Updated – 17/10/18
Pant Mawr Farmhouse Cheeses is committed to ensuring that your privacy is protected.
Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement.
Pant Mwar Farmhouse Cheeses may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes.
What data we collect
We may collect the following information:
- Contact information including email address
- Demographic information such as postcode, preferences and interests
- Other information relevant to customer surveys and/or offers
What legal basis we process data on
The incoming GDPR (General Data Protection Regulation) sets out multiple lawful basis under which companies may process your information. Pant Mawr Farmhouse Cheeses relies on the following:
In some circumstances we will request your consent in contacting you for marketing and special offer communications. This consent will always be requested in a clear manner and detailed what communications that you are consenting to receive.
The most common basis we use for process personal data is under contractual obligation. The data that we require to process your order (Such as Name, Address, E-mail address etc.) will all be processed under this basis and processed by the relevant third party to fulfil your order.
If Pant Mawr Farmhouse Cheeses is required by law to provide personal data to comply with a statutory obligation or common law, then Pant Mawr Farmhouse Cheeses is bound to providing that information only to the relevant authority.
What we do with the data we gather
We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
- To process orders via our website, phone or postal orders.
- To respond to order queries, requests, complaints and to provide high quality customer service.
- Internal record keeping.
- We may use the information to improve our products and services.
- We may periodically send promotional emails about new products, special offers or other information which we think you may find interesting using your email address, where consent has been provided.
- From time to time, we may also use your information to contact you for market research purposes.
- We may contact you by email, phone, fax or mail with notifications of our current live orders.
- We may contact our previous purchasing customers via post with Pant Mawr Farmhouse Cheeses annual brochure periodically, under the basis of legitimate interests and to keep you up-to-date with our latest products.
We will never share your information to any third parties for any purposes other than to process your order and provide you with the best retail experience possible.
Pant Mawr Farmhouse Cheeses data integrity and compliance with data protection laws is of the highest priority.
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
Our systems are regularly monitored and tested for vulnerabilities via methods such as penetration testing. Access to personal data is securely password protected and encrypted with SSL/TLS encryption.
Pant Mawr Farmhouse Cheeses is an accredited PCI DSS compliant retailer, ensuring your payment information is securely handled through all mediums of transaction.
Who do we share your personal data with?
We may share elements of your personal data with trusted third parties as part of our business operations.
Each third party will ONLY be provided with the information necessary to perform their required services. They also may only use your data for the exact purposes required and are not permitted to share your data further.
Once the required data is no longer necessary to provide the relevant service, it is then deleted or rendered anonymous. Any third party that we terminate relations with have a responsibility to delete the data that we have provided.
We have categorised these third parties as follows:
- Delivery and Distribution Services
These are the various operational companies such as delivery couriers and parcel services. They will require details such as your name, address and contact number to provide our delivery service across the globe.
- Payment Acquirers
We work with several payment acquirers to provide the most flexible checkout service possible for our customer. They will require personal and payment data in order to process your transaction. The transmission and processing of this data is highly scrutinised and complies fully with PCI DSS regulations.
- IT Infrastructure Services
These are companies that we work with to provide our web hosting, platforms and site features to provide our order process. We work closely with all of these third parties to ensure that all acquired data is stored securely and managed responsibly.
- Marketing Processors
We engage with several third parties to provide our electronic and physical marketing communications. They assist in tailoring the best marketing solution for both us and our customers to keep you in the know of our current products. Data shared with these third parties is only done so under the basis of clear, concise consent which is gathered during the checkout process. We actively monitor the consent for this information to be shared and may be withdrawn via various means (Such as unsubscribing from a marketing e-mail or contacting us via e-mail at email@example.com).
Links to other websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over external websites.
Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement.
You should exercise caution and look at the privacy statement applicable to the website in question.
Controlling your personal information
You may choose to restrict the collection or use of your personal information in the following ways:
- Whenever you are asked to fill in a form on the website, look for the box that you can click to indicate that you do not want the information to be used by anybody for direct marketing purposes
- If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by writing to or emailing us at firstname.lastname@example.org
We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so. We may use your personal information to send you promotional information about third parties which we think you may find interesting where the necessary consent is granted.
Data Subject Rights
Data protection laws grants all data subjects the following individual rights over your data:
Right of access – You have the right to access and request a copy of all the data that we hold for you.
Right of rectification – If you feel that any data that we hold about you is inaccurate or incomplete, you have the right to request for us to amend this data. We must action a request for rectification within one calendar month. Please note that in some circumstances we may refuse a request if we are under a legal obligation to.
Right of erasure – This may also be referred to as "the right to be forgotten"