Privacy Policy & Data Protection
Effective Date: May 12, 2024 | Version 2.1 (UK Compliance)
1. Introduction and Scope
CHAPEL FOODS LIMITED ("the Company", "We", "Us", "Our") is committed to protecting the privacy and security of your personal data. This policy describes how we collect, use, and process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy applies to all users of our website, our commercial clients, and our logistics partners.
2. Data Controller Information
For the purposes of the Data Protection Act 2018, the data controller is CHAPEL FOODS LIMITED, a company registered in England and Wales. Our registered office and primary processing facility is located at: South Park Suite, Unit 1 & 2 North Farm Road, South Park Industrial Estate, Bottesford, DN17 2AY, England, United Kingdom.
3. The Categories of Data We Collect
We process several types of personal data about you, including but not limited to:
- Identity Data: Full name, company title, and professional credentials.
- Contact Data: Delivery addresses, billing addresses, email addresses, and telephone numbers.
- Financial Data: Bank account details and payment card information (processed via secure, encrypted gateways).
- Technical Data: Internet protocol (IP) address, login data, browser type and version, time zone setting, and location data.
- Transaction Data: Historical records of services purchased and logistics movements.
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Performance of Contract: Where we need to perform the contract we are about to enter into or have entered into with you (e.g., executing a delivery).
- Legal Obligation: Where we need to comply with a legal or regulatory obligation (e.g., food safety traceability or tax reporting).
- Legitimate Interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
5. Data Retention and Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.
6. Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to receive a copy of the personal data we hold about you (Subject Access Request) and the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).
[Extended 800+ words of legal clauses regarding international transfers, automated decision making, cookies, and specific liability limitations follow in the full legal repository...]