Last updated: 03/04/26.
This Privacy Policy explains how Serena Haywood, also known as Sweena, collects, uses, stores and protects your personal data when you visit this website, sign up to my mailing list, contact me, place an order, or otherwise interact with my work online.
For the purposes of UK data protection law, the data controller is:
Serena Haywood
Trading name, if any: Serena Haywood / Sweena
Location: United Kingdom
Contact me here.
Website: https://www.sweena.co.uk
Who this policy applies to:
This policy applies to visitors to this website and to anyone who contacts me, joins my mailing list, purchases directly from this website, submits a form, or interacts with linked services connected to my work.
The personal data I may collect:
Depending on how you use the site, I may collect and process the following personal data:
Your name
Your email address
Your billing and delivery address
Your phone number, if you provide one
Order and transaction details
Details you submit through contact forms or email
Marketing preferences and newsletter sign-up information
Technical data such as IP address, browser type, device type, operating system and basic usage data
Cookie and analytics data
Any other information you choose to send to me.
I do not intentionally collect special category personal data through this website. Please do not send sensitive personal information unless it is genuinely necessary.
How I collect your data:
I may collect your personal data when:
You browse this website
You fill in a contact form
You sign up to receive emails or updates
You buy a book, signed copy or other product directly from this site
You contact me by email or through social media
You interact with embedded content, external links or connected services
You accept or reject cookies through the cookie banner.
How I use your data:
I may use your personal data to:
Respond to your messages or enquiries
Send newsletters, launch updates, release news or marketing emails where you have agreed to receive them
Process and fulfil orders
Take payment or work with payment providers
Arrange shipping or delivery
Improve the website, user experience and performance
Monitor traffic, site usage and content engagement
Prevent fraud, misuse or technical issues
Comply with legal, tax and accounting obligations
Keep appropriate internal records.
I will never share or sell your personal data.
My lawful bases for processing:
Under UK data protection law, I rely on one or more of the following lawful bases depending on the activity:
Consent
Where you sign up to receive marketing emails, newsletters or updates, I rely on your consent. You can withdraw that consent at any time by clicking unsubscribe in any email or by contacting me directly.
Contract
Where you place an order, ask me to provide a product or service, or take steps before entering into a contract, I may process your data because it is necessary to perform that contract or respond to your request.
Legal obligation
I may process certain information where I need to comply with a legal obligation, for example for tax, accounting or consumer law requirements.
Legitimate interests
I may process personal data where it is necessary for my legitimate interests in running, protecting and improving my website, business, books and reader communications, provided those interests are not overridden by your rights and freedoms.
Marketing communications:
If you sign up to my mailing list, I may send you emails about books, graphic novels, launches, Kickstarters, updates, events, behind-the-scenes content and other related news.
I will only send you marketing emails where I am allowed to do so by law. You can unsubscribe at any time using the link in any email or by contacting me here.
I do not sell your personal data to third parties for their own marketing.
Payments and orders:
If you buy directly from this website, I may need to collect the personal data required to process your order, take payment, arrange delivery and keep proper transaction records for tax and or VAT purposes.
Payments may be handled by third-party payment processors. I do not store full card details on my own systems unless clearly stated otherwise. Please also review the privacy policies of any payment provider used on this website.
If products are fulfilled through third-party platforms, printers, shipping services or marketplaces, your information may be shared with them only where needed to complete your order or comply with legal obligations.
Third-party services and processors:
I may use trusted third-party service providers to operate this website and related services, including services for:
Website hosting and site management
Email newsletters and mailing list management
Payment processing
Order fulfilment and delivery
Website analytics
Spam prevention and site security
Social media embeds or integrations.
These providers process personal data on my behalf where necessary. Some may also act as independent controllers for their own services. You should check their own privacy notices where relevant.
Examples may include, if used on this site:
Squarespace
Stripe
PayPal
Mailchimp, Kit or other email platform
Google Analytics
Facebook, Instagram, TikTok, Threads, Twitter or social media platforms
Amazon or Kickstarter, if you follow links to those services.
Cookies and similar technologies:
This website may use cookies and similar technologies to make the site work properly, remember preferences, measure traffic and understand how visitors use the site.
Some cookies are strictly necessary for the website to function. Others, such as analytics or marketing cookies, should only be used where valid consent has been obtained.
A separate Cookies Policy should be read alongside this Privacy Policy.
Sharing your data:
I may share your personal data where necessary with:
Website platform providers
Email marketing platforms
Payment processors
Delivery, printing or fulfilment providers
Professional advisers such as accountants, lawyers or insurers
IT, analytics and security providers
Regulators, law enforcement or courts where/if required by law.
I only share the minimum information reasonably necessary for the relevant purpose.
International transfers:
Some of the third-party providers I use may store or process personal data outside the UK. Where that happens, I take steps intended to ensure your data is given an appropriate level of protection in line with UK data protection law.
This may include relying on adequacy regulations, contractual safeguards, or other lawful transfer mechanisms required under the UK GDPR.
How long I keep your data:
I keep personal data only for as long as reasonably necessary for the purposes set out in this policy, including to satisfy legal, accounting, tax, reporting and record-keeping requirements.
Typical retention periods may include:
Contact form enquiries: up to 24 months after the last meaningful contact, unless a longer period is needed
Newsletter subscriber data: until you unsubscribe or request deletion, subject to limited suppression records so I can respect your unsubscribe request
Order and transaction records: usually up to 6 years for tax and accounting purposes
Technical and analytics data: for as long as reasonably necessary for security, performance and reporting purposes, depending on the tool used.
I may retain data for longer where required by law, to deal with disputes, or to enforce legal rights.
Your data protection rights:
Depending on the circumstances, you may have the right to:
Be informed about how your personal data is used
Request access to the personal data I hold about you
Request correction of inaccurate or incomplete data
Request deletion of your data
Request restriction of processing
Object to certain processing, including some uses based on legitimate interests and direct marketing
Request transfer of certain data to you or another provider
Withdraw consent at any time where consent is the basis for processing.
These rights are not absolute and may only apply in certain circumstances. To exercise any of them, contact me here.
If you are unhappy with how your data has been handled, you have the right to complain to the Information Commissioner’s Office in the UK.
Children’s privacy:
This website is not intended to knowingly collect personal data from children under 13 without appropriate parental involvement. If you believe a child has provided personal data through this website, please contact me and I will deal with it appropriately.
Security:
I take reasonable technical and organisational measures to help protect personal data from unauthorised access, loss, misuse, alteration or disclosure. However, no online system can ever be guaranteed completely secure, so you use the site at your own risk.
External links:
This website may contain links to third-party websites, platforms or shops, including social media, Amazon, Kickstarter or other services. Once you leave this website, I am not responsible for the privacy practices of those third parties. Please review their privacy policies separately.
Changes to this policy:
I may update this Privacy Policy from time to time to reflect changes in the law, my website, or how I process personal data. The latest version will always be posted on this page with the updated date shown at the top.
Contact:
If you have any questions about this Privacy Policy or how your data is handled, contact:
Serena Haywood
Contact me here.
Website: https://sweena.co.uk

