Last updated: 03/04/26.

This Privacy Policy explains how Serena Haywood, also known as Sweena, collects, uses, stores and protects your personal data when you visit this website, sign up to my mailing list, contact me, place an order, or otherwise interact with my work online.

For the purposes of UK data protection law, the data controller is:

Serena Haywood
Trading name, if any: Serena Haywood / Sweena
Location: United Kingdom
Contact me here.
Website: https://www.sweena.co.uk

Who this policy applies to:

This policy applies to visitors to this website and to anyone who contacts me, joins my mailing list, purchases directly from this website, submits a form, or interacts with linked services connected to my work.

The personal data I may collect:

Depending on how you use the site, I may collect and process the following personal data:

  • Your name

  • Your email address

  • Your billing and delivery address

  • Your phone number, if you provide one

  • Order and transaction details

  • Details you submit through contact forms or email

  • Marketing preferences and newsletter sign-up information

  • Technical data such as IP address, browser type, device type, operating system and basic usage data

  • Cookie and analytics data

  • Any other information you choose to send to me.

I do not intentionally collect special category personal data through this website. Please do not send sensitive personal information unless it is genuinely necessary.

How I collect your data:

I may collect your personal data when:

  • You browse this website

  • You fill in a contact form

  • You sign up to receive emails or updates

  • You buy a book, signed copy or other product directly from this site

  • You contact me by email or through social media

  • You interact with embedded content, external links or connected services

  • You accept or reject cookies through the cookie banner.

How I use your data:

I may use your personal data to:

  • Respond to your messages or enquiries

  • Send newsletters, launch updates, release news or marketing emails where you have agreed to receive them

  • Process and fulfil orders

  • Take payment or work with payment providers

  • Arrange shipping or delivery

  • Improve the website, user experience and performance

  • Monitor traffic, site usage and content engagement

  • Prevent fraud, misuse or technical issues

  • Comply with legal, tax and accounting obligations

  • Keep appropriate internal records.

I will never share or sell your personal data.

My lawful bases for processing:

Under UK data protection law, I rely on one or more of the following lawful bases depending on the activity:

Consent
Where you sign up to receive marketing emails, newsletters or updates, I rely on your consent. You can withdraw that consent at any time by clicking unsubscribe in any email or by contacting me directly.

Contract
Where you place an order, ask me to provide a product or service, or take steps before entering into a contract, I may process your data because it is necessary to perform that contract or respond to your request.

Legal obligation
I may process certain information where I need to comply with a legal obligation, for example for tax, accounting or consumer law requirements.

Legitimate interests
I may process personal data where it is necessary for my legitimate interests in running, protecting and improving my website, business, books and reader communications, provided those interests are not overridden by your rights and freedoms.

Marketing communications:

If you sign up to my mailing list, I may send you emails about books, graphic novels, launches, Kickstarters, updates, events, behind-the-scenes content and other related news.

I will only send you marketing emails where I am allowed to do so by law. You can unsubscribe at any time using the link in any email or by contacting me here.

I do not sell your personal data to third parties for their own marketing.

Payments and orders:

If you buy directly from this website, I may need to collect the personal data required to process your order, take payment, arrange delivery and keep proper transaction records for tax and or VAT purposes.

Payments may be handled by third-party payment processors. I do not store full card details on my own systems unless clearly stated otherwise. Please also review the privacy policies of any payment provider used on this website.

If products are fulfilled through third-party platforms, printers, shipping services or marketplaces, your information may be shared with them only where needed to complete your order or comply with legal obligations.

Third-party services and processors:

I may use trusted third-party service providers to operate this website and related services, including services for:

  • Website hosting and site management

  • Email newsletters and mailing list management

  • Payment processing

  • Order fulfilment and delivery

  • Website analytics

  • Spam prevention and site security

  • Social media embeds or integrations.

These providers process personal data on my behalf where necessary. Some may also act as independent controllers for their own services. You should check their own privacy notices where relevant.

Examples may include, if used on this site:

  • Squarespace

  • Stripe

  • PayPal

  • Mailchimp, Kit or other email platform

  • Google Analytics

  • Facebook, Instagram, TikTok, Threads, Twitter or social media platforms

  • Amazon or Kickstarter, if you follow links to those services.

Cookies and similar technologies:

This website may use cookies and similar technologies to make the site work properly, remember preferences, measure traffic and understand how visitors use the site.

Some cookies are strictly necessary for the website to function. Others, such as analytics or marketing cookies, should only be used where valid consent has been obtained.

A separate Cookies Policy should be read alongside this Privacy Policy.

Sharing your data:

I may share your personal data where necessary with:

  • Website platform providers

  • Email marketing platforms

  • Payment processors

  • Delivery, printing or fulfilment providers

  • Professional advisers such as accountants, lawyers or insurers

  • IT, analytics and security providers

  • Regulators, law enforcement or courts where/if required by law.

I only share the minimum information reasonably necessary for the relevant purpose.

International transfers:

Some of the third-party providers I use may store or process personal data outside the UK. Where that happens, I take steps intended to ensure your data is given an appropriate level of protection in line with UK data protection law.

This may include relying on adequacy regulations, contractual safeguards, or other lawful transfer mechanisms required under the UK GDPR.

How long I keep your data:

I keep personal data only for as long as reasonably necessary for the purposes set out in this policy, including to satisfy legal, accounting, tax, reporting and record-keeping requirements.

Typical retention periods may include:

  • Contact form enquiries: up to 24 months after the last meaningful contact, unless a longer period is needed

  • Newsletter subscriber data: until you unsubscribe or request deletion, subject to limited suppression records so I can respect your unsubscribe request

  • Order and transaction records: usually up to 6 years for tax and accounting purposes

  • Technical and analytics data: for as long as reasonably necessary for security, performance and reporting purposes, depending on the tool used.

I may retain data for longer where required by law, to deal with disputes, or to enforce legal rights.

Your data protection rights:

Depending on the circumstances, you may have the right to:

  • Be informed about how your personal data is used

  • Request access to the personal data I hold about you

  • Request correction of inaccurate or incomplete data

  • Request deletion of your data

  • Request restriction of processing

  • Object to certain processing, including some uses based on legitimate interests and direct marketing

  • Request transfer of certain data to you or another provider

  • Withdraw consent at any time where consent is the basis for processing.

These rights are not absolute and may only apply in certain circumstances. To exercise any of them, contact me here.

If you are unhappy with how your data has been handled, you have the right to complain to the Information Commissioner’s Office in the UK.

Children’s privacy:

This website is not intended to knowingly collect personal data from children under 13 without appropriate parental involvement. If you believe a child has provided personal data through this website, please contact me and I will deal with it appropriately.

Security:

I take reasonable technical and organisational measures to help protect personal data from unauthorised access, loss, misuse, alteration or disclosure. However, no online system can ever be guaranteed completely secure, so you use the site at your own risk.

External links:

This website may contain links to third-party websites, platforms or shops, including social media, Amazon, Kickstarter or other services. Once you leave this website, I am not responsible for the privacy practices of those third parties. Please review their privacy policies separately.

Changes to this policy:

I may update this Privacy Policy from time to time to reflect changes in the law, my website, or how I process personal data. The latest version will always be posted on this page with the updated date shown at the top.

Contact:

If you have any questions about this Privacy Policy or how your data is handled, contact:

Serena Haywood
Contact me here.
Website: https://sweena.co.uk