Privacy Policy
This policy explains what personal data Hawkins & Wells handles, why it is used, who receives it, how long it is needed, and the choices and legal rights available to you.
Important: Hawkins & Wells Publishing, based in Reading, Berkshire, United Kingdom, is responsible for the personal data it controls on this site. An external retailer is separately responsible for a purchase completed on its website.
1. Who and what this policy covers
This policy applies when you browse the Hawkins & Wells storefront, create or use a reader account, buy or access a direct digital edition, subscribe to correspondence, join a reward activity, contact Reader Care, send a publishing inquiry, or exercise a privacy right.
It does not govern an external retailer, social network or other independent service reached through a link. Review that service’s privacy information before giving it personal data.
2. Personal data we handle
The data involved depends on how you use the publishing house. We do not ask for information that is not reasonably connected to a defined service, security or legal purpose.
- Identity and account data: name, email address, authentication identifiers, preferred locale and account status.
- Order data: order lines, price, currency, tax evidence, payment-provider reference, refund and dispute status. Hawkins & Wells does not store your full card credentials.
- Library data: purchased entitlements, delivery events, downloads, and reading or listening information used by an enabled feature.
- Support and inquiry data: messages, attachments, case history, contact details and resolution notes.
- Security and technical data: IP address, browser or device information, session identifiers, audit events, request metadata and fraud signals.
- Newsletter data: email address, topics, cadence, locale, double-opt-in evidence, delivery events and unsubscribe status.
- Rewards data: referral code, pseudonymous attribution, activity proof, review decisions, point ledger, redemptions and anti-abuse signals.
- Privacy-request data: request history and proportionate information needed to verify and complete the request securely.
3. Where the data comes from
Most data comes directly from you. We also receive verified payment events from the payment provider, authentication events from the account service, delivery events from approved communications providers, and transaction or referral data generated when you use a feature.
We may receive limited public information when you submit a public contribution URL, and fraud or dispute information from payment and security providers. We do not buy unrelated consumer profiles for sale or combine reader data with book-content generation unless a separately described feature lawfully requires it.
4. Why we use personal data and our legal bases
Where UK or European data-protection law applies, each use must have a legal basis. The basis depends on the context and may be performance of a contract, compliance with law, our legitimate interests, your consent, or the establishment and defence of legal claims.
- Contract: create and secure an account when you request one, take and fulfil account or guest orders, provide library or email delivery, provide support, handle refunds, and administer rewards you choose to use.
- Legal obligation: keep required tax and accounting records, respond to valid rights requests, and comply with consumer, fraud-prevention and regulatory duties.
- Legitimate interests: protect readers and services, prevent abuse, maintain reliable operations, understand failures, enforce rights and improve non-consent-dependent features, after balancing those interests against your rights.
- Consent: send optional marketing, activate non-essential analytics where offered, or use information for another clearly described optional purpose. You may withdraw consent prospectively at any time.
- Legal claims and substantial public interests: investigate disputes, preserve evidence subject to a lawful hold, and respond to legally authorised requests.
6. Payments and external retailers
A direct checkout sends payment information to the payment provider. Hawkins & Wells receives a provider reference, status and limited transaction details needed to reconcile the order; it does not receive or retain the full card number or security code.
If you buy from Amazon or another external retailer, that retailer is independently responsible for its account, payment, fulfilment and customer-service data. Hawkins & Wells receives information from it only where a separate lawful distribution, reporting or support arrangement permits.
7. International transfers
Publishing and technology providers may process data outside your country. Before a restricted international transfer, we use a legally recognised mechanism such as an adequacy decision, approved contractual clauses or another valid safeguard, and assess supplementary technical and organisational measures where required.
You may ask Reader Care for information about the safeguard relevant to your data. Confidential commercial or security terms may be redacted, but we will explain the protection in a meaningful way.
8. How long we keep data
We keep personal data only for the shortest approved period needed for its purpose, including account and library operation, tax and accounting records, fraud controls, support, contract enforcement and legal claims. The period may be stated as a fixed duration or determined by documented criteria such as account activity, the life of a contract, a statutory recordkeeping period or an active dispute.
Account deletion removes or de-identifies data that is no longer needed. Order, payment, tax, audit and fraud records may remain where law or a compelling legal purpose requires them. Marketing stops when you unsubscribe, while a minimal suppression record is retained so the opt-out is respected. Private reward evidence is scheduled for deletion after review, normally within 90 days of the final decision unless a dispute or legal hold requires longer retention.
9. Your rights and choices
Depending on where you live, you may have rights to be informed; obtain access and a portable copy; correct inaccurate data; request deletion or restriction; object to particular processing; withdraw consent; and complain to a regulator. A right may have lawful limits—for example, where records must be retained for tax, fraud prevention or a legal claim.
Signed-in readers can open My desk and choose Privacy to request an export or account deletion. For another request, or if you cannot sign in, use the public About contact form and state that the message concerns privacy. We verify identity proportionately and do not ask for more proof than the risk requires.
11. Automated decisions and AI
Security and fraud tools may flag activity for review, but an adverse customer outcome should receive proportionate human review. Hawkins & Wells does not currently describe any solely automated customer decision that produces a legal or similarly significant effect.
Editorial or book-production tools are kept separate from customer account data unless a future feature clearly explains the data use and establishes an appropriate legal basis before activation.
12. Security
We use layered safeguards appropriate to risk, including access controls, multi-factor protection for privileged administration, encryption in transit, managed secrets, private object delivery, signed provider events, audit logging, backups, monitoring and incident response. No online system is risk-free, so we also limit collection and retention to reduce impact.
If a personal-data breach creates a legal notification duty, we will notify the relevant authority and affected people within the required time and provide practical steps where appropriate.
13. Children
The direct account and purchase services are intended for people legally able to create the relevant account or contract, or acting with valid parent or guardian involvement. We do not knowingly use a child’s data for behavioural advertising.
A parent or guardian who believes a child supplied personal data without the permission required by law should contact us so we can investigate and take appropriate action.
14. Questions and complaints
Use My desk > Support and refunds or the public About contact form for a privacy question. Please write “Privacy” in the subject or opening line so the request reaches the appropriate reviewer.
You may also complain to the UK Information Commissioner’s Office at ico.org.uk. If you are in the European Economic Area, you may complain to the data-protection authority where you live, work or believe an infringement occurred. Contacting us first is welcome but not required.
15. Changes to this policy
We give each published policy a version and effective date. Material changes are reviewed before release and, where required, are brought to your attention or presented for renewed consent. Earlier versions and the change record are retained internally for accountability.