top of page

Privacy Policy

Gemba Tools Ltd
71-75 Shelton Street
Covent Garden
London
United Kingdom
WC2H 9JQ

Company registered in England and Wales
SIC: 47910 – Retail sale via mail order houses or via Internet

Last updated: Wednesday, 18 Feb 2026

1. Introduction

Gemba Tools Ltd (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy.

We operate as an online retail business supplying Continuous Improvement and facilitation tools via mail order and online sales.

This Privacy Policy explains:

  • What information we collect

  • How we use it

  • How we store and protect it

  • Your rights under UK data protection law

We process personal data in accordance with:

  • The UK General Data Protection Regulation (UK GDPR)

  • The Data Protection Act 2018
     

2. Information We Collect

We collect information in the following ways:
 

A. Information You Provide Directly

When you:

  • Place an order

  • Contact us by email

  • Subscribe to updates

  • Request information

  • Make a payment

We may collect:

  • Full name

  • Billing address

  • Delivery address

  • Email address

  • Phone number

  • Company name (if applicable)

  • Payment details (processed securely via third-party payment providers)

  • Order history
     

B. Information Collected Automatically

When you visit our website, we may collect:

  • IP address

  • Browser type

  • Device information

  • Pages visited

  • Time spent on pages

  • Referring website

This information helps us improve website performance and user experience.
 

C. Payment Information

We do not store full card details.

Payments are processed securely via trusted third-party payment providers. These providers operate under strict security standards (PCI-DSS compliant).

3. How We Use Your Information

We use personal data to:

  • Process and fulfil orders

  • Deliver purchased products

  • Provide customer support

  • Respond to enquiries

  • Send order confirmations and updates

  • Improve our products and services

  • Maintain financial and legal records

  • Comply with legal obligations

Where you opt in, we may also use your email address to send:

  • Product updates

  • Workshop resources

  • CI insights

  • Promotional content

You may unsubscribe at any time.

4. Legal Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

Contractual necessity – To fulfil your order and deliver products.

Legal obligation – To comply with tax, accounting, and regulatory requirements.

Legitimate interests – To improve our services, prevent fraud, and operate efficiently.

Consent – For marketing communications (where required).

5. Retail & Online Sales Data Handling

As an online retail business (SIC 47910), we process customer data specifically to:

  • Confirm purchases

  • Arrange shipping

  • Provide tracking details

  • Handle returns and exchanges

  • Manage warranties (if applicable)

  • Process refunds

We only collect information necessary to complete transactions and provide support.

Customer purchase history may be retained for:

  • Accounting purposes

  • Warranty support

  • Fraud prevention

  • Business analysis
     

6. Sharing of Information

We do not sell personal data.

We may share limited information with:

  • Payment processors

  • Shipping and logistics providers

  • Website hosting providers

  • Accountants or legal advisors (where required)

  • Regulatory authorities (if legally required)

All third parties are required to handle data securely and in accordance with UK data protection laws.

7. Data Storage & Security

We take appropriate security measures to protect personal data, including:

  • Secure hosting environments

  • Encrypted payment processing

  • Restricted access to customer data

  • Password-protected systems

  • Regular system updates

While no online system is completely risk-free, we take reasonable steps to protect your information.

8. Data Retention

We retain personal data only as long as necessary for:

  • Fulfilling contracts

  • Accounting and tax compliance (typically 6 years under UK law)

  • Resolving disputes

  • Legal obligations

Marketing data is retained until you unsubscribe.
 

9. Cookies

Our website may use cookies to:

  • Improve website functionality

  • Analyse website performance

  • Understand visitor behaviour

You can manage cookie preferences through your browser settings.

Where required, cookie consent is obtained via our website banner.

10. International Transfers

Where third-party providers are based outside the UK, we ensure appropriate safeguards are in place, such as:

  • UK-approved standard contractual clauses

  • Adequacy decisions

  • Secure processing agreements
     

11. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure (where legally permitted)

  • Restrict processing

  • Object to processing

  • Data portability

  • Withdraw consent (for marketing)

To exercise your rights, contact:

Email: support@gembatools.com

We will respond within one month.
 

12. Complaints

If you believe your data has been handled improperly, you may contact:

Information Commissioner’s Office (ICO)
Website: https://ico.org.uk

However, we encourage you to contact us first so we can resolve the issue directly.
 

13. Children’s Data

Our products are intended for professional and educational use. We do not knowingly collect personal data from children under 16.
 

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect:

  • Legal changes

  • Business changes

  • Operational improvements

The latest version will always be published on our website.
 

15. Contact Information

Gemba Tools Ltd
71-75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom

Email: support@gembatools.com

bottom of page