment service providers generally process this data as independent controllers in their own right. The privacy notices of the relevant provider, which are made available to you during the payment process, apply.
The transmission of the data serves to perform the contract concluded with you for the purchase of goods (Art. 6(1)(b) UK GDPR).
The categories of payment service providers we use include credit card providers, direct debit/bank transfer systems, invoice and instalment payment services, and digital wallet services. The specific payment providers available to you are shown transparently before completion of purchase during the relevant checkout process.
Website visitors can leave reviews of our goods, services or our company in general on our website. In addition to the data entered, we process meta or communication data. We have a legitimate interest in receiving feedback on our offering from website visitors (Art. 6(1)(f) UK GDPR). We use the tool Reviews.io to collect and manage reviews; further information on this provider can be found in Section 6.5 “Reviews.io”.
Where customers participate in our rewards programme, we process the personal data required for this purpose. In particular, we process:
- Master data (e.g. name, email address),
- Customer account data,
- Transaction data,
- Programme data (e.g. coins, level status, redeemed rewards),
- Activity and communication data.
The processing takes place for the operation and management of the rewards programme, in particular the registration and management of participation, the crediting, management and redemption of coins, the calculation and display of level status, the provision of rewards and benefits, and communication regarding programme status, coin expiry or changes to the programme.
The legal basis for processing is Art. 6(1)(b) UK GDPR, insofar as the processing is necessary for participation in the rewards programme. Insofar as we process data to prevent and detect abuse or manipulation, the legal basis is Art. 6(1)(f) UK GDPR. Our legitimate interest lies in ensuring the functionality, fairness and security of the programme. Where statutory retention obligations apply, the legal basis is Art. 6(1)(c) UK GDPR.
When you contact us via the contact form on our website, we store the data requested there and the content of your message. The legal basis for the processing is our legitimate interest in responding to enquiries addressed to us (Art. 6(1)(f) UK GDPR). We delete the data arising in this context once storage is no longer necessary, or we restrict processing where statutory retention obligations apply.
We publish job postings on our website, on pages linked to our website, or on third-party websites. The data provided as part of an application is processed to carry out the recruitment process. Insofar as this is necessary for our decision to enter into an employment relationship, the legal basis is paragraph 1 of Schedule 1 to the DPA 2018 (processing necessary for employment purposes) in conjunction with Art. 6(1)(b)/(f) UK GDPR. We have marked, or otherwise indicated, the data required to carry out the recruitment process. If applicants do not provide this data, we may be unable to process the application. Further data is voluntary and not required for an application. Where applicants provide further information, the basis is their consent (Art. 6(1)(a) UK GDPR).
We ask applicants to refrain from including information on political opinions, religious beliefs and similarly sensitive data in their CV and covering letter. This is not required for an application. If applicants nevertheless provide such information, we cannot prevent its processing as part of the processing of the CV or covering letter. Its processing is then also based on the applicant’s consent (Art. 9(2)(a) UK GDPR).
Finally, we process applicant data for further recruitment processes where applicants have given us their consent to do so (Art. 6(1)(a) UK GDPR).
We pass on applicant data to the relevant HR staff, to our processors in the recruitment field, and to other staff involved in the recruitment process.
We use the applicant tracking system (ATS) Personio to manage job postings and applications. The provider is Personio GmbH, Rundfunkplatz 4, 80335 Munich, Germany. The provider processes the data provided as part of the application (e.g. name, contact details, CV, covering letter and other application documents) in the EU. Personio acts as our processor in this respect; processing takes place exclusively on our instructions and for the purposes described in this section. The legal basis for processing follows the bases set out above for the recruitment process.
Further information: https://www.personio.com/privacy-policy/.
If, following the recruitment process, we enter into an employment relationship with the applicant, we delete the data only after the employment relationship has ended. Otherwise, we delete the data no later than six months after an applicant has been rejected. Where applicants have given us their consent to also use their data for further recruitment processes, we delete their data only one year after receipt of the application.
Our website uses cookies. Cookies are small text files that are stored in the web browser on a website visitor’s device. Cookies help make the service more user-friendly, effective and secure.
Insofar as these cookies are necessary for the operation of our website or its functions (“Strictly Necessary Cookies”), the legal basis for the associated data processing is Art. 6(1)(f) UK GDPR. We have a legitimate interest in providing customers and other website visitors with a functional website.
We specifically use strictly necessary cookies for the following purposes:
- Cookies that store the shopping basket
- Cookies that store login data
- Cookies that retain language settings
- Cookies set by payment providers to process payments, which do not analyse user behaviour
- Flash cookies set to play media content
We only set cookies that are not strictly necessary (e.g. for analytics and marketing) on the basis of your consent (Regulation 6(1) PECR, Art. 6(1)(a) UK GDPR). You manage your consent via our consent management tool (CookieFirst) and can withdraw it at any time with effect for the future. The services used are listed in Section 6.
In addition to the providers already listed in this privacy policy, we in particular use the following third-party providers. Where processing is based on consent, you can withdraw it at any time with effect for the future; the lawfulness of processing carried out up to that point remains unaffected.
Fairing (post-purchase surveys)
We use the service Fairing for voluntary post-purchase surveys (Fairing, Inc., 12 E 49th St, New York, NY 10017, USA). If you take part in our voluntary surveys after purchase, we process the information you voluntarily provide (e.g. answers on origin/purchase motivation, as well as demographic information such as age, gender or living environment) together with order and meta data (e.g. IP address, order ID). All information is optional. The processing serves market research, analysis of marketing channels and improvement of our product range. Legal basis: legitimate interest (Art. 6(1)(f) UK GDPR); insofar as sensitive/demographic data is voluntarily provided: consent (Art. 6(1)(a) UK GDPR). Processing in the USA on the basis of the UK Extension to the EU-US Data Privacy Framework and/or the International Data Transfer Agreement (IDTA). Privacy notice: https://fairing.co/privacy-policy.
Google Analytics
We use Google Analytics for analytics purposes. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The provider processes meta/communication data and usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases to apply. Privacy notice: https://business.safety.google/privacy/.
Hotjar
We use Hotjar for analytics purposes. The provider is Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian’s, STJ 3141, Malta. The provider processes meta/communication data (e.g. device information, IP addresses) and usage data (e.g. websites visited, interest in content, access times) in the EEA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Data is deleted once the purpose of its collection has ceased and no retention obligation applies. Privacy notice: https://www.hotjar.com/legal/policies/privacy/.
Klar
We use Klar for analytics purposes. The provider is Klar Insights GmbH, Marktstr. 18, 80802 Munich, Germany. The provider processes meta/communication data (e.g. device information, IP addresses), contact data (e.g. email addresses, phone numbers) and usage data in the EEA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Data is deleted once the purpose has ceased. Privacy notice: https://www.getklar.com/data-protection.
Lifetimely
We use Lifetimely for analytics purposes. The provider is Lifetimely Oy, Revontulentie 11, 02100 Espoo, Finland. The provider processes contract data (e.g. subject matter of the contract, duration), master data (e.g. names, addresses) and usage data (e.g. websites visited, interest in content, access times) in the EEA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Data is deleted once the purpose has ceased. Privacy notice: https://www.lifetimely.io/policies/privacy-policy.
Rebuy
We use Rebuy for artificial-intelligence-based features, personalisation, operation of an online shop, and A/B testing. The provider is Rebuy, Inc., 6004 St Johns Ave, Minneapolis, MN 55424, USA. The provider processes contact data, meta/communication data and usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: International Data Transfer Agreement (IDTA). Deletion once the purpose ceases. Privacy notice: https://www.rebuyengine.com/legal/privacy-notice.
Shopify
We use Shopify to operate an online shop. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. The provider processes meta/communication data (e.g. device information, IP addresses) in the EEA. Legal basis: Art. 6(1)(f) UK GDPR (legitimate interest in making products easily accessible for purchase). Data is deleted once the purpose has ceased. Privacy notice: https://www.shopify.com/legal/privacy.
Shoplift
We use Shoplift for A/B testing. The provider is Plurality Web Technologies, LLC, 712 Fifth Ave, Floor 7, New York, NY 10019, USA. The provider processes meta/communication data and usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: International Data Transfer Agreement (IDTA). Deletion once the purpose ceases. Privacy notice: https://www.shoplift.ai/privacy-policy.
Facebook Conversion API
We use Facebook Conversion API for analytics purposes. The provider is Meta Platforms Ireland Ltd., Dublin, Ireland. Processes meta/communication data and usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases. Privacy notice: https://www.facebook.com/policy.php.
Facebook Custom Audiences
We use Facebook Custom Audiences for advertising purposes. The provider is Meta Platforms Ireland Ltd., Dublin, Ireland. Processes usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases. Privacy notice: https://www.facebook.com/policy.php.
Google Conversion Tag
We use Google Conversion Tag for conversion tracking. The provider is Google Ireland Limited, Dublin, Ireland. Processes usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases. Privacy notice: https://business.safety.google/privacy/.
Google Marketing Platform
We use Google Marketing Platform for advertising and analytics purposes. The provider is Google Ireland Limited, Dublin, Ireland. The provider processes meta/communication data and usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases. Privacy notice: https://business.safety.google/privacy/.
Google Merchant Center
We use Google Merchant Center to operate an online shop. The provider is Google Ireland Limited, Dublin, Ireland. Processes meta/communication data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases. Privacy notice: https://business.safety.google/privacy/.
Google Tag Manager
We use Google Tag Manager for advertising and analytics purposes. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases. Privacy notice: https://business.safety.google/privacy/.
Google Webfonts
We use Google Webfonts for typography on the website. The provider is Google Ireland Limited, Dublin, Ireland. Processes meta/communication data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Privacy notice: https://business.safety.google/privacy/.
Meta Pixel
We use Meta Pixel for analytics purposes. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Processes usage data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: UK Extension to the EU-US Data Privacy Framework. Deletion once the purpose ceases. Privacy notice: https://www.facebook.com/policy.php.
Sovendus
We use Sovendus to boost sales engagement and operate an online shop. The provider is Sovendus GmbH, Hermann-Veit-Straße 6, 76135 Karlsruhe, Germany. Processes meta/communication data and contact data in the EEA. Legal basis: Art. 6(1)(f) UK GDPR (legitimate interest in making products easily accessible and optimising them through special offers). Deletion once the purpose ceases. Privacy notice: https://online.sovendus.com/online-datenschutzhinweise/.
TikTok Pixel
We use TikTok Pixel for advertising and analytics purposes. The provider is TikTok, Inc., 10100 Venice Blvd Suite 401, Culver City, CA 90232, USA. Processes meta/communication data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: International Data Transfer Agreement (IDTA). Deletion once the purpose ceases. Privacy notice: https://www.tiktok.com/legal/privacy-policy.
Klaviyo (webforms)
We use Klaviyo (webforms) for questionnaires and forms for email marketing. The provider is Klaviyo, Inc., 125 Summer St, Floor 6, Boston, MA 02111, USA. Processes contact data and meta/communication data in the USA. Legal basis: Art. 6(1)(a) UK GDPR (consent). Third-country transfer: International Data Transfer Agreement (IDTA). Deletion once the purpose ceases. Privacy notice: https://www.klaviyo.com/privacy/policy.
Hive
We use Hive for fulfilment purposes. The provider is Hive Technologies GmbH, Karl-Liebknecht-Str. 14, 10178 Berlin, Germany. Processes contact data, meta/communication data and content data in the EEA. Legal basis: Art. 6(1)(f) UK GDPR (legitimate interest in making products easily accessible for purchase). Deletion once the purpose ceases. Privacy notice: https://www.hive.app/legal/privacy-policy.
TikTok Shop (e-commerce platform & marketplace)
We use TikTok Shop as an external sales channel to also offer our goods via the TikTok platform. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. If you place orders via TikTok Shop, TikTok initially processes your order data as an independent controller. TikTok then transmits to us the data necessary for contract performance and logistics (name, delivery address, telephone number, ordered items). We process this data to carry out your order (legal basis: Art. 6(1)(b) UK GDPR) and for the cross-platform profile consolidation described in Section 4.5.1 (legal basis: Art. 6(1)(f) UK GDPR). Privacy notice: https://www.tiktok.com/legal/privacy-policy.
Reviews.io
We use Reviews.io for customer reviews. The provider is Liquid New Media Limited, 29 St Nicholas Place, Leicester, LE1 4LD, United Kingdom. Processes usage data in the United Kingdom. Legal basis: Art. 6(1)(a) UK GDPR (consent). Deletion once the purpose ceases. Privacy notice: https://www.reviews.io/front/user-privacy-policy.
CookieFirst
We use CookieFirst to manage consent. The provider is Digital Data Solutions B.V. (CookieFirst), Plantage Middenlaan 42a, 1018DH, Amsterdam, Netherlands. Processes meta/communication data in the EEA. Legal basis: Art. 6(1)(f) UK GDPR (legitimate interest in the straightforward management of consent). Deletion once the purpose ceases. Privacy notice: https://cookiefirst.com/legal/privacy-policy/.
heyData (privacy seal)
We have integrated a data protection seal on our website. The provider is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. The provider processes meta/communication data (e.g. IP addresses) in the EEA. Legal basis: Art. 6(1)(f) UK GDPR (legitimate interest in confirming our data protection compliance, as well as the provider’s own audit interest). The data is masked after collection so that it can no longer be linked to a person. Privacy notice: https://heydata.eu/datenschutzerklaerung.
We use the messaging service WhatsApp for communication and to run prize draws. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (parent company: Meta Platforms Inc., USA). Your mobile number and the content of communications are processed. The legal basis for use in connection with prize draws is your consent and/or our legitimate interest in fast and effective communication and running the prize draw (Art. 6(1)(a) and (f) UK GDPR). The transfer of data to the USA is safeguarded through the UK Extension to the EU-US Data Privacy Framework.
If you purchase goods or services from us, we may inform you by email or post about similar goods and offers from our range, unless you have objected to this use. The legal basis for this processing is Art. 6(1)(f) UK GDPR. Our legitimate interest lies in direct marketing (see Recital 47 UK GDPR). For postal advertising, we process your name and address for this purpose. For printing and handling postal mailings, we work with mailing service providers (currently in particular Mailody GmbH, Im Mediapark 5, 50670 Cologne, Germany, as well as, where applicable, local print and mailing partners).
You can object to the use of your data for advertising purposes at any time, free of charge, e.g. via the link at the end of every email for email advertising, or by informal notice to our email or postal address above for postal advertising.
To permanently observe objections to postal advertising and avoid renewed unwanted contact, we maintain an internal suppression list (“blocklist”) with the contact details (name, address) of individuals who have objected. The legal basis for this is our legitimate interest under Art. 6(1)(f) UK GDPR in reliably implementing objections raised. Data on the suppression list is retained for as long as necessary to observe the objection.
Prospective customers may subscribe to a free newsletter. We process the data provided at sign-up exclusively to send the newsletter. Sign-up takes place by selecting the relevant field on our website, ticking the relevant box on a paper document, or by another unambiguous action through which prospective customers indicate their agreement to the processing of their data, such that the legal basis is Art. 6(1)(a) UK GDPR. Consent can be withdrawn at any time, e.g. by clicking the relevant link in the newsletter or by notice to our email address above. Processing of the data up to the point of withdrawal remains lawful even in the event of withdrawal.
On the basis of recipients’ consent (Art. 6(1)(a) UK GDPR), we also measure the open and click rates of our newsletters to understand which content is relevant to our recipients.
Tools used:
ChatArmin (WhatsApp marketing)
We also send marketing messages via WhatsApp (on the basis of separate, express consent under Art. 6(1)(a) UK GDPR) using the tool ChatArmin, provided by chatarmin.com GmbH, Kaiserstraße 89, 1070 Vienna, Austria. The provider processes contact data (e.g. mobile number), content and communication data in the EEA. The legal basis is the consent of recipients (Art. 6(1)(a) UK GDPR), obtained via a double opt-in process. Consent can be withdrawn at any time.
Klaviyo
We send newsletters using the tool Klaviyo, provided by Klaviyo, Inc., 125 Summer St, Floor 6, Boston, MA 02111, USA. The provider processes content, usage, meta/communication and contact data in the USA. The transfer takes place on the basis of the International Data Transfer Agreement (IDTA). Privacy notice: https://www.klaviyo.com/privacy/policy.
When you contact us, e.g. by email, telephone or via social media, the data you provide to us (e.g. names and email addresses) is stored by us in order to answer enquiries. The legal basis for the processing is our legitimate interest (Art. 6(1)(f) UK GDPR) in responding to enquiries addressed to us. If you are enquiring about a prospective or existing contractual relationship, the processing takes place to carry out (pre-)contractual steps under Art. 6(1)(b) UK GDPR. We delete the data arising in this context once storage is no longer necessary, or restrict processing where statutory retention obligations apply.
From time to time we offer prize draws for consumers (B2C) as well as for distribution partners and retailers (B2B/retailer), via our website, social media channels, messaging services or other means. We process the data requested in this context (e.g. name, email address, mobile number, address, date of birth, and, where applicable, photo, company/branch details depending on the specific prize draw) to enable participation, verify eligibility, determine and notify winners, and dispatch prizes.
The legal basis for this processing is Art. 6(1)(b) UK GDPR (performance of a contract) and/or our legitimate interest in customer and retailer engagement and sales promotion under Art. 6(1)(f) UK GDPR. Where winners are published (e.g. name and photo), this takes place solely on the basis of prior consent under Art. 6(1)(a) UK GDPR. Once the relevant prize draw has been fully concluded, the data is deleted, unless statutory retention obligations apply.
From time to time we carry out customer surveys to better understand our customers and their preferences. We collect the data requested in this context. It is our legitimate interest to better understand our customers and their preferences, such that the legal basis for the associated data processing is Art. 6(1)(f) UK GDPR. We delete the data once the results of the surveys have been evaluated.
As part of campaigns, events and other marketing activities, we create photo and video recordings and process these for the purposes of advertising, marketing and public relations.
Such recordings may be published in particular on our website, in newsletters, on our social media channels, in print media, at the point of sale, and as part of paid advertising campaigns.
The legal basis is the consent of participants (or of holders of parental responsibility for minors) pursuant to Art. 6(1)(a) UK GDPR.
The recordings may be transmitted to production service providers, marketing agencies, printing service providers, cooperation partners for the relevant campaign, and operators of the platforms used, insofar as this is necessary to carry out the campaign. Where published via social networks or comparable platforms, personal data may be transferred to third countries, in particular the USA (see Sections 2.2 and 9).
We maintain a presence on social media networks in order to present our organisation and our services there. The operators of these networks regularly process their users’ data for advertising purposes. Among other things, they create user profiles from online behaviour, which are used, for example, to display advertising on the networks’ pages and elsewhere on the internet that corresponds to users’ interests. To do so, network operators store information on usage behaviour in cookies on users’ devices. It cannot be ruled out that operators combine this information with further data. Further information, as well as guidance on how users can object to processing by the platform operators, can be found in the privacy policies of the relevant operators listed below. Operators or their servers may also be located outside the UK, meaning they process data there. This can create risks for users, e.g. because enforcement of their rights is more difficult or government authorities may access the data.
When users of these networks contact us via our profiles, we process the data they provide to us in order to respond to their enquiries. This constitutes our legitimate interest, such that the legal basis is Art. 6(1)(f) UK GDPR.
Discord
We run our own Discord server. The provider is Discord Inc., 444 De Haro Street, Suite 510, San Francisco, CA 94107, USA. Data processing for server administration and responding to enquiries (Art. 6(1)(f) UK GDPR). Privacy policy: https://discord.com/privacy.
We maintain a profile and a closed group (“Facebook Squad Group”) on Facebook. Operator: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Joint controllership for Page Insights. We process group membership under Art. 6(1)(f) UK GDPR. Privacy policy: https://www.facebook.com/policy.php | Opt-out: https://www.facebook.com/settings?tab=ads.
We maintain a profile on Instagram. Operator: Meta Platforms Ireland Ltd., Dublin, Ireland. Privacy policy: https://help.instagram.com/519522125107875.
We maintain a profile on LinkedIn. Operator: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Privacy policy: https://www.linkedin.com/legal/privacy-policy | Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
We maintain an account/profile on the Reddit platform in order to respond reactively to user enquiries where needed. Operator: Reddit Inc., 1455 Market Street, Suite 1600, San Francisco, CA 94103, USA. Privacy policy: https://www.reddit.com/policies/privacy-policy.
TikTok
We maintain a profile on TikTok. Operator: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. Privacy policy: https://www.tiktok.com/privacy-policy.
X (formerly Twitter)
We maintain a profile on X. Operator: X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Privacy policy: https://twitter.com/en/privacy | Ad settings: https://twitter.com/personalization.
YouTube
We maintain a profile on YouTube. Operator: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy.
If you have any questions or comments regarding this privacy policy, we are happy to help using the contact details set out in Section 1. Our reservation of the right to amend this privacy policy with effect for the future, and the reference to the current version, are set out in the introduction (“Your data at HOLY”).

France
Poland
United Kingdom



