Data Processing Information
Last updated: 6 August 2026
On this page
1. Purpose of this page
This page supplements the Privacy Policy with practical detail about processing activities, providers and safeguards. It is intended for customers who need to record how their supplier handles data.
2. Roles
For enquiries and purchases made through this website, NorthLens Studio is the data controller. Where you use the supplied workflow resources to record information about your own clients, you are the controller for that information and NorthLens Studio does not have access to it unless you send it to us for support purposes.
3. Processing activities
- Receiving and responding to website enquiries.
- Creating Stripe Checkout Sessions using server-side package data only.
- Verifying Checkout Sessions with Stripe before displaying order details.
- Receiving signature-verified Stripe webhooks and writing minimal event records.
- Preparing and sending digital access or setup instructions by email.
- Handling refund requests, duplicate-payment investigations and complaints.
4. Categories of data
- Identity and contact data — name, email address, telephone number if you provide it.
- Transaction data — package purchased, amount, currency, payment status, order reference.
- Correspondence data — the content of enquiries and support messages.
- Technical data — IP address and standard server log entries, used for security and abuse prevention.
5. Sub-processors
- Stripe — payment processing, Checkout, receipts, refunds and fraud prevention.
- Hostinger — website hosting, email delivery and server logs.
- Business email provider — storage and delivery of correspondence.
6. Location and transfers
Hosting and email are provided within the UK or EEA where available. Stripe operates internationally and applies its own transfer safeguards, including standard contractual clauses where relevant.
7. Retention
- Enquiry correspondence — normally up to 24 months from last contact.
- Transaction and accounting records — at least six years.
- Payment-event log entries — normally up to 12 months.
- Server logs — the hosting provider's standard retention period.
8. Security measures
- HTTPS across the whole website, with HSTS and a restrictive content security policy.
- Stripe credentials stored in a protected configuration file outside the publicly served directory.
- Webhook payloads verified against the Stripe signature before processing.
- Payment logs stored in a directory that denies all web access, containing truncated identifiers only.
- Rate limiting on the payment and contact endpoints.
- No card data collected, transmitted or stored by NorthLens Studio.
9. Data subject requests
Requests to access, correct, delete or restrict personal information should be sent to info@northlensstudio.co.uk. We aim to respond within one calendar month.
10. Breach handling
If a personal data breach occurs that is likely to result in a risk to individuals, it will be assessed promptly, reported to the Information Commissioner's Office where required within 72 hours, and affected individuals will be informed where the law requires it.
11. Contact
NorthLens Studio is a trading name operated by Aayush Rai as an independent sole trader in the United Kingdom.
1 Bateson Street, London, SE18 1DA, United KingdomEmail: info@northlensstudio.co.uk · Telephone: +44 7867 527009
Questions about this document should be sent to info@northlensstudio.co.uk. This policy is written for the NorthLens Studio website and its one-time digital software packages, and is not legal advice.