GDPR, Cookies & Privacy Policy.

GDPR, Cookies & Privacy Policy.


We are M Lucking & Sons. 195 New London Road, Chelmsford, Essex.  CM2 0AE – Tel: 01245 353733.


When you purchase or contact us through our website, we collect the personal information you give us such as your name, address and email address. We use this information for sales and services communication.

When you browse our website, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system. Please see Section 6 for more details about specific cookies we collect.

Email marketing

With your permission, we may send you emails about our services, new products and other updates.

We do not have an expiry on the amount of time we will hold your data for. We do offer withdrawal of consent and deletion of your data at any time upon your request.


How do you get my consent?

When you provide us with personal information to complete a transaction or to contact us, we require your acceptance of the content of this privacy policy, that you consent to our collecting it and using it for that specific reason only.

If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent or provide you with an opportunity to say no.

How do I withdraw my consent or request my data to be removed?

If after you opt-in, you change your mind, you may withdraw your consent for us to store any personal data about you, contact you, for the continued collection, use or disclosure of your information, at any time, by contacting us at [email protected] or mailing us at:

M Lucking & Sons. 195 New London Road, Chelmsford, Essex.  CM2 0AE.


Our website is hosted on Amazon’s servers. Data is stored through in Amazon’s data storage, databases and the general hosting application. They store your data on a secure server behind a firewall.


All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.

PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.

Data breaches

In the rare occurrence of a data breach, which would significantly harm individuals, we will be report it within 72 hours to the ICO. We will also notify any customers affected.


In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways, email marketing systems and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.

For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.

In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.

Donations & Announcements Pages iFrame – 3rd Party [Cloudberry FMS]

How do we collect information from you?

We obtain information about you when you use our website, for example, when you contact us about products and services; make
a donation in memory of a deceased person, or to donate to one of our fundraising activities.

What type of information is collected from you?

The personal information we collect will include your name, address and email address. If you make a donation online or purchase
a product from us, your credit or debit card information is not held by us, it is collected by our third-party payment processors, who
specialise in the secure online capture and processing of credit/debit card transactions, as explained below.

How is your information used?

We may use your information to:
Process a donation that you have made;
Feedback details of a donation to the deceased person’s family (usually their next of kin) and the charity(s) or group(s) that
they have collected in memory of.

We review our retention periods for personal information on a regular basis. We are legally required to hold some types of
information to fulfil our statutory obligations (for example the collection of Gift Aid). We will hold your personal information on
our systems for as long as is necessary for the relevant activity.

Who has access to your information?
Where you have a made a donation with UK Gift Aid added, we share your address and email address with the charity(s) or
group(s) as this information is a mandatory requirement for them to claim the Gift Aid from HMRC.
Where you are donating in memory of a deceased person, we share your name (but not the individual donation amount) with the
next of kin in a letter which advises who has donated and the total amount raised.
In the event of a Gift Aid Audit by HMRC, we and our partners are committed to provide and share information regarding any
donation where a Gift Aid declaration has been made to HMRC.

Cloudberry Funeral Management Systems Limited (“Cloudberry”): Cloudberry act as a data processor for us. They developed,
operate and manage the donations element of our website, they have access to and store on our behalf name, address, donation
amounts and email address information that you have given for the purposes of completing donations on our website and
providing services to you on our behalf (for example to process donations). We disclose only the personal information that is
necessary to deliver the service, they cannot use it, sell it or rent it. Please be reassured that we will not release your information to
third parties beyond ourselves for direct marketing purposes, unless you have requested us to do so, or we are required to do so by
law, for example, by a court order or for the purposes of prevention of fraud or other crime.

When you are using our secure online donation pages, your donation is processed by a third party payment processor, who
specialises in the secure online capture and processing of credit/debit card transactions. Our processor been audited by an
independent PCI Qualified Security Assessor (QSA) and is certified as a PCI Level 1 Service Provider. This is the most stringent level of
certification available in the payments industry.

If you have any questions regarding secure payment transactions, please contact us.
We may transfer your personal information to a third party as part of a sale of some or all of our business and assets to any third
party or as part of any business restructuring or reorganisation, or if we’re under a duty to disclose or share your personal data in

order to comply with any legal obligation or to enforce or apply our terms of use or to protect the rights, property or safety of our
supporters and customers. However, we will take steps with the aim of ensuring that your privacy rights continue to be protected.

Your choices
You have a choice about whether or not you wish to receive information from us. If you want to receive direct marketing
communications from us about products services and events, then you can select to be contacted by email or post by ticking the
relevant boxes situated at the foot of the donation form.
We will not contact you for marketing purposes by email or post unless you have given your prior consent. You can change your
marketing preferences at any time by contacting us by email: [email protected] or telephone on 01245 353733.

How you can access and update your information
You have the right to ask for a copy of the information that we hold about you.
Security precautions in place to protect the loss, misuse or alteration of your information
When you give us personal information, we take steps to ensure that it’s treated securely. When you are on a secure page e.g. our
donations page, a lock icon will appear on the bottom of web browsers such as Microsoft Internet Explorer.
Transferring your information outside of Europe

As part of the services offered to you through this website, the information which you provide to us may be transferred to countries
outside the European Union (“EU”). By way of example, this may happen if any of our servers are from time to time located in a
country outside of the EU. These countries may not have similar data protection laws to the UK. By submitting your personal data,
you’re agreeing to this transfer, storing or processing. If we transfer your information outside of the EU in this way, we will take
steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be
protected as outlined in this Policy.

Once you leave our website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy.


When you click on links on our website, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.


To protect your personal information, we take precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.

If you provide us with your credit or debit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.


This site uses only anonymous cookies, meaning that our cookies are not collecting any information which would be enable you to be to identified personally.

Cookies are small text files that are placed on your machine to help the site provide a better user experience. In general, cookies are used to retain user preferences, store information for things like shopping carts, and provide anonymised tracking data to third party applications like Google Analytics. As a rule, cookies will make your browsing experience better.

However, you may prefer to disable cookies on this site and on others. The most effective way to do this is to disable cookies in your browser. We suggest consulting the Help section of your browser or taking a look at the About Cookies website which offers guidance for all modern browsers.

These are the cookies we use:

Google Analytics Cookies

We use Google Analytics on our website to improve customer experience and make future improvements on our website. They are as follows:

  • collect Used to send data to Google Analytics about the visitor’s device and behaviour. Tracks the visitor across devices and marketing channels.
  • NID Registers a unique ID that identifies a returning user’s device. The ID is used for targeted ads.
  • _ga 2 years Used to distinguish users.
  • _gid 24 hours Used to distinguish users.
  • _gat 1 minute Used to throttle request rate.
  • AMP_TOKEN 30 seconds to 1 year Contains a token that can be used to retrieve a Client ID from AMP Client ID service. Other possible values indicate opt-out, inflight request or an error retrieving a Client ID from AMP Client ID service.
  • _gac_ 90 days Contains campaign related information for the user.

The ga.js JavaScript library present on our website and uses first-party cookies to:

  • Determine which domain to measure
  • Distinguish unique users
  • Throttle the request rate
  • Remember the number and time of previous visits
  • Remember traffic source information
  • Determine the start and end of a session
  • Remember the value of visitor-level custom variables

Specific ga.js cookies are as follows:

  • __utma 2 years from set/update Used to distinguish users and sessions. The cookie is created when the javascript library executes and no existing __utma cookies exists. The cookie is updated every time data is sent to Google Analytics.
  • __utmt 10 minutes Used to throttle request rate.
  • __utmb 30 mins from set/update Used to determine new sessions/visits. The cookie is created when the javascript library executes and no existing __utmb cookies exists. The cookie is updated every time data is sent to Google Analytics.
  • __utmc End of browser session Not used in ga.js. Set for interoperability with urchin.js. Historically, this cookie operated in conjunction with the __utmb cookie to determine whether the user was in a new session/visit.
  • __utmz 6 months from set/update Stores the traffic source or campaign that explains how the user reached your site. The cookie is created when the javascript library executes and is updated every time data is sent to Google Analytics.
  • __utmv 2 years from set/update Used to store visitor-level custom variable data. This cookie is created when a developer uses the _setCustomVar method with a visitor level custom variable. This cookie was also used for the deprecated _setVar method. The cookie is updated every time data is sent to Google Analytics.

Wordfence Cookies

  • wfvt_# Remembers the user’s submitted data when a comment is submitted in a blog post. The purpose is to auto-populate form fields for subsequent comments, in order to save time for the user.

Cloudflare Cookies

  • __cfduid Used by the content network, Cloudflare, to identify trusted web traffic.
  • __cfduid Used by the content network, Cloudflare, to identify trusted web traffic.
  • expanded Used by the content network, Cloudflare, to optimise website performance.
  • superMinimize Used by the content network, Cloudflare, to optimise website performance.

  • PHPSESSID Cookie purpose description: Preserves user session state across page requests. – Data is sent to the Netherlands

Your Data

Your data is stored through Digital Ocean’s data storage and databases. They are stored on a secure server behind a firewall. We use SSH to access our servers and use public key authentication when accessing them. We do not have any public facing control panels exposed on our server.


We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.


If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at [email protected] or by mail at:

M Lucking  & Sons

Re: Privacy Compliance Officer

195 New London Road, Chelmsford, Essex. CM2 0AE

Added: 05/04/2018