Last Updated: 1 June 2026
This Privacy Policy explains how LIFENEX LTD ("we", "us", or "our"), a merchant wholesaler registered and operating in England and Wales, United Kingdom, collects, uses, stores, shares, and protects personal data when you visit lifenex.guru, communicate with us, place wholesale orders, or otherwise interact with our business. LIFENEX LTD is the data controller for personal data processed in connection with our wholesale distribution activities across apparel, piece goods and notions, grocery, beer and ale, wine and distilled alcoholic beverages, chemicals and allied products, hardware, plumbing and heating equipment, furniture, farm product raw materials, and druggists sundries merchant wholesale channels.
We are committed to processing personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) as incorporated into United Kingdom law by the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and applicable guidance issued by the Information Commissioner's Office (ICO). This Policy applies to retail buyers, procurement officers, logistics coordinators, accounts payable personnel, website visitors, marketing contacts, supplier representatives, and any other individuals whose personal data we process in the course of our wholesale operations.
By using our website, submitting an enquiry, entering into a wholesale account relationship, or otherwise providing personal data to us, you acknowledge that you have read this Privacy Policy. Where we rely on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal, subject to contractual and legal limitations described herein. This Policy should be read together with our Cookie Policy, Terms of Service, and Terms and Conditions.
The data controller responsible for your personal data is LIFENEX LTD, whose registered business address is 29 Drove Road, Weston-Super-Mare, United Kingdom, BS23 3NN. You may contact us regarding data protection matters by email at info@lifenex.guru or by telephone at +447446968859. We will respond to data protection enquiries within the timeframes required by applicable law, typically within one calendar month unless an extension is permitted.
Where we appoint processors to handle personal data on our behalf, such as IT hosting providers, payment facilitators, carriers, or accountancy services, we ensure appropriate contractual safeguards are in place requiring processors to process data only on documented instructions and to implement suitable technical and organisational security measures.
We collect and process personal data that you provide directly, that we obtain from third parties where lawful, and that is generated through your use of our website and wholesale services. The categories of data depend on your relationship with us and the nature of your interactions.
This includes your name, job title, business name, business address, delivery addresses, email address, telephone numbers, and account identifiers assigned within our wholesale systems. We collect this information when you complete contact forms, request a wholesale session, open or maintain a trade account, place orders, or correspond with our sales, logistics, or accounts teams.
We process details relating to wholesale orders including product codes, quantities, pricing, delivery instructions, purchase order references, invoices, credit notes, payment records, and delivery confirmations. This data is necessary to perform contracts, manage accounts receivable, resolve disputes, and maintain accurate commercial records required under United Kingdom tax and company law.
Where you make payments or establish credit terms, we may process bank account details for BACS transfers, payment card tokens processed by regulated payment service providers, credit reference information obtained lawfully from credit agencies with your knowledge where required, and records of payment history. We do not store full payment card numbers on our own servers where processing is delegated to PCI-DSS compliant providers.
When you visit lifenex.guru, we may collect Internet Protocol addresses, browser type and version, time zone, browser plug-in types, operating system, device identifiers, pages viewed, referral URLs, session duration, and interaction events. This data is collected through cookies and similar technologies as described in our Cookie Policy.
We retain records of emails, telephone notes, meeting summaries, and other communications where relevant to managing wholesale relationships, fulfilling orders, handling complaints, or demonstrating compliance with regulatory obligations applicable to the product categories we supply.
For certain regulated product categories, including alcoholic beverages, chemicals, and druggists sundries, we may collect additional verification data such as trade licence numbers, age verification confirmations for authorised signatories, premises licences held by your business, and documentation supporting your entitlement to receive controlled or restricted goods.
We process personal data only where a lawful basis under Article 6 UK GDPR applies. The primary lawful bases we rely upon are: performance of a contract or steps prior to entering a contract; compliance with legal obligations; legitimate interests pursued by us or third parties where not overridden by your rights; and consent where specifically obtained for particular processing activities such as non-essential marketing cookies or optional newsletter subscriptions.
We use identity and contact data to register wholesale accounts, authenticate users, communicate order confirmations, coordinate deliveries, and provide customer support. Transaction data is used to fulfil orders, manage inventory allocation, produce invoices, and maintain audit trails. Financial data is used to process payments, assess creditworthiness where trade credit is offered, and prevent fraud.
Technical data is used to administer and protect our website and IT infrastructure, conduct troubleshooting, analyse trends, and measure the effectiveness of our digital presence. Where we rely on legitimate interests, we have conducted balancing assessments considering the nature of data, reasonable expectations of wholesale customers operating in a B2B context, and the impact on individuals.
We may send wholesale trade updates, new product range announcements, and service information to business contacts where permitted under PECR and UK GDPR. For existing customers, we may communicate similar products and services based on legitimate interests in growing our wholesale business, always providing a clear opt-out mechanism in each communication.
Where we send electronic marketing to prospective business contacts who have not previously purchased from us, we will obtain appropriate consent or rely on the soft opt-in provisions only where strictly applicable to corporate subscribers. You may unsubscribe from marketing emails using the link provided or by contacting info@lifenex.guru at any time.
We share personal data with trusted third parties only where necessary for the purposes described in this Policy and subject to appropriate safeguards. Categories of recipients include carriers and logistics partners for delivery fulfilment; warehouse and fulfilment operators; payment processors and banks; professional advisers including solicitors and accountants; IT service providers hosting our website and business systems; credit reference agencies where trade accounts are underwritten; and regulatory or law enforcement bodies where required by law.
We require third-party processors to protect personal data in accordance with data protection law and to process data only for specified purposes. We do not sell personal data to third parties. Where data is transferred outside the United Kingdom, we implement appropriate transfer mechanisms such as UK International Data Transfer Agreements or adequacy regulations as applicable at the time of transfer.
Our primary systems and data storage are located within the United Kingdom. Where we or our processors transfer personal data to countries outside the UK, we ensure a level of protection essentially equivalent to that under UK GDPR through approved transfer tools, supplementary measures where required following transfer risk assessments, and contractual clauses mandated by the ICO.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, tax, accounting, or reporting requirements. Wholesale transaction records are typically retained for seven years from the end of the financial year in which the transaction occurred to comply with HM Revenue and Customs requirements unless a longer period is required for ongoing disputes or regulatory investigations.
Marketing suppression lists are retained indefinitely where necessary to honour opt-out requests. Website server logs may be retained for a shorter period consistent with security monitoring needs. When personal data is no longer required, we securely delete or anonymise it in accordance with our data retention schedule.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, destruction, accidental loss, and other unlawful processing. Measures include access controls limiting data to personnel with legitimate business need, encrypted connections for website traffic, secure backup procedures, staff training on data protection, and incident response processes.
While we take security seriously, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but will notify you and the ICO of personal data breaches where required by law.
Subject to applicable exemptions, you have the following rights: the right of access to your personal data; the right to rectification of inaccurate data; the right to erasure in certain circumstances; the right to restrict processing; the right to data portability where processing is based on consent or contract and carried out by automated means; the right to object to processing based on legitimate interests or for direct marketing; and rights related to automated decision-making including profiling where applicable.
To exercise your rights, contact info@lifenex.guru with sufficient information to verify your identity and specify the right you wish to exercise. We will respond within one month unless the request is complex or numerous, in which case we may extend by a further two months with explanation. You have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk if you believe our processing infringes data protection law.
Our website and wholesale services are directed at businesses and trade buyers. We do not knowingly collect personal data from individuals under eighteen years of age. If you believe we have inadvertently collected data relating to a minor, please contact us promptly so we can take appropriate steps to delete such information.
We do not generally make solely automated decisions producing legal or similarly significant effects concerning individuals without human involvement. Credit assessments for trade accounts may involve automated scoring supplemented by manual review by authorised personnel. Where solely automated decision-making is introduced in future, we will provide required information and safeguards.
Our website may contain links to third-party websites such as carrier tracking portals or payment gateways. We are not responsible for the privacy practices of those websites and encourage you to read their privacy policies before providing personal data.
As a merchant wholesaler supplying regulated product categories, certain personal data processing activities are incidental to compliance with the Licensing Act 2003, Food Safety Act 1990, UK CLP regulations for chemicals, Health and Safety at Work etc. Act 1974, and associated secondary legislation. We process identification and premises data of authorised recipients to verify lawful supply chains and to maintain records that may be inspected by relevant authorities.
Processing for regulatory compliance is based on legal obligation and, where appropriate, legitimate interests in preventing unlawful distribution of restricted goods. We minimise data collected to what is necessary for verification and record-keeping duties.
This Policy primarily addresses data relating to customers, website users, and business contacts. Separate privacy notices apply to employees, workers, and job applicants, available upon request to candidates and staff. Employee data is processed for employment administration, payroll, health and safety, and legal compliance.
We may update this Privacy Policy periodically to reflect changes in law, regulatory guidance, technology, or our business practices. Material changes will be communicated through prominent notice on lifenex.guru or direct communication to registered account holders where appropriate. The Last Updated date at the top of this document indicates when the Policy was most recently revised.
We do not routinely process special category personal data as defined in UK GDPR. Where health and safety incident reports incidentally contain health data, we process such data only as necessary for legal claims, health and safety compliance, or vital interests with appropriate safeguards. We do not process criminal offence data except where necessary for regulatory compliance relating to alcohol licensing verification using publicly available registers.
We embed data protection considerations into new projects affecting personal data, including wholesale portal enhancements, CRM deployments, and logistics integrations. Default settings minimise data collection and retention periods are configured to the shortest period compatible with business and legal needs unless Customers request extended archival for audit cooperation.
Data protection complaints are logged, investigated, and responded to without undue delay. Escalation paths are available where initial responses are unsatisfactory. We cooperate with ICO investigations and implement remedial actions identified through audit or regulatory feedback.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
When engaging subprocessors for cloud hosting or courier integrations, we perform due diligence on security certifications and require breach notification within twenty-four hours of awareness.
Marketing suppression flags are honoured across all outbound channels including email, telephone campaigns where permitted, and posted trade catalogues upon request.
We do not use personal data for automated profiling that produces legal effects concerning individuals without explicit disclosure and appropriate safeguards.
Data portability requests are fulfilled using structured, commonly used machine-readable formats where technically feasible and where processing is based on consent or contract.
We review our data processing activities annually and following material changes to systems, suppliers, or product lines to ensure continued compliance with UK data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Where personal data is processed for credit management, we retain records demonstrating lawful basis, retention periods applied, and any objections received, in line with Information Commissioner guidance on business-to-business processing.
Our Weston-Super-Mare operations centre coordinates data subject requests across sales, logistics, and accounts functions to ensure responses are complete and timely.
Staff with access to personal data receive induction and refresher training covering phishing risks, secure disposal, and escalation of suspected breaches to designated data protection contacts.
We maintain records of processing activities as required by Article 30 UK GDPR, documenting categories of data subjects, personal data types, recipients, transfers, retention, and security measures.
Privacy impact assessments are conducted before deploying new systems that involve large-scale processing, sensitive categories, or systematic monitoring of publicly accessible areas.
Related legal documents: Privacy Policy, Cookie Policy, Terms of Service, Terms & Conditions.
For questions regarding this document, contact LIFENEX LTD at info@lifenex.guru, telephone +447446968859, or by post to 29 Drove Road, Weston-Super-Mare, United Kingdom, BS23 3NN.