Privacy Policy
Gemba Tools Ltd
71-75 Shelton Street
Covent Garden
London
United Kingdom
WC2H 9JQ
Company registered in England and Wales
SIC: 47910 – Retail sale via mail order houses or via Internet
Last updated: Wednesday, 18 Feb 2026
1. Introduction
Gemba Tools Ltd (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy.
We operate as an online retail business supplying Continuous Improvement and facilitation tools via mail order and online sales.
This Privacy Policy explains:
-
What information we collect
-
How we use it
-
How we store and protect it
-
Your rights under UK data protection law
We process personal data in accordance with:
-
The UK General Data Protection Regulation (UK GDPR)
-
The Data Protection Act 2018
2. Information We Collect
We collect information in the following ways:
A. Information You Provide Directly
When you:
-
Place an order
-
Contact us by email
-
Subscribe to updates
-
Request information
-
Make a payment
We may collect:
-
Full name
-
Billing address
-
Delivery address
-
Email address
-
Phone number
-
Company name (if applicable)
-
Payment details (processed securely via third-party payment providers)
-
Order history
B. Information Collected Automatically
When you visit our website, we may collect:
-
IP address
-
Browser type
-
Device information
-
Pages visited
-
Time spent on pages
-
Referring website
This information helps us improve website performance and user experience.
C. Payment Information
We do not store full card details.
Payments are processed securely via trusted third-party payment providers. These providers operate under strict security standards (PCI-DSS compliant).
3. How We Use Your Information
We use personal data to:
-
Process and fulfil orders
-
Deliver purchased products
-
Provide customer support
-
Respond to enquiries
-
Send order confirmations and updates
-
Improve our products and services
-
Maintain financial and legal records
-
Comply with legal obligations
Where you opt in, we may also use your email address to send:
-
Product updates
-
Workshop resources
-
CI insights
-
Promotional content
You may unsubscribe at any time.
4. Legal Basis for Processing
Under UK GDPR, we rely on the following lawful bases:
Contractual necessity – To fulfil your order and deliver products.
Legal obligation – To comply with tax, accounting, and regulatory requirements.
Legitimate interests – To improve our services, prevent fraud, and operate efficiently.
Consent – For marketing communications (where required).
5. Retail & Online Sales Data Handling
As an online retail business (SIC 47910), we process customer data specifically to:
-
Confirm purchases
-
Arrange shipping
-
Provide tracking details
-
Handle returns and exchanges
-
Manage warranties (if applicable)
-
Process refunds
We only collect information necessary to complete transactions and provide support.
Customer purchase history may be retained for:
-
Accounting purposes
-
Warranty support
-
Fraud prevention
-
Business analysis
6. Sharing of Information
We do not sell personal data.
We may share limited information with:
-
Payment processors
-
Shipping and logistics providers
-
Website hosting providers
-
Accountants or legal advisors (where required)
-
Regulatory authorities (if legally required)
All third parties are required to handle data securely and in accordance with UK data protection laws.
7. Data Storage & Security
We take appropriate security measures to protect personal data, including:
-
Secure hosting environments
-
Encrypted payment processing
-
Restricted access to customer data
-
Password-protected systems
-
Regular system updates
While no online system is completely risk-free, we take reasonable steps to protect your information.
8. Data Retention
We retain personal data only as long as necessary for:
-
Fulfilling contracts
-
Accounting and tax compliance (typically 6 years under UK law)
-
Resolving disputes
-
Legal obligations
Marketing data is retained until you unsubscribe.
9. Cookies
Our website may use cookies to:
-
Improve website functionality
-
Analyse website performance
-
Understand visitor behaviour
You can manage cookie preferences through your browser settings.
Where required, cookie consent is obtained via our website banner.
10. International Transfers
Where third-party providers are based outside the UK, we ensure appropriate safeguards are in place, such as:
-
UK-approved standard contractual clauses
-
Adequacy decisions
-
Secure processing agreements
11. Your Rights
Under UK GDPR, you have the right to:
-
Access your personal data
-
Request correction of inaccurate data
-
Request erasure (where legally permitted)
-
Restrict processing
-
Object to processing
-
Data portability
-
Withdraw consent (for marketing)
To exercise your rights, contact:
Email: support@gembatools.com
We will respond within one month.
12. Complaints
If you believe your data has been handled improperly, you may contact:
Information Commissioner’s Office (ICO)
Website: https://ico.org.uk
However, we encourage you to contact us first so we can resolve the issue directly.
13. Children’s Data
Our products are intended for professional and educational use. We do not knowingly collect personal data from children under 16.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect:
-
Legal changes
-
Business changes
-
Operational improvements
The latest version will always be published on our website.
15. Contact Information
Gemba Tools Ltd
71-75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
Email: support@gembatools.com
