GDPR Privacy Statement

INTRODUCTION

Lazy Day Foods Ltd (LDF) is strongly committed to protecting personal data. This privacy statement describes why and how we collect and use personal data. It also provides information about individuals' rights. It applies to personal data provided to us, both by individuals themselves and others. We may use personal data provided to us for any of the purposes described in this privacy statement or otherwise stated at the point of collection.

Personal data is any information relating to an identified or identifiable living person. LDF processes personal data for numerous purposes. The means of collection, lawful basis of processing, use, disclosure, and retention periods for each purpose may differ.

When collecting and using personal data, our policy is to be transparent about why and how we process personal data.

1.     BUSINESS CONTACTS

LDF processes personal data about contacts (existing and potential customers and individuals associated with them) using a Customer Relationship Management System (CRM).

An LDF user initiates the collection of personal data about contacts and the addition of that personal data to the CRM. It will include name, employer name, contact, title, phone, email and other business contact details. In addition, the CRM may collect data from email (sender name, recipient name, date and time) and calendar (organiser name, participant name, date and time of event) systems concerning interactions between LDF users and contacts or third parties.

Use of personal data

Personal data relating to business contacts may be visible to and used by LDF users to learn more about a customer or opportunity they have an interest in and may be used for the following purposes:

  • Administering, managing and developing our business

  • Providing information about us and our products

  • Making contact information available to LDF users

  • Identifying customers or contacts with similar needs

  • Describing the nature of a contact's relationship with LDF

  • Performing analytics, including producing metrics for LDF leadership such as sales intelligence and progress against business goals.

Data retention

Personal data will be retained on the LDF CRM for as long as is necessary for the purposes set out above.

2.     CUSTOMERS

Our policy is to collect only the personal data necessary for agreed purposes. We ask our customers to only share personal data where it is strictly needed for those purposes.

Where we need to process personal data to provide our products, we ask our customers to provide the necessary information to the data subjects regarding its use. Our customers may use relevant sections of this privacy statement or refer data subjects to this privacy statements if they consider it appropriate to do so.

Generally, we collect personal data from customers or third parties acting on the instructions of the relevant customer.

Use of personal data

We use personal data for the following purposes:

  • Providing our products - we provide a wide range of free-from bakery products. 

  • Administering, managing and developing our business

We process personal data in order to run our business, including:

  • Managing our relationship with customers

  • Developing our business through identifying customer needs

  • Maintaining and using IT systems

  • Hosting events

  • Administering and managing our website and systems applications.

Security, quality and risk management activities

We have security measures to protect our customers' information (including personal data), which involves detecting, investigating, and resolving security threats. Personal data may be processed as part of the security monitoring that we undertake, for example, automated scans to identify harmful emails.

We monitor the products we provide to customers for quality purposes, which may involve processing personal data stored in the relevant customer file.

We collect and hold personal data as part of our customer engagement and acceptance procedures. As part of those procedures, we carry out searches using publicly available sources to check that there are no issues that would prevent us from working with a particular customer.

Providing our customers with information about us and our range of products

Unless we are asked not to, we use customer contact details to provide information that we think will be of interest about us and our products.

Seeking feedback from our customers about our range of products

Unless we are asked not to, we use customer contact details to invite feedback about our range of products. We also provide customer contact details to a third-party online review platform.

Complying with any requirement of law, regulation or a professional body of which we are a member

As with any business, we are subject to legal, regulatory and professional obligations. We need to keep certain records to demonstrate that our products comply with those obligations. Those records may contain personal data.

Data retention

We retain the personal data processed by us for as long as is considered necessary for the purpose for which it was collected (including as required by applicable law or regulation).

3.     SUPPLIERS (INCLUDING SUBCONTRACTORS AND INDIVIDUALS ASSOCIATED WITH OUR SUPPLIERS AND SUB-CONTRACTORS)

We collect and process personal data about our suppliers in order to manage the relationship; the contract to receive goods and services from our suppliers and, where relevant, to provide products to our customers.

Use of personal data

We use personal data for the following purposes:

  • Receiving goods and services

o   We process personal data concerning our suppliers and their employees as necessary to receive goods and services. 

  • Providing our products to customers

o   Where a supplier is helping us to deliver our products to our customers, we process personal data about the individuals involved to administer and manage our relationship with the supplier and the relevant individuals and provide our products to our customers.

  • Administering, managing and developing our business

o   We process personal data in order to run our business

o   Managing our relationship with our suppliers

o   Developing our business, such as identifying customer needs

o   Maintaining and using IT systems

o   Administering and managing our website and systems applications.

Security, quality and risk management activities

We have security measures to protect our supplier information (including personal data), which involves detecting, investigating, and resolving security threats. Personal data may be processed as part of the security monitoring that we undertake, for example, automated scans to identify harmful emails.

We have policies and procedures in place to monitor the quality and manage risk concerning our suppliers.  

We collect and hold personal data as part of our supplier contracting procedures.

Providing our customers with information about us and our range of products

Unless we are asked not to, we use supplier contact details to provide information that we think will be of interest about us and our products.

Complying with any requirement of law, regulation or a professional body of which we are a member

As with any business, we are subject to legal, regulatory and professional obligations. We need to keep certain records to demonstrate that our products comply with those obligations. Those records may contain personal data.

Data retention

We retain the personal data processed by us for as long as is considered necessary for the purpose for which it was collected (including as required by applicable law or regulation).

4.     VISITORS TO OUR BAKERY

We have security measures in place at our Bakery, including CCTV and building access controls.

There are signs around our premises showing that CCTV is in operation. The images captured are securely stored and only accessed on a need to know basis (e.g. to look into an incident). CCTV recordings are typically automatically overwritten after a short period of time unless an issue is identified that requires investigation.

We require visitors to our Bakery to sign in at reception and keep a record of visitors for a short time. Our visitor records are securely stored and only accessible on a need to know basis (e.g. to look into an incident).

 

5.     VISITORS TO OUR WEBSITE

Visitors to our website are generally in control of the personal data shared with us. We may capture limited personal data automatically via the use of cookies on our website. 

We receive personal data such as name, title, company address, email address and telephone numbers from website visitors.

Visitors are also able to send an email to us through our website. Their messages will contain the user's screen name and email address and any additional information the user may wish to include in the message.

We ask that you do not provide sensitive information (such as race or ethnic origin, political opinions, religious or philosophical beliefs; trade union membership; physical or mental health; genetic data; biometric data; sexual life or sexual orientation; and criminal records) to us when using our website; if you choose to provide sensitive information to us for any reason, the act of doing so constitutes your explicit consent for us to collect and use that information in the ways described in this privacy statement or as described at the point where you chose to disclose this information.

Use of personal data

When a visitor provides personal data, we will use it for the purposes for which it was provided to us, as stated at the point of collection.

Typically, personal data is collected to:

  • Access certain areas of the site

  • Subscribe to updates

  • Enquire for further information

  • Order products

  • Monitor and enforce compliance with our terms and conditions for the use of our website

  • Administer and manage our website, including confirming and authenticating identity and preventing unauthorised access to restricted areas

  • Aggregate data for website analytics and improvements.

Our website does not collect or compile personal data to disseminate or sell to outside parties for consumer marketing purposes or host mailings on behalf of third parties. If there is an instance where such information may be shared with a party that is not Lazy Day Foods, the visitor will be asked for their consent beforehand.

Data retention

We retain the personal data processed by us for as long as is considered necessary for the purpose for which it was collected (including as required by applicable law or regulation).

 

6.     OTHERS WHO GET IN TOUCH WITH US

We collect personal data when an individual gets in touch with us with a question, complaint, comment, or feedback (such as name, contact details, and communication contents). In these cases, the individual is in control of the personal data shared with us. We will only use the data to respond to the communication.