Privacy Policy & GDPR

Privacy Policy & GDPR Statement

Last Updated: 31st July 2026

At Wholesale Security Europe Limited ("we," "our," or "us"), operated via rfidmagic.co.uk, we are committed to protecting your personal data and respecting your privacy. This Privacy Statement explains how we collect, use, store, and share your personal information when you visit or make a purchase from our website, in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

1. Who Is the Data Controller?

For the purposes of the GDPR, the data controller is:

  • Company Name: Wholesale Security Europe Limited

  • Address: 9 Norton Road, Pelsall, Walsall, West Midlands. WS3 4AY

2. Personal Data We Collect

When you visit or purchase from our store, we collect personal data necessary to complete your transaction, provide services, and improve your experience:

  • Order Information: Name, billing address, shipping address, payment information (e.g., credit card details processed securely via third parties), email address, and phone number.

  • Account Details: Username, password, and order history (if you create an account).

  • Technical Data: IP address, browser type, device information, time zone, and cookies (see Section 8).

  • Communication Data: Information you provide when contacting customer support or subscribing to our newsletter.

3. Legal Grounds for Processing Your Data

Under the GDPR, we rely on the following legal bases to process your personal data:

  1. Performance of a Contract: Processing required to fulfil your orders, process payment, ship products, and handle customer service requests.

  2. Legitimate Interests: Improving our website, security and fraud prevention, and communicating with existing customers about relevant products.

  3. Legal Compliance: Fulfilling accounting, tax, or legal requirements.

  4. Consent: Sending marketing emails, newsletter subscriptions, or non-essential cookies (which you can withdraw at any time).

4. How We Use Your Data

We use your personal data to:

  • Process payments and deliver your purchases.

  • Provide order updates, invoices, and tracking details.

  • Manage customer support inquiries and returns.

  • Prevent fraudulent transactions and secure our platform.

  • Send marketing communications (only if you have explicitly opted in).

5. Sharing Your Personal Data

We do not sell or rent your personal information to third parties. We share data only with trusted third-party service providers ("Data Processors") necessary to operate our store, including:

  • Payment Gateway: SQUARE (We do not store your card details on our servers).

  • Fulfilment & Shipping Carriers: [e.g., Yodel, InPost, DHL, FedEx, UPS, Royal Mail]

  • Legal Obligations: If required by law, regulation, or court order.

All third-party processors are contractually bound to process your data securely and in accordance with GDPR regulations.

6. International Data Transfers

If we transfer your personal data outside the European Economic Area (EEA) or UK, we ensure adequate safeguards are in place, such as using European Commission-approved Standard Contractual Clauses (SCCs) or transferring to countries recognised as providing an adequate level of data protection.

7. Data Retention

We retain your personal data only as long as necessary to fulfil the purposes outlined in this policy:

  • Order and Invoicing Data: Retained for [e.g., 6 to 10 years] to comply with tax and statutory record-keeping obligations.

  • Account & Marketing Data: Retained until you request account deletion or unsubscribe from marketing updates.

8. Cookies and Tracking Technologies

We use essential cookies only to run our online store.

  • Essential Cookies: Necessary for the shopping cart and checkout to function (no user consent required)

  • Analytics/Marketing Cookies: Require your explicit consent via a cookie banner before being set on your browser. (We do not use these tools on our site).

You can adjust your cookie settings at any time in your browser settings.

9. Your GDPR Rights

If you reside in the EEA or UK, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.

  • Right to Rectification: Request correction of inaccurate or incomplete data.

  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal record-keeping requirements.

  • Right to Restrict Processing: Request limited processing of your data under specific conditions.

  • Right to Data Portability: Request a copy of your data in a structured, machine-readable format.

  • Right to Object: Object to data processing based on legitimate interests or direct marketing.

  • Right to Withdraw Consent: Revoke consent for marketing or cookies at any time.

To exercise any of these rights, please contact us. We will respond within 30 days.

10. Complaints & Regulatory Authority

If you believe we have not processed your data in accordance with the law, you have the right to lodge a complaint with your local Data Protection Authority (e.g., the Information Commissioner's Office (ICO) in the UK, or your national Supervisory Authority in the EU).

11. Contact Us

If you have questions about this Privacy Policy or your personal data, please contact us via our contact form.