GDPR / DPA 2018

Privacy Policy

This privacy policy sets out how FORESTER CREDO LIMITED Limited uses and protects any information that you give us when you use this website.

Last Updated: March 2026


1. Important Information & Who We Are

FORESTER CREDO LIMITED Limited is the controller and responsible for your personal data (collectively referred to as "we", "us" or "our" in this privacy policy).

Full Company Name: FORESTER CREDO LIMITED Limited

Company Number: 16995618

Registered Address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

Data Protection Officer (DPO): legal@forester-credo.com

2. The Data We Collect About You

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:

  • Identity Data: First name, last name, username or similar identifier.
  • Contact Data: Billing address, delivery address, email address and telephone numbers.
  • Financial Data: Bank account and payment card details (Processed securely via Stripe/PayPal; we do not store raw card numbers).
  • Transaction Data: Details about payments to and from you and other details of products and services you have purchased from us.
  • Technical Data: Internet Protocol (IP) address, your login data, browser type and version, time zone setting and location, operating system and platform.
  • Profile Data: Your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.

3. How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Performance of Contract

Processing your data where it is necessary for the performance of a contract to which you are a party (e.g., providing hosting services).

Legitimate Interest

Conducting and managing our business to enable us to give you the best service/product and the best and most secure experience (e.g., fraud prevention, network security).

Legal Obligation

Processing your personal data where it is necessary for compliance with a legal or regulatory obligation (e.g., Tax reporting to HMRC, KYC/AML checks).

4. Disclosures of Your Personal Data

We may have to share your personal data with the parties set out below for the purposes set out in paragraph 3 above.

  • Service Providers: Acting as processors based in the UK/EEA who provide IT and system administration services (e.g., Data Center operators).
  • Professional Advisers: Acting as processors or joint controllers including lawyers, bankers, auditors and insurers.
  • Regulators: HM Revenue & Customs, regulators and other authorities acting as processors or joint controllers based in the United Kingdom.
  • Payment Processors: Stripe, PayPal (for processing payments and anti-fraud checks).

5. International Transfers

Some of our external third parties are based outside the UK and the European Economic Area (EEA) so their processing of your personal data will involve a transfer of data outside the UK/EEA.

Whenever we transfer your personal data out of the UK/EEA, we ensure a similar degree of protection is afforded to it by using specific contracts approved by the European Commission/UK Government which give personal data the same protection it has in Europe.

6. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

7. Data Retention

How long will you use my personal data for?

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

By law, we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.

8. Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data:

  • Request access to your personal data.
  • Request correction of your personal data.
  • Request erasure of your personal data.
  • Object to processing of your personal data.
  • Request restriction of processing your personal data.
  • Request transfer of your personal data.
  • Right to withdraw consent.

If you wish to exercise any of the rights set out above, please contact us at legal@forester-credo.com.