Chestnuts & Fields
EN
Privacy

Privacy & Data Use

We are committed to handling personal data responsibly and transparently.

This Privacy Policy explains how we collect, use and protect your information when you visit our website.

01

General Information and Data Controller

This Privacy Policy informs you about how we handle personal data when you visit our website.

The data controller responsible for the processing of personal data on this website in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws is:

Chestnuts & Fields
Global Office

Regus (Central Working) White City
84 Wood Lane
White City
London W12 0BZ
United Kingdom

Email: privacy.chestnutsfields [ at ] proton [ dot ] me

02

Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee compliance with data protection laws.

You can contact our Data Protection Officer directly for any questions or concerns regarding your personal data.

Jo Brewer
Data Protection Officer
Email: privacy.chestnutsfields [ at ] proton [ dot ] me

03

No Use of Cookies or Tracking

This website serves purely as a corporate showcase and a portal to direct you to our external shop partners.

We do not use any cookies, web trackers, pixel tags, analytics tools such as Google Analytics, or advertising networks. Your browsing behavior on our site is not tracked, profiled, or analyzed.

04

Collection of Information When Visiting Our Website (Server Log Files)

We host our website with Netlify (Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA). Netlify provides a globally distributed Content Delivery Network (CDN) to ensure our website loads quickly and securely.

When you visit our website, Netlify automatically collects and stores technical connection data (server log files) on its servers. This information is collected automatically by your browser and includes:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the retrieved file
  • Website from which the access is made (referrer URL)
  • Browser type, device type, and operating system

These data are processed by us and our hosting provider to ensure a smooth connection to the website, a comfortable user experience, and to evaluate system security and stability.

The legal basis for this data processing is Art. 6 (1) lit. f GDPR (Legitimate Interest). Our legitimate interest follows from the purposes listed above. We do not use this data to draw conclusions about you personally.

Data Processing Agreement and International Data Transfers

We have concluded a Data Processing Agreement (DPA) with Netlify. Because Netlify is based in the USA, technical data, such as the IP address, is transferred to and processed in the United States. Transfers to the US are secured by Netlify's certification under the EU-US Data Privacy Framework, providing an adequate level of data protection in accordance with Art. 45 GDPR.

For more information, please refer to Netlify's privacy policy at: https://www.netlify.com/privacy/

05

External Links to Partner Shops

Our website contains text and image links to external shops and platforms, such as Redbubble. We have no influence on the content, security, or data protection practices of these external sites.

If you click on such a link, you will leave our website and be redirected to a third-party platform. The data processing on the linked target pages is the sole responsibility of the respective operators.

When you click a link, your browser only transmits the information to the target server indicating which website you came from (referrer data). Please refer to the privacy policies of the respective providers to understand how they collect and handle your personal data, including their use of cookies and consent banners.

06

Your Rights as a Data Subject

Under the GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15 GDPR)
You have the right to request access to your personal data processed by us.

Right to Rectification (Art. 16 GDPR)
You can request the correction of inaccurate or incomplete personal data.

Right to Erasure (Art. 17 GDPR)
You can request the deletion of your personal data stored by us, provided no legal retention periods apply.

Right to Restriction of Processing (Art. 18 GDPR)
You can request that the processing of your personal data be restricted.

Right to Object (Art. 21 GDPR)
You have the right to object to the processing of your data based on our legitimate interests.

Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a supervisory data protection authority in your country of residence or where the alleged infringement took place.

If you wish to exercise any of these rights, please contact our Data Protection Officer, Jo Brewer, at privacy.chestnutsfields [ at ] proton [ dot ] me.