Privacy Policy
Last update: December 22, 2026
Websitewww.bigserpent.com
1. Introduction
This Privacy Policy explains howThe Lead Empire L.L.C-FZoperating the online store (hereinafter referred to as the “Company”, “we”, “our”, or “us”), collects, processes, stores, and protects personal data when users access or use our website and services.
This policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the ePrivacy Directive (2002/58/EC), and other applicable European data protection laws.
We are committed to ensuring transparency regarding how personal data is handled and to protecting the privacy rights of our customers and website visitors.
This Privacy Policy applies to all users accessing or purchasing products through our website.
2. Data Controller Identification
In accordance with Article 4(7) of the GDPR, the entity responsible for processing personal data is
Company NameThe Lead Empire L.L.C-FZ
Registered Address
Meydan Grandstand
6th floor, Meydan Road
Dubai
United Arab Emirates
Telephone: +44 20 3807 7181
Email for privacy matters: info@bigserpent.com
The Lead Empire L.L.C-FZdetermines the purposes and means of processing personal data collected through its website and services.
3. Legal Basis for Processing Personal Data (GDPR Article 6)
Personal data is processed only when a lawful basis exists under Article 6 of the GDPR. Processing may rely on one or more of the following legal bases
3.1 Performance of a Contract (Article 6(1)(b))
Personal data is processed when necessary to perform a contract with the customer, including
- Processing orders
- Delivering purchased products
- Providing customer support
- Processing payments
- Managing returns and refunds
3.2 Legal Obligations (Article 6(1)(c))
We may process personal data to comply with legal obligations, including
- Tax and accounting regulations
- Consumer protection laws
- Regulatory reporting obligations
- Fraud prevention requirements
3.3 Legitimate Interests (Article 6(1)(f))
Processing may be carried out to pursue legitimate business interests, including
- Preventing fraud and abuse
- Improving website performance
- Maintaining security of our systems
- Customer service and dispute resolution
- Analytics for service optimization
3.4 Consent (Article 6(1)(a))
Where legally required, we process personal data based on the user’s consent, including
- Marketing communications
- Non-essential cookies
- Advertising tracking technologies
Users may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
4. Categories of Personal Data Collected
We collect and process several categories of personal data depending on how users interact with the website.
4.1 Data Provided Directly by Users
When placing an order or contacting support, we may collect
- Full name
- Billing address
- Shipping address
- Email address
- Phone number
- Order details
- Customer communication records
This information is necessary for processing and fulfilling customer orders.
4.2 Data Collected During Transactions
When customers place an order, the following information may be processed
- Product selections
- Transaction history
- Payment method details
- Delivery instructions
- Order identification numbers
Financial information is handled through secure payment systems and is not stored unnecessarily.
4.3 Automatically Collected Data
When users visit our website, certain technical information may be automatically collected
- IP address
- Browser type and version
- Device type
- Operating system
- Time zone settings
- Pages visited
- Referral sources
- Interaction patterns
This information helps us ensure security, detect fraud, and improve website performance.
4.4 Data Collected Through Cookies and Tracking Technologies
Cookies and similar technologies may collect
- Session identifiers
- Website preferences
- Navigation behavior
- Analytics data
- Advertising interaction data
Further details are provided in our Cookie Policy.
5. Purpose of Data Processing
Personal data is processed for the following purposes
- Order processing and fulfillment
- Customer identity verification
- Payment processing and fraud prevention
- Shipping and logistics coordination
- Customer support and dispute resolution
- Legal compliance and regulatory reporting
- Service improvement and website optimization
- Security monitoring and fraud detection
- Marketing communications (where consent is provided)
6. Data Retention Periods
Personal data is retained only for as long as necessary to fulfill the purposes outlined in this policy.
Retention periods depend on the category of data
- Customer Account and Order Data– Stored for up to 6 years to comply with accounting and tax obligations.
- Customer Support Communications– Retained for up to 3 years to resolve disputes and maintain service quality.
- Website Analytics Data– Typically stored between 12 and 26 months depending on the analytics provider.
- Marketing Consent Data– Retained until the user withdraws consent or requests deletion.
After the retention period expires, personal data is securely deleted or anonymized.
7. Third-Party Data Processors
We may share personal data with trusted third-party service providers acting as data processors under Article 28 of the GDPR.
These providers assist with
- Payment processing
- Shipping and logistics
- Website hosting
- Data analytics
- Customer support infrastructure
- Fraud prevention services
All third-party processors are contractually required to maintain strict data protection standards and process personal data only according to our instructions.
8. Data Security Measures
We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, alteration, disclosure, or destruction.
Security measures include
- SSL encryption for data transmission
- Secure server infrastructure
- Access control systems
- Data minimization practices
- Regular system monitoring
- Fraud detection mechanisms
- Employee confidentiality obligations
While we take extensive measures to protect data, no online transmission system can be guaranteed to be completely secure.
9. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), such transfers occur only when appropriate safeguards are implemented.
These safeguards may include
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers to jurisdictions with adequacy decisions
- Data processing agreements compliant with GDPR
These measures ensure that personal data receives an equivalent level of protection.
10. Customer Rights Under GDPR (Articles 12–23)
Under GDPR, individuals have several rights regarding their personal data.
10.1 Right of Access (Article 15)
Users have the right to obtain confirmation of whether their personal data is being processed and to receive a copy of the data held about them.
10.2 Right to Rectification (Article 16)
Users have the right to request correction of inaccurate or incomplete personal data without undue delay.
10.3 Right to Erasure (Article 17)
Users may request deletion of their personal data where it is no longer necessary for the purposes for which it was collected, or where consent has been withdrawn and no other legal basis applies.
10.4 Right to Restriction of Processing (Article 18)
Users may request that processing of their personal data be restricted in certain circumstances, such as when the accuracy of data is contested or processing is unlawful.
10.5 Right to Data Portability (Article 20)
Where processing is based on consent or contract, users have the right to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
10.6 Right to Object (Article 21)
Users have the right to object to processing of their personal data carried out on the basis of legitimate interests or for direct marketing purposes.
10.7 Right to Withdraw Consent
Where processing is based on consent, users may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
10.8 Right to Lodge a Complaint
Users have the right to lodge a complaint with the competent data protection supervisory authority in their country of residence if they believe their data protection rights have been violated.
11. Children’s Privacy
Our website and services are intended for individuals aged 18 or older. We do not knowingly collect personal data from children.
If personal data of minors is discovered, it will be deleted immediately.
12. Data Breach Procedures
In the event of a personal data breach that poses a risk to individual rights and freedoms, we will
- Notify the competent supervisory authority within 72 hours, as required by GDPR Article 33.
- Inform affected individuals where required under Article 34.
- Implement corrective measures to mitigate potential risks.
13. Automated Decision-Making and Profiling
We do not conduct automated decision-making that produces legal or similarly significant effects on individuals.
Any profiling conducted is limited to analytics and website optimization.
14. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect
- Legal or regulatory changes
- Updates to our services
- Changes in data processing practices
When updates occur, the revised policy will be published on our website.
Users are encouraged to review this policy regularly.
15. Contact for Privacy Matters
For any questions regarding this Privacy Policy or requests concerning personal data rights, users may contact
The Lead Empire L.L.C-FZ
Meydan Grandstand
6th floor, Meydan Road
Dubai
United Arab Emirates
Email: info@bigserpent.com
Telephone: +44 20 3807 7181
Requests related to data protection will be handled in accordance with applicable data protection legislation.