Customer support

PRIVACY POLICY – MULTIFOLKS

Effective Date: 27th July 2025

Entity Responsible: GA Multilens Limited (“Multifolks”), a company registered in England & Wales, Company No. 16406960, with its registered office at 2 Leman Street, London, E1W 9US

By using our website (www.multifolks.com and all subdomains, the “Platform”) or providing us with your personal data, you agree to the terms of this Privacy Policy, our Terms of Use, and acknowledge that your data is processed under UK and EU law, not US law.

1. INFORMATION WE COLLECT

We collect and process the following categories of data when you use the Platform:

  • Identity Data – Name, date of birth, prescription details, gender (if provided voluntarily).
  • Contact Data – Email, phone, billing and shipping addresses.
  • Payment Data – Billing details, encrypted card data (processed by PCI-compliant providers).
  • Technical Data – IP address, browser type, cookies, usage statistics, session logs.
  • Health-Related Data (Optional) – Prescription information you upload or enter for lens customization (processed only to fulfill your order).
  • Marketing Data – Preferences for newsletters, promotions, and advertising.

We do not intentionally collect data from minors under the age of 18. If we discover such data, it will be deleted promptly.

2. HOW WE USE YOUR INFORMATION

We use your information strictly for:

  • Order processing and delivery of Products purchased through the Platform.
  • Customer service, returns, refunds, and complaints resolution.
  • Compliance with UK legal obligations, including tax and fraud prevention.
  • Analytics and site improvements, via aggregated or anonymized data.
  • Marketing communications (if you opt in).
  • Cross-border shipping and customs compliance for international orders, including the US.

We do not sell your personal data.

3. INTERNATIONAL DATA TRANSFERS (INCLUDING US CUSTOMERS)

  • All customer data is processed and stored primarily in the United Kingdom and European Economic Area (EEA).
  • If you are located outside the UK (including the US), you consent to the transfer of your data to the UK for processing, where privacy laws differ from those in your jurisdiction.
  • By placing an order, US customers specifically waive any claims under US federal or state privacy laws (including CCPA, CPRA, or similar statutes) and agree that UK GDPR governs their data rights.

4. LEGAL BASIS FOR PROCESSING

We process your data based on:

  • Contractual necessity (to process and deliver your orders).
  • Legitimate interests(to improve our services and prevent fraud).
  • Consent (for optional marketing and health-related data).
  • Legal obligations (such as tax and accounting compliance).

5. DATA RETENTION

  • Order and transaction data: retained for 6 years (as required by UK tax law).
  • Prescription and health data: retained only as long as necessary to fulfill your order, unless you opt to store it for reorders.
  • Marketing data: retained until you withdraw consent.

6. COOKIES & TRACKING

We use cookies and similar technologies to:

  • Enable core site functions (shopping cart, checkout).
  • Measure site performance and traffic (Google Analytics).
  • Deliver personalized ads (Meta/Facebook, Google Ads, or similar).

You may manage or disable cookies in your browser, but certain features of the Platform may not function properly.

7. SHARING WITH THIRD PARTIES

We share your personal data only with:

  • Payment processors (PCI-DSS compliant).
  • Logistics partners (for shipping and customs clearance).
  • IT service providers (for hosting, analytics, and email).
  • Professional advisers (for legal or tax purposes).

We do not authorize third parties to use your data for their own marketing.

8. YOUR RIGHTS (UNDER UK GDPR)

Depending on your location, you have the right to:

  • Access your personal data.
  • Request correction or deletion.
  • Object to processing (including marketing).
  • Request data portability.
  • Withdraw consent at any time (without affecting prior lawful processing).

To exercise your rights, contact us at support@multifolks.com. We may verify your identity before acting on your request.

9. LIMITATION OF LIABILITY FOR DATA BREACHES

While we take appropriate technical and organizational measures to protect your data, we do not guarantee that the Platform or data transmissions are free from unauthorized access or breaches caused by third parties (such as hackers or internet failures).

To the fullest extent permitted by law, Multifolks disclaims liability for any indirect, consequential, or punitive damages arising from such incidents.

10. GOVERNING LAW

This Privacy Policy is governed by the laws of England & Wales.

Any disputes shall be resolved exclusively in the courts of London, UK.

US and other non-UK customers expressly waive the right to bring claims under foreign data protection or privacy statutes, including class actions.

11. UPDATES TO THIS POLICY

We may update this Privacy Policy periodically. Continued use of the Platform after such changes constitutes your acceptance of the updated terms.

12. CONTACT

For questions or data-related requests, contact:

Multifolks (GA Multilens Limited)

Email: support@multifolks.com