GDPR

Kebab Carvery (Bognor Branch)
Website: https://kebabcarvery.com
Effective date: 28 July 2026
Last updated: 28 July 2026

1. Purpose

This UK GDPR Data Protection Statement describes the governance, principles and operational commitments used by Kebab Carvery (Bognor Branch) to protect personal data. It supplements our customer-facing Privacy Policy.

It is designed to support compliance with:

  • the UK General Data Protection Regulation (UK GDPR);

  • the Data Protection Act 2018;

  • the Privacy and Electronic Communications Regulations 2003 (PECR), as amended;

  • the Data (Use and Access) Act 2025 and regulations brought into force under it;

  • other applicable UK privacy, electronic communications and consumer laws.

2. Controller information

Data controller: Kebab Carvery (Bognor Branch)
Address: 226 Chichester Road, Bognor Regis, West Sussex, PO21 5BE, United Kingdom
Telephone: +44 1243 822822
Data protection contact: The Manager
Email: bognorregis@kebabcarvery.co.uk

3. Data protection principles

We aim to ensure that personal data is:

  1. processed lawfully, fairly and transparently;

  2. collected for specified, explicit and legitimate purposes and not reused incompatibly;

  3. adequate, relevant and limited to what is necessary;

  4. accurate and kept up to date where needed;

  5. retained no longer than necessary;

  6. protected by appropriate security and confidentiality controls;

  7. processed under documented accountability measures demonstrating compliance.

4. Scope of processing

Our processing may cover:

  • customers and prospective customers;

  • account holders;

  • order recipients;

  • website visitors;

  • complainants and enquirers;

  • marketing subscribers;

  • suppliers, contractors and professional contacts;

  • delivery personnel and authorised restaurant users.

Relevant data includes identity, contact, account, order, delivery, transaction, payment-status, communications, marketing preference, technical, security and limited allergy or dietary information.

5. Records of processing

We maintain proportionate records of processing activities, including:

  • processing purpose;

  • categories of individuals and personal data;

  • lawful basis;

  • recipients and processors;

  • international transfer safeguards;

  • retention periods;

  • technical and organisational security controls;

  • data subject rights procedures;

  • high-risk processing assessments where applicable.

Records are reviewed when systems, suppliers, purposes or legal requirements change.

6. Lawful basis assessment

Before processing personal data, we identify and document an appropriate lawful basis. The principal bases used are:

  • contract: to create accounts, accept and fulfil orders, process payments and provide support;

  • legal obligation: for tax, accounting, food safety, regulatory, law-enforcement and compliance duties;

  • legitimate interests: for security, fraud prevention, service administration, limited service improvement and defence of claims, after balancing individual rights;

  • consent: for optional marketing, non-essential cookies and any processing that specifically requires consent;

  • vital interests: in exceptional situations involving serious allergy or immediate health risk;

  • legal claims or another Article 9 condition: where special category data must be processed lawfully.

We do not retrospectively change a lawful basis merely because another basis becomes more convenient.

7. Special category data

Allergy, intolerance or medical dietary information may constitute health data. We minimise such processing and restrict it to order safety, complaint handling, legal obligations and claims.

Where required, we obtain explicit consent. In urgent circumstances, processing may be necessary to protect vital interests. Access is limited to personnel and service providers who need the information to fulfil or investigate the order.

Special category data is not used for unrelated marketing or profiling.

8. Transparency

We provide clear privacy information at appropriate points, including:

  • account registration;

  • checkout;

  • marketing opt-in;

  • cookie consent;

  • contact and complaint forms;

  • material changes to processing.

Privacy information explains the controller, purposes, lawful bases, recipients, retention, international transfers, rights and complaint routes.

9. Consent management

Where consent is required, it must be:

  • freely given;

  • specific;

  • informed;

  • unambiguous;

  • given by a clear positive action;

  • separate from unnecessary contractual conditions;

  • as easy to withdraw as to give.

We keep proportionate consent records showing what the person agreed to, when, how and which notice version applied.

Silence, inactivity, pre-ticked boxes or continued website use are not treated as consent to non-essential cookies or optional direct marketing.

10. Direct marketing and PECR

Promotional email and SMS campaigns are sent only where:

  • valid consent exists; or

  • all conditions of the PECR soft opt-in are met.

Each marketing message identifies the sender and provides a simple opt-out. Opt-out requests are actioned promptly. A suppression list may be retained to prevent future marketing.

Service communications about an order or account are not used as disguised marketing.

11. Cookies and similar technologies

We maintain a cookie and tracking technology inventory. Before deploying a technology, we assess:

  • its provider and purpose;

  • information stored or accessed;

  • whether it is first- or third-party;

  • duration;

  • whether a PECR exemption applies;

  • whether consent is required;

  • UK GDPR lawful basis for subsequent processing;

  • international transfer implications.

Non-exempt technologies are blocked until consent. Users are offered a genuine choice, including rejection and category controls, and can later withdraw consent through an accessible settings mechanism.

12. Data minimisation and privacy by design

New or materially changed processing is reviewed before launch. We seek to:

  • collect only necessary fields;

  • avoid compulsory marketing consent;

  • use privacy-protective defaults;

  • separate service and marketing preferences;

  • restrict staff access;

  • minimise third-party scripts;

  • avoid retaining full payment card details;

  • pseudonymise or aggregate analytics where practical;

  • define deletion and review dates;

  • document supplier and transfer risks.

13. Data Protection Impact Assessments

We carry out a Data Protection Impact Assessment (DPIA) before processing likely to result in high risk, including potentially:

  • large-scale or systematic monitoring;

  • innovative profiling or behavioural advertising;

  • extensive processing of special category data;

  • matching data from multiple sources;

  • use of new technology with significant privacy impact;

  • automated decisions producing legal or similarly significant effects.

Where residual high risk cannot be mitigated, we will consult the ICO before starting the processing where required.

14. Processor management

Processors are selected through proportionate due diligence. Written agreements require, as applicable:

  • processing only on documented instructions;

  • confidentiality;

  • appropriate security;

  • controls over sub-processors;

  • assistance with rights requests, DPIAs and breaches;

  • deletion or return of data at contract end;

  • compliance evidence and audit rights;

  • lawful international transfer mechanisms.

We periodically review material processors and sub-processors.

15. International transfers

Restricted transfers from the UK are made only where a lawful transfer mechanism exists, such as:

  • UK adequacy regulations;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to EU Standard Contractual Clauses;

  • another statutory derogation available in limited circumstances.

Where necessary, we conduct transfer risk assessments and apply supplementary technical or organisational safeguards.

16. Security controls

Our risk-based security programme may include:

  • encrypted HTTPS connections;

  • secure password hashing;

  • least-privilege access;

  • multi-factor authentication for privileged systems where available;

  • access logging and review;

  • supported software and timely security updates;

  • secure backups and recovery testing;

  • malware, firewall and endpoint controls;

  • vulnerability and supplier risk management;

  • secure disposal;

  • staff training and confidentiality obligations;

  • documented incident response.

Security measures are reviewed in light of risk, available technology, cost and the nature of the data.

17. Personal data breaches

Suspected incidents must be reported internally without delay. We assess:

  • what happened and when;

  • affected systems, individuals and data;

  • likely consequences;

  • containment and recovery steps;

  • whether processor or third-party notification is needed;

  • whether the breach is reportable to the ICO;

  • whether affected individuals must be informed.

Where required, we notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. High-risk breaches are communicated to affected individuals without undue delay. We maintain an incident and breach log, including non-reportable incidents.

18. Individual rights procedure

Requests may be made verbally or in writing. Staff should recognise and promptly escalate requests involving:

  • access;

  • rectification;

  • erasure;

  • restriction;

  • objection;

  • data portability;

  • withdrawal of consent;

  • automated decision safeguards;

  • complaints about data use.

We verify identity proportionately, search relevant systems, apply exemptions carefully, communicate clearly and normally respond within one month. Extensions or fees are used only where legally permitted.

Contact for requests:

FAO: The Manager – Data Protection Request
Kebab Carvery (Bognor Branch)
226 Chichester Road
Bognor Regis
West Sussex
PO21 5BE
United Kingdom

Email: [INSERT PRIVACY/CONTACT EMAIL]
Telephone: +44 1243 822822

19. Retention and deletion

Retention periods are based on purpose, legal duties, limitation periods, food safety, financial recordkeeping, security and customer expectations.

We maintain a retention schedule and periodically delete, anonymise or securely archive records that are no longer needed. Legal holds suspend deletion where records are required for a complaint, investigation, audit or claim.

20. Data accuracy

Reasonable steps are taken to keep important data accurate. Customers can update account information or contact us. Inaccurate data is corrected or annotated without undue delay where appropriate, and relevant recipients are informed where legally required.

21. Automated decisions and profiling

We do not intend to use solely automated decision-making that produces legal or similarly significant effects. If this changes, we will:

  • identify a valid legal condition;

  • provide meaningful information about the logic and consequences;

  • implement safeguards including human intervention and challenge rights;

  • complete a DPIA where required.

Third-party payment and fraud providers may perform their own risk assessments and should provide their own privacy information where acting as controllers.

22. Children's data

We do not intentionally design behavioural advertising or profiling for children. Where a service is likely to be accessed by children, we will consider age-appropriate transparency, data minimisation, high-privacy defaults and the Children's Code where applicable.

23. Training and accountability

Staff with access to personal data receive proportionate guidance on:

  • confidentiality and secure handling;

  • recognising rights requests;

  • marketing consent and opt-outs;

  • phishing and account security;

  • breach escalation;

  • allergy and special category data;

  • disposal and retention.

Compliance documentation is reviewed periodically and after material changes or incidents.

24. Complaints and regulatory contact

Individuals are encouraged to contact us first. They may also complain to the Information Commissioner's Office at ico.org.uk.

We will cooperate with regulatory enquiries and take appropriate corrective action where shortcomings are identified.

25. Review

This Statement is reviewed at least annually and whenever there is a material change to law, processing, technology, suppliers or business operations.