Privacy Policy

Who we are


Amanda Sivewright operates as a sole trader providing equestrian confidence coaching services and selling original artwork and prints through this website.


Website address: www.amandasivewright.com
Contact email: amandajsivewright@gmail.com


01. What personal data do we collect and why?

Information you give us directly

When you book coaching services:

  • Name, email address, phone number
  • Information you share during coaching sessions
  • Payment information (processed securely through our payment provider)

Why we collect it: To provide coaching services, communicate about sessions, and process payments.

Legal basis: Contract performance and legitimate business interests.

How long we keep it: Coaching records are kept for 7 years in line with professional standards and HMRC requirements. Session notes are kept confidentially and securely.

When you purchase artwork:

  • Name, email address, delivery address
  • Payment information (processed securely through our payment provider)
  • Order history

Why we collect it: To fulfil your order, send shipping updates, and handle any queries or returns.

Legal basis: Contract performance.

How long we keep it: Order records are kept for 7 years for accounting and legal purposes.

When you contact us:

  • Name, email address, and any information you include in your message

Why we collect it: To respond to your enquiry.

Legal basis: Legitimate business interests (responding to enquiries) or consent.

How long we keep it: We keep correspondence for up to 3 years, or longer if needed for legal reasons.

When you subscribe to our mailing list:

  • Name and email address

Why we collect it: To send you updates, coaching insights, and information about new artwork (only if you've opted in).

Legal basis: Consent (you can unsubscribe at any time).

How long we keep it: Until you unsubscribe or we no longer send marketing emails.


02. Cookies and tracking?
What are cookies?

Cookies are small text files stored on your device when you visit a website. They help the site remember your preferences and understand how you use it.

Cookies we use

Essential cookies:

  • Shopping cart functionality (remembers items you've added)
  • Payment processing (secure transaction completion)
  • Session management (keeps you logged in during your visit)

These cookies are necessary for the website to function and cannot be disabled.

Analytics cookies:

  • Google Analytics (if we use it) - helps us understand how visitors use the site, which pages are popular, and how we can improve

We use this information to make the website better. These cookies don't identify you personally.

You can control cookies: Most browsers let you refuse cookies or delete them. Check your browser settings. Note that disabling essential cookies may affect website functionality.


03. Third parties who process your data
We work with trusted third-party services that may process your personal data on our behalf:

Payment processing:

  • Stripe and/or PayPal process payments securely
  • We never see or store your full payment card details
  • They comply with PCI-DSS security standards

Print-on-demand fulfilment:

  • Printify processes and fulfils orders for printed artwork
  • They receive your name and delivery address to ship your order
  • View Printify's privacy policy: [Printify privacy policy link]

Email communications:

  • [Email service provider - e.g., MailerLite, if used] sends newsletters and order confirmations
  • You can unsubscribe at any time

Website hosting:

  • [Hosting provider - e.g., Pebble platform] hosts our website
  • They may process technical data like IP addresses for security

Analytics:

  • Google Analytics (if used) - anonymised data about website usage

All third parties are GDPR-compliant and process data securely according to our instructions.


04.  Your rights under GDPR

 You have the right to:

Access your data: Request a copy of the personal data we hold about you.

Correct your data: Ask us to correct any inaccurate or incomplete information.

Delete your data: Request deletion of your personal data (with some exceptions - e.g., we must keep financial records for 7 years).

Restrict processing: Ask us to limit how we use your data.

Data portability: Request your data in a portable format.

Object to processing: Object to us processing your data for marketing purposes (you can unsubscribe from emails at any time).

Withdraw consent: If we process data based on your consent, you can withdraw it at any time.

To exercise any of these rights, email: amandajsivewright@gmail.com

We'll respond within one month. If your request is complex, we'll let you know if we need more time.


05.  Confidentiality (coaching clients)

 Everything you share in coaching sessions is treated as strictly confidential.

Exceptions to confidentiality:

  • If you're at immediate risk of serious harm to yourself or others
  • If required by law (e.g., court order)
  • If you give explicit written consent to share specific information

Session notes are stored securely and never shared with third parties except in the circumstances above.


06.  Data security

 We take data security seriously:

  • All data transmitted to and from our website is encrypted (SSL/TLS)
  • Payment processing is handled by PCI-DSS compliant providers
  • We use secure passwords and two-factor authentication where available
  • Access to personal data is restricted to authorised personnel only
  • Coaching session notes are stored securely and separately from other business data

If there's a data breach affecting your personal data, we'll notify you and the ICO within 72 hours as required by law.


07.  children's privacy

This website is not intended for children under 16. We don't knowingly collect data from children. If you're a parent/guardian and believe your child has provided us with personal data, please contact us, and we'll delete it.


08.  International data transfers

Your data is primarily stored and processed within the UK/EEA. If any third-party service we use transfers data outside the UK/EEA, they do so using appropriate safeguards (e.g., Standard Contractual Clauses) as required by GDPR.


09.  Changes to this privacy policy

We may update this privacy policy occasionally. Changes will be posted on this page with a new "last updated" date. Significant changes will be highlighted on the website or communicated by email if we have your contact details.


10.  Complaints

 If you're unhappy with how we've handled your personal data, please contact us first so we can try to resolve it.

You also have the right to complain to the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Phone: 0303 123 1113
Website: www.ico.org.uk


11. Contact us

If you have any questions about this privacy policy or how we handle your data:

Email: amandajsivewright@gmail.com

We'll respond to your enquiry as soon as possible, and within one month for formal data protection requests.