Welcome to HALO FOODS LIMITED privacy policy

This privacy policy sets out how Halo Foods Limited (company number 02411911) uses and protects your Personal Data .

1. Important information and who we are 
2. The types of Personal Data we collect about you 
3. How is your Personal Data collected? 
4. How we use your Personal Data 
5. Disclosures of your personal data 
6. International transfers 
7. Data security 
8. Data retention 
9. Your legal rights 
10. Contact details 
11. Complaints 
12. Changes to the privacy policy and your duty to inform us of changes 
13. Third-party links 
14. Definitions 

1. Important information and who we are

Privacy policy

This privacy policy is issued by Halo Foods Limited as the Controller (referred to as the  “Company”, “we”, “us” or “our” in this privacy policy) and is addressed to individuals outside our organisation with whom we interact, including customers, visitors to our website, users of our products, personnel of corporate customers and vendors, applicants for employment, and visitors to our premises (together, “you”). Defined terms used in this privacy policy are explained in Section 14 below.

This privacy policy gives you information about how Halo Foods Limited collects and uses your Personal Data through your use of this website, including any Personal Data you may provide when you leave comments on our website.

This website is not intended for children and we do not knowingly collect Personal Data relating to children.

This privacy policy may be amended or updated from time to time to reflect changes in our practices with respect to the Processing of Personal Data, or changes in applicable law. We encourage you to read this privacy policy carefully, and to regularly check this page to review any changes we might make in accordance with the terms of this privacy policy.

This privacy policy was last updated on 20th February 2025.

Controller

Halo Foods Limited is the Controller.

If you have any questions about this privacy policy, including any requests to exercise your legal rights ( Section 9), please contact us using the information set out in the contact details section (Section 10).

2. The types of Personal Data we collect about you

We may collect, use, store, transfer or otherwise Process different kinds of Personal Data about you which we have grouped together as follows:

  • Identity data includes first name, last name, salutation and title, any previous names, username or similar identifier, marital status, nationality, title, date of birth and gender.
  • Contact Data includes billing address, delivery address, email address and telephone numbers; details of personal assistants, where applicable; messenger app details; online messaging details; and social media details.
  • Correspondence includes records and copies of your correspondence if you contact us.
  • Professional details include your CV; records of your expertise; professional history; practising details and qualification details; information about your experience; participation in meetings, seminars, advisory boards and conferences; information about your professional relationship with other individuals or institutions; language abilities; and other professional skills.
  • Technical data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website.
  • Visitor data includes records of visits to our premises.
  • Payments-related data includes invoice records; payment records; billing address; payment method; bank account number or credit card number; cardholder or accountholder name; card or account security details; card ‘valid from’ date; card expiry date; BACS details; SWIFT details; IBAN details; payment amount; payment date; and records of cheques.
  • Profile data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
  • Usage data includes information about how you interact with and use our website, products and services.
  • Employer details: where you interact with us in your capacity as an employee of a third party; and the name, address, telephone number and email address of your employer, to the extent relevant.
  • Content and advertising data: records of your interactions with our online advertising and content, records of advertising and content displayed on pages displayed to you, and any interaction you may have had with such content or advertising (e.g., mouse hover, mouse clicks, any forms you complete in whole or in part) and any touchscreen interactions.
  • Cookie data: we collect information via Cookies and similar technologies. Please see our Cookies Policy for more details.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
  • Consent records: records of any consents you have given, together with the date and time, means of consent, and any related information (e.g., the subject matter of the consent).
  • Views and opinions: any views and opinions that you choose to send to us, or publicly post about us on social media platforms.

We also collect, use and share aggregated data such as statistical or demographic data which is not Personal Data as it does not directly (or indirectly) reveal your identity. For example, we may aggregate individuals’ Usage Data to calculate the percentage of users accessing a specific website feature in order to analyse general trends in how users are interacting with our website to help improve the website and our service offering.

We also create Personal Data about you in certain circumstances, such as records of your interactions with us. We may also combine Personal Data from our website, products, or services, including where those data are collected from different devices or sources.

Sensitive Personal Data

We do not seek to collect or otherwise Process Sensitive Personal Data in the ordinary course of our business.

Where it becomes necessary to Process your Sensitive Personal Data for any reason, we rely on one of the following legal bases:

  • Compliance with applicable law: We may Process your Sensitive Personal Data where the Processing is required or permitted by applicable law (e.g., to comply with our diversity reporting obligations);
  • Detection and prevention of crime: We may Process your Sensitive Personal Data where the Processing is necessary for the detection or prevention of crime (e.g., the prevention of fraud);
  • Establishment, exercise or defence of legal claims: We may Process your Sensitive Personal Data where the Processing is necessary for the establishment, exercise or defence of legal claims; or
  • Consent: We may Process your Sensitive Personal Data where we have, in accordance with applicable law, obtained your express consent prior to Processing your Sensitive Personal Data (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way).

If you provide Sensitive Personal Data to us, you must ensure that it is lawful for you to disclose such data to us, and you must ensure a valid legal basis applies to the Processing of those Sensitive Personal Data.

3. How is your Personal Data collected?

 Collection of Personal Data

We use different methods to collect Personal Data from and about you including through:

  • Data provided to us. We obtain Personal Data when those data are provided to us. For example, you may give us your Personal Data by filling in online forms or by corresponding with us by post, phone, email or otherwise. This includes Personal Data you provide when you:
    • leave comments on our website: or
    • request marketing to be emailed to you.
  • Data we obtain in person. We may obtain Personal Data during meetings, during visits from sales or marketing representatives, or at events we attend.
  • Relationship data. We collect or obtain Personal Data in the ordinary course of our relationship with you (e.g., we provide a service to you, or to your employer).
  • Data you make public. We collect or obtain Personal Data that you manifestly choose to make public, including via social media (e.g., we may collect information from your social media profile(s), if you make a public post about us).
  • Automated technologies or interactions. As you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns. We collect this Personal Data by using Cookies and other similar technologies. We may also receive technical data about you if you visit other websites employing our Cookies. Please see our Cookies Policy for further details.
  • Third parties or publicly available sources. We may receive Personal Data about you from various third parties and public sources as set out below:
    • Technical data may be collected from the following parties:
      • analytics providers;
      • advertising networks; and
      • search information providers.
    • Identity and contact data may be collected from data brokers or aggregator.
    • Identity and contact data may be collected from publicly available sources.
  • Third party information: We collect or obtain Personal Data from third parties who provide it to us (e.g., credit reference agencies; law enforcement authorities; etc.).

Creation of Personal Data

We create Personal Data about you (e.g., records of your interactions with us).

We also create Personal Data about you in certain circumstances, such as records of your interactions with us. We may also combine Personal Data from our website, products, or services, including where those data are collected from different devices or sources.

4. How we use your Personal Data

Legal basis

The law requires us to have a legal basis for collecting and using your Personal Data. We rely on one or
more of the following legal bases:

  • Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you.
  • Legitimate interests: We may use your Personal Data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and enable us to give you the best and most secure customer experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we Process your Personal Data for our legitimate interests. We do not use your Personal Data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
  • Legal obligation: We may use your Personal Data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.
  • Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to an email newsletter.

Purposes for which we will use your Personal Data

We have set out below, in a table format, a description of all the ways we plan to use the various categories of your Personal Data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Purpose/Use

Type of data

Legal basis and retention period

To manage our relationship with
you which will include:
(a) Notifying you about changes to our terms or privacy policy
(b) Dealing with your requests,
complaints and queries

(c) providing our products and promotional items upon request; and communicating with you in relation to those.

(a) Identity data
(b) Contact data
(c) Profile data

(d) Correspondence
(e) Marketing and Communications data

(f) Consent records

(g) Payment-related data

(h) Employer details

(i) Content and advertising data

(j) Views and opinions

(a) Performance of a contract with you
(b) Necessary to comply with a legal
obligation
(c) Necessary for our legitimate interests (to keep our records updated and manage our relationship with you) (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

(d) your prior consent (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way)

[Compliance checks: To fulfil our regulatory compliance obligations; ‘Know Your Client’ checks; and confirm and verify your identity.

(a) Identity data

(b) Contact data

(c) Correspondence

(d) Professional details

(e) Consent records

(f) Payment-related data

(g) Employer details

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests for the purpose of fulfilling our regulatory and compliance obligations (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

(d) your prior consent (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way)]

To administer and protect our business, to carry out financial management, to operate this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data), communicate and interact with you via our website, and notify you of changes to any of our products or website.

(a) Identity data
(b) Contact data
(c) Technical data

(d) Correspondence

(e) Consent records

(f) Payment-related data

(g) Views and opinions

(h) Employer details

(i) Content and advertising data

(a) Necessary for our legitimate interests (for running our business, managing and operating the financial affairs of our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)
(b) Necessary to comply with a legal obligation

(c) Performance of a contract with you

(d) your prior consent (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way)

To deliver relevant website content and online advertisements to you and measure or understand the effectiveness of the advertising we serve to you

(a) Identity data
(b) Contact data
(c) Profile data
(d) Usage data
(e) Marketing and Communications data
(f) Technical data

(g) Content and advertising data

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

To use data analytics to improve our website, products/services, customer relationships and experiences and to measure the effectiveness of our communications and marketing

(a) Technical data
(b) Usage data

(c) Profile data

(d) Content and advertising data

(a) Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

(b) your prior consent (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way)

To send you relevant marketing communications and make personalised suggestions and recommendations to you about goods or services that may be of interest to you based on your Profile Data

(a) Identity data
(b) Contact data
(c) Technical data
(d) Usage data
(e) Profile data
(f) Marketing and Communications data

(a) Necessary for our legitimate interests (to carry out direct marketing, develop our products/services and grow our business), subject always to compliance with applicable law

(b) your prior consent (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way)

To carry out market research through your voluntary participation in surveys

(a) Identity data

(b) Contact data

(c) Correspondence

(d) Profile data

(e) Content and advertising data

(f) Consent records

(g) Views and opinions

(a) Necessary for our legitimate interests (to study how customers use our products/services and to help us improve and develop our products and services) (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

(b) your prior consent (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way)

To carry out product safety communications in relation to product safety, including product recalls and product safety advisory notices

(a) Identity data

(b) Contact data

(c) Payment-related data

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests for the purpose of ensuring the safety, and proper use, of our products (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

To carry out organisational planning, succession planning, making changes to the nature and scope of our operations or our business, mergers, acquisitions, dissolutions demergers, liquidations, asset sales, divestitures, reorganisations and similar corporate structuring arrangements

(a) Identity data

(b) Contact data

(c) Professional details

(d) Usage data

(e) Employer details

(f) Content and advertising data

(g) Views and opinions

Necessary for our legitimate interests for the purpose of planning the future operation of our operations or our business (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

To carry out health and safety assessments and record keeping, provide a safe and secure environment at our premises, and comply with related legal obligations.

(a) Identity data

(b) Contact data

(c) Correspondence

(d) Visitor data

(a) Necessary to comply with a legal obligation where applicable

(b) Necessary for our legitimate interests for the purpose of ensuring a safe environment at our premises (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

(c) Necessary to protect the vital interests of any individual

To carry out physical security of our premises (including records of visits to our premises); CCTV recordings; and electronic security (including login records and access details).

(a) Identity data

(b) Contact data

(c) Visitor data

(a) Necessary to comply with a legal obligation where applicable

(b) Necessary for our legitimate interests for the purpose of ensuring the physical and electronic security of our business and our premises (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

To detect, investigate and prevent breaches of policy, and fraud or criminal offences, in accordance with applicable law.

Each category of Personal Data identified in the ‘The types of Personal Data we collect about you’  above, to the extent necessary in the context of the relevant legal obligation or regulatory requirements or guidance

(a) Necessary to comply with a legal obligation where applicable

(b) Necessary for our legitimate interests for the purpose of detecting, and protecting against, breaches of our policies and applicable laws (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

To comply with our legal and regulatory obligations under applicable law.

Each category of Personal Data identified in the ‘The types of Personal Data we collect about you’ above, to the extent necessary in the context of the relevant legal obligation or regulatory requirements or guidance

(a) Necessary to comply with a legal obligation where applicable

(b) Necessary for our legitimate interests for the purpose of detecting, and protecting against, breaches of our policies and applicable laws (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

To establishment, exercise and defend legal claims, such as managing legal claims, establishing facts and claims (including collection), reviewing and producing documents, facts, evidence and witness statements, and  exercising and defending legal rights and claims, including formal legal proceedings

Each category of Personal Data identified in the ‘The types of Personal Data we collect about you’ above, to the extent necessary in the context of the relevant legal obligation or regulatory requirements or guidance

(a) Necessary to comply with a legal obligation where applicable

(b) Necessary for our legitimate interests for the purpose of establishing, exercising or defending our legal rights (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

(c) Necessary for the establishment, exercise or defence of legal claims

To carry out recruitment and consider job applications, by undertaking recruitment activities, advertising of positions, interview activities, analysis of suitability for the relevant position, records of hiring decisions, offer details, and acceptance details.

(a) Identity data

(b) Contact data

(c) Correspondence

(d) Professional details

(e) Profile data

(f) Visitor data

(g) Consent records

(h) Usage data

(i) Employer details

(j) Content and advertising data

(k) Views and opinions

(a) Necessary to comply with a legal obligation (especially in respect of applicable employment law)

(b) Necessary for our legitimate interests for the purpose of recruitment activities and handling job applications (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms)

(c) your prior consent (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way)

Direct marketing

You will receive marketing communications from us if you have requested information from us and you have not opted out of receiving the marketing.

We may Process Personal Data to contact you via email, telephone, direct mail or other communication formats to provide you with information regarding our products that may be of interest to you. We also Process Personal Data for the purposes of displaying content tailored to your use of our website, products, services and offers. If we provide the website, products or services to you, we may send or display information to you regarding those, or upcoming promotions and other information that may be of interest to you, including by using the contact details that you have provided to us, or any other appropriate means, subject always to obtaining your prior opt-in consent to the extent required under applicable law.

Third-party marketing

We will get your express consent before we share your Personal Data with any third party for their own direct marketing purposes.

Opting out of marketing

You can ask to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us enquiries@skinnybars.co.uk. Please note that it may take up to 2 weeks to process your opt-out request during which time you may continue to receive communications from us.

If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes for example relating to order confirmations, updates to our Terms and Conditions, checking that your contact details are correct.

Cookies

For more information about the Cookies we use and how to change your cookie preferences, please see our Cookie policy.

5. Disclosures of your personal data

  • We disclose Personal Data to other entities within the Halo Foods group, for legitimate business purposes and the operation of our website, products, or services to you, in accordance with applicable law.
  • In addition, we may disclose Personal Data to:
    • you and, where appropriate, your appointed representatives;
    • accountants, auditors, consultants, lawyers and other outside professional advisors to Halo Foods, subject to binding contractual obligations of confidentiality;
    • third party Processors (such as payment services, subject to the requirements noted below);
    • any relevant party, regulatory body, governmental authority, law enforcement agency or court, to the extent necessary for the establishment, exercise or defence of legal claims;
    • any relevant party, regulatory body, governmental authority, law enforcement agency or court, for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties;
    • any relevant third-party acquirer(s) or successor(s) in title, in the event that we sell or transfer all or any relevant portion of our business or assets (including in the event of a reorganization, dissolution or liquidation); and
    • any relevant third-party provider, where our website uses third party advertising, plugins or content. If you choose to interact with any such advertising, plugins or content, your Personal Data may be shared with the relevant third-party provider. We recommend that you review that third party’s privacy policy before interacting with its advertising, plugins or content.
  • If we engage a third-party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to: (i) only Process the Personal Data in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of the Personal Data; together with any additional requirements under applicable law.

6. International transfers

  • We do not transfer your Personal Data outside the UK.

7. Data security

  • We have put in place appropriate security measures to prevent your Personal Data from being accidentally or unlawfully destroyed, lost, used or accessed in an unauthorised way, altered or disclosed in accordance with applicable law.
  • In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know. They will only Process your Personal Data on our instructions and they are subject to a duty of confidentiality.
  • Because the internet is an open system, the transmission of information via the internet is not completely secure. Although we will implement all reasonable measures to protect your Personal Data, we cannot guarantee the security of your data transmitted to us using the internet – any such transmission is at your own risk, and you are responsible for ensuring that any Personal Data that you send to us are sent securely.

8. Data retention

How long will you use my Personal Data for?

We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we Process it for (as set out in this privacy policy), including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you. The criteria for determining the duration for which we will retain your personal data are as follows:

(1)  we will retain personal data in a form that permits identification only for as long as:

(a)  we maintain an ongoing relationship with you (e.g., where you are a customer, or you are lawfully included in our mailing list and have not unsubscribed); or

(b)  your Personal Data are necessary in connection with the lawful purposes set out in this privacy policy, for which we have a valid legal basis (e.g., where your Personal Data are included in a contract between us and your employer, and we have a legitimate interest in Processing those Personal Data for the purposes of operating our business and fulfilling our obligations under that contract; or where we have a legal obligation to retain your Personal Data),

plus:

(2)  the duration of:

(a)  any applicable limitation period under applicable law (i.e., any period during which any person could bring a legal claim against us in connection with your Personal Data, or to which your Personal Data are relevant); and

(b)  an additional two (2) month period following the end of such applicable limitation period (so that, if a person brings a claim at the end of the limitation period, we are still afforded a reasonable amount of time in which to identify any Personal Data that are relevant to that claim),

and:

(3)  in addition, if any relevant legal claims are brought, we continue to Process Personal Data for such additional periods as are necessary in connection with that claim.

During the periods noted in paragraphs (2)(a) and (2)(b) above, we will restrict our Processing of your Personal Data to storage of, and maintaining the security of, those data, except to the extent that those data need to be reviewed in connection with any legal claim, or any obligation under applicable law.

Once the periods in paragraphs (1), (2) and (3) above, each to the extent applicable, have concluded, we will either:

  • permanently delete or destroy the Relevant Personal Data; or
  • anonymize the Relevant Personal Data.

By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.

In some circumstances you can ask us to delete your data: see Section 9 below for further information.

In some circumstances we will anonymise your Personal Data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

9. Your legal rights

Subject to applicable law, you may have a number of rights under data protection laws in relation to your Personal Data:

  • Request access to Personal Data (commonly known as a “subject access request”). This enables you to request access to, or copies of, Relevant Personal Data, together with information regarding the nature, Processing and disclosure of those Personal Data.
  • Request correction of Personal Data that we hold about you. This enables you to have any incomplete or inaccurate Relevant Personal Data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your Personal Data in certain circumstances. This enables you to ask us to delete or remove Relevant Personal Data where there is no good reason for us continuing to Process it. You also have the right to ask us to delete or remove Relevant Personal Data where you have successfully exercised your right to object to Processing (see further below), where we may have Processed your information unlawfully or where we are required to erase Relevant Personal Data to comply with applicable law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the
    time of your request.
  • Request the transfer of your Personal Data to you or to a third party. Where applicable, we will provide to you, or a third party you have chosen, Relevant Personal Data in a structured, commonly used, machine- readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Withdraw consent at any time where we are relying on consent to Process your Personal Data (see the table in section 4 for details of when we rely on your consent as the legal basis for using your Personal Data). However, this will not affect the lawfulness of any Processing carried out before you withdraw your consent and will not prevent the Processing of your Personal Data in reliance upon any other available legal bases. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
  • Request restriction of Processing of your Personal Data in certain circumstances. This enables you to ask us to suspend the Processing of Relevant Personal Data in one of the following scenarios:
    • If you want us to establish the data’s accuracy;
    • Where our use of the data is unlawful but you do not want us to erase it;
    • Where you need us to hold the data even if we no longer require it as you need it to
      establish, exercise or defend legal claims; or
    • You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request not to provide your Personal Data to us. However, please note that we will be unable to provide you with the full benefit of our website or services, if you do not provide us with your Personal Data in certain circumstances – e.g., we might not be able to process your requests without the necessary details).

 

Subject to applicable law, you may also have the following additional rights regarding the Processing of your Relevant Personal Data:

•       the right to object, on grounds relating to your particular situation, to the Processing of your Relevant Personal Data by us or on our behalf, where such processing is based on Articles 6(1)(e) (public interest) or 6(1)(f) (legitimate interests) of the UK GDPR; and

•       the right to object to the Processing of your Relevant Personal Data by us or on our behalf for direct marketing purposes.

This does not affect your statutory rights.

To exercise one or more of these rights, or to ask a question about these rights or any other provision of this privacy policy, or about our Processing of your Personal Data, please use the contact details provided in Section 10 (Contact Details) below. Please note that:

  • in some cases it will be necessary to provide evidence of your identity before we can give effect to these rights; and
  • where your request requires the establishment of additional facts (e.g., a determination of whether any Processing is non-compliant with applicable law) we will investigate your request reasonably promptly, before deciding what action to take.

No fee usually required

You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. In certain circumstances, we could refuse to comply with your request in these circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated, and will respond no later than two further months.

10. Contact details

If you have any questions about this privacy policy or about the use of your Personal Data or you want to exercise your privacy rights, please contact us in the following ways:

11. Complaints

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

12. Changes to the privacy policy and your duty to inform us of changes

We keep our privacy policy under regular review.

It is important that the Personal Data we hold about you is accurate and current. We also take every reasonable step to ensure that:

  • your Personal Data that we Process are accurate and, where necessary, kept up-to-date; and
  • any of your Personal Data that we Process that are inaccurate (having regard to the purposes for which they are Processed) are erased or rectified without delay.

From time to time we may ask you to confirm the accuracy of your Personal Data.

Please also keep us informed if your Personal Data changes during your relationship with us, for example a new address or email address.

13. Third-party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

14. Definitions

  • Cookie” means a small file that is placed on your device when you visit a website (including our website). In this privacy policy, a reference to a “Cookie” includes analogous technologies such as web beacons and clear GIFs.
  • Controller” means the entity that decides how and why Personal Data are Processed. In many jurisdictions, the Controller has primary responsibility for complying with applicable data protection laws.
  • Personal Data” means information that is about any individual, or from which any individual is directly or indirectly identifiable, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.
  • Process”, “Processing” or “Processed” means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Processor” means any person or entity that Processes Personal Data on behalf of the Controller (other than employees of the Controller).
  • Relevant Personal Data” means Personal Data in respect of which we are the Controller.
  • Sensitive Personal Data” means Personal Data about race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, biometric data, physical or mental health, sexual life, any actual or alleged criminal offences or penalties, national identification number, or any other information that are deemed to be sensitive under applicable law.
  • UK GDPR” means General Data Protection Regulation (EU) 2016/679 as it forms part of the laws applicable in the UK by virtue of section 3 of the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018, and as applied and modified by Schedule 2 of the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419) or as modified from time to time.

Newsletter

join our mailing list now