Kesseler UK Limited (“we”, “us”, “our”) are committed to protecting and respecting your privacy.
For the purpose of the Data Protection Act 1998 (the “Act”), and the General Data Protection Regulation (“GDPR”) the data controller is Kesseler UK Limited, company number 07036375 whose registered address is 81 Burton Road, Derby, Derbyshire, DE1 1TJ.
You are not required to provide the personal information that we request, but, if you choose not to do so, in many cases we will not be able to provide you with our products or services or respond to any queries you may have.
1. Information we may collect from you
1.1. Information collected directly from you
1.1.1 We may collect the following information directly from you:
(a) Your name, e-mail address and phone number.
(b) Information that you provide by filling in forms on prept-kitchens.co.uk; (“Site”) or by corresponding with us by e-mail or otherwise, for instance, through surveys.
1.1.2 We may also collect information when you:
(a) search for goods;
(b) place an order; or
(c) when you report a problem with the Site.
1.2. Information collected automatically
We gather some information automatically and store it in log files. This information includes Internet Protocol (IP) addresses, browser type and language, Internet service provider (ISP), referring and exit websites and applications, operating system, date/time stamp, and clickstream data.
We use this information to understand and analyse trends, to administer the Site, to learn about user behaviour on the Site, to improve our product and services, and to gather demographic information about our user base as a whole.
1.3. Information collected via Third Parties
We may collect the following information via trusted third parties who provide services to you through different websites we operate or other services we provide including business partners, sub-contractors (including those providing payment and delivery services) advertising networks, analytics providers, search information providers, credit reference agencies, and website, hosting and maintenance providers.
For detailed information on the cookies we use and the purposes for which we use them see our Cookies Policy.
3. Uses made of the information
3.1.1 We use information held about you in the following ways:
(a) to provide goods and services to you;
(b) to process orders;
(c) to train our employees in respect of providing services to users;
(d) to ensure that content from our Site is presented in the most effective manner for you and for your computer and as part of our efforts to keep our Site safe and secure;
(e) to administer our Site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
(f) with your agreement, to send you our promotional materials or provide you with information regarding special offers and new ranges that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes;
(g) to allow you to participate in interactive features of our service when you choose to do so;
(h) to notify you about changes to our service;
(i) where we have a legal duty to use or disclose your information (for example, in relation to an investigation by a public authority or in a legal dispute); and
(j) to assess your credit scores via third party credit reference agencies, where this is a condition of us entering into a contract with you.
4. Legal basis for us processing your personal data
In general, we only rely on consent as a legal basis for processing in relation to sending direct marketing communications to you via email or post.
You have the right to withdraw consent at any time and where consent is the only legal basis for processing, we will cease to process data after your consent is withdrawn.
4.1.1. We collect and use your personal data because it is necessary for:
(a) the purposes of complying with our duties and exercising our rights under a contract for the sale of goods to you;
(b) complying with our legal obligations; or
(c) the pursuit of our legitimate interests including but not limited to:
(i) selling and supplying goods and services to you;
(ii) protecting customers, employees and other individuals and maintaining their safety, health and welfare;
(iii) promoting, marketing and advertising our products and services;
(iv) understanding our customers’ behaviour, activities, preferences, and needs;
(v) improving existing products and services and developing new products and services;
(vi) complying with our legal and regulatory obligations;
(vii) preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies;
(viii) handling customer contacts, queries, complaints or disputes;
(ix) managing insurance claims by customers;
(x) protecting Kesseler UK Ltd, its employees and customers, by taking appropriate legal action against third parties who have committed criminal acts or are in breach of legal obligations to Kesseler UK Ltd;
(xi) effectively handling any legal claims or regulatory enforcement actions taken against Kesseler UK Ltd;
(xii) fulfilling our duties to our customers, colleagues, shareholders and other stakeholders; and
(xiii) training our employees in respect of providing services to users.
5. Disclosure of your information to third parties
5.1. Service Providers
5.1.1 In order to make certain services available to you, we may need to share your personal data with members of our group and some of our service partners including:
(a) couriers used by us from time to time for the purposes of delivering goods ordered by you;
(b) advertisers and advertising networks that require the data to select and serve relevant adverts to you and others; and
(c) analytics and search engine providers that assist us in the improvement and optimisation of our Site.
5.2. Other Third Parties
5.2.1 Aside from our service providers, we will not disclose your personal data to any third party, except as set out below and we will never sell or rent your data to other organisations for marketing purposes.
5.2.2 We may, however, share your data with:
(a) credit reference agencies, where necessary for card payments;
(b) prospective sellers or buyers, in the event that we sell or buy any business or assets, in which case we may need to disclose your personal data to a prospective buyer or seller; and
(c) prospective third parties which acquire our assets, in the event that we are acquired by a third party, in which case personal data we hold will be transferred to the third party acquiring our other assets.
(d) Governmental bodies, regulators, law enforcement agencies, courts/tribunals and insurers:
(i) where we are under a duty to disclose or share your personal data in order to comply with any legal obligation;
(ii) in order to enforce or apply our terms of website use or terms and conditions of sale and other agreements;
(iii) to protect the rights, property, or safety of Kesseler UK Ltd, our customers, or others (this includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction; or
(iv) where we are required to do so to comply with our legal obligations, to exercise our legal rights (for example in court cases), for the prevention, detection, investigation of crime or prosecution of offenders; and for the protection of our employees and customers.
6. Where we store your personal data
6.1. The personal data that we collect from you will not be transferred or stored at a destination outside the European Economic Area (“EEA”).
7. How we protect your data
7.1. We are committed to keeping your personal data safe and secure.
7.1.1 Our security measures include:
(a) [encryption of data];
(b) [regular cyber security assessments of all service providers who may handle your personal data];
(c) [regular scenario planning and crisis management exercises to ensure we are ready to respond to cybersecurity attacks and data security incidents];
(d) [[daily/monthly/yearly] penetration testing of systems]];
(e) [security controls which protect the entire Kesseler UK Ltd infrastructure from external attack and unauthorised access]; and
(f) [internal policies setting out our data security approach and training for employees.]
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our Site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the Internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our Site; any transmission is at your own risk.
8. Duration of storage
8.1. We will not retain your data for longer than necessary for the purposes set out in this policy unless a longer retention period is required or permitted by law.
9. Links to other Websites
9.1. Our Site may contain links to third-party websites, and some of our services provide you with access to third-party services (such as social networks).
9.2. We have no control over how third-party websites and services process your personal information. We do not review third-party websites and services, and we are not responsible for such third party websites and services or their privacy practices. Please read the privacy statements of any third party websites or services that you access from our websites or services.
10. Your rights
10.1. The rights that you have in your personal data are due to be expanded significantly after a new law, the General Data Protection Regulation (GDPR) comes into force on 25 May 2018.
10.1.1 We are committed to handling your personal data in the right way and we welcome the new rights introduced; your enhanced rights as from 25 May 2018 are set out below:
(a) You may opt out of any marketing communications that we send you, even after initially consenting.
(b) Your information will be treated securely and strictly in accordance with the Data Protection Act 1998.
(c) You have the right to access information held about you. Any access request may be subject to a fee specified by law (currently of £10.00). After 25 May 2018, we will not charge a standard administrative fee of £10.00 but please note we may still be able to recover costs from you where your request is vexatious or very repetitive in nature.
(d) You have the right to ask us (at no cost) to update and correct any personal information which is out of date or incorrect.
(e) You have the right to ask us to erase your personal data or restrict our processing of the data if you wish.
(f) Where you have consented to our processing your data in a certain manner, you have the right to withdraw that consent at any time.
(g) You have the right to make a complaint directly with the Information Commissioner’s Office. In order to report a concern, you should follow the directions given on www.ico.org.uk which contains details about available methods of complaint.
(h) You have the right to receive from us a copy of the personal data in a commonly used, machine-readable format and the right to store it for further personal use on a private device.
(i) You have the right to transmit the personal data to another entity where this is technically possible.
You can help ensure that your contact information and communication preferences are accurate, complete, and up to date by contacting us at firstname.lastname@example.org
Kesseler UK Limited
81 Burton Road