Park House Kitchens Ltd Date of Issue: 1st November 2024
- Purpose
This General Data Protection Regulation (GDPR) policy outlines how Park House Kitchens collects, processes, stores, and protects personal data in compliance with the GDPR and the UK Data Protection Act 2018. Our aim is to ensure transparency and safeguard the privacy rights of all individuals whose data we handle. - Scope
This policy applies to:
- All employees, contractors, and third parties working with Park House Kitchens.
- All personal data processed by the company, including customer, employee, and supplier data.
- Definitions
- Personal Data: Any information that can identify a person, directly or indirectly, such as name, email, phone number, or IP address.
- Data Subject: The individual whose personal data is being processed.
- Data Controller: The organisation that determines the purposes and means of processing personal data.
- Data Processor: Any party processing personal data on behalf of the Data Controller.
- Principles of Data Processing
Park House Kitchens adheres to the following principles when handling personal data: - Lawfulness, Fairness, and Transparency: Data must be processed legally and in a transparent manner.
- Purpose Limitation: Data will only be collected for specified, explicit, and legitimate purposes.
- Data Minimisation: We collect only the data necessary for the intended purpose.
- Accuracy: We keep data accurate and up-to-date.
- Storage Limitation: Personal data will be kept for no longer than necessary.
- Integrity and Confidentiality: We ensure appropriate security of personal data.
- Rights of Data Subjects
Data subjects have the following rights under GDPR:
- Access: The right to know what personal data we hold about them.
- Rectification: The right to have inaccurate or incomplete data corrected.
- Erasure: The right to request deletion of their data (“Right to be Forgotten”).
- Restriction: The right to limit the processing of their data.
- Objection: The right to object to data processing, including for direct marketing.
- Data Collection and Processing
Park House Kitchens collects and processes personal data for the following purposes:
- To provide products or services.
- To comply with legal obligations.
- To communicate with customers, employees, and suppliers.
We will obtain explicit consent where required and ensure that individuals can easily withdraw their consent.
- Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
- IT Security
- Data Protection practices advised to all employees.
- Secure access controls to limit data access to authorised personnel only.
- Regular audits of data processing activities.
- Data Sharing and Third Parties
We do not share personal data with third parties unless:
- It is necessary to fulfil work obligations
- Required by law
- Consent has been provided by the data subject
Third-party processors should comply with GDPR and have adequate security measures in place.
- Data Breaches
In the event of a personal data breach:
- The Data Protection Officer (DPO) will assess the risk to data subjects.
- Affected individuals and the Information Commissioner’s Office (ICO) will be notified within 72 hours if the breach poses a high risk to rights and freedoms.
- Roles and Responsibilities
- Emily Rowland oversees GDPR compliance and acts as the main point of contact for data protection queries.
- Employees: All employees are responsible for ensuring compliance with this policy and reporting any data protection issues to Emily Rowland.
- Retention Policy
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or as required by law. Once data is no longer needed, it will be securely deleted or anonymised. - Review and Updates
This policy will be reviewed periodically or as required by changes in GDPR regulations.