Who we are
Deskrove Ltd is the data controller for any personal information we hold about you. We're a UK company registered in England and Wales, trading as Deskrove.
14782345Sheffield S4 7YB
ZB912345GB 428 5691 38We don't have a formal Data Protection Officer because we don't meet the UK GDPR threshold (we're too small and don't do large-scale profiling). For any data question, Anya Petrosyan, our co-founder, is the named point of contact.
What we collect
We collect the minimum needed to ship you a product and keep the website running. Every category below has a lawful basis under UK GDPR.
We do not collect: phone numbers (unless you provide one in delivery notes), date of birth, gender, any "special category" data (health, ethnicity, politics, religion), device fingerprints, or your social media handles.
Why we use it
Each piece of data above has one purpose — fulfil your order and keep the website running. We don't use your data for anything you haven't asked for.
- Fulfilling your order — processing payment, printing the label, emailing tracking, handling warranty claims and returns
- Running the business — VAT returns, bookkeeping, responding to your questions, preventing fraud
- Improving the site — aggregated analytics only, no individual profiling, no A/B testing on you without you knowing
- Keeping you informed — important order updates (always), marketing emails (only if you opt in)
Who we share it with
We share your data only with processors that help us run the business. Each one is contractually bound to use your data only for the service they provide us.
For US-based processors, we rely on the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses. For EU-based processors, the UK has an adequacy decision with the EU, so no additional safeguards are required.
We don't use: Google Analytics, Meta Pixel, TikTok Pixel, Mailchimp, HubSpot, Zendesk, Intercom, or any ad-tech partners.
How long we keep it
We keep personal data only for as long as we genuinely need it. After that, it's deleted on a rolling automated schedule.
- Order records — 6 years after the end of the tax year the order was placed in. This is the HMRC requirement for financial records; we can't delete it earlier.
- Support emails — 3 years from last activity on the thread. Then archived and deleted.
- Marketing list — until you unsubscribe or we shut down the list, whichever comes first. Unsubscribing removes you within 48 hours.
- Website analytics (Plausible) — aggregated, not linked to individuals. Retained indefinitely at the aggregate level, but there's nothing to delete because it's not about a specific person.
- Server logs (Netlify) — 90 days, then auto-purged. IP addresses, timestamps, page requested.
- Backups — rolling 30-day backup window. Data deleted from live systems persists in backups for up to 30 more days.
Your rights under UK GDPR
You have eight rights under UK GDPR. Here they all are. To exercise any of them, email privacy@deskrove.co.uk — we respond within one calendar month (usually one working day for simple requests).
You're reading it. This page exists to tell you what we do with your data, and we update it when things change.
You can ask for a copy of everything we hold on you. We'll send it as a JSON or PDF file within one month. Free.
If we've got something wrong (name spelling, address typo) email us and we'll fix it within 48 hours.
You can ask us to delete everything — except what we're required to keep for HMRC (order + invoice records for 6 years).
You can ask us to stop doing certain things with your data (e.g., sending marketing) while keeping the data itself.
You can ask for your data in a machine-readable format (JSON) to take somewhere else. Again — free, one month.
You can object to us processing your data based on legitimate interest. In practice this means analytics — object, and we exclude you.
We don't make automated decisions about you — no algorithmic pricing, no risk scoring, no AI moderation. Nothing to object to yet.
Cookies — there's almost none
We use one first-party cookie and no third-party cookies.
deskrove_cart_v1— stores your cart contents so they persist if you close the tab. Strictly necessary for the site to work. No consent banner required under PECR for strictly-necessary cookies.- No analytics cookies. Plausible is cookieless — it identifies unique visitors by a hashed combination of IP + user agent that rotates daily and can't identify you.
- No advertising cookies. We don't run ads on the site and don't use remarketing pixels.
- No social media cookies. We don't embed Facebook, Twitter, or Instagram widgets.
Because the only cookie is strictly necessary, we don't show a cookie consent banner. If we ever add an analytics cookie, we'll add a banner and this policy will change.
Complaints & questions
First — email us at privacy@deskrove.co.uk. Anya or James responds personally within one working day. 90% of privacy issues are resolved this way — usually someone wants their account deleted or their mailing list preference changed, both 2-minute jobs.
Still unhappy? You have the right to complain to the UK's data protection authority:
Wilmslow, Cheshire SK9 5AF
We'd appreciate you coming to us first — faster, friendlier, and usually enough. But if you don't feel we've handled your concern well, you absolutely have that escalation route.