Skip to main content

Privacy Policy

Nadura Wellness Ltd  |  Effective 10 September 2026

1 Who we are

Nadura Wellness Ltd is the controller of personal information collected through NaduraWellness.com and in connection with our customer relationships. Our company number is 17295066 and our registered office is 2 Whitby Court Abbey Road, Shepley, Huddersfield, West Yorkshire, England, HD8 8EL. Contact us at hello@nadurawellness.com.

2 Information we collect

  • Identity and contact information, including name, billing and delivery address, email address and account details.
  • Order and transaction information, including products ordered, payment status, delivery details, refunds and correspondence. We do not normally receive full payment-card details from the payment provider.
  • Eligibility and professional information where needed to verify a trade customer or a person’s eligibility to purchase a restricted product.
  • Customer-service information, including enquiries, complaints, product-safety reports, photographs or documents a customer chooses to send us.
  • Marketing preferences and engagement, including subscriptions, campaign interactions and consent records.
  • Technical and usage information, including IP address, device and browser information, cookie identifiers, referral source, pages viewed and interactions, subject to cookie choices.
  • Information required to prevent fraud, keep the website secure, comply with law, respond to regulators or establish and defend legal claims.

Information collected automatically

When a person visits the website, our servers and enabled technologies may collect IP address, approximate location derived from IP address, browser and device type, operating system, referring page, pages and products viewed, timestamps, basket and checkout activity, marketing attribution data and technical error or security information. Non-essential analytics and advertising information is collected only in accordance with the visitor’s cookie choices.

Information received from other sources

We may receive information from payment providers, couriers, fraud-prevention services, marketing platforms, review providers, professional advisers, publicly available professional registers and social or advertising platforms. The information received depends on the service and may include payment status, delivery status, advertising attribution, account identifiers, review activity or verification results.

Please do not send medical records or detailed health information unless we specifically request information that is necessary to handle a safety concern, complaint or legal obligation. If you report an adverse reaction or other safety issue, the information may reveal health data. We will handle that information only where a lawful condition permits us to do so.

Health and product safety information

We do not use health information for advertising profiling. Where a customer reports an adverse reaction, suspected product defect, contraindication, injury or product-safety concern, we may record symptoms, timing, product and batch details, administration information and relevant correspondence. We use only what is reasonably needed to protect the person, investigate the report, comply with safety duties, notify insurers, manufacturers or regulators where required, and establish or defend legal claims.

3 How and why we use information

Purpose Information used Lawful basis
Process and deliver orders Identity, contact, order and payment information Performance of a contract
Operate accounts and provide support Identity, contact, account and correspondence information Contract and legitimate interests
Manage returns, complaints and product-safety matters Order, correspondence and relevant safety information Contract, legal obligation, legitimate interests and, where relevant, legal claims or substantial public interest conditions
Prevent fraud and secure our services Transaction, technical and account information Legitimate interests and legal obligation
Send requested email marketing Contact details, preferences and engagement Consent, or soft opt-in where the law permits
Analyse and improve the website Cookie, device and usage information Consent for non-essential technologies; legitimate interests for essential security and service data
Meet legal and tax duties Order, payment, identity and correspondence records Legal obligation

4 Marketing

We may send marketing where a person has consented or where the privacy rules allow us to contact an existing customer about similar products and the customer had a clear opportunity to opt out. Every marketing email will include an unsubscribe method. A person can also contact hello@nadurawellness.com. We may retain a minimal suppression record so that we respect an opt-out.

Klaviyo may record whether a message was delivered, opened or clicked and may associate a visit or purchase with a profile where tracking is permitted. We may use this information to measure campaigns, tailor content, control message frequency and operate automated flows such as welcome, basket reminder, replenishment and post-purchase messages. Marketing choices can be changed through an unsubscribe link or preference centre. Service messages about an order, account, subscription, safety alert or product recall may still be sent where necessary.

5 Analytics, advertising and profiling

With consent, we use Google Analytics 4 to measure website use and ecommerce performance. With advertising consent, Meta Pixel and Meta Conversions API may receive identifiers and events such as page view, product view, add to basket, checkout and purchase. We use these services for attribution, campaign measurement and audience management. We do not knowingly send detailed health information, free-text medical enquiries or payment-card data to analytics or advertising platforms.

These activities may involve profiling, meaning automated analysis of interests or likely behaviour. We do not use advertising profiling to make decisions that produce legal or similarly significant effects. Visitors can refuse or withdraw cookie consent, and subscribers can object to direct marketing at any time.

6 Who receives information

We disclose only the information reasonably needed for the relevant service. Recipients may include:

  • website, hosting, IT, security and support suppliers;
  • WooCommerce and connected ecommerce service providers;
  • WooPayments and other payment, fraud-prevention or banking providers enabled at checkout;
  • Royal Mail, DPD and other delivery or fulfilment providers used for an order;
  • Klaviyo for customer communications and marketing, according to preferences;
  • Trustpilot where review services are used;
  • professional advisers, insurers, auditors, regulators, courts, law-enforcement bodies or other parties where disclosure is required or reasonably necessary; and
  • a buyer, seller or adviser involved in a genuine business reorganisation, financing or sale, subject to appropriate confidentiality and data-protection safeguards.

We do not sell personal information.

Processor responsibilities

Service providers acting for us may use personal information only under contract, for documented purposes and with appropriate confidentiality and security obligations. Some providers also act as independent controllers for parts of their service, for example payment risk decisions, courier operations or a platform’s own legal obligations. Their privacy notices explain that independent processing.

7 International transfers

Some providers may process information outside the United Kingdom. Where UK data-protection law requires safeguards, we use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard. Information about a relevant safeguard can be requested from us, subject to confidentiality and security restrictions.

8 How long we keep information

  • Core order, payment, tax and accounting records: normally six years after the end of the relevant financial year or longer where law or a dispute requires it.
  • Customer accounts: while active and then normally up to six years after the last transaction or closure.
  • Routine customer-service correspondence: normally up to three years after the matter closes; complaint, safety and legal-claim records may be kept for up to six years or longer where reasonably necessary.
  • Marketing records: until consent is withdrawn, the person objects, or the information is no longer useful; suppression records may be retained to honour an opt-out.
  • Cookie and consent records: for the duration shown in the live cookie settings panel and as reasonably needed to demonstrate consent.

We may keep information for longer when a complaint, chargeback, safety investigation, product recall, litigation hold, regulatory enquiry or reasonably anticipated legal claim requires it. When information is no longer required, we delete or anonymise it in accordance with our retention process.

9 Automated checks

Payment and fraud-prevention providers may use automated checks to assess a transaction, device or payment method. This may result in a payment being challenged, delayed or declined. Where a decision is made solely by automated means and has a legal or similarly significant effect, a person may have rights to request human involvement, express their view and challenge the decision. Contact us and we will explain the available route or direct the request to the relevant provider.

10 Your rights

Depending on the circumstances, individuals may have rights to access their personal information; correct inaccurate information; request erasure; restrict processing; object to processing based on legitimate interests or direct marketing; receive certain information in a portable format; and withdraw consent at any time. These rights are not absolute and lawful exemptions may apply.

To exercise a right, contact hello@nadurawellness.com. We may need to verify identity. Individuals may complain to the Information Commissioner’s Office at ico.org.uk, but we would appreciate the opportunity to address the concern first.

11 Security and data breaches

We use role-based access, secure connections, account controls, backups, malware protection, payment-provider security and supplier due diligence as appropriate to the risks. Customers are responsible for keeping account credentials confidential and should contact us promptly if they suspect unauthorised account use. Where a personal-data breach creates a legal notification duty, we will notify the Information Commissioner’s Office and affected individuals as required.

12 Children

Our products and website are intended for adults aged 18 or over. We do not knowingly permit children to place orders or intentionally collect children’s information for ordering or marketing purposes. A parent or guardian who believes a child has provided information to us should contact hello@nadurawellness.com.

13 Business transfers and legal requests

If our business or assets are reorganised, financed or transferred, relevant information may be disclosed under confidentiality and data-protection safeguards. We may preserve or disclose information where reasonably necessary to comply with law, respond to a lawful request, protect safety, investigate fraud, enforce agreements or establish and defend legal rights.

14 Cookies, links and changes

Our Cookie Policy explains our use of cookies and similar technologies. Third-party sites linked from our website operate under their own privacy information. We may update this policy and will publish the revised date and provide additional notice where a change materially affects individuals.

©2026 All Rights Reserved.