Lavenders Privacy Policy & GDPR Compliance - updated 4th January 2022.
How we use your personal information when you visit this website:
​
About us
Howard Yorkshire Limited trading as Lavenders Tea Rooms is held as the ‘Controller’ of personal data that we collect about you. This notice will explain how we use and share your information.
​
Why do we collect personal information?
We process and hold your information in the course of dealing with your enquiries, bookings and purchases in relation to the nature of our tea room business.
​
How do we collect personal data?
Information may be collected in several different ways but predominantly as set out below:
​
Face to Face
If you visit our tea rooms now for the foreseeable future we will collect your name and telephone contact number or email address for the reasonable purpose of the NHS Track and Trace process due to Covid-19. There will be no admittance to the tea room without giving us this information. This data will be stored securely by us for the statutory time limit required, and will only be used for the purposes of Track and Trace.
Telephone Calls
If you telephone us personal data may be recorded dependent on the nature of the call.
Emails
If you email us we may keep your email address and the email as evidence of contact. We are unable to guarantee the security of any email contact initiated by you and we recommend that you keep the amount of confidential information to a minimum.
Using our website
In order to provide you with a personalised experience while using our Website, we may collect and process information about you, including but not limited to your name, address, contact details such as your email address and phone number, date of birth, payment card details, products you buy and information about the way you have viewed and used our website (personal information).
The most common ways in which we collect information about you are as follows.
-
Ordering Products - if you order products on our Website or correspond with us by phone or e-mail you will give us personal information necessary to process, confirm and complete your order. This will include your delivery address and your payment card details.
-
Social Media – you may give us information when you participate in discussions or other social media functions on our Website or other social media accounts. We do not accept liability for the control of the privacy of your data given to Social Media websites.
-
Registering / Purchasing Online – if you decide to register as a customer on our Website, you will complete a registration form which requests personal information about you.
-
Competitions, Promotions and Surveys – if you enter any competition or promotion we run, you will provide personal information to us.
-
Your Preferences – you may choose to provide us with information about your marketing preferences to enhance and personalise your use of our Website.
-
Email data is securely stored within our email server.
-
ALL online payments are processed through secure HSBC Bank, or PayPal, or First Data Merchant Services, or Payment Sense Card Processing PCI DSS compliant systems. No credit or debit card details are kept on our servers.
​
Credit / Debit Card
Online payments can be refunded through HSBC Bank, PayPal, or First Data Merchant Services, or Payment Sense Card Processing PCI DSS compliant systems. We store a unique reference / order number against your card details which allows us to process refunds. Only the last four digits of your card number are available to our administrative staff. The first twelve digits are hidden so that our staff cannot see your full card details. None of your card or billing details are published on the Website in any way, nor are they visible to other users on your membership account.
Website Analytics
We use Wix and Google Analytics to understand how the Website is being used in order to improve the user experience. User data is all anonymous. You can find out more about Wix and Google's position on privacy as regards its analytics services by visiting www.wix.com or www.google.co.uk.
CCTV
We do not operate any CCTV system at the tea rooms.
​
EMPLOYEES
Our employees are protected by a separate privacy policy in relation to their employment with us. A copy can be provided on request to Howard Duckwith (Data Protection Officer).
​
Your rights
You have several rights which relate to your personal data.
You are entitled to request access to any personal data that we may hold about you and you can also request a copy.
Where we are relying on your consent to process personal data you have the right to withdraw your consent at any time.
You can also request that we correct any personal data that we may hold about you that you believe is inaccurate. You may also request the deletion of any personal data that we may hold about you.
We are obliged to consider and respond to any request within one calendar month.
Further information
If you wish to make a request or complaint regarding how your personal data has been handled please contact:
Howard Duckwith, (The Data Protection Officer), Howard Yorkshire Limited, North Yorkshire, YO13 9HU.
If you are not satisfied with our response or believe we are not processing your personal data in accordance with the law you can complain to the Information Commissioner’s Office (ICO) www.ico.org.uk