Hebridean Smokehouse is committed to protecting and respecting your privacy. Our data protection policy outlines what information we store, how we collect it, what we do with it, and how you can see it.
Hebridean Smokehouse is committed to meeting its data protection obligations under the General Data Protection Regulation ("GDPR") and the Data Protection Act 2018
Under the GDPR, there are six data protection principles that Hebridean Smokehouse must comply with. These provide that the personal information we hold about you must be:
- Processed lawfully, fairly and in a transparent manner.
- Collected only for legitimate purposes that have been clearly explained to you and not further processed in a way that is incompatible with those purposes.
- Adequate, relevant and limited to what is necessary in relation to those purposes.
- Accurate and, where necessary, kept up to date.
- Kept in a form which permits your identification for no longer than is necessary for those purposes.
- Processed in a way that ensures appropriate security of the data.
Information we collect from you, includes
- Contact Number
- Email Address
- Or alternatively the Name, Address, Postcode and Contact Number of any gift recipient nominated by the person placing an order with us.
This information is required so that we can process your order efficiently. This information is saved securely on our website and local servers.
Payment data, including credit cards used to pay over the phone or online are securely sent to our payment provider, Datacash ( https://en.wikipedia.org/wiki/DataCash) and we do not hold any payment details on any of our data storage systems or servers.
Your delivery address, name, telephone numbers and/or email address will be passed on to our carriers (Royal Mail, DHL or TNT) in order that they can expedite our delivery request.
What do we use your personal information for?
1. Information that is used to fulfil a contract with you
We use your personal information to fulfil our contract with you - something that you enter willingly by placing an order online, verbally over the telephone or by sending us a written instruction.
- To provide payment processing with our partners Datacash or our banking partners Bank of Scotland.
- To provide you with a personalised experience with the ability to contact you to troubleshoot any problems that may arise and clarify detailed requests
- To contact with you about your orders by email, telephone or postal means
2. Additional processing of your information that requires your consent
With your consent, we may use your personal information to contact you with news or services provided by Hebridean Smokehouse, for example information about date deadlines for Christmas orders. We do not pass your information to ANY other agencies or parties for the purposes of marketing.
You chose to have this contact with Hebridean Smokehouse and have the right to withdraw your consent to receive information from us at any time.
If you fail to provide certain personal information when requested or required, we may not be able to perform the contract we have entered with you, or we may be prevented from complying with our legal obligations.
Protection of your personal information
Hebridean Smokehouse has measures in place to protect the security of your personal information. It has internal policies, procedures, controls and routines in place to prevent your personal information from being accidentally lost or destroyed, altered or disclosed in an unauthorised way. In addition, we limit access to your personal information to those employees, and agents, like payment processing, who have a business need to know in order to perform their job duties and contractual obligations. You can obtain further information about these measures by contacting us directly.
Where your personal information is shared with third-party service providers, such as payment processing provider Mastercard, we require all third parties to take appropriate technical and organisational security measures to protect your personal information and to treat it subject to a duty of confidentiality and in accordance with data protection law. We only allow them to process your personal information for specified purposes and in accordance with our written instructions and we do not allow them to use your personal information for their own purposes.
Hebridean Smokehouse also has in place procedures to deal with a suspected data security breach and we will notify the Information Commissioner's Office (or any other applicable supervisory authority or regulator) and you of a suspected breach where we are legally required to do so.
Duration of Personal Data Storage
Personal information that is required in order to perform a contract, will be retained on Hebridean Smokehouse systems for a period of up to seven years
Data that is no longer deemed necessary will be deleted from our system.
Your rights in connection with your personal information:
As a data subject, you have a number of statutory rights. Subject to certain conditions, and in certain circumstances, you have the right to:
- Request access to your personal information - this is usually known as making a data subject access request and it enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request rectification of your personal information - this enables you to have any inaccurate or incomplete personal information we hold about you corrected.
- Request the erasure of your personal information - this enables you to ask us to delete or remove your personal information where there is no compelling reason for its continued processing, e.g. it's no longer necessary in relation to the purpose for which it was originally collected.
- Restrict the processing of your personal information - this enables you to ask us to suspend the processing of your personal information, e.g. if you contest its accuracy and so want us to verify its accuracy.
- Object to the processing of your personal information where we are relying on the legitimate interests of the business as our legal basis for processing a contract or receiving news or services and there is something relating to your particular situation which makes you decide to object to processing on this ground.
- Data Portability - this gives you the right to request and receive the transfer of your personal information to another party so that you can reuse it across different services for your own purposes.
If you wish to exercise any of these rights, please contact Hebridean Smokehouse by emailing us at firstname.lastname@example.org We may need to request specific information from you in order to verify your identity and check your right to access the personal information or to exercise any of your other rights.
If you believe that the Company has not complied with your data protection rights, you have the right to make a complaint to the Information Commissioner's Office (ICO) at any time. The ICO is the UK supervisory authority for data protection issues.
Hebridean Smokehouse reserves the right to update or amend this privacy notice at any time, Hebridean Smokehouse will issue you with a new privacy notice when we make updates or amendments. Where a change requires consent opting it will be sought prior to implementation.