Privacy and personal data
Clear information about what personal data the Clinic collects, why we use it, who may process it and how long we keep it.
Address: 2 White Cottages, Capenhurst Lane, Capenhurst, Chester, Cheshire CH1 6HF
Email: richard@reddington.tech
1. What this policy covers
This Privacy Policy applies to personal data handled by The Garment Tech Clinic through this website, enquiries, payment and order administration, customer file submission, Tech Pack Health Checks and related garment-technology services.
Confidential product/design information is also protected under our Confidentiality Commitment, Data Handling Policy and any signed NDA.
2. Personal data we may collect
- name, email address, brand/company name and contact details;
- order, job reference, product type, development stage and information entered into Clinic forms;
- payment/transaction status and related records supplied by Stripe (the Clinic does not need to store full card details);
- customer correspondence and support/complaint information;
- technical files and supporting material where they contain personal data;
- website and security information such as technical request/log information processed by our hosting/service providers; and
- information needed for invoices, accounting, insurance, legal or dispute-resolution records.
Please avoid including unnecessary personal or special-category data in a tech pack or supporting file.
3. Why we use personal data and our lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Responding to an enquiry, taking an order, receiving files, performing the Health Check, issuing the report and reasonable follow-up | Contract, or steps requested before entering a contract |
| Payment administration, transaction records and fraud/security handling | Contract, legal obligation and/or legitimate interests in operating a secure service |
| Service administration, technical security, troubleshooting, quality assurance, insurance and defending legal claims | Legitimate interests and/or legal obligation, depending on the activity |
| Accounting, tax and regulatory record keeping | Legal obligation |
| Optional marketing emails, where offered | Consent or another lawful basis permitted by applicable direct-marketing law; any opt-in will be separate from the paid service |
Where we rely on legitimate interests, those interests are running, securing and improving a small professional service, keeping appropriate business records and protecting legal rights. We consider whether those interests are overridden by the rights and interests of the individual concerned.
4. Who may receive or process personal data
We use service providers only where reasonably necessary. Current core categories/providers include:
- Netlify — website hosting and website-form handling;
- Stripe — payment processing;
- Dropbox — confidential customer file-request upload and transfer;
- OpenAI API — AI-assisted technical analysis;
- email/communications providers;
- professional advisers, insurers, security providers and authorities where reasonably necessary or legally required.
We do not sell personal data to advertisers.
5. OpenAI API processing
The Clinic's current PDF Health Check analyser uses the OpenAI API. OpenAI states that API inputs and outputs are not used to train its models by default. The Clinic has relevant API data-sharing controls disabled and does not opt customer content into model-training programmes.
The analyser requests responses with store:false, applies a one-hour expiry safeguard to temporary file uploads where supported, and requests deletion of the temporary API file immediately after analysis. OpenAI's published standard API terms state that API inputs and outputs may nevertheless be retained for up to 30 days for service provision and abuse monitoring unless a different retention control applies.
AI output is not used to make a solely automated legal or similarly significant decision about a person. A Senior Garment Technologist reviews the technical findings before a customer-facing report is issued.
6. International transfers
Some service providers operate internationally and may process personal data outside the UK. Where UK data-protection law requires safeguards for an international transfer, we rely on an applicable adequacy arrangement or appropriate contractual/other safeguards made available by the relevant provider. You can contact us if you want more information about safeguards relevant to a particular provider.
7. How long we keep personal data
- Working customer technical files: normally deleted within 30 days after the final report and immediate follow-up are complete, unless there is a continuing legal, security, insurance or customer-requested reason to retain them.
- OpenAI API processing: temporary uploaded files are requested for deletion immediately by the Clinic analyser, while OpenAI may retain API inputs/outputs for up to 30 days under its published standard API terms unless another retention control applies.
- Final reports, correspondence, invoices and transaction/business records: retained only for as long as reasonably necessary for the service, accounting, insurance, legal, security or dispute-resolution purposes and any applicable statutory record-keeping period.
- Website/security logs: retained according to operational/security needs and the relevant provider's service settings and policies.
8. Your data-protection rights
Depending on the circumstances and lawful basis, you may have rights to access your personal data, ask us to correct it, request erasure, request restriction, object to processing, and receive certain data in a portable format. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing.
Your right to object: where we rely on legitimate interests, you may object to that processing. We will consider the objection in accordance with data-protection law. You can also object to direct marketing at any time.
To exercise a right, email richard@reddington.tech. We may need to verify your identity before responding.
9. If you provide information about another person
If a tech pack or other file contains personal data about somebody else, you are responsible for ensuring you have an appropriate basis to provide that information to the Clinic. Please provide only what is reasonably necessary for the requested technical service.
10. Cookies and similar technology
The Clinic does not currently operate its own behavioural advertising or analytics programme on this website. Essential website, payment, fraud-prevention or security technologies may be used by service providers such as Netlify or Stripe where needed to provide their services. If the Clinic later introduces non-essential analytics or advertising cookies, we will update our notices and introduce consent controls where required.
11. Security
We use reasonable technical and organisational measures appropriate to the service and the information handled. No internet-based service can guarantee absolute security.
12. Complaints
Please contact us first if you have a concern so we can try to resolve it. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
13. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The latest version and update date will be published here.
14. Contact
Richard Reddington
The Garment Tech Clinic
2 White Cottages, Capenhurst Lane, Capenhurst, Chester, Cheshire CH1 6HF
Email: richard@reddington.tech