Privacy Policy of Hillside Heritage Goats Ltd
This Privacy Policy explains how Hillside Heritage Goats Ltd collects, uses, discloses, and protects personal data when you interact with our business, website, services, products, enquiries, bookings, events, and communications. We are committed to handling personal data lawfully, fairly, and transparently, and to protecting the privacy of individuals who contact us or use our services.
1. Introduction and Company Information
This Privacy Policy applies to the processing of personal data by Hillside Heritage Goats Ltd in connection with our goat-related business activities, including sales, enquiries, customer support, bookings, farm visits, events, memberships, marketing communications, and any related administrative functions.
Data Controller: Hillside Heritage Goats Ltd
Address: Hillside Heritage Goats, 14 Meadow Lane, Skipton, North Yorkshire, BD23 1AA, United Kingdom
Email: [email protected]
Phone: +44 1723 846 291
For the purposes of this Privacy Policy, “we”, “us”, and “our” refer to Hillside Heritage Goats Ltd.
2. Data Collection and Processing
We may collect and process personal data about you directly from you, automatically through your use of our website or services, and from third parties where lawful. The types of personal data we may collect include:
- Identity data, such as your name, title, and, where relevant, business name.
- Contact data, such as postal address, email address, and telephone number.
- Transaction data, such as details relating to purchases, bookings, payments, invoices, and refunds.
- Communication data, such as correspondence, enquiries, complaints, feedback, and records of our interactions.
- Technical data, such as IP address, browser type, device information, operating system, and website usage information.
- Marketing preferences, such as your consent choices and communication preferences.
- Any other information you choose to provide to us in the course of doing business with us.
We may also process limited information relating to animal-related services, bookings, or events where necessary to manage our services effectively. We do not intentionally collect special category data unless it is provided by you and is necessary for a lawful purpose, such as accessibility requirements, and only where appropriate safeguards are in place.
3. Purpose of Data Processing
We use personal data for the following purposes:
- To respond to enquiries and provide information about our goats, products, services, and events.
- To manage customer relationships, bookings, orders, and service delivery.
- To process payments, issue invoices, and maintain financial records.
- To communicate with you about your purchase, booking, or enquiry.
- To send administrative notices, service updates, and policy changes.
- To improve our website, services, and customer experience.
- To conduct marketing activities where permitted by law and, where required, with your consent.
- To comply with legal, regulatory, accounting, and tax obligations.
- To protect our business, staff, customers, property, and legitimate interests, including fraud prevention and security.
4. Legal Basis for Processing
We only process personal data where we have a lawful basis to do so. Depending on the context, our legal bases may include:
- Performance of a contract: where processing is necessary to provide our services, fulfil orders, or manage bookings.
- Consent: where you have given clear consent, for example for certain marketing communications.
- Legitimate interests: where processing is necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms, such as managing enquiries, improving services, preventing fraud, and securing our systems.
- Legal obligation: where we must process information to comply with applicable legal or regulatory requirements.
Where we rely on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. Data Sharing and Third Parties
We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy. These may include:
- Payment service providers and banking partners.
- Website hosting, maintenance, and IT service providers.
- Email communication and customer relationship management providers.
- Professional advisers, such as accountants, auditors, insurers, and legal advisers.
- Delivery, logistics, and fulfilment partners where relevant.
- Regulatory bodies, law enforcement authorities, or other public authorities where required by law.
We require third parties who process personal data on our behalf to implement appropriate safeguards and to use the data only in accordance with our instructions and applicable legal requirements.
6. Data Transfer to Third Countries
Some of our service providers may be located outside the United Kingdom. Where personal data is transferred to countries outside the UK, we take appropriate steps to ensure that the transfer is lawful and that your data remains protected. These steps may include the use of adequacy regulations, standard contractual clauses, international data transfer agreements, or other legally recognised safeguards.
If you would like more information about the safeguards used for international data transfers, you may contact us using the details provided below.
7. Storage Duration
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, tax, and reporting requirements. The retention period will depend on the type of data and the purpose of processing.
- Enquiry and communication records are generally retained for as long as necessary to manage the relevant matter and for a reasonable period thereafter.
- Transaction and financial records are retained for the period required by law and accounting obligations.
- Marketing preferences are retained until you unsubscribe, withdraw consent, or object where applicable.
- Technical and website data are retained for a limited period necessary for security, analytics, and operational purposes.
When personal data is no longer required, we will securely delete or anonymise it.
8. User Rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: the right to request confirmation of whether we process your personal data and to receive a copy of that data.
- Rectification: the right to request correction of inaccurate or incomplete personal data.
- Erasure: the right to request deletion of your personal data in certain circumstances.
- Restriction: the right to request that we limit the processing of your personal data in certain cases.
- Data portability: the right to receive your personal data in a structured, commonly used, machine-readable format and, where technically feasible, to request transfer to another controller.
- Objection: the right to object to processing based on legitimate interests and, in some cases, to object to direct marketing.
To exercise any of these rights, please contact us using the details in the “Contact Information” section. We may need to verify your identity before responding. We will respond within any timeframe required by applicable law.
9. Withdrawal of Consent
Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. If you withdraw consent, we may still be able to continue processing where we have another lawful basis to do so.
You can withdraw consent by contacting us at [email protected] or by using any unsubscribe mechanism included in our communications, where applicable.
10. Right to Complain
If you have concerns about how we handle your personal data, we encourage you to contact us first so that we can try to resolve the issue informally.
You also have the right to lodge a complaint with the relevant data protection authority in the United Kingdom. If you are based in the UK, this is normally the Information Commissioner’s Office (ICO). We recommend that you contact the ICO if you believe your rights have been infringed or if you are dissatisfied with our response.
11. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include:
- Access controls and role-based permissions.
- Secure storage and encryption where appropriate.
- Regular software updates and security monitoring.
- Staff awareness and confidentiality obligations.
- Procedures for identifying and responding to security incidents.
While we take reasonable steps to protect personal data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we work to maintain a high level of protection.
12. Contact Information
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact:
Hillside Heritage Goats Ltd
Hillside Heritage Goats, 14 Meadow Lane, Skipton, North Yorkshire, BD23 1AA, United Kingdom
Email: [email protected]
Phone: +44 1723 846 291
13. Changes to Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any changes will be posted on this page with an updated effective date where appropriate.
We encourage you to review this Privacy Policy periodically so that you remain informed about how Hillside Heritage Goats Ltd processes personal data.