TYRRELLS GROUP LTD
PRIVACY NOTICE FOR CUSTOMERS AND PROSPECTIVE CUSTOMERS

This notice applies to you if you are an individual customer (including a sole trader or partnership) of ours or an employee of our corporate customer or group company of our corporate customer, who (i) has contracted with us to purchase our services/products; or (i) we have contacted you about the services/products we offer as a business.

This notice does not form part of any contract for services or products.

References to we, our or us in this privacy notice are to the Tyrrells Group (being Tyrrells Group Limited, and each of its direct and indirect subsidiaries).  Details of our main trading entities are as follows:

Tyrrells Potato Crisps Limited is a limited company incorporated in England and Wales. Registered Number: 04339626. Registered Office: Tyrrells Court, Stretford Bridge, Leominster, Herefordshire HR6 9DQ.

Glennans Limited is a limited company incorporated in England and Wales. Registered Number: 2220633.  Registered Office:  Tyrrells Court, Stretford Bridge, Leominster, Herefordshire HR6 9DQ.

Aroma Snacks GmbH & Co KG is a limited company incorporated in Germany.  Registered Number: HRB 722711.  Registered Office: Geiselharz 23, 88279, Amtzell, Germany.

This privacy notice also covers any joint venture companies, bodies or organisation that we have an interest in and to which you are seconded, carrying out activities on behalf of or are appointed as one of its officers or representatives.

We have not appointed a Data Protection Officer to oversee our compliance with data protection laws as we are not required to do so, but our Data Protection Compliance Manager has overall responsibility for data protection compliance in our organisation.  Contact details are set out in the “Contacting us” section at the end of this privacy notice.

We are committed to respecting your privacy. This notice is to explain how we may use the personal information we collect and use about you during and after your working relationship with us. This notice also explains how we comply with the law on data protection and what your rights are.

For the purposes of this notice the controller is the Tyrrells Group entity that is undertaking the relevant customer relationship with you or the organisation you work for.

PERSONAL INFORMATION WE COLLECT

When you interact with us or we interact with you in relation to our products and services, you may provide us with or we may obtain personal information about you, such as the following:

  • Contact details: information that allows us to contact you directly such as your name, email address, telephone number, addresses, emergency contact details, family members and details of availability.
  • Purchase details and requirements: details of the products or services you have asked us to provide to you, details relating to any property you are asking us to repair or replace and any associated repair or replacement options selected or other instructions and decisions made by you in relation to our products or services;
  • Financial information: bank accounts, credit/debit card details, payment and receipt details, refund or credit details and details of payment transactions with you;
  • Records of your interactions with us: such as any enquiries or complaints you make, telephone conversations, letters and other correspondence (including e-mail) and your usage of our website.
  • Online account information: use of and movements through our online portal, passwords, personal identification numbers, IP addresses, user names and other IT system identifying information.
  • Responses to surveys, competitions and promotions: we keep records of any surveys you respond to or your entry into any competition or promotion we run and any prizes which may be won.
  • Your marketing preferences: so that we know whether and how we should contact you.
  • Videos, photographs and audio recordings: which you or other people take and provide to us or we take ourselves including at events or by mystery shoppers.

SPECIAL CATEGORIES OF PERSONAL INFORMATION

We will not generally collect, store and use “special categories” of more sensitive personal information regarding you except information about your health, including any medical condition, health and sickness records, medical records and health professional information and disability information.

If we do collect any special category personal information, we do not currently rely on consent as a basis for processing special category personal information.

WHERE WE COLLECT YOUR INFORMATION

We will collect personal information from a number of sources. These include the following:

  • Directly from you: from yourself, when you use our website, make a claim, make a complaint, contact us by phone, email or communicate with us directly in some other way.
  • Companies in the same group of companies as us: for the purpose of providing services or products to you.
  • Third parties authorised by you: a family member or someone else authorised by you.
  • Advisors: either advisors appointed by you, for example legal advisors, or advisors appointed by us.
  • Our website: provides us with information about how you use it and the devices that you use to connect to our website.
  • Providers of information: which may include credit reference agencies, private investigators, Companies House, LinkedIn, Facebook and other web platforms, social media and printed and on-line publications.
  • Sub-contractors: such as our couriers, import/export agents, shippers, service sub-contractors, payment processors and any other sub-contractors;

We will also collect additional personal information throughout the period of the services and/or products we provide.

If you are providing information regarding other individuals to us, it is your responsibility to ensure that you have the right to provide the information to us.

If you are providing us with details about other individuals they have a right to know and to be aware of what personal information we hold about them, how we collect it and how we use and may share that information.  Please share this privacy notice with those of them whom you feel are sufficiently mature to understand it. They also have the same rights as set out in the “Your rights in relation to personal information” section below.

WHAT WE USE YOUR PERSONAL INFORMATION FOR

The table below describes the main purposes for which we process your personal information, the categories of your information involved and our lawful basis for being able to do this.

Purpose Personal information used Lawful basis
To enable us to provide our services or products to you or the organisation you work for All the personal information we collect excluding special category information

This is necessary to fulfil our contract with you

We have a legitimate interest to fulfil our contracts with third parties

Make payments to and receive  payments from you or the organisation you work for Transaction and payment information

This is necessary to fulfil our contract with you

We have a legitimate interest to fulfil our contracts with third parties

Marketing our services or products which may be of potential interest to you or the organisation you work for Name, personal contact details and other identifiers, and marketing preferences and other information relevant to marketing or your preferences

We have a legitimate interest in marketing our services or products to you or the organisation you work for in order to make new sales

You may have requested that we send to you details of certain products and/or services

We also may have obtained your explicit consent

To manage our relationship with you and any organisation you work for and operate and manage our business and internal reporting All the personal information we collect about you

We have a legitimate interest to ensure that we operate efficiently and manage our business properly

To be able to manage and perform our contract with you

We have a legitimate interest to fulfil our contracts with third parties

To establish, defend or bring legal claims or comply with our legal obligations

To deal with enquiries, complaints and other communications from you or the organisation you work for and dealing with legal disputes involving you or the organisation you work for All the personal information we collect about you

We have a legitimate interest to ensure that we operate efficiently and deal with any enquiries, complaints or other communications

To establish, defend or bring legal claims or comply with our legal obligations

We have a legitimate interest to ensure that all legal claims are managed effectively

For the purposes of staff training All the personal information we collect  excluding special category information We have a legitimate interest to improve the services or products we provide
To perform credit checks Contact details and payment information We have a legitimate interest in ensuring we are likely to be paid for our products or services
To provide you with and update our customer portal and/or website access and for the purposes of ensuring the security of our systems and our information including preventing unauthorised access to our computer and electronic communications systems and preventing malicious software distribution Online account information and your usage of our website and any IT services or functions we make available to you.

We have a legitimate business in ensuring our systems are secure

To be able to manage and perform our contract with you

We have a legitimate interest to fulfil our contracts with third parties

To conduct data analytics studies and customer satisfaction surveys, competitions and promtions to review, and better understand our customer, retention, attrition and satisfaction levels and our brands Our client records and any information you provide in response to our client  satisfaction surveys, competitions and promotions We have a legitimate interest in order to improve as a business and to promote our brands
For the purpose of complying with any legal and regulatory requirements All the personal information we collect about you We have a legal obligation to comply with any legal requirements and we have a legitimate interest in complying with any regulatory requirements
Storage of records relating to you and also records relating to our business All the personal information we collect about you

To be able to manage and fulfil our contract with you, we may have a legal and/or regulatory obligation to do so and we also have a legitimate interest to keep proper records

To establish, bring or defend legal claims

For some of your personal information you will have a legal, contractual or other requirement or obligation for you to provide us with your personal information.  If you do not provide us with the requested personal information we may not be able to properly perform our contract with you or comply with legal obligations.  For other personal information, whilst you may not be under an obligation to provide it to us, if you do not provide it then we may not be able to properly perform our services for you as an asset manager.

You should be aware that it is not a condition of any contract with us that you agree to any request for consent from us and we do not usually rely on consent as a basis for processing your personal information.  However if we have asked you for consent, and you have given us your consent to use your personal information, you have the right to withdraw this consent at any time, which you may do by contacting us as described in the “Contacting us” section below.

Please note however that the withdrawal of your consent will not affect any use of the data made before you withdrew your consent and we may still be entitled to hold and process the relevant personal information to the extent that we are entitled to do so on bases other than your consent.  Withdrawing consent may also have the same effects as not providing the information in the first place, for example we may no longer be able to provide carry out certain activities.

WHO WE SHARE YOUR PERSONAL INFORMATION WITH

We share personal information with the following parties:

  • Any party approved by you: for example family members.
  • Credit reference agencies and background check providers.
  • Companies in the same group of companies as us: for the purpose of providing services or products to you.
  • Other service providers to our business and advisors: third party banks, administration and IT services, social media and other service providers. All our third-party service providers are required to take appropriate security measures to protect your personal information.
  • Advisors: either advisors appointed by you, for example legal advisors, or advisors appointed by us.
  • Purchasers of our business: buyers or perspective buyers to whom we may sell or negotiate to sell our business.
  • Sub-contractors: such as our couriers, import/export agents, shippers, service sub-contractors, payment processors and other sub-contractors.
  • The Government, government bodies or our regulators: where we are required to do so by law or to assist with their investigations or initiatives, for example HMRC or the Information Commissioner’s Office.
  • Police, law enforcement and security services: to assist with the investigation and prevention of crime and the protection of national security.

We do not disclose personal information to anyone else except as set out above unless we have your consent or we are legally obliged to do so.  We do not sell, rent or trade your data.

DIRECT MARKETING

Email, post, telephone and SMS marketing: from time to time, we may contact you by email, post, telephone or SMS with information about products or services we believe you may be interested in.

We will only send marketing messages to you in accordance with the marketing preferences you set when you create your account or that you tell us afterwards you are happy to receive or where you or the organisation you represent have purchased similar services or goods from us previously or you ask us to send you the information.

You can then let us know at any time that you do not wish to receive marketing messages by sending an email to us at: datacompliance@tyrrellscrisps.co.uk or by using the by using the details set out in the “Contacting us” section below.  You can also unsubscribe from our marketing by clicking on the unsubscribe link in any written marketing messages we send to you or letting us know during any marketing telephone call.

TRANSFERRING YOUR PERSONAL INFORMATION INTERNATIONALLY

The personal information we collect about you is not transferred to or stored in countries outside of the UK or European Union except as set out in this section.

Our staff and other individuals working for us may in limited circumstances access personal information outside of the UK and European Union if they are on holiday or working abroad outside of the UK or European Union.  If they do so they will be using our security measures and will be subject to their arrangements with us which are subject to English Law and the same legal protections that would apply to accessing personal data within the UK.

In limited circumstances the people to whom we may disclose personal information as mentioned in the section “Who we share your personal information with” above may be located outside of the UK and European Union.  In these cases we will impose any legally required protections to the personal information as required by law before it is disclosed.

If you require more details on the arrangements for any of the above then please contact us using the details in the “Contacting us” section below.

HOW LONG DO WE KEEP PERSONAL INFORMATION FOR?

The duration for which we retain your personal information will differ depending on the type of information and the reason why we collected it from you. However, in some cases personal information may be retained on a long term basis: for example, personal information that we need to retain for legal purposes will normally be retained in accordance with usual commercial practice and regulatory requirements.  Generally, where there is no legal requirement, we retain all physical and electronic records for a period of approximately 6 years following the end of our customer relationship with you or the organisation you work for because this is the limitation period for claims related to breach of contract. The exceptions to this general rule are:

  • Where you or the organisation you work for have not yet become a customer and we are only engaged in marketing to you, we will retain your details for a period of 3 years since our last interaction, unless you or the organisation you work for later becomes a customer;
  • Audio recordings will generally be retained for approximately 60 days and then overwritten or deleted, unless required for any reason.

It is important to ensure that the personal information we hold about you is accurate and up-to-date, and you should let us know if anything changes, for example if you move home or change your phone number or email address. You can contact us by using the details set out in the “Contacting us” section below.

YOUR RIGHTS IN RELATION TO PERSONAL INFORMATION

You have the following rights in relation to your personal information:

  • the right to be informed about how your personal information is being used;
  • the right to access the personal information we hold about you;
  • the right to request the correction of inaccurate personal information we hold about you;
  • the right to request the erasure of your personal information in certain limited circumstances;
  • the right to restrict processing of your personal information where certain requirements are met;
  • the right to object to the processing of your personal information;
  • the right to request that we transfer elements of your data either to you or another service provider; and
  • the right to object to certain automated decision making processes using your personal information.

You should note that some of these rights, for example the right to require us to transfer your data to another service provider or the right to object to automated decision making, may not apply as they have specific requirements and exemptions which apply to them and they may not apply to personal information recorded and stored by us.  For example we do not use automated decision making in relation to your personal data.  However some have no conditions attached, so your right to withdraw consent or object to processing for direct marketing are absolute rights.

Whilst this privacy notice sets out a general summary of your legal rights in respect of personal information, this is a very complex area of law. More information about your legal rights can be found on the Information Commissioner’s website at https://ico.org.uk/for-the-public/.

To exercise any of the above rights, or if you have any questions relating to your rights, please contact us by using the details set out in the “Contacting us” section below.

If you are unhappy with the way we are using your personal information you can also complain to the UK Information Commissioner’s Office or your local data protection regulator. We are here to help and encourage you to contact us to resolve your complaint first.

CHANGES TO THIS NOTICE

We may update this privacy notice from time to time. When we change this notice in a material way, we will update the version date at the bottom of this page. For significant changes to this notice we will try to give you reasonable notice unless we are prevented from doing so. Where required by law we will seek your consent to changes in the way we use your personal information.

CONTACTING US

In the event of any query or complaint in connection with the information we hold about you, please email: datacompliance@tyrrellscrisps.co.uk  or write to us at Tyrrells Group, Tyrrells Court, Stretford Bridge, Leominster, Herefordshire HR6 9DQ.

Version 1, 24 May 2018