Privacy Policy
1. Introduction and company information
This Privacy Policy explains how Greenfields Dairy Limited collects, uses, stores, shares, and protects personal data when you interact with us, including when you visit our website, contact us, place an order, make an enquiry, or otherwise use our services. This policy applies to personal data processed by Greenfields Dairy Limited in connection with its dairy business operations.
Greenfields Dairy Limited is the data controller responsible for your personal data for the purposes described in this Privacy Policy.
Company details:
Greenfields Dairy Limited
Unit 4, Riverside Industrial Estate, Station Road, Stowmarket, Suffolk, IP14 1EX, UK
Email: [email protected]
Phone: +44 1449 782 463
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identity data: name, title, username, and similar identifiers.
- Contact data: address, email address, telephone number, and delivery details.
- Transaction data: order history, invoices, payment status, and purchase records.
- Account and communication data: correspondence with us, enquiries, complaints, and customer support records.
- Technical data: IP address, browser type, device information, cookies, and website usage data.
- Marketing preferences: communication preferences and consent choices.
- Special categories of data: we do not intentionally collect special category data; however, you may choose to provide information that could reveal health or dietary preferences, for example in relation to product suitability or allergens. We will process such data only where lawful and necessary.
We may collect personal data directly from you, automatically through our website and systems, or from third parties such as payment providers, delivery partners, and business counterparties where appropriate.
3. Purpose of data processing
We use personal data for the following purposes:
- to supply our dairy products and fulfil orders;
- to manage customer accounts and communications;
- to process payments, refunds, and invoicing;
- to arrange delivery and logistics;
- to respond to enquiries, complaints, and service requests;
- to operate, maintain, and improve our website and services;
- to comply with legal and regulatory obligations, including accounting, tax, food safety, and record-keeping requirements;
- to detect, prevent, and investigate fraud, misuse, and security incidents;
- to send marketing communications where permitted by law and where you have not opted out;
- to analyse trends and improve our products, services, and customer experience.
4. Legal basis for processing
We process personal data only where we have a lawful basis to do so. Depending on the circumstances, our legal bases may include:
- Performance of a contract: where processing is necessary to provide goods or services you have requested, manage orders, or take steps at your request before entering into a contract.
- Legitimate interests: where processing is necessary for our legitimate business interests, such as operating and improving our business, protecting our systems, handling enquiries, and preventing fraud, provided those interests are not overridden by your rights and freedoms.
- Legal obligation: where processing is necessary to comply with applicable laws and regulations.
- Consent: where we rely on your consent, for example for certain marketing communications or non-essential cookies, you may withdraw consent at any time.
- Vital interests: in limited circumstances where processing is necessary to protect someone’s life or physical safety.
Where we process special category data, we will do so only if a valid legal condition applies under applicable law.
5. Data sharing and third parties
We may share personal data with trusted third parties only where necessary and appropriate for the purposes described in this policy. These third parties may include:
- payment service providers;
- delivery and logistics partners;
- IT, hosting, cloud, and software service providers;
- professional advisers such as accountants, auditors, insurers, and legal advisers;
- customer service and communications providers;
- regulatory authorities, law enforcement, courts, and other public bodies where required by law;
- business partners involved in supplying or supporting our products and services.
We require third parties processing personal data on our behalf to protect it and to use it only in accordance with our instructions and applicable law.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom or to countries that may not provide the same level of data protection, we will take appropriate safeguards to ensure that the data remains protected. These safeguards may include:
- relying on an adequacy decision where available;
- using approved contractual safeguards;
- implementing additional technical and organisational measures where necessary.
Where permitted by law, you may request further information about the safeguards we use for international transfers by contacting us using the details below.
7. Storage duration
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, tax, regulatory, and reporting requirements.
When determining retention periods, we consider:
- the nature and sensitivity of the data;
- the purpose for which it was processed;
- whether we have a legal or regulatory obligation to retain it;
- the period within which claims may be made;
- our legitimate business needs.
When personal data is no longer required, we will securely delete, anonymise, or restrict it in accordance with applicable law and internal retention procedures.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: to request confirmation of whether we process your personal data and obtain a copy of it.
- Rectification: to request correction of inaccurate or incomplete personal data.
- Erasure: to request deletion of your personal data in certain circumstances.
- Restriction: to request limitation of processing in certain circumstances.
- Data portability: to receive certain personal data in a structured, commonly used, machine-readable format and, where technically feasible, have it transferred to another controller.
- Objection: to object to processing based on legitimate interests or for direct marketing purposes.
To exercise your rights, please contact us using the details provided in this Privacy Policy. We may need to verify your identity before responding to your request.
We will respond to requests within the timeframe required by applicable law. Certain rights may be limited where legal exceptions apply.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
If you withdraw consent, we may still be able to process your personal data where another lawful basis applies.
You can withdraw consent by contacting us using the contact details below or by using any opt-out mechanism included in our communications, where applicable.
10. Right to complain
If you have concerns about how we handle your personal data, please contact us first so that we can try to resolve the issue.
You also have the right to lodge a complaint with the relevant supervisory authority or data protection regulator in your jurisdiction. If you are in the UK, you may be entitled to complain to the Information Commissioner’s Office (ICO).
11. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, disclosure, or misuse. These measures may include:
- access controls and authentication measures;
- secure storage and transmission methods;
- staff confidentiality obligations and training;
- regular review of systems and security practices;
- backup and business continuity procedures;
- monitoring for suspicious activity and security incidents.
Although we take reasonable steps to protect personal data, no system can be guaranteed to be completely secure. You are responsible for keeping any account credentials confidential and for notifying us promptly of any suspected unauthorised access.
12. Contact information
If you have any questions about this Privacy Policy or our handling of personal data, or if you wish to exercise your rights, please contact:
Greenfields Dairy Limited
Unit 4, Riverside Industrial Estate, Station Road, Stowmarket, Suffolk, IP14 1EX, UK
Email: [email protected]
Phone: +44 1449 782 463
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. Any updated version will be posted on our website with a revised effective date where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how Greenfields Dairy Limited protects your personal data.