Chopstix Noodle Bar
Customer and Supplier Privacy Notice
We are Chopstix Restaurant Limited (trading as Chopstix Noodle Bar) (we, us, our). This privacy notice explains how we collect, use, store and process your personal data. We respect your privacy and are committed to protecting your personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This privacy notice explains how we collect and process your personal data when you:
- visit our restaurants (including when you use our WiFi service)
- visit our website (Website)
- use our mobile application (Chopstix App)
- order our food through third-party food delivery platforms (such as Deliveroo, Uber Eats, or Just Eat); or
- provide goods or services to us as a supplier or interact with us in connection with our supplier relationship.
This privacy notice should be read alongside any other privacy notices we may provide on specific occasions. It supplements but does not replace other notices. When you order through third-party food delivery platforms (such as Deliveroo, Uber Eats or Just Eat) or conduct business through third-party platforms as part of our supplier relationship, you will also be subject to their privacy policies, which we encourage you to review.
Who we are and how to contact us
Chopstix Restaurant Limited is the data controller and responsible for your personal data.
If you have any questions about this privacy notice or our data protection practices, please contact us using the details below:
Email: info@chopstixgroup.com
Post: 29a Kentish Town Road, London, England, NW1 8NL
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Third-party links
Our Website and Chopstix App may include links to third-party websites, plug-ins and applications. When you click on these links or enable these connections, third parties may collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. Before clicking on any external links or enabling third-party connections, we encourage you to read the privacy policy of the relevant third party. Please note that these third parties may have different data protection standards than we do, and we are not responsible for their practices.
The Website and App may include social media features and widgets, such as the Facebook Like button, the Share button or interactive mini programs that run on the Website and App. These features may collect your IP address and which page you are visiting on our Website and App and may set a cookie or other identifier to enable the feature to function properly. Social media features and widgets are either hosted by a third party or hosted directly on our Website or App. Your interactions with these features are governed by the privacy notice of the company providing it. While we take reasonable steps to only work with reputable third parties, we are not responsible for their data processing practices. We encourage you to review their privacy notices before engaging with these features.
The data we collect about you
Personal data means any information that can identify you as an individual. This does not include anonymous data where your identity has been removed.
We collect different types of personal data about you, which we have grouped into categories below. The specific types we collect depend on whether you are a customer or supplier and the nature of our relationship:
- Identity Data includes first name, last name, username or similar identifier, marital status, title, date of birth, gender, membership details, supplier registration details and business information.
- Contact Data includes address, business address, postcode, email address, telephone numbers, and emergency contact details.
- Communications Data includes any communications and conversations between us including order history, dietary preferences, allergies, special requests, feedback, customer support interactions, contract negotiations, delivery schedules, quality specifications, compliance requirements, and supplier support interactions.
- Financial Data includes bank account and payment card details, payment terms, invoicing information, and tax details.
- Transaction Data includes details about payments to and from you, purchase orders, delivery confirmations, and other details of services you have purchased from us or our partner restaurants, or goods or services you have provided to us.
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the App, our Website, or our supplier portals.
- Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses, benefits and rewards information, supplier performance history, certifications, compliance records, and supplier evaluation feedback.
- Usage Data includes information about how you use our App, Website, supplier portals and services.
- Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
- CCTV Data includes information captured through CCTV recordings at our restaurants and premises for security and safety purposes, including when you visit our premises for supplier-related activities.
- WiFi Service Data includes information collected when you connect to and use our WiFi service at our restaurants, including connection logs, session duration, bandwidth usage, device identifiers, and network activity metadata.
If you provide personal information about anyone other than yourself (e.g. your family members or friends), you are responsible for informing that person that we are collecting their personal information and for ensuring that you have valid permission to provide such personal information to us.
We also collect and use aggregated data (such as statistical or demographic information) for any purpose. Aggregated data may come from your personal data but does not identify you and is not considered personal data under law. For example, we may combine usage data to calculate how popular certain features are. We use technical measures to prevent anyone from being identified from aggregated data. If we combine aggregated data with personal data in a way that could identify you, we will treat it as personal data under this privacy notice.
Special categories of personal data
We may collect information about your dietary preferences, allergies, and accessibility requirements when you choose to provide this to us as a customer. For suppliers, we may collect information about health and safety requirements, accessibility needs, or medical conditions when your employees visit our premises or when such information is relevant to the safe provision of your services. This information constitutes special categories of personal data under the UK GDPR.
For customer data, we process this information based on your explicit consent under Article 9(2)(a) of the UK GDPR and, where applicable, to protect your vital interests under Article 9(2)(c) of the UK GDPR (for example, in cases of severe allergic reactions) and to comply with our legal obligations regarding food safety and public health under Article 9(2)(b) of the UK GDPR, in accordance with the Food Information Regulations 2014 and other applicable food safety legislation.
For supplier data, we process this information primarily to comply with our legal obligations regarding health and safety under Article 9(2)(b) of the UK GDPR, and where applicable, to protect vital interests under Article 9(2)(c) of the UK GDPR (for example, in cases of medical emergencies). In some cases, we may also process this information based on your explicit consent under Article 9(2)(a) of the UK GDPR, in accordance with the Health and Safety at Work etc. Act 1974 and other applicable health and safety legislation.
You can withdraw your consent at any time by contacting us, though this may affect our ability to accommodate your specific requirements or ensure appropriate safety measures. We retain this information only for as long as necessary to fulfil these purposes and comply with our legal obligations. We do not collect any other special categories of personal data about you (such as details about your race, ethnicity, religious beliefs, political opinions, trade union membership, sex life, sexual orientation, or genetic and biometric data).
We do not collect any information about criminal convictions and offences.
Children’s data
Our App and Website are not intended for children under 16 years old, and we do not knowingly collect data from children under this age.
If you are under 16 years old, you must obtain consent from your parent or guardian before providing any personal information to us. If you are a parent or guardian and believe your child under 16 has provided us with personal information without your consent, please contact us immediately so we can delete their information and remove them from our mailing lists.
If we become aware that we have inadvertently received personal information from a child below 16 years of age, we will delete such information from our databases.
If you fail to provide personal data
Sometimes we are required by law to collect certain personal data, or we need it to fulfil our contract with you (for example, to process your food order or manage our supplier relationship). If you do not provide this required data, we may not be able to provide our services or continue our business relationship with you. We will always tell you if this situation applies.
How we collect your personal data
We collect and process your personal data in the following ways:
- Information you provide directly to us when you:
- Visit any of our restaurants;
- Purchase gift vouchers;
- Visit or make transactions on our Website, App, supplier portals, or in our establishments;
- Respond to our promotions or supplier communications or subscribe to our mailing lists or supplier mailing lists;
- Participate in competitions, contests, supplier events, training, or initiatives we organise; and
- Communicate with us by telephone, email, website, or through social media platforms.
- Information we collect automatically, including:
- Payment and transaction information when you make purchases or when we make payments to you or when you make payments to us; and
- Transaction Data, Technical Data, Profile Data, Usage Data, and Marketing and Communications Data when you use our App, Website, and supplier portals. This includes information about your equipment, usage patterns, and marketing preferences. We may also receive technical data when you visit other websites through links in our App or Website. When you use our WiFi service, we collect WiFi Service Data including connection logs, session times, device identifiers, and network usage patterns. We may anonymise your Technical Data, Profile Data, Usage Data, and WiFi Service Data.
- When you order through third-party delivery platforms or when we conduct business through third-party platforms in connection with our supplier relationship, we receive and process limited Transaction Data (such as order details, delivery instructions, delivery confirmations and service records), Contact Data (such as delivery address, business addresses), and Communications Data (such as special requests, dietary requirements, service specifications or compliance requirements) necessary to fulfil your order, manage our supplier relationship and comply with our legal obligations. This data sharing is governed by our agreements with these platforms and their respective privacy policies. We only process this data for order fulfilment, food safety compliance, customer service purposes, supplier relationship management, compliance, and business purposes.
- Information we receive from third parties, including:
- Third parties providing advertising, marketing, and promotional services);
- Social networks; and
- Regulatory authorities, law enforcement agencies, and other public bodies (where legally required).
How and why we use your personal data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Performance of a contract: where we need to perform the contract, we are about to enter into or have entered into with you.
- Legitimate interests: where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. Legitimate interests means our business interests in conducting and managing our operations effectively and lawfully. When we process your personal data based on legitimate interests, we first conduct a balancing test to ensure our interests do not override your fundamental rights and freedoms. We only rely on legitimate interests where we are satisfied this balance is met, unless we have your consent or are otherwise required or permitted by law to process the data.
- Legal obligation: where we need to comply with a legal obligation.
We generally do not rely on consent as our main legal reason for processing your personal data. However, where we do rely on consent (such as for processing dietary requirements, health and safety information, or for direct marketing), you can withdraw it at any time by contacting us at info@chopstixgroup.com. We will process your withdrawal request within one month (though this may be extended by up to two additional months for complex cases – we will inform you of any extension and explain why). Withdrawing consent will not affect any processing we did before you withdrew consent, but it may impact our ability to provide certain services. Where we have other valid legal reasons to process your data, we may continue processing on those grounds.
Purposes for which we will use your personal data
The table below describes how we use your personal data and the legal bases we rely on. We may process your personal data for more than one lawful purpose depending on the specific reason for using your data. Please contact us if you need details about the specific legal ground we are relying on where more than one ground is listed.
| Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
|
To register you as a new customer or supplier and manage your account, including to: · create and manage your user account in the Website, the App, or our supplier portals;
· verify your identity; and
· set up your preferences and account settings, including supplier preferences and account settings. |
a) Identity
b) Contact
c) Financial
d) Profile |
a) Performance of a contract with you
b) Necessary for our legitimate interests (to maintain accurate customer records, prevent fraud, and ensure efficient account management)
c) Necessary to comply with a legal obligation (for identity verification and anti-fraud measures)
|
|
To process and deliver our services and manage our supplier relationship including to: · handle special requests and requirements,
· process orders for collection or delivery (where available),
· record dietary requirements and preferences;
· process purchase orders and delivery schedules, and record quality specifications and compliance requirements;
· manage payments, fees and charges; and
· collect and recover money owed to us and process payments to you and collect any amounts you may owe to us. |
a) Identity
b) Contact
c) Profile
d) Financial
e) Transaction
f) Marketing and Communications
g) Technical
h) Special categories of personal data |
a) Performance of a contract with you
b) Necessary for our legitimate interests (to recover debts due to us, to maintain accurate financial records and ensure business sustainability)
c) Necessary for our legitimate interests (to provide appropriate service and ensure customer satisfaction)
d) Necessary to comply with a legal obligation (for financial records, food safety compliance and tax purposes)
e) For special categories of personal data (dietary requirements and health information): i. Primary basis: Explicit consent under Article 9(2)(a) UK GDPR (for customer dietary requirements and supplier health and safety requirements where consent is provided); and ii. Additional basis: Substantial public interest under Article 9(2)(g) UK GDPR (for food safety) and Legal obligation under Article 9(2)(b) UK GDPR (for health and safety compliance), and to protect vital interests under Article 9(2)(c) UK GDPR |
|
To manage our relationship with you and enhance your dining experience or business partnership, which will include: · replying to requests for information;
· notifying you about changes to our terms or privacy notice; and
· asking you to leave a review, take a survey, or provide feedback or participate in supplier surveys. |
a) Identity
b) Contact
c) Profile
d) Marketing and Communications
e) Usage |
a) Performance of a contract with you
b) Necessary to comply with a legal obligation (to inform you of material changes to our terms)
c) Necessary for our legitimate interests (to keep our records updated and to study how potential customers use our goods or services) |
| To send you notifications on the App or through our supplier portals containing information about our services or business requirements and supplier-related matters (where you have given us permission to do so by enabling this feature on the App or supplier portals) |
a) Identity
b) Contact
c) Profile
d) Marketing and Communications |
a) Necessary for the performance of the contract with you for the operation of your account
b) Necessary for our legitimate interests (to ensure that you receive an appropriate level of service) |
| To administer Chopstix loyalty scheme and supplier performance management, including processing points, rewards, personalised offers based on your preferences and dining history, performance metrics, compliance records, and business development opportunities based on your service history |
a) Identity
b) Contact
c) Profile
d) Usage
e) Transaction
f) Marketing and Communications |
a) Necessary for the performance of the contract with you for the operation of your account
b) Necessary for our legitimate interests (to ensure that customers receive rewards and points that are tailored to them and that suppliers receive appropriate performance feedback and business opportunities that are tailored to them and that are in line with expectations)
c) Special categories of personal data (where you have provided explicit consent under Article 9(2)(a) UK GDPR or where necessary to protect your vital interests relating to food allergies, dietary requirements, and health and safety requirements under Article 9(2)(c) UK GDPR) |
| To deal with and respond to any complaints you raise |
a) Identity
b) Contact
c) Profile
d) Marketing and Communications
e) Technical
f) Special categories of personal data (only where relevant to the complaint and necessary for resolution) |
a) Necessary for our legitimate interests (to maintain service standards, handle customer complaints effectively, and improve customer satisfaction)
b) Where necessary for the establishment, exercise or defence of legal claims
c) For special categories of personal data (dietary requirements, health information, and health and safety requirements – only where relevant to the complaint): We process this information based on your explicit consent under Article 9(2)(a) UK GDPR and, where necessary, to protect your vital interests under Article 9(2)(c) UK GDPR where you cannot give consent. |
| To enable you to partake in a prize draw or competition |
a) Identity
b) Contact
c) Profile
d) Marketing and Communications
e) Usage |
a) Performance of a contract with you
b) Necessary for our legitimate interests (to maintain accurate customer records, analyse service usage patterns to improve customer experience, and develop our business offerings). |
|
To ensure safety and security during customer visits and supplier visits and activities: · monitoring premises through CCTV;
· maintaining incident logs;
· managing access control systems; and
· ensuring food safety and health and safety and business compliance. |
a) Identity
b) Technical
c) Usage
d) CCTV Data
|
a) Necessary for our legitimate interests (to ensure the security and safety of our premises, staff, customers and suppliers)
b) Necessary to comply with legal obligations under food safety and health & safety legislation |
|
To administer and protect our business, the App and our Website, including: · troubleshooting technical issues;
· payment processing and fraud prevention (including customer transactions through third-party delivery platforms and supplier transactions through third-party platforms);
· food safety and allergen tracking;
· compliance and quality tracking;
· customer service quality monitoring;
· system maintenance and security;
· data analysis and reporting; and
· hosting and backup of data. |
a) Identity
b) Contact
c) Profile
d) Transaction
e) Usage
f) Technical |
a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
b) Necessary to comply with a legal obligation |
| To deliver relevant App, Website content and business communications and advertisements to you and measure or understand the effectiveness of the advertising and business communications we serve to you |
a) Identity
b) Contact
c) Profile
d) Usage
e) Marketing and Communications
f) Technical |
a) Necessary for our legitimate interests (to study how customers and suppliers use our services, to develop them and our supplier relationships, to grow our business partnerships and to inform our marketing and operational communication strategy) |
| To enable you to use our WiFi service |
a) Contact
b) Technical
c) Usage
d) WiFi Service Data |
a) Necessary for our legitimate interests (to provide WiFi services to enhance customer experience and to maintain network security) |
| To use data analytics to improve our App, Website, services, marketing, customer relationships, supplier relationships and business partnerships |
a) Identity
b) Technical
c) Usage |
a) Necessary for our legitimate interests (to provide our services, to keep our App and Website updated and relevant, to develop our business and supplier relationships and to inform our marketing and operational communication strategy) |
| To make suggestions and recommendations to you about services that may be of interest to you |
a) Identity
b) Contact
c) Technical
d) Usage
e) Profile
f) Marketing and Communications |
a) Necessary for our legitimate interests (to develop our services and grow our business) |
We give you specific choices about how we use your personal data for marketing and advertising if you are a customer. This applies whether you order directly from us or through third-party delivery platforms. Please note that delivery platforms have their own privacy policies that govern how they use your data.
Promotional offers from us
We may use your Identity, Contact, Technical, Profile and Usage Data to form a view on what products, services and offers may be relevant or of interest to you (we call this marketing). This includes analysing your order history, and interaction with our services (including orders placed through third-party delivery platforms such as Deliveroo) to provide you with personalised recommendations and offers.
You will receive marketing communications from us if you have explicitly consented to such communications or, in relation to similar services you have purchased from us, where we rely on legitimate interests (subject to your right to opt-out at any time). You have the right to opt out of receiving this marketing at any time.
Third-party marketing
We will obtain your explicit opt-in consent before sharing your personal data with any third party for marketing purposes. This includes sharing data received through third-party delivery platforms. When you order through such platforms, please note that they may also collect and process your personal data as separate data controllers. You can withdraw your consent for our use of your data at any time by contacting us or using the opt-out methods described below. For data processing by delivery platforms, please refer to their respective privacy policies.
Opting out of marketing
You can ask us or third parties to stop sending you marketing messages by:
- Following the opt-out links on any marketing message sent to you;
- Adjusting your marketing preferences in your account settings; or
- Contacting us at any time.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product or service purchase, product or service experience or other transactions.
Supplier business communications
Where you are a supplier, you will receive business communications from us where we have a legitimate interest based on our existing business relationship, except where such communications are necessary for the performance of our contract with you or to comply with legal obligations. We do not send marketing communications to our suppliers – all communications will be strictly related to our business relationship and operational requirements.
Opting out of non-essential business communications
You can ask us or third parties to stop sending you non-essential business communications by:
- Following the opt-out links on any non-essential business communication sent to you;
- Adjusting your non-essential business communication preferences in your account settings; or
- Contacting us at any time.
Where you opt out of receiving these non-essential business communications, this will not apply to personal data provided to us as a result of goods or services you provide to us, business transactions or other supplier relationship activities.
Our App and Website use cookies and similar technologies to distinguish you from other users and improve your experience. We use different types of cookies: essential cookies (necessary for our services to work), functional cookies (to remember your preferences), analytics cookies (to understand how you use our services), and marketing cookies (to show you relevant advertisements). You can control and manage non-essential cookies through your browser settings or our cookie preference centre. For detailed information about the specific cookies we use and how to manage your preferences, please see our separate cookies policy available on our Website and App.
Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Disclosures of your personal data
We may share your personal data with these types of organisations:
- Our Group primarily for business and operational purposes.
- Third parties including professional advisors, social media networks, data management companies, digital agencies, payment processors, gift voucher solutions providers, distribution & delivery partners (including third-party food delivery platforms such as Deliveroo, who may act as independent data controllers for customer data collected through their platforms), CRM software providers, automated customer service providers, and IT consultants carrying out testing and development work on our business technology systems.
- External third parties who act as processors providing IT and system administration services to us.
- Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
- HM Revenue & Customs, regulators and other authorities based in the United Kingdom who require reporting of processing activities in certain circumstances.
- Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We implement data processing agreements with our third-party service providers that comply with Article 28 of the UK GDPR, including requirements to process personal data only on our documented instructions, implement appropriate technical and organisational security measures, assist with data subject rights requests, and notify us of any personal data breaches. For orders placed through third-party food delivery platforms and for business conducted through third-party platforms as part of our supplier relationship, please note that these platforms may collect and process your personal data as independent data controllers, subject to their own privacy policies and data protection practices. We receive only necessary order fulfilment data and supplier relationship management data from these platforms.
We do not allow our service providers to use your personal data for their own purposes – they can only use it to provide services to us.
International transfers
Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data.
- Where we use certain service providers, we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.
Automated decision making
We do not use automated systems to make decisions about you that would have legal effects or significantly affect you without human involvement.
Data security
We have implemented appropriate technical and organisational security measures including encryption, access controls, and regular security assessments to protect your personal data from unauthorised access, accidental loss, alteration, or disclosure. Access to your personal data is strictly limited to employees, agents, contractors and other third parties who have a legitimate business need, are bound by contractual confidentiality obligations, and process data only on our documented instructions. We regularly review and update these measures to maintain the security of your data.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Data retention
How long will you use my personal data for?
We only keep your personal data for as long as necessary for the purposes we collected it, including to meet legal, tax, and accounting requirements. We may keep it longer if there is a complaint or potential legal action. Generally, we keep customer data for up to 6 years after your last interaction with us, and supplier data for up to 7 years after our business relationship ends. This helps us comply with legal obligations, unless the law requires us to keep it longer or allows us to delete it sooner.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
Your legal rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to:
- Request access to your personal data (commonly known as a data subject access request). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
- Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us to continue processing it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully, or where we are required to erase your personal data to comply with local law. Note that we may need to retain certain information for legal or administrative purposes (such as fraud prevention) or to complete transactions. However, we may not always be able to comply with your request for erasure for specific legal reasons, which will be explained to you at the time of your request if applicable.
- Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
- If you want us to establish the data’s accuracy.
- Where our use of the data is unlawful, but you do not want us to erase it.
- Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
- You have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
- Request the transfer of your personal data to you or to a third party (data portability). We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format (such as CSV or XML). Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are processing your consent based on your personal data. This will not affect any processing we did before you withdrew consent. If you withdraw consent, we may not be able to provide certain services to you (such as personalised recommendations or loyalty program benefits). We will tell you if this affects any services when you withdraw consent.
If you wish to exercise any of the rights set out above, please contact us using the details set out in this privacy notice.
No fee usually required
You will not usually have to pay a fee to access your personal data or exercise your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. We could also refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We will respond to all legitimate requests within one month of receiving your request. Occasionally it may take us up to two additional months if your request is particularly complex or you have made multiple requests. If we need extra time, we will notify you within one month of receiving your request and explain why the extension is necessary. We will keep you updated on the progress of your request.
Changes to the privacy notice and your duty to inform us of changes
This privacy notice was last updated on 10 October 2025. Historic versions are available upon request. Please keep your personal information up to date by updating your account settings or contacting our customer service team. This helps us comply with data protection laws and provide you with the best service.


