Relish School Food Ltd Privacy Notice



Relish School Food Limited ("We") are committed to protecting and respecting your privacy. This policy (together with our website terms of use and any other documents referred to in it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.


For the purpose of the Data Protection Act 1998 (the Act), the data processor is Relish School Food Limited, a private limited company, with company number 5772759, having its registered office at Suite EFG, Monarch House, Eastwood, NG16 3RY.



Information We May Collect From You



We may collect and process the following data about you:


  • information that you provide by filling in forms and permitting your School (or your child's School) to use your (or your child's data) on our site Relish School Food (our site). This includes information provided at the time of registering to use our site, use of our service, posting or processing data material including data about you and your child's name, address, date of birth, facial photograph, bank details and other data we may seek from time to time or when you request further services. We may also ask you for information if you report a problem with our site.
  • If you contact us, we may keep a record of that correspondence.
  • We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
  • Details of the transactions you carry out through our site and of the fulfilment of your orders.
  • Details of your visits to our site including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise and the resources that you access.


IP Addresses



We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration. This is statistical data about our users' browsing actions and patterns, and does not identify any individual.



Cookies



A cookie is a small file which asks permission to be placed on your computer's hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.


We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.


Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.


You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the web site.



Where We Store Your Personal Data



Relish School Food Ltd will never sell your information for marketing purposes to outside third parties and all personal data will stay within the EEC.


All information you provide to us is stored on our secure system. Any payment transactions will be encrypted using SSL technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.



Third Parties



We use an external data centre to host our servers and databases. All our data is securely located within their facilities based in Reading, UK. All data resides within the EEA. The facilities and staff are ISO27001 certified.



Uses Made Of The Information



We use information held about you in the following ways:


  • To ensure that content from our site is presented in the most effective manner for you.
  • To carry out our obligations arising from any contracts entered into between you, your child's School, Caterer or LEA and us.
  • To notify you about changes to our service.
  • We may also use your data, to provide you with information about goods and services which may be of interest to you.


We will only share your data with your child's School, Payment Processor, Caterers or LEA. We will never sell or supply your data to any other third parties.


If you are an existing customer, we will only contact you by electronic means (e-mail or SMS) with information about services.


If you are a new customer we will contact you by electronic means only if you have consented to this.


If you do not want us to use your data in this way, or to pass your details on to third parties, please tick the relevant box situated on the form on which we collect your data (the registration form) or notify us by email at dpo@relishschoolfood.co.uk


We do not disclose information about identifiable individuals to advertisers.



Disclosure Of Your Information



We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the Companies Act 2006.


We may disclose your personal information to third parties:


  • In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
  • If Relish School Food or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
  • If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use and other agreements; or to protect the rights, property, or safety of Relish School Food, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.


Your Rights



You have the right to ask us not to process your personal data for marketing purposes. We will prompt you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at dpo@relishschoolfood.co.uk


Our site may, from time to time, contain links to and from the websites of our partner networks and affiliates. If you follow a link to any of these websites, please note that these websites have their own Privacy Notices and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.



Retention Of Data



We only retain personal data whilst a child remains on the school MIS. Non-identifiable information, such as sales data for example, is retained in the system for as long as a school remains a Relish Client. Non-identifiable information is not attributable to a person or persons.



General Data Protection Regulations (GDPR)



On 27th April 2016, the European Parliament, Council of the European Union and the European Commission adopted new regulations regarding data protection and the rights of individuals within the European Union. The regulations come into force on the 25th May 2018.


The GDPR regulations will replace and build upon elements of the Data Protection Act 1998 (DPA). GDPR will still be implemented irrespective of Brexit, however we are closely monitoring proposed or actual changes to the regulations and will amend our Privacy Notice and processes to reflect these.


We are prepared to align with and meet the policies and principles, where applicable, set out within the GDPR regulations.


We take information, advice and recommendations from the Information Commissioner's Office (ICO), the UKs independent authority to uphold information rights and data privacy.


For the GDPR regulations under article 37 we have appointed a Data Protection Officer (DPO). The DPO, can be contacted via dpo@relishschoolfood.co.uk



Purpose For Processing



To provide catering consultancy, supplier ordering, school menu management and mealtime processing systems for school catering, cleaning, local authorities and service organisations.



Special Categories Of Data



Special category data is personal data which the GDPR regards as more sensitive, and so requires more protection.


We process two types of special category health information:


  • Allergens
  • Dietary information

Article 9(2) of the GDPR sets out the conditions for the processing of special category data to be lawful.


The processing of allergen and dietary information is necessary for reasons of substantial public interest, to safeguard the health of data subjects.



Access To Information - Subject Access Requests



A Subject Access Request (SAR), is a written, signed request from a data subject to identify what personal data an organisation is processing on their behalf, why that organisation holds it, and who it is disclosed to. This right, commonly known as subject access, is set out in section 7 of the Data Protection Act (1998). Relish School Food recognises the rights of the data subject under the GDPR.


In accordance with GDPR, a Subject Access Request is no longer subject to a fee, as incurred under the DPA. However, Relish School Food has a right to charge a reasonable fee, should the requests from the Data Subject be manifestly unfounded or excessive, in particular because of their repetitive character. For the same reasons, Relish School Food can refuse the request. However, Relish School Food must respond to all written requests within one calendar month stating our progress or the reasons for the refusal, or any charge that may be incurred. Relish School Food can extend the time to deal with the request by two further months considering the complexity and number of requests, so long as we respond to the initial request within one calendar month and state the reasons for the delay. Relish School Food will authenticate all individuals requesting data, by either contacting the Data Controller who is providing the Relish School Food service, or requesting photographic I.D.


All data associated with the Subject Access Request will be stored within our in-house support mechanisms, with a unique reference code for that Data Subject, and will include the initial request, email correspondence and responses. This will be kept for one year, following a completed response or resolution and deleted.


If you wish to exercise your right of access, please email dpo@relishschoolfood.co.uk and we will supply you with an Access Request Form. Data subjects can also submit request by post to: Relish School Food Ltd, 83 Main Road, Smalley, Ilkeston, Derbyshire, DE7 6DS. The Subject Access Request Form is a guideline for a Data Subject to use their rights and what data they are requesting. The ICO states that there is no legally prescribed form nor can Relish School Food force the Data Subject to use our in-house form, however should the data subject choose not to use our guideline form, then we will be requesting further information email with similar questions.


The Data Subject ("You"), may not be aware of the rights you have under GDPR. This policy sets out the additional rights which a living natural person or individual can exercise once GDPR comes into force. The rights which you the Data Subject wish to exercise must be defined within the Subject Access Request.



Your Rights



  1. The right to be informed

    Relish School Food will inform data subject(s) about the reasons for which their data is processed. This must be explicit and transparent through the company Privacy Notice. The Privacy Notice must be easily accessible.

  2. The right of access

    Relish School Food will confirm with the data subject(s) whether we process their data. In the event, we do process that data, we must provide the data subject(s) access to that data in a readable and portable format such as excel or .csv

  3. The right of rectification

    Data subject(s) have a right to have their personal data rectified, if the data is inaccurate or incomplete. If the data has been shared with a third party, that data must also be rectified. Relish School Food will perform the rectification and inform the data subject to whom the data has been disclosed.

  4. The right of removal

    Otherwise known as "The right to be forgotten", Relish School Food must enable data subject(s) to request that their personal data is deleted or removed from Relish School Food Personal Information Management systems (PIMS). Relish School Food will endeavour to remove all identifiable instances of the data subject from Relish School Food where the data subject exists. Relish School Food reserves the right to preserve aspects of the data, if:
    • The data relates to a wider statistical reporting mechanism;
    • The data is used for scientific or historical or public health research;
    • The data is required to comply with a legal obligation or to exercise the defence of legal claims;
    • The data is required to exercise the right of freedom of expression and information.

  5. The right to restrict processing

    Data subject(s) have the right to block or suppress processing personal data. In this situation, Relish School Food can continue to hold the data which has been processed already, however, Relish School Food must not further process data on behalf of the data subject(s). This means Relish School Food must disable accounts or records for that data subject or apply the necessary changes to the functionality of the software, to prevent further data processing on behalf of that data subject.

  6. The right to data portability

    Relish School Food must provide the data subject(s) data in an easily accessible, portable and legible format. Examples of portable data can include, but are not limited to:
    • Microsoft Excel spreadsheet
    • .csv spreadsheet
    • Microsoft Word document

    The data must be provided to the data subject in a safe and secure way, typically encrypted with a password. Relish School Food adheres to a document encryption policy, referenced within the Relish School Food Information Security & Business Continuity Policy. We encrypt all documents with personally identifiable information with a password before submitting to the relevant individual(s).

  7. The right to object

    Data subject(s) can object to Relish School Food data processing on grounds relating to their "particular situation". The following reasons are valid to object:
    • The data is processed based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling);
    • The data is used for direct marketing (including profiling);
    • The data is processed for purposes of scientific/historical research and statistics.

    If the Data subject exercises their right to object, Relish School Food must stop processing their data (as defined in 5. The right to restrict processing) unless we can show that; The processing is based on legitimate interests, such as:
    • To demonstrate compelling legitimate grounds, which override the interests, rights and freedoms of the individual;
    • The processing is for the establishment, exercise or defence of legal claims;
    • We are conducting research where the processing of personal data is necessary for the performance of a public interest task.

    If Relish School Food stops processing for the reasons above, then it must be "explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information".

  8. Rights in relation to automated decision making and profiling

    Individuals have the right not to be subject to a decision when:
    • It is based on automated processing;
    • It produces a legal effect or a similarly significant effect on the individual;

    Relish School Food must ensure that individuals can:
    • Obtain human intervention;
    • Express their point of view;
    • Obtain an explanation of the decision and challenge it.


Changes To Our Privacy Notice



Any changes we may make to our Privacy Notice in the future will be posted on this page.



Contact



Questions, comments and requests regarding this Privacy Notice are welcomed and should be addressed to dpo@relishschoolfood.co.uk