Privacy Policy

This notice was last updated on 24/05/2018

CONTENTS
1. Introduction
2. The legal framework we rely on
3. When do we collect your personal data?
4. What personal data do we collect?
5. How do we use your personal data?
6. How do we protect your personal data?
7. How long will we keep your personal data?
8. Who do we share your personal data with?
9. Transfer of data outside EEA
10. What are your rights over your personal data?
11. How can you stop the use of your personal data for direct marketing?
12. Contacting the Regulator
13. Links to other sites
14. Status of Privacy Notice and updates
15. Security
16. Scope of This Privacy Notice
17. Any questions?

1. Introduction

Coffee#1 Limited (“we”, “us”, “our”) are committed to protecting and respecting your personal data. We take the privacy of our guests, customers, job applicants and any other individuals with whom we engage very seriously.

We want to share with you how we treat personal data that we receive about you. We only collect personal data about you if you choose to provide information to us when you opt in or show interest in receiving updates from Coffee#1, or when you apply for a job vacancy.

This Privacy Notice (together with our Terms of Use and any other documents referred to in it) explains in detail the types of personal data we may collect about you when you interact with us and also how we use, store and keep safe your data. It also details your rights and how you can stop the use of your personal data.

For the purpose of the relevant data protection legislation, which includes the General Data Protection Regulation (GDPR) the data controller is Coffee#1 Limited, The Cardiff Brewery, PO Box 53, Crawshay Street, Cardiff, CF10 1SP.

2. The legal framework we rely on

The law on data protection sets out a number of different reasons for which a company may collect and process your personal data, including:
⦁ Consent. In specific situations, we can collect and process your data with your consent – for example when you opt in to receiving information or updates from us.
⦁ Legitimate interest. In specific situations, we require your data to pursue our legitimate interests in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interests – for example when you have shown interest in receiving information or updates from us. Where we are relying on legitimate interests as the lawful; basis for processing your personal data you have a right to object.
⦁ Contractual obligations. In certain circumstances, we need your personal data to comply with our contractual obligations.
⦁ Legal compliance. If the law requires us to, we may need to collect and process your data.

In some limited circumstances, we may also need to collect and process special category personal data about you. We will only do so on the basis of your explicit consent or where there is specific legal basis for doing so.

3. When do we collect your personal data?

The occasions on which we collect your data include, but are not limited to:
⦁ When you visit our website and enter information about yourself.
⦁ When you make a booking/reservation at one of our coffee shops.
⦁ When you contact us or correspond with us by any means with enquiries, complaints etc.
⦁ When you engage with us on social media.
⦁ When you choose to complete a survey, research or feedback form, for example in relation to your experience when visiting one of our coffee shops.
⦁ When you provide your personal or employment details to enter a prize draw, competition or to receive any other communication.
⦁ When you fill in any forms, for example an Accident Form should an incident occur in one of our coffee shops.
⦁ When you use our Wi-Fi networks to access the internet.
⦁ When you purchase a product.
⦁ When you download or install one of our apps.
⦁ When you apply for a loyalty or gift card.
⦁ When you apply for a job vacancy.
⦁ When you’ve given a third party permission to share the information they hold about you with us.

4. What personal data do we collect?

The personal data which we may collect depends upon the means by which you choose to engage with Coffee#1 and the information that you choose to provide. This may include the following:

Personal data you choose to give us
⦁ Your name, gender and date of birth.
⦁ Your address, postcode, e-mail address and mobile/telephone contact information.
⦁ Your financial information.
⦁ Your personal description and photograph.
⦁ Your experiences, reviews, interests and preferences, for example in relation to your previous visits or future visits to our coffee shops.
⦁ Your business card details, for example job title and employer’s details or cv details when applying for a job vacancy.
⦁ Your social media username, if you interact with us through those channels, to help us respond to your comments, questions or feedback.
⦁ Your transactional details relating to your purchase of a product or service
⦁ Information about your qualifications and experience where relevant to your application for a job vacancy.

Information we may collect about you
⦁ We generate personal data about you in the course of our dealings and correspondence with you. This includes keeping records of our engagement with you.
⦁ Your image may be recorded on CCTV when visiting some of our coffee shops or Registered Office for security and safety reasons.
⦁ Your vehicle registration number may be recorded at our Registered Office for security and safety reasons.
⦁ To deliver the best possible web or app experience, we may automatically collect the following:
⦁ technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, geographic location, browser plug-in types and versions, operating system and platform;
⦁ information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our site (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs) and methods used to browse away from the page and any phone number used to call us. We may track where you came to our site from and where you went when you left our site and how often you visit and use our site.
⦁ via cookies on our website to distinguish you from other users. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. For detailed information on the cookies we use and the purposes for which we use them see our Cookie Policy.

Information we receive from other sources about you
⦁ We may receive information about you if you use any of the other websites we operate or the other services we provide. We also work closely with third parties (for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, customer insight companies, credit reference agencies, recruitment agencies and job boards) and may receive information about you from them.
⦁ If you are applying for a job vacancy we may undertake verification checks to establish if the information you have provided is correct, including taking up references about you.

5. How we use your personal data?

We want to give you the best possible customer experience by combining the data we have about you to provide you with updates, offers and promotions on our products and coffee shops that are most likely to interest you. In the case of loyalty scheme members, we’ll also offer you relevant rewards.

We will also use your personal data in the following ways:
⦁ To carry out our obligations arising from any contracts or agreements entered into between you and us, for example to process any bookings/reservations that you make by using our websites, apps or in outlet.
⦁ To notify you about updates and information about our products, services and job vacancies that we think may be of interest to you, including special offers, discounts, promotions, events, competitions etc.
⦁ To provide you with information about other products, services and job vacancies we offer that are similar to those that you have already purchased, booked or enquired about.
⦁ To administer any of our prize draws or competitions which you enter, based on your consent given at the time of entering.
⦁ To help us make improvements to our systems, products and services.
⦁ For research and marketing purposes.
⦁ To respond to your queries and complaints. We may also keep a record of these to inform any future communication with us and to demonstrate how we communicated with you throughout.
⦁ To ensure that content from our site, mobile apps and other services and activities is presented in the most effective manner for you and for your computer.
⦁ To protect our company, customers, premises, assets and staff from crime.
⦁ To comply with our contractual or legal obligations to share data with law enforcement.
⦁ To send you communications required by law or which are necessary to inform you about our changes to the services we provide you.

6. How do we protect your personal data?

We will treat your data with the utmost care and take appropriate steps to protect it and we have defined security and privacy controls, processes and procedures to protect your data.

Our systems comply with high-standard business-grade specifications, including:
⦁ Secure access to all transactional areas of our websites and apps using ‘https’ technology.
⦁ Access to your personal data being password-protected and sensitive data (such as payment card information) being secured by SSL encryption.
⦁ Regularly monitoring our system for possible vulnerabilities and attacks, as well as carrying out penetration testing to identify ways to further strengthen security.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

7. How long will we keep your personal data?

Whenever we collect or process your personal data, we’ll keep it no longer than is necessary for the purposes for which the personal data is processed.

Your personal data will then either be deleted or destroyed.

8. Who do we share your personal data with?

We may share your personal data with any member of our group, as defined in section 1159 of the UK Companies Act 2006.

In certain situations we may disclose your personal data to third parties:
⦁ In the event that we sell any business or assets, in which case we may disclose your personal data to the prospective buyer of such business or assets.
⦁ If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use and other agreements; or to protect the rights, property, or safety of Coffee#1 Limited, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.

We may sometimes share your personal data with selected, trusted third parties, including but not limited to:
⦁ Business partners, suppliers and service providers for the performance of any contract we enter into with them or you.
⦁ IT companies who support and improve our website and other business systems.
⦁ Direct marketing, research and advertising companies that help us with our marketing strategy and communications with you.
⦁ Data insight companies to ensure your details are up to date and accurate.

We provide only the information to these trusted third parties that they need to perform their specific service. They are contractually bound to use your personal data that we share with them with the sole purpose of performing the services we have engaged them to provide.

We may also share your contact details with selected, trusted third parties who offer products and services that we believe may be of interest to you who will wish to contact you directly. We are careful about the amount of information that we share and consider this is in our legitimate interests, as well as those of the relevant third parties, and is not overridden by your privacy rights. You have the right to object to this.

9. Transfer of data outside EEA

All countries in the European Economic Area (EEA), which includes the UK, have similar standards of legal protection for your information. We may store your information on third party data centres located outside the EEA, where there is not a similar standard of data protection laws. If so, we will take steps to ensure that adequate levels of protection are applied to your information.

10. What are your rights over your personal data?

You are receiving relevant communications from us because you have previously consented to receiving communications from us, or you have engaged with us or shown interest in receiving updates about our products, services and job vacancies by providing such personal data to us. The data protection laws allow us to treat your previous engagement as amounting to a “soft opt-in.”

You have the right to ask us to stop sending you communications at any time if you wish, as described below.

Under the data protection laws you have the right:
⦁ To request a copy of the personal data we hold about you, free of charge in most cases.
⦁ To ask us to correct your personal data when incorrect, out of date or incomplete.
⦁ To ask us to stop using your personal data for direct marketing (either through specific channels, or all channels) or any other consent-based processing of your information.
⦁ To ask that we delete your information if we do not have a good cause to retain it.
⦁ To otherwise object to the way in which we use your information.

If you wish to exercise any of these rights, or if you have any questions about our use of your information, please email us at DPO@coffee1.co.uk or write to or contact Data Protection Officer, Coffee#1 Limited, The Cardiff Brewery, Crawshay Street, Cardiff, CF10 1SP, +44 (0) 29 2040 2060.
You also have a right to complain to the Information Commissioner’s Office or other appropriate regulatory authority in relation to your information held by us, and how we use it.

11. How can you stop the use of your personal data for direct marketing?

When you provide your personal data we give you the opportunity to choose to receive further information about our products, services and job vacancies which we believe may be of interest to you.

  • There are several ways that you can opt out of receiving direct marketing communications from us:
    ⦁ By clicking the ‘unsubscribe’ link in any email communication that we send you. By emailing us at DPO@coffee1.co.uk.
    ⦁ By writing to or contacting Data Protection Officer, Coffee#1 Limited, The Cardiff Brewery, Crawshay Street, Cardiff, CF10 1SP, +44 (0) 29 2040 2060

Please note that you may continue to receive communications for a short period after changing your preferences while our systems are fully updated. If you ask us to stop sending you communications, we will continue to keep a record of you and your request not to hear from us. If we deleted all of your information from our database, we would have no record of the fact that you have asked us not to communicate with you and it is possible that you may start receiving communications from us at some point in the future, if we obtain your details from a different source.

12. Contacting the Regulator

If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests or queries you have made regarding the use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office. You can contact them by calling 0303 123 1113 or by visiting their website www.ico.org.uk/concerns.

13. Links to other sites

You may, from time to time, receive links to and from third-party websites of our partner networks, advertisers and affiliates.  If you follow a link to any of these websites, please note that these websites have their own privacy policies, terms and conditions and we do not accept any responsibility or liability in connection with any access or use by you of these sites.  Please check the policies, terms and conditions of such websites before you submit any personal data.

14. Status of Privacy Notice and updates

This Privacy Notice is non-contractual. We reserve the right to amend it from time to time. Amendments will be posted to our website and, where appropriate, through e-mail notification. Unless otherwise specified all such changes will take effect immediately upon posting to the website.

For the avoidance of doubt, no change to the Privacy Notice will change the content of your consent that you may have granted.

15. Security

Where we have given you (or where you have chosen) a password or PIN which enables you to access certain parts of our website, you are responsible for keeping this password or PIN confidential. We ask you not to share a password or PIN with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

16. Scope of This Privacy Notice

This Privacy Notice is directed at our guests, customers, job applicants, and any external individuals with whom we engage. In relation to personal data our current and former employees are covered by separate internal documentation and operational practices, including individual employee contracts and company rules, policies, processes and procedures.

17. Any questions?

We hope this Privacy Notice has been helpful in setting out the way we handle your personal data and your rights to control it.

If you have any questions in relation to this Privacy Notice, please feel free to contact the Data Protection Officer:
⦁ By emailing us at DPO@coffee1.co.uk.
⦁ By writing to or contacting Data Protection Officer, Coffee#1 Limited, The Cardiff Brewery, Crawshay Street, Cardiff, CF10 1SP, +44 (0) 29 2040 2060

OTHER USEFUL DOCUMENTS
Terms & Conditions
Cookie Policy



JOIN COFFEE#1 ON
SOCIAL MEDIA