Privacy Policy & Data Governance
Effective Date: May 12, 2024
THE GOOD PREP LIMITED ("we," "our," or "us") is committed to protecting the privacy and security of your personal data. This policy outlines our stringent data processing activities in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Identification
THE GOOD PREP LIMITED, located at Crown House High Street, Tyldesley, Manchester, M29 8AL, serves as the data controller for all personal information collected through our meal delivery services and digital platforms. Our Data Protection Officer can be reached at info@paddyandbeef.sbs.
2. Categories of Data Collected
We process several categories of personal data, including but not limited to:
• Identity Data: Full names, birth dates (for age verification).
• Contact Data: Delivery addresses, billing addresses, email, and UK phone numbers.
• Health Data: Special categories of data including dietary requirements, allergies, and fitness goals (processed under explicit consent).
• Financial Data: Payment card details (processed via PCI-DSS compliant third-party gateways; we do not store full card numbers locally).
• Technical Data: IP addresses, browser types, and usage patterns.
3. Legal Basis for Processing
We rely on several legal grounds:
A. Contractual Necessity: Processing required to deliver your meals.
B. Legal Obligation: Processing required for tax and accounting.
C. Legitimate Interests: Improving our service efficiency and fraud prevention.
D. Explicit Consent: For marketing and the processing of health-sensitive dietary data.
4. Data Retention and Deletion
We do not retain data longer than necessary. Transactional records are kept for six years following the end of the financial year in which the transaction occurred, in compliance with UK HMRC requirements. Health-related data is purged within 90 days of an inactive subscription unless otherwise requested by the user. Users have the right to request the "Right to be Forgotten" under Article 17 of the GDPR.
5. International Data Transfers
Primarily, all data is stored within the UK or European Economic Area (EEA). If we utilize cloud-based tools that store data in the United States, we ensure that standard contractual clauses (SCCs) and robust encryption are in place to provide an equivalent level of protection as required by the UK Information Commissioner's Office (ICO).
6. Your Statutory Rights
Under UK law, you possess the right to access your data (Subject Access Request), the right to rectification of errors, the right to object to automated decision-making, and the right to data portability. To exercise these rights, please contact our legal team with proof of identity.
[Content truncated for display - Total policy exceeds 1200 words in full production deployment]