GDPR Compliance Statement - PhilsKitchen.co.uk
Last Updated: 02/12/2024
Introduction
At PhilsKitchen.co.uk ("we," "us," "our"), we are committed to protecting and respecting your privacy and personal data in compliance with the EU General Data Protection Regulation (GDPR). This statement explains when and why we collect personal information, how we use it, the conditions under which we may disclose it to others, and how we keep it secure.
1. Data Controller
PhilsKitchen.co.uk is the data controller for the personal information we collect. For questions regarding our GDPR compliance, please contact: Philip Gahan gahandesign@gmail.com
2. Personal Data We Collect
We may collect and process the following types of personal data:
- Identity Data (name, username)
- Contact Data (email address, telephone number, postal address)
- Technical Data (IP address, browser type, device information)
- Usage Data (how you use our website)
- Marketing and Communications Data (your preferences in receiving marketing)
- Transaction Data (details about purchases and payments)
- Profile Data (your preferences, feedback, and survey responses)
3. Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: Where you have explicitly agreed to the processing
- Contractual Necessity: To fulfill our contractual obligations
- Legal Obligation: To comply with legal requirements
- Legitimate Interests: Where processing is in our legitimate business interests
4. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure ('right to be forgotten')
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making and profiling
5. Data Security
We implement appropriate technical and organizational measures to ensure security including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Regular backup procedures
- Staff training on data protection
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Legal, accounting, or reporting requirements
- Customer service purposes
- Technical support resolution
7. International Data Transfers
If we transfer data outside the EEA, we ensure adequate protection through:
- EU-approved standard contractual clauses
- Privacy Shield certification (where applicable)
- Adequate country status as determined by the EU Commission
8. Cookie Policy
Our website uses cookies and similar technologies. Our Cookie Policy details:
- Types of cookies we use
- Purpose of each cookie
- How to manage cookie preferences
- Third-party cookies
9. Third-Party Processors
We may use third-party processors for:
- Payment processing
- Analytics services
- Email marketing services
- Customer support services
All third-party processors are GDPR compliant and have appropriate data processing agreements in place.
10. Data Breach Procedures
In the event of a data breach, we will:
- Notify affected individuals within 72 hours
- Inform relevant supervisory authorities
- Provide details of the breach and mitigation measures
- Document all incidents and responses
11. Children's Privacy
We do not knowingly collect or process data from children under 16 without parental consent.
12. Marketing Communications
We will:
- Obtain explicit consent for marketing communications
- Provide opt-out options in all marketing materials
- Honor all unsubscribe requests promptly
- Maintain accurate records of consent
13. Data Protection Impact Assessments
We conduct DPIAs when:
- Implementing new technologies
- Processing sensitive personal data
- Conducting large-scale data processing
14. How to Contact Us
For any GDPR-related queries or to exercise your rights, contact us at: [Your Contact Information] [Physical Address] [Email Address] [Phone Number]
15. Complaints
You have the right to lodge a complaint with your local data protection authority if you are unhappy with how we handle your personal data.
16. Updates to This Statement
We regularly review and update this statement to reflect changes in our practices and legal requirements. The latest version will always be available on our website.
17. Documentation and Accountability
We maintain records of our data processing activities and regularly review our compliance through:
- Internal audits
- Staff training
- Policy reviews
- Processing activity records
By using PhilsKitchen.co.uk, you acknowledge you have read and understood this GDPR Compliance Statement.