Privacy Policy

Last updated: 29 June 2026

Data Protection Officer

We have appointed a Data Protection Officer for our group:

Frank Steinbrügger
RT Data & IT Consulting GmbH
Gravenreutherstr. 2
95445 Bayreuth, Germany
Email: datenschutz@rtdata-it.de

1. Who we are and the legal framework

This privacy policy explains how STEINER Vision processes your personal data when you visit our website, book a consultation, take a sight test or buy glasses from us. We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications Regulations (PECR).

The UK controller of your personal data is:

Specsfactory Germany Ltd
Standard Court, 1 Park Row
Nottingham NG1 6GN, United Kingdom
Companies House no. 09754623
Email: privacy@steiner-vision.co.uk

Specsfactory Germany Ltd is a subsidiary of SuperVista AG and also acts as the UK representative under Article 27 UK GDPR for our group companies established outside the UK.

No member of STEINER Vision will ever ask you for your password, PIN or one-time security codes.

2. Categories of personal data we collect

Depending on how you interact with us, we may process the following categories of personal data:

  • Identity & contact data — name, postal address, email address, telephone number, date of birth.
  • Account data — login credentials, preferences and consultation history.
  • Order & transaction data — items purchased, prices, invoices, payment status.
  • Payment data — billing details, card or bank details (processed by our payment providers, not stored by us in plain text).
  • Health data (special category, Art. 9 UK GDPR) — prescription/refraction values, pupillary distance, sight-test results, lens and frame measurements.
  • Consultation inputs — answers you give in the AI consultation (lifestyle, screen use, vision needs).
  • Technical data — IP address, device and browser information, referrer URL, log files.
  • Usage & consent data — pages viewed, interactions, cookie and marketing consent choices.
  • Communications — messages you send us by email, chat, web form or phone.

3. Purposes and legal bases

We only process your personal data where we have a lawful basis under Article 6 UK GDPR (and, for health data, Article 9):

  • Performing your contract (Art. 6(1)(b)) — to provide the consultation, process orders, manufacture and ship your glasses, and handle returns or warranty claims.
  • Legal obligation (Art. 6(1)(c)) — to comply with accounting, tax (HMRC), consumer protection and other statutory duties.
  • Legitimate interests (Art. 6(1)(f)) — to secure our website, prevent fraud, improve our products and services, and carry out direct marketing to existing customers within PECR's "soft opt-in".
  • Consent (Art. 6(1)(a) and, for health data, Art. 9(2)(a)) — for non-essential cookies and similar technologies, electronic marketing to non-customers, and the processing of prescription and sight-test data.

You may withdraw any consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.

4. How long we keep your data

  • Order and invoicing records — 6 years after the end of the relevant financial year, in line with HMRC requirements.
  • Customer account data — for the life of your account and up to 3 years after your last interaction, unless you ask us to close it sooner.
  • Prescription and sight-test data — for as long as needed to fulfil your order and any after-care, and otherwise as required by professional standards (typically up to 7 years).
  • Marketing data — until you unsubscribe or object, and for a short suppression period thereafter to honour your choice.
  • Website and consent logs — typically 12–24 months for security and audit purposes.
  • Enquiries and support messages — up to 2 years after the matter is closed.

When personal data is no longer required, we either delete it securely or anonymise it.

5. Security

We use TLS/SSL encryption when you submit data or place an order on our website. Orders are transmitted to our manufacturing partners over encrypted channels. We apply appropriate technical and organisational measures, including access controls, encryption at rest where appropriate, and regular review of our processors. Please also help to protect your data by keeping your account credentials and device secure.

6. Sharing your data with third parties

We share personal data only where necessary for the purposes described above. Recipients may include:

  • STEINER partner opticians who carry out your in-person sight test, fitting and after-care.
  • Lens and frame manufacturers and laboratories who produce your glasses.
  • Logistics and delivery partners.
  • Payment service providers (see Section 7).
  • IT, hosting, analytics, customer-service and security providers acting as our processors.
  • Professional advisers, auditors and insurers.
  • Public authorities and law enforcement where we are legally required to do so.

We do not sell your personal data.

7. Payment providers

Stripe

Card and similar payments may be processed by Stripe Payments Europe Ltd (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland) and its UK affiliate Stripe Payments UK Ltd. When you pay through Stripe, your payment data (e.g. name, billing address, email, amount and card or bank details) is sent directly to Stripe.

The legal basis is Article 6(1)(b) UK GDPR (performance of the contract) and Article 6(1)(f) (our legitimate interest in secure and reliable payments). Stripe may also process the data for fraud prevention and service improvement, including transfers to the United States. Such transfers are protected by the UK Extension to the EU-U.S. Data Privacy Framework and, where appropriate, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. See Stripe's privacy notice: https://stripe.com/gb/privacy.

8. Remote and in-person sight tests

Your sight test will normally take place in person at a STEINER partner optician. Where the optician offers a telemedical option, the test may be carried out under medical supervision by a clinical partner. In that case, we share the data needed to run the test (such as your name and contact details), and the resulting refraction values are returned to us so that your glasses can be made.

Refraction values and other sight-test results are special category health data under Article 9 UK GDPR. We process this data on the basis of your explicit consent (Art. 9(2)(a)), and additionally, where relevant, on the basis of Article 6(1)(b) for the performance of your order. The clinical partner conducting the telemedical test acts as an independent controller for that part of the processing and will provide its own privacy information at the point of the test.

9. Website performance, support and fraud prevention

Baqend (performance / caching)

We use Baqend GmbH (Stresemannstraße 23, 22769 Hamburg, Germany) to speed up our website. Baqend may receive technical data such as IP address, browser information and access times. Legal basis: Art. 6(1)(f) UK GDPR (our legitimate interest in a fast and reliable website). Information: baqend.com/privacy-policy.

Melibo chatbot

Where the chatbot is enabled, we use Melibo by Thinking Tech GmbH (Eisenlohrstr. 13, 76135 Karlsruhe, Germany) to handle customer enquiries. Data processed includes the messages you enter, technical metadata and any contact details you choose to share. Legal basis: Art. 6(1)(f) UK GDPR (efficient customer service) and, where the chat leads to a contract, Art. 6(1)(b). Information: melibo.de/datenschutz.

PPC Protect (click-fraud prevention)

We use PPC Protect Ltd (The Landing, Blue, MediaCityUK, Salford M50 2ST, United Kingdom) to detect and prevent click-fraud on our advertising. PPC Protect may process technical data such as IP address, device, browser and referrer. Legal basis: Art. 6(1)(f) UK GDPR (legitimate interest in protecting our advertising spend). Information: ppcprotect.com/privacy-policy.

10. Cookies and similar technologies

We use cookies and similar technologies to operate our website, remember your settings, measure performance and (with your consent) deliver relevant advertising. Strictly necessary cookies do not require consent. All other cookies — including analytics and marketing cookies — are only set after you give consent through our cookie banner, in line with PECR and UK GDPR.

You can change or withdraw your cookie choices at any time via the cookie settings link in our footer. Your consent is recorded and stored so we can demonstrate compliance.

Analytics — Google Analytics 4

Where you consent, we use Google Analytics 4 provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) to understand how visitors use our website. IP addresses are truncated and we do not use Analytics to identify individual visitors. Data may be transferred to the United States under the UK Extension to the EU-U.S. Data Privacy Framework. Legal basis: Art. 6(1)(a) UK GDPR (your consent). You can withdraw consent at any time via our cookie settings.

11. Marketing communications

We will only send you marketing emails or SMS where you have given consent, or where you are an existing customer and we are marketing similar products under PECR's "soft opt-in". Every marketing message contains a one-click unsubscribe link. You can also opt out at any time by emailing privacy@steiner-vision.co.uk.

12. International transfers

Some of our processors are based outside the UK. Where this is the case, we ensure an adequate level of protection by relying on UK adequacy regulations (including the UK Extension to the EU-U.S. Data Privacy Framework for certified US recipients) or by putting in place the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supplemented by additional safeguards where necessary.

13. Your rights

Under UK GDPR you have the right to:

  • access your personal data and request a copy;
  • have inaccurate data corrected;
  • request erasure of your data (where one of the legal grounds applies);
  • restrict or object to processing, including direct marketing;
  • data portability for data you provided to us under consent or contract;
  • withdraw any consent at any time; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not carry out such decisions).

To exercise any of these rights, contact us at privacy@steiner-vision.co.uk. We will respond within one month.

If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk, helpline 0303 123 1113. We would, however, appreciate the chance to address your concerns first.

14. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our services or the law. The "last updated" date at the top shows when it was last revised. Material changes will be highlighted on our website or notified to you directly where appropriate.