Privacy Policy & Data Protection
Effective Date: May 2024
POLSCO LTD ("we," "us," or "our") is committed to protecting the privacy and security of your personal data. This policy outlines our practices in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Introduction and Scope
This privacy policy applies to all data subjects who interact with POLSCO LTD via our website (spicealley.sbs), our mobile applications, or our physical logistics services. As a "Data Controller," we are responsible for deciding how we hold and use personal information about you.
2. Data We Collect
We collect and process various categories of personal data, including: - Identity Data: Name, title, and job role. - Contact Data: Billing address, delivery address (43 Mortonhall Park Crescent and others), email, and phone numbers. - Financial Data: Bank account and payment card details (processed via secure PCI-compliant gateways). - Transaction Data: Details about payments to and from you and services you have purchased. - Technical Data: IP address, login data, browser type, and location data for delivery optimization. - Profile Data: Your interests, preferences, and dietary requirements.
3. Legal Basis for Processing
We only process your data when we have a legal basis to do so: - Contractual Necessity: To fulfill our delivery contract with you. - Legal Obligation: To comply with UK tax, health, and safety laws. - Legitimate Interests: To improve our logistics and marketing (where your rights do not override these interests). - Consent: Where you have explicitly opted into marketing communications.
4. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. Financial records are maintained for a minimum of 6 years to comply with HMRC regulations. Analytical data is typically anonymized after 24 months.
5. Your Rights
Under UK law, you have the following rights: - The Right to Access: Request a copy of your personal data. - The Right to Rectification: Correct any inaccurate data. - The Right to Erasure: Request the deletion of your data (subject to legal overrides). - The Right to Data Portability: Request the transfer of your data to another service provider. - The Right to Object: Object to processing based on legitimate interests.
6. Security Measures
POLSCO LTD employs advanced encryption (AES-256) for data at rest and TLS 1.3 for data in transit. We conduct regular penetration testing and staff training on social engineering and data handling. Access to sensitive data is restricted to "Need to Know" personnel only.
7. Contacting the DPO
If you have questions regarding your data, please contact our Data Protection Officer at dpo@spicealley.sbs or via mail to our Edinburgh headquarters.