Dooley's Wool Privacy Policy
Last updated: 9 September 2026
At Sommer’s Seasonal Surprises, we respect your privacy and take the protection of your personal information seriously.
This Privacy Policy explains what information we collect when you visit our website, contact us or place an order, why we use it and the rights you have in relation to your personal data.
1. Who We Are
Sommer’s Seasonal Surprises is a small, family-run gift hamper business based in Roscrea, Co. Tipperary, Ireland.
For the purposes of applicable data protection law, Sommer’s Seasonal Surprises is the data controller in respect of the personal information described in this policy.
Trading name: Sommer’s Seasonal Surprises
2. Information We Collect
Depending on how you interact with us, we may collect information including:
-
your name;
-
billing address;
-
delivery address;
-
email address;
-
telephone number;
-
details of products you order;
-
order value and payment status;
-
gift recipient details that you provide;
-
gift messages or order notes;
-
correspondence you send to us;
We only collect information that is reasonably necessary for the operation of our business and website.
3. Information About Gift Recipients
Many of our products are purchased as gifts.
If you provide another person’s name, address or telephone number so that we can deliver a gift to them, we will use that information only as reasonably necessary to prepare, arrange and complete the delivery, deal with any issue relating to it, and meet applicable legal requirements.
We do not add gift recipients to marketing lists simply because somebody has sent them a gift.
4. Why We Use Your Information
We may use your personal information to:
-
process and fulfil your orders;
-
arrange and complete deliveries;
-
process or confirm payments;
-
communicate with you about an order;
-
provide customer service;
-
respond to questions and enquiries;
-
maintain appropriate business and accounting records;
-
prevent fraud or misuse of our website;
-
maintain the security and operation of our website;
-
improve our website and services; and
-
comply with legal and regulatory obligations;
We do not sell your personal information.
5. Our Legal Bases for Processing
Under the General Data Protection Regulation (GDPR), we must have a lawful reason for using your personal information.
Depending on the circumstances, we process personal information on the following bases:
Contract
We process information where it is necessary to fulfil an order or take steps requested by you before entering into a contract.
For example, we need your name and delivery details in order to deliver your hamper.
Legal Obligation
We may process or retain information where required to meet legal, taxation, accounting or other regulatory obligations.
Legitimate Interests
We may process certain information where reasonably necessary for the legitimate operation, security and improvement of our business, provided those interests do not override your rights and freedoms.
Consent
Where processing requires your consent, such as certain marketing communications or non-essential cookies, we will ask for it.
You may withdraw your consent at any time.
6. Online Orders and WooCommerce
Our online shop is powered by WordPress and WooCommerce.
When you place an order, information required to process that order is stored within our website and e-commerce system.
This can include your contact details, billing and delivery information, products ordered, order notes, payment status and order history.
We restrict access to this information to people and service providers who need it for legitimate business purposes.
7. Payments
Payments made through our website may be processed by the payment provider made available to you at checkout.
The payment provider may process information necessary to authorise and complete your payment in accordance with its own privacy and security practices.
Sommer’s Seasonal Surprises will retain appropriate transaction and payment-status records but does not intentionally collect more payment information than is necessary for the transaction and operation of our business.
8. Website Hosting and Data Security
Our website is hosted on a dedicated server located in Germany, within the European Economic Area.
We take reasonable technical and organisational measures to protect the personal information we hold against loss, misuse, unauthorised access, alteration and disclosure.
These measures include appropriate website, server and access security.
However, no internet-connected system can be guaranteed to be completely secure. We therefore continually take reasonable steps to protect the information entrusted to us.
9. Who We Share Information With
We do not sell or rent personal information.
Where necessary, information may be shared with trusted service providers that help us operate our business, such as:
-
website and hosting service providers;
-
payment processors;
-
email and communications providers;
-
IT and website support providers;
-
accountants or professional advisers; and
-
public authorities where disclosure is required by law.
We only provide service providers with the information reasonably necessary for them to perform their role.
Where a third party processes personal information on our behalf, we expect appropriate data protection and security arrangements to be in place.
10. International Data Transfers
Our core website hosting is located in Germany within the European Economic Area.
Some third-party services used in connection with our website, payments or communications may process information in other countries.
Where personal information is transferred outside the European Economic Area, we will rely on an appropriate legal mechanism or safeguard where required by applicable data protection law.
11. How Long We Keep Information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected and to comply with applicable legal requirements.
Order, invoice and transaction information may be retained for the period required for taxation, accounting and legal record-keeping purposes.
In Ireland, certain business and taxation records generally need to be retained for six years.
Other information will normally be retained for shorter periods where there is no ongoing reason or legal requirement to keep it.
For example:
-
enquiry information may be deleted when it is no longer reasonably required;
-
marketing information may be retained until you unsubscribe or withdraw your consent; and
-
website security logs may be retained for a limited period where necessary for security and troubleshooting.
12. Marketing
We don’t do any.
13. Cookies
Our website uses cookies and similar technologies.
Some cookies are necessary for the website and online shop to operate correctly. For example, WooCommerce may need cookies to remember the contents of your shopping basket and allow checkout functionality to work.
We may also use optional cookies for purposes such as analytics, website improvement or other non-essential functionality.
Where required, non-essential cookies will not be activated until you have made the relevant choice through our cookie consent system.
You can also control or delete cookies through your browser settings.
14. Your GDPR Rights
Depending on the circumstances, you may have the right to:
-
request access to the personal information we hold about you;
-
request correction of inaccurate or incomplete information;
-
request deletion of your information;
-
request restriction of how your information is processed;
-
object to certain types of processing;
-
receive certain personal information in a portable format;
-
withdraw consent where processing is based on consent; and
-
lodge a complaint with the Data Protection Commission.
Some of these rights are subject to legal conditions and exceptions.
For example, we may need to retain certain transaction information even after a deletion request where we have a legal obligation to keep it.
15. Exercising Your Rights
If you would like to exercise one of your data protection rights or have a question about how your personal information is handled, please contact us.
We may need to confirm your identity before responding to certain requests in order to protect your information.
We will deal with valid requests in accordance with applicable data protection law.
16. Data Protection Commission
You also have the right to raise concerns about the use of your personal information with the Irish Data Protection Commission.
Further information is available from the Data Protection Commission at www.dataprotection.ie.
17. Third-Party Websites
Our website may contain links to third-party websites or services.
We are not responsible for the privacy practices of websites operated by other organisations. We recommend reviewing their privacy information when leaving our website.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including where we change how the website operates or where legal requirements change.
The latest version will always be made available on our website and the date at the top of this policy will show when it was most recently updated.
19. Contact Us
If you have any questions about this Privacy Policy or how we handle personal information, please contact us.
Sommer’s Seasonal Surprises
Roscrea, Co. Tipperary, Ireland
