Skip to main content
Free 24-hour delivery over £60 · Same-day despatch

Referral partners

Affiliate privacy notice.

Last updated: 12 June 2026

This notice explains how Kovalabs handles your personal data when you apply to, or take part in, the Kovalabs Referral Partner Programme. The controller is Floww Group Ltd, registered in England and Wales (company number 15986643), registered office 66 Paul Street, London, EC2A 4NE, trading as Kovalabs. It covers the extra processing we do because you are a partner; how we handle your data as a customer is covered by our Privacy Policy, and cookies by our Cookie Policy.

What we collect about you

  • Identity and contact data: your name, email address and your Kovalabs customer-account identifier, plus the channels or sites you tell us you will promote through.
  • Account and contract data: your application status, the timestamp and version of the partner terms you accepted, and our correspondence with you, including compliance and monitoring records.
  • Payout data: the bank or payment-account details you give us so we can pay commission, and your payout history.
  • Tax data: your VAT-registration status (we presume partners are not VAT-registered unless you tell us otherwise) and related records we need to keep for HMRC.
  • Referral and performance data: your referral code, link and discount code; the clicks and orders attributed to you; and the commission, hold, clawback and balance records on your ledger. Click counts are anonymous tallies of link visits; they contain no visitor identity.
  • Verification data: before paying you we may verify your identity and screen against the UK sanctions list; where a third-party check is used we receive the result, not the underlying documents.

Providing identity, payout and tax data is a contractual requirement of being paid under the programme (and partly a statutory one). If you do not provide it, we cannot admit you or pay commission.

Why we use it, and our lawful bases

  • To assess your application, run your account, attribute orders, calculate commission and pay you: performance of our contract with you (UK GDPR Article 6(1)(b)).
  • To keep tax and self-billing records and meet financial-sanctions obligations: compliance with a legal obligation (Article 6(1)(c)).
  • To prevent and investigate fraud, self-referral and prohibited-claim breaches, monitor compliance (partner promotion is treated as our own regulated advertising), and establish or defend legal claims including clawback: our legitimate interests (Article 6(1)(f)). You can object at any time (see your rights below).

Decisions about applications, suspensions and clawbacks are made by a person. We do not use automated decision-making, including profiling, that produces legal or similarly significant effects about you.

Who we share it with

Only where necessary: the provider we use to pay your commission; our accountant and HMRC for tax and self-billing records; our hosting, database and software providers acting as processors under written terms; our professional advisers; and authorities or courts where we are legally required or permitted. We aim to keep your data in the UK or EEA. Where a provider processes it outside the UK, we rely on the UK adequacy regulations or the UK International Data Transfer Addendum to the EU standard contractual clauses; you can ask for a copy of these safeguards by emailing hello@kovalabs.co.uk. We never sell your personal data and never share it for third-party marketing.

How long we keep it

  • Tax, commission-ledger and self-billing records: 6 years after the end of the financial year they relate to (HMRC requirement).
  • Account, identity, contact and payout data: for the life of your participation, then alongside the ledger for up to 6 more years (the limitation period for contract claims).
  • Declined or closed applications: 12 months.

Your rights

You have the UK GDPR rights of access, rectification, erasure, restriction, objection and data portability, subject to the exemptions in the law (for example we must keep tax records even if you ask for erasure). To exercise them, email hello@kovalabs.co.uk and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to help first.

What you never receive: customer data

This is a deliberate feature of the programme. You are never given the personal data of the customers you refer: no names, no contact details, no addresses, and never which products or compounds were bought. Your ledger shows, per referred order, only the date, an order reference, a bare unit count, the order value after discount, your commission and its status. You must not attempt to identify, contact or track referred customers; if you capture customer data through your own tools you do so entirely outside the programme and are solely responsible for it.

The attribution cookie and click counts

When someone clicks your referral link we may set theaffiliate_ref andaffiliate_ref_atcookies on their device (not yours) so a qualifying order within 90 days can be credited to you. These are consent-gated marketing cookies on the visitor's side, disclosed in the Cookie Policy. You never receive the cookie value or any visitor identifier. We also count clicks on your link server-side as an anonymous tally (no cookie, no visitor identity) so your dashboard can show traffic and conversion. You must never interfere with the consent banner or run your own tracking on Kovalabs visitors.

Separately, when your link carries your active discount code, a visitor who clicks it gets a basket on our server that notes your referral code and the click time, so their 10% discount can be applied at checkout and the order credited to you. Where your link carries no discount, no basket is created at the click; but if the visitor starts a basket during that same visit, the basket record notes your referral code and click time so a qualifying order can still be credited to you. Both mechanisms use only the strictly necessary basket cookie (no marketing cookie) and are disclosed to visitors in the Cookie Policy.

Changes and contact

We may update this notice as the programme evolves; material changes will be notified to you by email or through your partner dashboard. Questions about this notice or your data: hello@kovalabs.co.uk. The programme terms themselves are at /affiliate-terms.