LoomTrend
Effective Date: 23 September 2026
Last Updated: 23 September 2026
This GDPR and International Data Rights Policy explains how LoomTrend handles personal information belonging to customers and website visitors who may be protected by the European Union General Data Protection Regulation (GDPR) or other applicable international data-protection requirements. LoomTrend is a Nigeria-based e-commerce business offering handcrafted beaded jewellery, including Bridal Beaded Jewelry Sets, Cultural Festival Beaded Accessories, and Statement Beaded Fashion Pieces.
LoomTrend’s primary data-protection obligations in Nigeria arise under the Nigeria Data Protection Act 2023. The GDPR does not automatically apply merely because a website can be accessed from Europe. Accordingly, the GDPR provisions described in this Policy apply where LoomTrend’s activities fall within the GDPR’s territorial scope.
This Policy should be read together with our Privacy Policy, Data Usage Policy, Cookie Policy, Account and Data Deletion Policy, Terms and Conditions, and other policies available on LoomTrend.
1. Scope of This Policy
This Policy applies to personal information processed by LoomTrend where applicable international data-protection requirements give an individual rights concerning that information.
Personal information may include:
- Name
- Email address
- Account information
- Billing address
- Delivery address
- Order details
- Product selections
- Transaction references
- Customer-support communications
- Return and refund information
- Marketing preferences
- Reviews and feedback
- Website usage data
- IP address
- Device and browser information
- Cookie identifiers
- Security and fraud-prevention information
The information processed will depend on how you interact with LoomTrend.
2. When the GDPR May Apply to LoomTrend
LoomTrend operates from Nigeria.
Factors relevant to whether goods or services are being offered to people in the EU may depend on the particular activities and circumstances involved.
Simply making LoomTrend’s website technically accessible from an EU country does not, by itself, mean every LoomTrend processing activity is automatically governed by GDPR.
Where GDPR applies to a particular individual’s personal data, LoomTrend will seek to respect the rights and obligations described below.
3. Data Protection Principles
Where GDPR applies, LoomTrend seeks to process personal data according to principles including:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Appropriate retention
- Integrity and confidentiality
- Accountability
Similar principles are also reflected in Nigeria’s data-protection framework.
4. Personal Data We May Process
Depending on how you use LoomTrend, we may process information such as:
Account Information
This may include:
- Name
- Email address
- Account credentials
- Saved preferences
- Account history
Order Information
This may include:
- Products purchased
- Quantity
- Product variation
- Price
- Currency
- Billing details
- Delivery information
- Order reference
Transaction Information
We may process limited information relating to:
- Transaction reference
- Payment status
- Amount paid
- Currency
- Refund status
- Transaction date
Customer-Support Information
This may include:
- Emails
- Enquiry details
- Complaint information
- Photographs submitted concerning products
- Return requests
- Refund communications
Technical Information
This may include:
- IP address
- Device type
- Browser information
- Operating system
- Cookie identifiers
- Pages visited
- Session information
- Website interactions
5. Purposes for Processing Personal Data
LoomTrend may process personal information to:
- Create and administer customer accounts
- Process orders
- Confirm payments
- Arrange product fulfilment
- Deliver products
- Communicate order updates
- Respond to enquiries
- Handle returns and refunds
- Prevent fraud
- Maintain website security
- Improve website functionality
- Maintain business and accounting records
- Send permitted marketing communications
- Comply with applicable legal requirements
- Establish, exercise, or defend legal claims
We seek not to use personal information for purposes materially incompatible with the reason it was originally collected unless another lawful basis permits such processing.
6. Lawful Bases for Processing
Where GDPR applies, LoomTrend will rely on an appropriate lawful basis for processing.
Depending on the situation, this may include:
Contract
Processing may be necessary to fulfil a purchase or provide a service requested by the customer.
For example, LoomTrend needs a delivery address to deliver jewellery you have ordered.
Consent
Consent may be relied upon for certain optional processing activities.
Examples may include:
- Certain marketing communications
- Certain non-essential cookies
- Other optional features
Where processing is based on consent, eligible individuals may withdraw that consent.
Legal Obligation
We may process or retain data where necessary to comply with an applicable legal obligation.
Legitimate Interests
Certain processing may be necessary for legitimate business purposes, provided those interests are not overridden by the individual’s applicable rights and freedoms.
Examples may include appropriate fraud prevention, website security, or limited business administration.
7. Contractual Information
Certain personal information is necessary for LoomTrend to fulfil a purchase.
For example, we may need:
- Customer name
- Product selection
- Payment confirmation
- Delivery address
- Contact information
If required information is not provided, we may be unable to complete the relevant order.
We will not treat consent to unrelated marketing as a mandatory requirement for ordinary order fulfilment where marketing consent is not necessary for the transaction.
8. Payment Data and Security
Payments may be processed using banks, payment gateways, or other payment providers available through LoomTrend’s checkout.
LoomTrend may receive limited transaction information such as:
- Transaction reference
- Payment status
- Amount
- Currency
- Payment date
- Refund status
Customers should enter confidential payment credentials only through the authorised payment interface.
LoomTrend will not ask you to send your:
- CVV
- UPI PIN
- Online banking password
- OTP
- Other confidential banking authentication information
through ordinary email, product reviews, or customer-support messages.
The statement:
“We do not store your debit or credit card numbers, CVV, or UPI PIN on our servers.”
should only be published as an unconditional technical statement after LoomTrend’s active payment integration has been verified by the relevant developer or payment provider.
9. Right to Be Informed
Where GDPR applies, individuals have a right to receive appropriate information about how their personal data is processed.
This may include information about:
- Who processes the data
- Categories of personal data
- Processing purposes
- Lawful basis
- Recipients
- International transfers
- Retention
- Applicable privacy rights
LoomTrend provides this information through its Privacy Policy and related data-protection policies.
10. Right of Access
Eligible individuals may request confirmation as to whether LoomTrend processes their personal data and may request access to that information.
A request may therefore include a request for a copy of eligible personal data held by LoomTrend.
We may verify your identity before providing personal information.
11. Right to Rectification
If personal information held by LoomTrend is inaccurate or incomplete, an eligible individual may request correction.
For example, customers may ask us to correct an inaccurate:
- Name
- Email address
- Account detail
- Delivery information
Some information associated with completed historical transactions may need to remain consistent with the original transaction record while corrections are appropriately documented.
12. Right to Erasure
In applicable circumstances, individuals may request deletion of personal data.
This is sometimes referred to as the right to erasure or right to be forgotten.
Deletion is not absolute.
Information may still need to be retained where necessary for matters such as:
- Legal obligations
- Accounting
- Transaction records
- Fraud prevention
- Consumer complaints
- Legal claims
- Dispute resolution
Further information is provided in our Account and Data Deletion Policy.
13. Right to Restriction of Processing
In certain circumstances, an eligible individual may request that LoomTrend restrict how personal information is processed.
Restriction may be relevant, for example, while:
- Accuracy is being verified.
- An objection is being considered.
- A legal dispute is pending.
- The person requests restriction instead of immediate deletion in applicable circumstances.
Restricted data may be retained but should not be actively used beyond what is legally permitted while the restriction applies.
14. Right to Data Portability
Where the legal conditions are met, an individual may request eligible personal information in a structured, commonly used and machine-readable format.
Where technically feasible and legally appropriate, the individual may also request direct transfer to another controller.
The right does not apply to every category of information held by LoomTrend.
15. Right to Object
Where GDPR applies, individuals may have a right to object to certain processing.
This can be particularly relevant where processing is based on legitimate interests.
If you object to direct marketing, LoomTrend will stop using your personal data for that marketing where required by applicable law.
Transactional communications relating to an existing order, refund, security matter, or customer-service issue are different from optional marketing communications.
16. Withdrawal of Consent
Where LoomTrend relies on your consent, you may withdraw it.
Examples may include consent for:
- Certain marketing communications
- Optional tracking technologies
- Other consent-based features
Withdrawal does not invalidate processing that lawfully occurred before consent was withdrawn.
It also does not necessarily require deletion where another lawful basis permits or requires continued processing.
17. Automated Decisions and Profiling
LoomTrend is primarily an e-commerce jewellery business.
Ordinary website automation may include:
- Shopping-cart calculations
- Order-status processing
- Product recommendations
- Security checks
- Fraud alerts
LoomTrend does not intend to make decisions producing legal or similarly significant effects on customers solely through automated processing unless appropriate safeguards and disclosures are provided.
18. Direct Marketing
Where LoomTrend sends marketing communications, applicable privacy and electronic-marketing requirements will be respected.
Marketing may include:
- New collection announcements
- Offers
- Promotions
- Jewellery styling information
- Sale information
Where consent is required, it should be obtained before the relevant marketing processing begins.
Customers should have a reasonable way to unsubscribe or withdraw consent.
Opting out of marketing will not prevent necessary communications relating to orders, payments, refunds, deliveries, or account security.
19. Cookies and Tracking Technologies
LoomTrend may use cookies for:
- Essential website functionality
- Shopping carts
- Account sessions
- Preferences
- Security
- Analytics
- Marketing where appropriately enabled
Where GDPR and related European electronic-communications requirements apply, non-essential tracking technologies may require appropriate consent before use.
Further information is provided in our Cookie Policy.
Refusing optional cookies should not by itself prevent a customer from using essential shopping functionality unless a particular technology is genuinely necessary for the requested function.
20. Children’s Personal Data
LoomTrend is an online jewellery business and is not intended as a service specifically directed toward children.
Additional safeguards apply when processing children’s information.
Where consent from a parent or guardian is legally required, LoomTrend will seek appropriate authorisation before relying on the child’s consent.
Nigeria’s Data Protection Act separately addresses children and persons who lack legal capacity to consent. (Nigeria Data Protection Commission)
Parents or guardians who believe a child has submitted personal data to LoomTrend inappropriately may contact us to request review or deletion.
21. Data Retention
LoomTrend seeks to retain personal data only for as long as reasonably necessary for its relevant purpose.
Retention may depend on:
- Order status
- Transaction history
- Legal requirements
- Accounting obligations
- Fraud-prevention needs
- Consumer disputes
- Refunds or chargebacks
- Customer-support requirements
For example, a marketing preference may not need to be retained for the same period as a completed financial transaction record.
Where information is no longer required, it may be deleted, anonymised, or securely disposed of.
22. Security of Personal Data
LoomTrend seeks to implement reasonable technical and organisational safeguards appropriate to the information and risks involved.
These may include:
- Access controls
- Authentication safeguards
- Secure website connections
- Restricted administrative access
- Software updates
- Security monitoring
- Backups
- Appropriate third-party controls
Nigeria’s Data Protection Act specifically includes obligations relating to security, integrity, confidentiality, and personal-data breaches. (Nigeria Data Protection Commission)
No internet-based system can guarantee absolute security.
Customers should also protect passwords and avoid sending confidential payment authentication information through ordinary communications.
23. Data Breaches
If a personal-data security incident occurs, LoomTrend will assess the nature and potential impact of the incident and take reasonable steps to:
- Contain it
- Investigate it
- Protect affected systems
- Limit further exposure
- Comply with applicable notification requirements
The specific notification obligations will depend on which data-protection law applies to the affected information and the risks resulting from the incident.
24. International Data Transfers
Because LoomTrend operates online and may use external service providers, personal information may in certain circumstances be transferred to or accessed from another country.
Potential providers may include:
- Hosting services
- Cloud infrastructure
- Payment providers
- Analytics providers
- Email services
- Security providers
- Delivery or fulfilment services
International transfers will be handled in accordance with applicable data-protection requirements.
Nigeria’s Data Protection Act specifically governs cross-border transfers in sections 41–43 and requires an appropriate basis for transferring personal data outside Nigeria. (Nigeria Data Protection Commission)
25. GDPR Transfers Outside the European Economic Area
Where GDPR applies and personal information is transferred from the European Economic Area to a country not covered by an applicable adequacy decision, LoomTrend or the relevant provider may need to rely on another lawful transfer mechanism.
Depending on the circumstances, safeguards may include contractual mechanisms recognised under GDPR.
26. Transfers Under Nigerian Data Protection Law
Nigeria’s Data Protection Act recognises cross-border data transfers but requires an adequate legal basis and appropriate protection.
The NDPC states that sections 41–43 deal with transfers of personal data to foreign countries and require controllers or processors to ensure an adequate level of protection or rely on another legally recognised basis. (NDPC FTP)
Relevant safeguards may depend on:
- The recipient country
- Rights available to individuals
- Contractual protections
- The nature of the processing
- Applicable statutory transfer mechanisms
LoomTrend will seek to assess relevant international transfers before relying on third-party services involving personal information.
27. Third-Party Data Processors
LoomTrend may engage service providers to support the operation of the website.
Depending on the services actually implemented, these may include providers responsible for:
- Hosting
- Payments
- Website security
- Analytics
- Email delivery
- Logistics
- Technical maintenance
Where an organisation processes personal information on LoomTrend’s behalf, appropriate processing and security requirements should be established where required by applicable law.
Where a third party independently determines its own processing purposes, it may have separate responsibilities concerning the personal information it processes.
28. Requests From Law Enforcement or Public Authorities
LoomTrend may disclose information where required by a valid legal obligation, court order, or lawful request from an authorised public body.
We will not intentionally disclose personal information merely because an informal or unsupported request has been made.
Where legally permitted, disclosures should be limited to information reasonably necessary for the relevant lawful purpose.
29. Identity Verification for Privacy Requests
Before providing, modifying, exporting, or deleting personal data, LoomTrend may need to verify the identity of the requester.
Verification protects customers from:
- Unauthorised disclosure
- Fraudulent deletion requests
- Account takeover
- Impersonation
We will seek to request only information reasonably necessary for verification.
LoomTrend will not require your CVV, UPI PIN, banking password, or payment OTP to exercise an ordinary privacy right.
30. Exercising More Than One Right
You may make more than one privacy request where applicable.
For example, you may request:
- Access followed by correction
- Data portability followed by account deletion
- Marketing objection without deleting your account
- Restriction while accuracy is being investigated
Each request will be considered according to the applicable legal requirements.
31. Privacy Requests and Response Periods
Where GDPR applies, requests concerning data-subject rights are generally required to be addressed without undue delay and ordinarily within one month, subject to permitted extensions for complex or numerous requests.
GDPR transparency provisions also use one month as a key response period in relevant circumstances. (Eur-Lex)
LoomTrend may request identity verification before completing a request.
Where an extension or limitation is legally permitted, the individual should receive appropriate information about that decision.
32. Requests That May Be Restricted
Privacy rights are important but not always absolute.
A request may be limited where continued processing is lawfully necessary for matters such as:
- Legal obligations
- Legal claims
- Fraud prevention
- Transaction records
- Accounting
- Protection of another person’s rights
For example, requesting account deletion immediately after a purchase does not necessarily require LoomTrend to destroy every record needed to demonstrate that the transaction took place.
33. Complaints
If you believe LoomTrend has not handled your personal information appropriately, you may contact us so that we can review your concern.
Where GDPR applies, an individual may also have the right to lodge a complaint with an appropriate European data-protection supervisory authority. Article 15 expressly identifies the right to lodge a complaint among the information available to data subjects. (Eur-Lex)
For processing governed by Nigerian data-protection law, complaints and investigations fall within the framework of the Nigeria Data Protection Commission (NDPC). The NDP Act expressly provides for complaints and investigations. (Nigeria Data Protection Commission)
34. Relationship With Nigerian Privacy Rights
Where GDPR does not apply, individuals interacting with LoomTrend may still have rights under the Nigeria Data Protection Act 2023.
The NDP Act contains specific provisions covering:
- Data-subject rights
- Withdrawal of consent
- Right to object
- Automated decision-making
- Data portability
- Security
- Personal-data breaches
- International transfers
- Complaints and enforcement
These matters are addressed across Parts VI, VII, VIII and X of the Act. (Nigeria Data Protection Commission)
Nothing in this Policy is intended to replace protections provided by mandatory Nigerian law.
35. Other International Privacy Laws
Customers outside Nigeria and the European Union may have privacy rights under the laws of their own jurisdiction.
Where such legislation applies to LoomTrend’s activities, we will seek to comply with the relevant mandatory requirements.
The existence of this Policy does not mean that every privacy law worldwide automatically applies to LoomTrend.
Rights and obligations depend on factors including:
- Customer location
- LoomTrend’s activities in that jurisdiction
- Nature of the transaction
- Nature of the processing
- Territorial scope of the relevant law
36. Changes to This Policy
LoomTrend may update this GDPR and International Data Rights Policy if:
- Our international operations change
- Shipping destinations change
- Website technologies change
- Data-processing practices change
- Service providers change
- Applicable privacy requirements change
The latest version will be made available on LoomTrend with an updated effective or revision date.
Material changes to processing will be communicated or accompanied by additional consent where applicable law requires it.
37. Contact Us
If you wish to exercise an applicable privacy right, request access, correction, deletion, restriction or portability, withdraw consent, object to processing, or ask questions about international data transfers or LoomTrend’s privacy practices, please contact:
LoomTrend
Website: https://loomtrend.net/
Support Email: support@loomtrend.net
Info Email: info@loomtrend.net
Address: 40, TOTAL STREET, OKO-OBA, TANKE, ILORIN, KWARA STATE, NIGERIA
