Privacy Policy

Norwich Sunblinds Privacy Policy


We respect your privacy and are committed to protecting your personal data. This privacy policy tells you how we collect and process your personal data which you provide to us or which we collect from other sources.

It is important that you read this privacy policy together with any other privacy information we may provide to you on occasion so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.

  9. Important information and who we are

Norwich Sunblinds Limited is the data controller responsible for your personal data. We have appointed a Data Protection Officer who is responsible for overseeing our compliance with data protection law. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact us using the details below.

Email address:              

Postal address:                        FREEPOST NC1013, PO Box 65, Norwich, NR6 6BR

Telephone number:                0800 9889398

We are part of the ASHI Group. For information about how the ASHI Group processes personal data, please see the Group privacy policy available

Our website includes links to other websites, plug-ins and applications owned and managed by third parties which may collect information about you. When you link to other websites, we encourage you to read their own privacy policies.

  1. The data we collect about you

Personal data means any information about an individual from which that person can be identified. It does not include anonymous data where the identity has been removed.

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

Identity Data Name, title and date of birth. If you visit one of our showrooms, depots or offices, this will include CCTV footage which may be captured of you.
Contact Data Billing address, delivery address, email address and telephone numbers.
Financial Data Bank account and payment card details.
Transaction Data Details about payments to and from you and other details of products and services you have purchased from us.
Technical Data IP address, device make and model, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website.
Profile Data Purchases or orders made by you, your interests, preferences, feedback and survey responses.
Usage Data Information about how you use our website, products and services.
Marketing and Communications Data Your preferences in receiving marketing from us and your communication preferences.

We may also collect about information about your health if there is something we need to know in order to adjust our sales and delivery process so that you are treated with appropriate care and kept you safe when we visit your home, or deliver and install our products there.

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

  1. How is your personal data collected?

You may give us your Identity, Contact and Financial Data when you contact us by any means to enquire about or purchase our products or services, book an appointment, request marketing material to be sent to you, enter a competition, promotion or survey, give us feedback or contact us for any reason.

We will also automatically collect Technical Data about your device, browsing actions and patterns when you interact with our website. We collect this data by using cookies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our Cookie Policy  for further information.

We will also receive personal data about your from various third parties, such as website analytics providers (as described in our Cookie Policy), third party payment services providers and delivery services providers.

Finally, we may receive your Identity and Contact Data from the Post Office’s National Change of Address Database, the National Deceased Register, the Telephone Preference Service, Mail Preference Service, our chosen supplier of personal data accuracy services or any similar external data lists we may cross reference either to keep the personal data we hold about you up to date or to ensure that we only communicate with you where we are allowed to do so.

  1. How we use your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data where we need to perform the contract we are about to enter into or have entered into with you, where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests, or where we need to comply with a legal obligation that we are subject to.

Our purposes for using personal data.

We have set out below a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. Where our legal basis is legitimate interests we have described the relevant interest.

Purpose/Activity Type of data Legal basis for processing
To register you as a new customer or register your interest in our products and services Identity and Contact Performance of a contract with you
To visit your property in order to provide you with a quote for our products or services. Identity, ContactMarketing and Communications Performance of a contract with youNecessary for our legitimate interests (to follow up on your interest and provide you with the information you need to decide whether you would like to purchase from us)
To process and deliver your order including management of fees and charges and the collection of money owed to us. Identity, Contact, Financial, Transaction Performance of a contract with youNecessary for our legitimate interests (to recover money due to us)
To manage our relationship with you. Identity, Contact, Profile and Marketing and Communications Performance of a contract with youNecessary to comply with a legal obligation

Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To enable you to partake in a prize draw, competition or complete a questionnaire or survey. Identity, Contact, Profile, Usage, Marketing and Communications Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
To administer and protect our business and our website(s) (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). Identity, Contact, Technical Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)Necessary to comply with a legal obligation
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences. Technical, Usage Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To operate CCTV in our premises. Identity Necessary for our legitimate interests (to ensure the safety of you and our people).
To make suggestions and recommendations to you about goods or services provided by us and other companies within our group that may be of interest to you Identity, Contact, Technical, Usage, Profile, Marketing and Communications Your consent where applicableNecessary for our legitimate interests (to develop our products/services and grow our business)

To introduce or refer you to other companies in our group which provide products which you have expressed an interest in.




 Your consent
To conduct customer research Identity, Contact, Transaction, Profile, Usage Necessary for our legitimate interests (to use customer feedback to improve our products and services)
To display case studies and / or testimonials through any Marketing channels Usage Your consent
To display case studies and / or testimonials through any ASHI Group Marketing channels Usage Your consent
To refer you to other companies within the Anglian Group where you have expressed interest in their products or services and enable them to communicate with you in relation to those products and services. Identity, Contact, Profile, Usage, Marketing and Communications Your consent



You will receive marketing communications from us if you have: (a) subscribed to our offers and updates and consented to receive them or; (b) if you have requested information from us or purchased products or services from us and you have not opted out of receiving marketing communications. You may opt out of receiving marketing from us at any time, either by following the opt-out link in any electronic marketing message or by emailing:

With your consent, we will share your personal data with members of the ASHI Group so that they may send you information about products and services which may be of interest to you. You may withdraw your consent to receive such marketing material at any time.




You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our website(s) may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy.

  1. Disclosures of your personal data

We may share your personal data with the third parties set out below for the purposes set out in this privacy policy. We take steps to ensure that these third parties look after your personal data to the same standard that we do.

  • Service providers who provide IT and system administration services and services platforms.
  • Other companies within our group which provide goods and services which we understand you to be interested in.
  • Service providers based in the UK to whom we may subcontract the delivery and installation of your
  • Delivery companies.
  • Our professional advisers including lawyers, bankers, auditors and insurers.
  • HM Revenue & Customs, regulators and other authorities.
  • Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets or from whom we may seek to acquire other businesses. Any new owners may use your personal data in the same way as set out in this privacy policy.
  • Third parties to perform as measurement services on our behalf.
  1. International transfers

We do not transfer your personal data outside the UK. If this changes, we will update this privacy policy.

  1. Data retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and any applicable legal or regulatory requirements.

  1. Your legal rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to:

Request access to your personal data (commonly known as a “data subject access request”).

Request correction of the personal data that we hold about you.

Request erasure of your personal data where we no longer have a good reason to process it.

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes.

Request restriction of processing of your personal data.

Request the transfer of your automated personal data to you or to a third party in a structured, commonly used, machine-readable format.

Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

For more information about your rights, please see

You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues ( We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please do contact us in the first instance.

If you wish to exercise any of the rights set out above, please contact our Data Protection Officer.