Privacy Policy

At Arisée, we believe privacy should be handled with the same care and consideration as design. This Privacy Policy explains how we collect, use, store, and share personal information when you visit our website, place an order, contact our team, or otherwise interact with us. It also explains your rights in relation to your personal data and how you can contact us if you have any questions or concerns.

This policy applies to Arisée’s website, customer service communications, marketing activities, and the sale of our furniture and related services. It is intended to be clear, accessible, and transparent, in line with UK data protection law. Under the UK GDPR and the Data Protection Act 2018, organisations must process personal data lawfully, fairly, and transparently, and individuals must be given clear privacy information.

For the purposes of data protection law, Arisée is the data controller of the personal information described in this policy, unless we state otherwise. In these terms, “Arisée”, “we”, “our”, and “us” refer to Arisée LTD, with registered address at 4 Malden Road, London, NW5 3HR. You can contact us about privacy matters at customerservice@arisee.uk or by post at 4 Malden Road, London, NW5 3HR. If you have appointed a data protection officer or a specific privacy contact, their details should also be listed here. The ICO’s guidance says a privacy notice should identify the organisation and provide relevant contact details so individuals know who is responsible for their information. 

We may collect personal information directly from you when you place an order, create an account, sign up to our mailing list, request information, contact customer care, enter a promotion, submit a review, or otherwise communicate with us. The information we collect may include your name, billing address, delivery address, email address, telephone number, order details, payment-related information, correspondence history, and any information you choose to provide when speaking with us about a product, delivery, return, or service issue. We may also collect limited technical information when you browse our website, such as your IP address, browser type, device information, pages visited, referral source, and cookie-related identifiers, depending on your settings and consent choices. The ICO says privacy notices should clearly explain what personal data is collected and why it is used.

When you make a purchase, we use your personal information primarily to process and fulfil your order, take payment, arrange delivery, provide order updates, and manage any aftercare, returns, refunds, or customer support related to that purchase. Where this processing is necessary to enter into or perform a contract with you, our lawful basis is contractual necessity. The ICO’s guidance explains that organisations must identify and communicate the lawful basis they rely on before processing begins.

We may also use your information where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. This may include reviewing order history, improving our product offering, understanding how customers use our website, preventing fraud, securing our systems, managing disputes, training our team, improving customer experience, and maintaining accurate business records. Where we rely on legitimate interests, we aim to use personal information in a way that is proportionate and expected within the context of a retail relationship. The ICO says that if an organisation relies on legitimate interests, it should explain what those interests are in its privacy information.

In some circumstances, we may process personal information because we are under a legal obligation to do so. This may include keeping accounting and tax records, complying with consumer, payment, fraud-prevention, or regulatory requirements, responding to lawful requests from public authorities, or retaining evidence needed to manage legal claims. UK data protection law recognises legal obligation as one of the lawful bases for processing personal data.

Where you choose to receive marketing from us, we may use your name, email address, purchase history, browsing behaviour, and preferences to send you updates about new arrivals, collections, product launches, editorial content, events, and other brand news. We will only send electronic marketing where we are permitted to do so under data protection and e-privacy rules. In the UK, PECR applies to electronic marketing and cookies, and the ICO explains that organisations must follow additional rules for email and similar marketing activity. You can unsubscribe from marketing emails at any time by using the unsubscribe link in the message or by contacting us directly.

We may use service providers and trusted third parties to help us operate our business and deliver our services. Depending on how Arisée is set up, this may include website hosting providers, ecommerce platforms, payment processors, fraud-screening tools, delivery partners, warehousing partners, customer service systems, email marketing platforms, analytics providers, and professional advisers such as accountants, insurers, and legal counsel. Where such providers process personal data on our behalf, we require them to handle it appropriately and only for authorised purposes. The ICO says individuals should be told who personal data is shared with, or at least the categories of recipients.

We do not sell your personal data. However, we may share personal information where necessary to complete your order, provide a requested service, comply with law, protect our rights, prevent fraud, enforce our terms, or respond to valid legal requests. In the event of a business restructuring, sale, merger, or transfer of assets, relevant personal information may also be transferred as part of that transaction, subject to applicable law and appropriate safeguards.

If you make a payment through our website, payment card information is usually processed by a third-party payment provider rather than stored directly by Arisée. We recommend that your live site policy matches the exact payment systems you use. If card payments, wallets, instalment providers, or checkout extensions are used, the policy should name or accurately describe them. Personal data should only be collected and processed for specified purposes and with an appropriate lawful basis.

We may use cookies and similar technologies on our website to support site functionality, remember your preferences, keep items in your basket, measure site performance, understand browsing behaviour, and improve our services and advertising. Some cookies are essential to provide an online service requested by you, while others are optional and require your consent. The ICO states that under PECR you must tell users if you set cookies, explain what they do and why, and obtain consent for non-essential cookies. Essential cookies that are strictly necessary for the service requested by the user do not require the same consent.

Where we use analytics, advertising, or social-media-related cookies or pixels, we will seek consent where required before placing them or activating them. You can usually manage your preferences through our cookie banner or your browser settings. Disabling some cookies may affect certain site features or checkout performance. If you use a separate cookie policy or cookie settings tool, this Privacy Policy should be read alongside those notices.

We may transfer personal information outside the United Kingdom where this is necessary for the operation of our business, such as when certain service providers store or process data internationally. Where we do so, we aim to ensure that appropriate safeguards are in place, such as adequacy regulations, approved contractual mechanisms, or other lawful transfer measures. The ICO’s privacy guidance requires organisations to tell individuals if personal data is transferred internationally and the safeguards used where relevant.

We keep personal information only for as long as reasonably necessary for the purposes for which it was collected, including to fulfil orders, provide aftercare, maintain business and financial records, resolve disputes, enforce agreements, and comply with legal, tax, and regulatory requirements. Different categories of information may be kept for different periods depending on the nature of the relationship and the reason the data was collected. If we do not set a fixed retention period for a particular category, we apply retention criteria based on business need, legal obligation, and the potential need to evidence transactions or resolve complaints. The ICO says a privacy notice should tell individuals how long information will be kept, or the criteria used to determine that period.

We take appropriate technical and organisational measures to help protect personal information against unauthorised or unlawful processing, accidental loss, destruction, damage, or disclosure. These measures may include access controls, secure platforms, restricted staff access, contractual controls with service providers, and security procedures designed to reduce risk. No system can be guaranteed to be completely secure, but we take the protection of personal information seriously and review our practices from time to time. The ICO’s UK GDPR resources emphasise accountability and appropriate organisational measures as part of compliance.

Under UK data protection law, you have a number of rights in relation to your personal data. Depending on the circumstances, these may include the right to access the information we hold about you, the right to ask us to correct inaccurate information, the right to request deletion, the right to restrict processing, the right to object to certain processing, and the right to data portability. Where we rely on consent, you also have the right to withdraw that consent at any time, although this does not affect the lawfulness of processing carried out before withdrawal. The ICO specifically says privacy information should explain the rights available to individuals and, where relevant, the right to withdraw consent.

If you would like to exercise any of your rights, please contact us using the details set out in this policy. We may need to verify your identity before responding. We will respond in accordance with applicable data protection law. If you are unhappy with how we have handled your information, we would appreciate the opportunity to address your concerns first. You also have the right to complain to the Information Commissioner’s Office, which is the UK supervisory authority for data protection matters. The ICO states that privacy notices should tell people how they can complain if they have concerns about the way their information is used.

Our website and products are generally intended for adults. We do not knowingly collect personal data from children through our website in a way that is inconsistent with applicable law. If you believe that a child has provided personal information to us inappropriately, please contact us and we will review the matter.

From time to time, we may update this Privacy Policy to reflect changes in law, regulatory guidance, technology, our operations, or the services we use. When we make material changes, we will update the “Last updated” date and, where appropriate, take additional steps to bring the revised policy to your attention. The ICO recommends that privacy information be kept up to date and easy for individuals to access.

If you have any questions about this Privacy Policy or about the way Arisée handles personal information, please contact us at customerservice@arisee.uk. If you have appointed a dedicated privacy contact, you should list that person or team here. The ICO’s guidance says contact details should be made clearly available in the notice.

Last updated:19 March 2026