Skip to content

GDPR Privacy Policy

 

GDPR / UK GDPR Privacy Policy

Last updated:

This Privacy Policy explains how C & M Navigation Systems (“we”, “us”, “our”) collects, uses, shares and protects personal data when you use our website and services, and what rights you have. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and, where relevant, the Age-Appropriate Design Code.

1. Controller & contact

Controller: C & M Navigation Systems
Address: PO BOX 31, Pontefract, United Kingdom
Website: https://cmnav.co.uk
Email: contact@cmnav.co.uk
Telephone: 07533088132

We are not required to appoint a Data Protection Officer. If that changes, we will update this page with DPO details.

2. Scope

This policy applies to personal data processed in the UK about website visitors, customers (current/former), prospects, and relevant suppliers/partners. It covers data collected directly (e.g. checkout, forms, email), automatically (cookies, logs, analytics), and from third parties (e.g. payment providers, couriers).

3. Key definitions

Personal Data: information relating to an identified or identifiable natural person.

Processing: any operation performed on personal data (collection, storage, use, sharing, deletion etc.).

Service: our website and related services at cmnav.co.uk.

Processor / Service Provider: a third party processing personal data on our behalf under contract (hosting, ecommerce, payments, couriers, analytics, email).

4. Data we collect

4.1 Data you provide

  • Identity & contact details (name, email, phone, billing & delivery address).
  • Account credentials (if you create an account).
  • Order details, warranty/returns information, support correspondence.
  • Preferences (marketing consents, cookie choices).

4.2 Usage & technical data (automatic)

  • IP address, device identifiers, browser type/version, OS, language settings.
  • Pages viewed, timestamps, session duration, referral URLs, diagnostic data.

4.3 From third parties

  • Payment status and fraud checks from payment processors (e.g. Shopify Payments/PayPal).
  • Delivery events from couriers (e.g. Royal Mail) to fulfil orders.
  • Platform analytics (e.g. ecommerce platform) where relevant.

5. Purposes & lawful bases

We process personal data under one or more of these lawful bases:

  • Contract – to provide our Service, process/fulfil orders, manage accounts, provide support.
  • Legal obligation – to meet UK legal requirements (tax, accounting, consumer protection, product safety).
  • Legitimate interests – to operate, secure and improve our business (fraud prevention, network security, analytics, service improvement, limited direct marketing to existing customers). We balance these interests against your rights and freedoms.
  • Consent – for non-essential cookies/analytics, certain electronic marketing, or where consent is the appropriate basis. You may withdraw consent at any time.

6. Marketing & PECR

We may email you about products/services similar to those you purchased or enquired about (our legitimate interests) unless you opt out. For other electronic marketing (including to new prospects), we will obtain your consent in line with PECR. You can unsubscribe at any time via the link in our emails or by contacting us.

7. Cookies & similar technologies

We use cookies and similar technologies (e.g. pixels, local storage) to keep the site secure/functional, remember preferences, measure performance and—where you agree—improve and market our products.

  • Strictly necessary – security, checkout, account sign-in.
  • Functionality – remember preferences (e.g. language, checkout choices).
  • Analytics/performance – understand usage and improve the Service.
  • Advertising/marketing – only with consent where required.

On your first visit we present a clear choice to accept or reject non-essential cookies. You can change your cookie settings any time via our banner or your browser. See our Cookie Policy for details (types, purposes, durations).

8. Sharing & processors

We may share personal data with:

  • Processors/Service Providers (hosting/ecommerce, payment processing, couriers, analytics, communications, IT/security) under contracts requiring confidentiality and appropriate security measures.
  • Affiliates/successors in connection with a business transfer (e.g. merger, acquisition), with appropriate safeguards.
  • Public authorities or advisers where required by law or to protect our legal rights.
  • With your consent or as disclosed at the point of collection.

9. International transfers

If we transfer personal data outside the UK (or EEA), we use appropriate safeguards—such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) / Addendum, or other recognised transfer mechanisms—and assess local laws where relevant.

10. Retention

We keep personal data only as long as necessary for the purposes collected and to meet legal, accounting and reporting obligations. Typical periods include:

  • Order & tax records: up to 7 years (statutory requirements).
  • Support correspondence: usually up to 3 years after closure unless needed longer for legal obligations or ongoing issues.
  • Analytics data: shorter periods where feasible; aggregated/anonymised where possible.

We periodically review retention and securely delete or anonymise data that is no longer required.

11. Security & breaches

We implement appropriate technical and organisational measures (e.g. encryption in transit, access controls, secure configuration, backups) to protect personal data. No online service is completely secure; if a personal data breach is likely to result in a risk to your rights and freedoms, we will notify you and (where required) the ICO in accordance with UK GDPR.

12. Children’s data

Our Service is not aimed at children and we do not knowingly collect personal data from children under 13 without verified parental consent. Where our Service is likely to be accessed by children, we follow the UK Age-Appropriate Design Code (e.g. high-privacy by default, data minimisation, clear language, and no profiling/behavioural advertising to children without strong justification and safeguards). If you believe a child has provided data without appropriate consent, contact us and we will delete it.

13. Your rights

You have the following rights under UK GDPR (subject to conditions):

  • Be informed about how we use your data (this policy).
  • Access your personal data.
  • Rectification of inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Objection to processing based on legitimate interests and to direct marketing.
  • Data portability (where processing is automated and based on consent or contract).
  • Withdraw consent at any time where consent is the legal basis.

To exercise your rights, email contact@cmnav.co.uk. We will respond within one month (or up to three months for complex requests, in which case we will let you know). We may need to verify your identity before acting on a request.

14. Third-party links

Our website may link to third-party websites/services. Their privacy practices are not covered by this policy; please review their policies before providing personal data.

15. Changes to this policy

We may update this policy from time to time. For material changes that affect how we process your data, we will provide a prominent notice on the website and, where appropriate, notify you by email. The “Last updated” date at the top reflects the most recent changes.

16. How to contact us & the ICO

Questions about this policy or your data? Contact us at:
Email: contact@cmnav.co.uk
Address: C & M Navigation Systems, PO BOX 31, Pontefract, United Kingdom
Telephone: 07533088132

If you are unhappy with our response, you can lodge a complaint with the UK Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint.

This policy is intended to satisfy the transparency requirements of UK GDPR Articles 12–14 and PECR marketing rules. It should be read alongside our Terms of Service and Cookie Policy.