Security Practices

PRIVACY POLICY – PROCESSING FRAMEWORK FOR FOOD SUPPLY OPERATIONS

SCOPE AND PURPOSE
This policy defines the processing of personal information within our international British food supply operation – covering order placement, payment security, logistics coordination, returns management, and regulatory compliance.

DIRECT DATA COLLECTION
Customers provide identity, address, contact, and delivery-preference data during account creation and order placement. Return-related information is collected as part of after-sales processes.

AUTOMATED DATA ACQUISITION
Technical metadata includes IP addresses, session identifiers, device/browser attributes, page interaction logs, basket events, and diagnostic telemetry for stability and security monitoring.

PAYMENT DATA PROCESSING
Payment processing is outsourced to PCI-compliant specialists. We retain neither complete Primary Account Numbers (PAN) nor CVV data. Transaction references and masked data are stored for reconciliation.

CARD DATA SECURITY
Encryption (TLS) and tokenisation are applied across all payment channels. Environments are logically segmented, and access to payment-related systems is subject to least-privilege controls.

CONTACT DATA PROTECTION
Contact information is processed exclusively for delivery execution and transactional notifications. Access is role-restricted, and sharing is confined to authorised logistics partners.

LAWFUL USE OF INFORMATION
Processing activities include order execution, delivery coordination, returns/refunds, fraud detection, accounting compliance, and user-experience enhancement.

FRAUD AND ABUSE MITIGATION
We analyse risk indicators – including repeated attempts, data inconsistencies, and anomalous session patterns – and may deploy enhanced verification procedures where risk thresholds are exceeded.

DATA SHARING WITH PROCESSORS
Information is shared with payment gateways, carriers, warehouse operators, hosting providers, and security/analytics partners – on a strict operational-need basis.

INTERNATIONAL DATA TRANSFERS
Data may be transferred to and processed in multiple jurisdictions. Transfers are governed by contractual clauses and supplementary technical measures.

COOKIE USAGE
Essential cookies support session and cart persistence. Non-essential cookies support analytics and personalisation subject to user consent. Browser-based controls are available.

RETENTION SCHEDULE
Data is retained in accordance with operational and statutory retention periods. Upon expiry, data is deleted or rendered anonymous for statistical use.

DATA MANAGEMENT BY CUSTOMERS
Customers may update primary account data directly. Transactional data may be retained for legal and audit compliance.

TECHNICAL SECURITY CONTROLS
We deploy encryption, access-control frameworks, audit logging, system monitoring, and backup/restoration protocols to protect personal data.