Privacy Policy
This Privacy Policy explains how Ta-Ha Publishers Ltd. (“we,” “us,” or “our”) collects, uses, stores, and protects your personal information when you visit or make a purchase on our website, www.tahapublishers.com, and when you interact with us through services such as signing up for our newsletter, or contacting us with a query. We are committed to protecting your privacy and being transparent about the data we handle.
1
Who We Are and How You Can Contact Us
1.1 Who We Are
Data Controller: Ta-Ha Publishers Ltd.
Address: Unit 4, The Windsor Centre, Advance Road, London, SE27 9LT, UK
Website: www.tahapublishers.com
1.2 Contact Us
If you have any questions or concerns about this policy or your data, please contact us at:
Email: support@tahapublishers.com
Phone or WhatsApp: 020 8670 1888
1.3 Effective Date
This policy is effective as of 1st January 2026.
2
Information We Collect and How We Use It
We collect and process various types of personal data based on how you interact with our company. We are committed to collecting only the data necessary for a specific, stated purpose.
2.1 Information You Provide to Us Directly
We collect personal data when you voluntarily provide it to us through website forms, direct emails, or other communications.
A. Customer Account and Sales (Individual and Trade)
Data Collected: Name, email address, physical shipping and billing addresses, phone number, password, purchase history, and payment method details (tokenised or securely handled by third-party processors).
Purpose: To process and fulfil your book orders, manage your account, provide customer support, and maintain sales records for legal and tax purposes.
B. Email Sign-up (Discount/Newsletter)
Data Collected: Email address, and optionally your name.
Purpose: To send you updates, promotional offers, news about new releases, and personalised discounts based on your consent.
C. Manuscript Submissions (via email)
Data Collected: Author name, contact details, submission title, synopsis, author biography, and the content of the manuscript itself, as provided in the email.
Purpose: To review, assess, and communicate with you regarding your potential manuscript for publication.
D. Job or Work Experience Applications (via email)
Data Collected: Name, contact details, CV, cover letter, employment history, and any other data provided in the email application.
Purpose: To evaluate your qualifications for employment with us and to communicate regarding your application status.
E. General Enquiries and Rights Requests
Data Collected: Name, email address, organisation, and the contents of your message regarding permissions, translation rights, or general queries.
Purpose: To respond to your query, manage licencing requests, and maintain a record of our communication.
F. Wishlists and Account Preferences
Data Collected: User ID, book titles added, and saved preferences.
Purpose: To provide the requested account functionality and save content for your future purchases.
2.2 Information We Collect Automatically
When you access our website, certain information about your device and browsing activity is collected automatically, primarily through cookies and server logs.
A. Usage and Log Data
Data Collected: IP address, browser type and settings, operating system, time and date of access, pages viewed, and referring URLs.
Purpose: To maintain the security and operational efficiency of our website, diagnose server problems, and generate aggregate usage statistics.
B. Cookies and Tracking Data
Data Collected: Unique identifiers, preferences, and details about your interaction with our site.
Purpose: To remember your preferences (e.g. shopping cart items), analyse website traffic, and to improve the user experience. Please see our dedicated Cookie Policy for more details.
3
Legal Basis for Processing Personal Data
We only process your personal data when we have a valid legal ground to do so. The legal grounds we rely on for collecting and using your data are detailed below, corresponding to the activities outlined in Section 2.
Performance of a Contract
This legal basis means the processing is necessary to complete a contract we have with you, or because you have asked us to take specific steps before entering into a contract (e.g. placing an order).
Customer Account and Sales (A): Processing your order, managing your account, and delivering the purchased books.
Job Applications (D): Processing your application and communicating with you as a necessary step prior to offering an employment contract.
Wishlists and Account Preferences (F): Providing the requested user account services and functionality.
Consent
This applies when you have given us clear, affirmative permission for us to process your data for a specific purpose. You are free to withdraw your consent at any time.
Email Sign-up (B): Sending you promotional and news updates, based on your explicit sign-up.
Sensitive Personal Data (2.3): If any rare sensitive data is provided, processing is based on your explicit consent.
Legitimate Interests
This refers to processing that is necessary for our legitimate business interests, provided your interests and fundamental rights do not override those interests. We ensure a balance between our commercial needs and your privacy rights.
Manuscript Submissions (C): Reviewing and assessing manuscripts to acquire new authors and titles, which is fundamental to the operation and growth of our publishing business.
General Enquiries and Rights Requests (E): Responding to communications, managing permissions, and servicing translation rights to run our business efficiently.
Usage and Log Data (2.2 A): Diagnosing website issues, maintaining security, and analysing site usage to improve our service offerings.
Cookies and Tracking Data (2.2 B): Processing non-essential data to enhance site functionality and marketing (where not based on consent).
Legal Obligation
This applies when processing is necessary for us to comply with a legal or regulatory requirement (e.g. tax, accounting, or security laws).
Sales Records: Retaining sales transaction records, invoices, and payment data for tax and financial auditing purposes.
Responding to Authorities: Responding to lawful requests for information from government or regulatory bodies.
4
How We Share and Disclose Your Information
We do not sell your personal data. We only share or disclose your personal information with the following categories of third parties when necessary to run our business, fulfil our contractual obligations to you, or when required by law.
Third-Party Categories and Purpose of Sharing
Payment Processors
Purpose: To securely process and complete your book purchases and transactions (e.g. Stripe, PayPal).
Data Shared: Name, billing address, purchase details, and payment information (often shared as a token, not raw credit card details).
Shipping and Fulfilment Partners
Purpose: To fulfil and deliver your book orders (e.g. warehouses, courier services, drop-shippers).
Data Shared: Name, shipping address, phone number, and order details.
Email Marketing and Newsletter Providers
Purpose: To manage our subscriber list and send you newsletters and promotional emails (e.g. Mailchimp, Constant Contact).
Data Shared: Email address, name, and subscription preferences.
Analytics and Service Providers
Purpose: To help us monitor and analyse website traffic, track user behaviour, and improve our services (e.g. Google Analytics).
Data Shared: IP address, usage data, browser information, and cookie identifiers (often anonymised or pseudonymised).
Hosting and Technology Providers
Purpose: To host our website, store data securely, and provide essential operational support (e.g. cloud storage, server providers).
Data Shared: All data stored on or processed through our website, including customer account data and manuscript content.
Professional Advisers
Purpose: To obtain professional advice, including legal, financial, or accounting services.
Data Shared: Relevant data necessary for the specific professional service (e.g. sales data for accounting).
Legal and Regulatory Authorities
Purpose: When we are under a legal obligation to do so, such as in response to a court order, subpoena, or government request.
Data Shared: Any data required by the specific legal order or regulatory requirement.
4.1 International Data Transfers
As we operate globally, some of the third parties we share data with may be located outside of the United Kingdom (UK) or the European Economic Area (EEA).
When personal data is transferred internationally (e.g. to a US-based cloud service):
We ensure the transfer is covered by adequate safeguards as required by the UK GDPR (and/or EU GDPR).
These safeguards typically include Standard Contractual Clauses (SCCs) approved by the UK or European Commission, or reliance on an adequacy decision for the destination country (e.g. the UK Extension to the EU-US Data Privacy Framework).
5
Data Security and Data Retention
5.1 Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it from unauthorised access, disclosure, alteration, or destruction.
Protection Measures: Our security measures include, but are not limited to, encrypting data during transmission (using SSL/TLS), using secure servers, restricting employee access to personal data on a need-to-know basis, and implementing strong password policies.
Payment Security: All payment transactions are processed through encrypted, third-party payment gateways that adhere to the Payment Card Industry Data Security Standard (PCI DSS). Crucially, we do not store or process full credit card details on our own servers.
5.2 Data Retention
We only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purpose of satisfying any legal, accounting, or reporting requirements.
The specific retention period depends on the type of data and the legal basis for processing:
Customer Order Data (Name, Address, Purchases)
Retention Policy: 7 years after the transaction.
Rationale: To comply with tax laws and financial auditing requirements.
Manuscript Submissions
Retention Policy: 12 months from the date of rejection or withdrawal.
Rationale: To allow for necessary consideration, communication, and internal record-keeping before deletion.
Newsletter Subscription Data (Email)
Retention Policy: Until you withdraw consent (i.e. unsubscribe).
Rationale: We delete the data upon receiving an unsubscribe request, unless it is also required for other legal purposes (e.g. linked to a recent purchase).
Job Application Data
Retention Policy: 6 months after the position is filled (for unsuccessful candidates).
Rationale: To meet potential legal challenge periods and for a brief reference should a similar role open up.
Once the retention period expires, we will securely destroy or anonymise your personal data.
6
Your Rights as a Data Subject
Under data protection law (such as the UK GDPR), you have specific rights regarding your personal data. We are committed to upholding these rights. To exercise any of the rights below, please contact us using the details provided in your introductory section (Section 1.2).
Your Data Rights
Right to Access (Subject Access Request)
What it Means: You can request a copy of the personal data we hold about you.
How it Applies: You can ask for confirmation that we are processing your data and receive a copy of that data (e.g. your account details, purchase history).
Right to Rectification
What it Means: You have the right to have inaccurate or incomplete data about you corrected.
How it Applies: If your name or address is wrong in your customer account, you can ask us to correct it.
Right to Erasure (Right to be Forgotten)
What it Means: You have the right to ask us to delete your personal data.
How it Applies: We will comply unless we have a legal or contractual reason to retain the data (e.g. keeping sales records for tax purposes).
Right to Restrict Processing
What it Means: You have the right to limit the way we use your data in certain circumstances.
How it Applies: For example, if you contest the accuracy of your data, you can ask us to stop using it until it is verified.
Right to Object to Processing
What it Means: You can object to processing based on “Legitimate Interests” (see Section 3) or used for direct marketing.
How it Applies: You can stop us from using your data for direct marketing immediately.
Right to Data Portability
What it Means: You can request your personal data be transferred to you or a third party in a structured, commonly used, and machine-readable format.
How it Applies: This applies to data processed by automated means where the legal basis is consent or performance of a contract.
Right to Withdraw Consent
What it Means: You can withdraw your consent at any time where we rely on consent as the legal basis for processing your data.
How it Applies: If you’ve signed up for our newsletter based on consent, you can withdraw that consent by unsubscribing.
6.1 Lodging a Complaint
If you are not satisfied with our response or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the relevant supervisory authority.
For UK Residents: The supervisory authority is the Information Commissioner’s Office (ICO). You can contact them via their website: https://ico.org.uk/
For EU Residents: You can lodge a complaint with the data protection authority in the EU Member State where you live or work.
7
Children’s Privacy and Age Limitation
We are committed to protecting the privacy of children. Our website, products, and services are not intended for, or directed at, individuals under the age of 18.
Age Restriction: By using our website and services, you affirm that you are 18 years of age or older and are capable of entering into a legally binding agreement.
No Intentional Collection: We do not knowingly collect personal data from children under the age of 18. If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will take reasonable steps to immediately delete that information from our records.
Parental Contact: If you are a parent or guardian and believe your child under the age of 18 has provided us with personal data, please contact us immediately using the details in Section 1.2 so we can take the necessary action.
8
International Data Transfers
As a global publishing house receiving orders and queries from around the world, the personal data we collect may be transferred to, and stored at, a destination outside of the country where you reside, including outside the UK and the European Economic Area (EEA).
8.1 Transfers to Third Countries
When we transfer your personal data to third parties or servers in countries that the European Commission or the UK government has not deemed to provide an adequate level of data protection, we take specific measures to ensure your data is protected and that the transfer complies with applicable data protection laws.
8.2 Safeguards We Use
We rely on the following safeguards to protect your data when it is transferred internationally:
Standard Contractual Clauses (SCCs): We implement the legally required contractual clauses (either the UK International Data Transfer Agreement/Addendum or the EU Standard Contractual Clauses) with the recipient to legally oblige them to protect your personal data to the same standards as in the UK/EEA.
Adequacy Decisions: We may transfer data to countries that the relevant authorities have officially deemed to have an adequate level of data protection (e.g. transfers to the UK from the EU, or certain certified U.S. companies under the Data Privacy Framework).
Consent: In some cases, we may rely on your explicit consent for the specific proposed transfer, after we have informed you of the possible risks.
By submitting your personal data, you agree to this transfer, storing, or processing. We will take all steps reasonably necessary to ensure your data is treated securely and in accordance with this Privacy Policy.
9
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations.
9.1 Notification of Changes
Minor Changes: For minor changes that do not significantly affect your rights (e.g. correcting a typo or updating a service provider’s name), we will post the updated policy on our website with a new “Effective Date” at the top of the policy.
Significant Changes: If we make a material change to how we collect, use, or share your personal data, we will take more prominent steps to notify you. This may include:
- Placing a prominent notice on our website.
- Sending you an email notification (if we hold your email address) explaining the changes before they take effect.
9.2 Your Responsibility
We encourage you to periodically review this page for the latest information on our privacy practices. Your continued use of the website or our services after the effective date of the revised policy constitutes your acceptance of the terms.
Since 1980
Who We Are
One of the First Islamic Publishers in the United Kingdom
Connecting English-speaking Muslims to the heart of their faith with authentic, accessible books.
At a time when there were limited faith-based resources to learn and teach Islam to the Muslim community in English, Afsar & Jamal-un-Nisa Siddiqui founded one of the first Islamic publishing houses in the UK. Leaving behind professional careers, they paved the way for future generations to enjoy a wide range of Islamic literature. Almost fifty years later, we continue to provide the highest quality books worldwide and support literacy charities.
Family Owned
Gives Back
45+ Years in Business
Customer Service
Our friendly customer support is here for you