FREE DELIVERY TO MAINLAND UK ON ORDERS OVER £25

Privacy Policy

Direct Lighting External Privacy Notice

This privacy notice was last updated on: 16/10/2025

Introduction Welcome to Direct Lighting’s privacy notice. Home Giant Ltd, trading as Direct Lighting, prioritizes your privacy and works diligently to secure your personal information. This document outlines our approach to managing your data, highlights your privacy entitlements, and explains the safeguards provided by law.

Presented in a layered format for ease, you can jump to relevant sections below. Consult the Glossary for clarifications on specialized terms.

  1. Important Information and Who We Are
  2. The Data We Collect About You
  3. How Your Personal Data Is Collected
  4. How We Use Your Personal Data
  5. Disclosures of Your Personal Data
  6. International Transfers
  7. Data Security
  8. Data Retention
  9. Your Legal Rights
  10. Glossary
  11. Cookie Policy

1. Important Information and Who We Are

1.1 Purpose of This Privacy Notice

This notice covers how Direct Lighting acquires and handles your personal data across our website (directlighting.uk), encompassing details shared when you join our newsletter, acquire products or services, or join contests. Data may also arise from our direct engagements, such as calls, emails, or correspondence. Our platform targets adults only, and we steer clear of collecting information from under-18s.

Pair this with any supplemental privacy disclosures we issue during targeted data activities for a complete view of our handling methods. It enhances those without superseding them.

1.2 Controller

As the controller of your personal data (collectively “we”, “us”, or “our”), Direct Lighting oversees its management. Without a formal data protection officer (DPO), direct inquiries about this notice or rights exercises to the contacts listed below.

1.3 Contact Details

Full entity details:

Full name of legal entity: Home Giant Ltd, trading as Direct Lighting, a private limited company incorporated in England and Wales under the Companies Act 2006 with company number 16787947, limited by shares, whose registered office is at 12 Gleneagles Drive, Lancaster, Lancashire LA1 3RP.

Data protection contact: Data Protection Lead

Email: [email protected]

Postal address: 12 Gleneagles Drive, Lancaster, Lancashire LA1 3RP.

Complaints can be filed anytime with the Information Commissioner’s Office (ICO), the UK data protection regulator (www.ico.org.uk). We’d value the opportunity to address issues internally first—please start with us.

1.4 Changes to the Privacy Notice and Your Duty to Inform Us of Changes

Current as of the top-listed date; archived versions available upon request.

Maintain the accuracy of your held data by updating us on any shifts in your details over time.

1.5 Third-Party Links

Links to outside sites, tools, or integrations may appear on our platform. Engaging them could expose your data to third-party tracking. These are beyond our oversight, so we disclaim liability for their policies. Review external notices upon navigation.

2. The Data We Collect About You

Personal data encompasses details identifying an individual, barring anonymized sets. Refer to Glossary for precise definition.

Categories of data we might gather, utilize, retain, and share include:

  • Identity Data: First/last name, title.
  • Contact Data: Addresses for billing/delivery, email, phone.
  • Transaction Data: Purchase records, payment histories.
  • Technical Data: Device login, browser specs, location/time zone, plugins, OS details.
  • Profile Data: Account username (encrypted passwords excluded), order logs, preferences, feedback/survey inputs.
  • Usage Data: Patterns in site/product/service engagement.
  • Marketing and Communications Data: Opt-ins for promotions from us/partners, preferred channels.

Aggregated Data (e.g., anonymized stats/demographics) supports broad uses. Derived from personal sources, it loses personal status if non-identifiable. Examples: Usage aggregates for feature stats; Transaction aggregates for trends. Re-identification triggers full personal data treatment under this notice.

Financial Data (cards/banks) and Transaction Data flow through our payment partner—we neither collect nor retain it, despite checkout needs.

No Special Category data (e.g., ethnicity, health, genetics) or criminal records are sought.

2.1 If You Fail to Provide Personal Data

Non-provision of required data (legal/contractual) could hinder service delivery (e.g., order fulfillment). We’ll alert you and potentially pause/cancel affected arrangements.

3. How Is Your Personal Data Collected?

Collection occurs via:

  • Direct Interactions: Forms, mail, calls, or emails yield Identity, Contact, Profile, and Marketing/Communications Data during service applications, account setups, marketing requests, contest entries, returns, or feedback.
  • Automated Technologies: Site visits auto-capture Technical/Usage Data through cookies/logs—details in Cookie Policy. Third-site cookies may contribute Technical Data.
  • Third Parties/Public Sources:
    • Analytics Technical Data (e.g., Google, non-UK).
    • Marketing Technical Data (e.g., Google Ads, non-UK).
    • Payment/tech Identity/Contact/Financial/Transaction Data (e.g., Stripe, UK/non-UK).
    • Shipping Identity/Contact Data (UK/non-UK).
    • Public Identity/Contact (e.g., Companies House, UK).
    • Feedback Identity Data (e.g., Trustpilot, UK).

4. How We Use Your Personal Data

Processing aligns strictly with legal allowances, chiefly:

  • Contract fulfillment.
  • Legitimate interests (balanced against your rights, e.g., targeted outreach).
  • Obligation compliance.

Glossary details bases. Consent is occasional—withdrawable anytime via contact. More here.

4.1 Purposes for Which We Will Use Your Personal Data

  • Your Inputs: Facilitate requests/services (incl. returns), operations, enhancements, preference-based marketing.
  • Third-Party Inputs: Merged for above aims.
  • Site Activity: Oversight, diagnostics, analytics, security, interactivity, ad optimization, tailored suggestions.

4.2 How We Use Your Personal Data for Marketing

Enquiries, buys, or opt-ins add you to lists. Outreach via email/SMS/calls/post. Customize channels or unsubscribe fully. Manage via account or us—initial prompts common.

4.3 Cookies

Enhance distinction—full policy below.

4.4 Change of Purpose

Original uses only, save compatible shifts (explanations on request). Unrelated needs prompt notice/basis/consent. Withdrawals honored; lawful prior acts stand. Law-mandated processing may bypass notice/consent.

5. Disclosures of Your Personal Data

Shares support section 4 with:

  • Glossary-listed External Third Parties.
  • Business transaction parties (sales/mergers), adhering to this notice.

Recipients bound to lawful security; processing limited to our directives, not self-use.

6. International Transfers

6.1 Select partners (e.g., logistics) process outside UK, necessitating exports.

6.2 Protections match UK standards through:

6.2.1 Adequacy-approved destinations (UK Gov: transfers guidance).

6.2.2 Standard contractual clauses.

6.2.3 US equivalents like Data Bridge.

6.2.4 Additional mechanisms with rights/remedies—details on request.

6.2.5 Absent above:

  • Informed explicit consent;
  • Contract necessity (yours/ours);
  • Third-party contracts benefiting you; or
  • Legal alignment.

7. Data Security

Robust protocols guard against loss/misuse/breaches. Need-to-know access enforced with confidentiality. Breaches trigger notifications as mandated.

8. Data Retention

Duration ties to purposes, plus legal/financial needs. Considerations: sensitivity, risks, alternatives, mandates (e.g., guarantees; 6-year tax holds on basics; partner terms).

Erasure requests possible (below). Anonymization enables perpetual research use.

9. Your Legal Rights

UK laws grant:

  • Data access.
  • Corrections.
  • Deletions.
  • Objections.
  • Restrictions.
  • Portability.
  • Consent revocation.

Exercise via contact.

9.1 No Fee Usually Required

Free for standard exercises; fees/refusals for excesses.

9.2 What We May Need from You

Identity verification/details for secure, swift handling.

9.3 Time Limit to Respond

Typically one month; extensions for complexity—with updates.

10. Glossary

10.1 Controller: Processing decider.

10.2 Lawful Basis

  • Legitimate Interest: Operations (e.g., security, outreach)—impacts assessed; inquire for specifics.
  • Performance of Contract: Deal execution/pre-steps.
  • Legal/Regulatory Obligation: Required compliances.

10.3 Personal Data: Identifiable individual info.

10.4 Processing: All data manipulations.

10.5 Processor: Delegate handler.

10.6 Third Parties

External Third Parties

  • Tech/support providers (UK).
  • Payments (UK/non-UK).
  • Logistics (UK/non-UK).
  • Advisors (UK).
  • Regulators (e.g., HMRC, UK).

10.7 Your Legal Rights (Detailed)

  • Access: Data copy/verification.
  • Correction: Amend errors (post-check).
  • Erasure: Remove sans need/unlawful/objection/legal (exceptions noted).
  • Object: Challenge interests/marketing (overrides possible).
  • Restriction: Pause for disputes/unlawful/claims/objections.
  • Transfer: Export in standard format (applicable subsets).
  • Withdraw Consent: Halts onward; prior valid. Services may adjust—we’ll note.

11. Cookie Policy

11.1 Tiny device files, consent-based, for traffic/personalization.

11.2 Usage trackers inform stats/upgrades.

11.3 Boost usability via prefs; no unauthorized access.

11.4 Browser controls acceptance; opt-out risks feature loss.

11.5 Full blocks via settings may hinder navigation.

Shopping Cart