-------   LEGAL

PRIVACY POLICY
& GDPR

-----------------

This policy explains what personal data susiesharp.co.uk collects, why it is collected, how it is used, and the rights you have under UK GDPR. It is written in plain English because that is how Susie writes everything.

Last updated: June 2025  ·  Applies to:susiesharp.co.uk   · Reflects  the Data (Use and Access) Act 2025

CONTENTS

-------   01

Who we are

The data controller for this website is:

Susie Sharp
Trading as: Susie Sharp (sole trader)
Website: www.susiesharp.co.uk
Email: info@susiesharp.co.uk
Based in: Brecon, Wales, United Kingdom

As a sole trader based in the United Kingdom, Susie Sharp is subject to the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA), which amended UK data protection law in stages from February 2026. This website is not required to register with the Information Commissioner's Office (ICO) unless personal data is processed for purposes beyond those covered by the sole trader exemption — but Susie Sharp is committed to handling all personal data responsibly and in accordance with this policy.

-------   02

What data we collect


DATA COLLECTED

WHERE COLLECTED

REQUIRED?

First name

Newsletter sign-up form, contact form

Newsletter: yes · Contact: yes

Email address

Newsletter sign-up form, contact form

Yes

Last name

Contact form

No (Optional)

Message content

Contact form

Yes

Enquiry type

Contact form

Yes

IP address & browsing data

Google Analytics (automatic)

Automatic

Payment information

 PayPal (for signed copy orders)

Yes — processed by PayPal

Note on payment data: 
Susie Sharp does not directly collect or store any payment card or financial data. All payments for signed copies are processed by PayPal, whose own privacy policy and data practices apply to payment transactions.content

-------   03

Why we collect it

Newsletter subscriptions

When you subscribe to Susie's News, your name and email address are used to send you Susie's monthly newsletter. This includes writing updates, book announcements, early access to new releases, giveaways, and the free Midlife Plot Twist Playbook delivered on sign-up. You can unsubscribe at any time using the link at the bottom of every email.

Contact form submissions

When you submit the contact form, your name, email address, and message are used solely to respond to your enquiry. Messages are not added to any mailing list without your separate consent.

Analytics

This website uses Google Analytics to understand how visitors use the site — which pages are visited, how long visitors stay, and how they arrived. This data is used only to improve the website. It does not identify you personally. Google Analytics data is processed by Google LLC. For more information, see Google's privacy policy.

Signed copy orders

When you order a signed copy, your name, postal address, and payment details are required to fulfil your order. Payment is handled by PayPal. Susie Sharp retains your name and postal address for the purpose of posting your order and, where required, for financial record-keeping as a sole trader.

-------   04

Lawful basis for processing

Under UK GDPR and the Data (Use and Access) Act 2025, personal data must be processed on a lawful basis. The lawful bases used by this website are:

PURPOSE

LAWFUL BASIS

Sending Susie's News newsletter

Consent — you have actively opted in by subscribing

Responding to contact form enquiries

Legitimate interests — to respond to your enquiry as requested

Processing signed copy orders

Contract — to fulfil the order you have placed

Financial record-keeping

Legal obligation — HMRC requirements for sole traders

Google Analytics

Consent (via cookie consent) and legitimate interests — improving the website

-------   05

Third parties & data processors

Susie Sharp uses the following third-party services which may process your personal data on her behalf:

MailerLite

Email newsletter delivery. Your name and email address are stored on MailerLite's servers to enable the sending of Susie's News. MailerLite is GDPR-compliant and based in the EU. MailerLite privacy policy →

Google Analytics

Website analytics. Anonymised usage data is shared with Google LLC. Google may transfer data to the United States. Under the Data (Use and Access) Act 2025, such transfers are assessed against the UK's data protection test — whether the standard of protection in the destination country is not materially lower than in the UK. Google operates under an International Data Transfer Agreement (IDTA) for UK data transfers. Google privacy policy →

PayPal

Payment processing for signed copies. PayPal processes your payment data in accordance with their own privacy policy. Susie Sharp does not have access to your payment card details. PayPal privacy policy →

Yola (website hosting)

This website is hosted on Yola. Yola may collect standard server log data (such as IP addresses) as part of normal website hosting operations. Yola privacy policy →

No selling of data: 
Susie Sharp does not sell, rent, or share your personal data with any third party for marketing purposes. Your data is used only as described in this policy.

-------   06

How long we keep your data

DATA TYPE

RETENTION PERIOD

Newsletter subscriber data

Until you unsubscribe, after which it is deleted from MailerLite within 30 days

Contact form messages

Up to 12 months, or until the enquiry is resolved and the correspondence is no longer needed

Signed copy order details (name & address)

Up to 6 years, in accordance with HMRC requirements for sole trader financial records

Google Analytics data

26 months (Google Analytics default retention period)

-------   07

Cookies

Cookies are small text files stored on your device when you visit a website. This website uses the following types of cookies:

ESSENTIAL COOKIES ALWAYS ACTIVE
These cookies are required for the website to function. They do not collect personal information and cannot be switched off. They may be set by Yola as the website host. 
ANALYTICS COOKIES REQUIRES CONSENT
Google Analytics uses cookies to collect anonymised information about how visitors use this website. These cookies do not identify you personally. They collect information such as the number of visitors, the pages they visit, and how they arrived at the site.

If you wish to opt out of Google Analytics tracking, you can do so by installing the Google Analytics Opt-out Browser Add-on.

Note: Yola, the platform on which this site is hosted, may set additional cookies as part of its standard hosting operation. Susie Sharp does not control these cookies. Please check Yola's privacy policy for details.

You can control and delete cookies through your browser settings. Note that disabling cookies may affect the functionality of some parts of this website.

-------   08

Your rights under UK GDPR

Under UK GDPR and the Data (Use and Access) Act 2025, you have the following rights in relation to your personal data:

Right of access

You can request a copy of the personal data Susie Sharp holds about you at any time.

Right to rectification

You can ask for inaccurate or incomplete personal data to be corrected.

Right to erasure

You can ask for your personal data to be deleted — sometimes known as the "right to be forgotten" — where there is no compelling reason for its continued processing.

Right to restrict processing

You can ask for the processing of your personal data to be restricted in certain circumstances.

Right to data portability

Where processing is based on consent or contract and carried out by automated means, you can request your data in a structured, commonly used, machine-readable format.

Right to object

You can object to the processing of your personal data where it is based on legitimate interests. You can also object to receiving direct marketing at any time.

Right to withdraw consent

Where processing is based on consent (for example, newsletter subscription), you can withdraw your consent at any time. This does not affect the lawfulness of processing that took place before withdrawal.

Right to complain to the controller NEW — JUNE 2026

Under the Data (Use and Access) Act 2025, from 19 June 2026 you have a specific right to raise a data protection complaint directly with Susie Sharp as the data controller. Susie Sharp will acknowledge your complaint within 30 days and provide a full response within a reasonable timeframe.

Please email info@susiesharp.co.uk with the subject line "Data Protection Complaint."

 To exercise any of these rights, please contact Susie Sharp by email at info@susiesharp.co.uk. Requests and complaints will be acknowledged within 30 days in accordance with the Data (Use and Access) Act 2025.

If you are unhappy with how Susie Sharp has handled your complaint or data request, you then have the right to escalate to the Information Commissioner's Office (ICO). Under the Data (Use and Access) Act 2025, from June 2026 you are expected to raise your concern with the controller first before contacting the ICO.

ico.org.uk/make-a-complaint  ·  Telephone: 0303 123 1113

-------   09

Children

This website is intended for adults. The content — women's fiction for women over 40 — is not directed at children under the age of 18.

Susie Sharp does not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data through this website, please contact info@susiesharp.co.uk and it will be deleted promptly.

-------   10

Changes to this policy

This privacy policy may be updated from time to time to reflect changes in law, technology, or how this website operates. The date at the top of this page will always show when it was last updated. Significant changes will be communicated to newsletter subscribers by email.

Continued use of this website after any changes constitutes acceptance of the updated policy.

-------   11

Get in touch

For any questions, requests, or concerns about this privacy policy or the way your personal data is handled, please contact:

Susie Sharp
Email: info@susiesharp.co.uk
Website: susiesharp.co.uk/contact

Susie aims to respond to all data-related requests within one calendar month as required by UK GDPR. If your request is particularly complex or you have made multiple requests, she may extend this period by a further two months — but will let you know within the first month if this is the case.

Susie  Sharp

Writing emotionally layered women's fiction for midlife women. Based in Brecon, Wales.

© 2026 Susie Sharp