Carma Retail Ltd – GDPR Policy for Data Protection and Privacy
1. Introduction
Carma Retail Ltd, trading as Carma Coffee (“Carma”), is committed to protecting the privacy and security of personal data. This GDPR Policy outlines our practices and principles in handling personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR) as applicable.
2. Scope of Personal Data Processing
Carma collects personal data through various means, including but not limited to, Carma’s mobile application downloads, online forms, and social media interactions. The personal data collected may include names, email addresses, phone numbers, and other relevant information provided by users or collected through user interactions with our services.
3. Purpose and Lawful Basis for Processing
Carma processes personal data for direct marketing, upselling opportunities, and improving our products and services. The lawful basis for such processing includes consent (where users have explicitly agreed), the performance of a contract (to deliver services requested by the user), and legitimate interests pursued by Carma (for marketing to existing customers under the “soft opt-in” rule).
4. Consent Management
Carma ensures that consent, when required, is obtained in a clear, specific, and informed manner. Users have the right to withdraw their consent at any time, and Carma provides easy mechanisms for users to manage their consent preferences.
5. Data Sharing and Transfer
Personal data may be shared with third parties for the purposes of marketing, analytics, and service improvement, under strict confidentiality agreements. Data transfers outside the UK and EU are conducted in compliance with GDPR requirements, ensuring adequate levels of protection.
6. Data Subject Rights
Carma acknowledges and facilitates the rights of data subjects, including the right to access, rectify, erase, restrict processing, object to processing, and data portability. Requests from data subjects will be addressed promptly within the statutory timeframes.
7. Data Security and Breach Notification
Carma implements robust technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, and destruction. In the event of a data breach, Carma will notify the relevant authorities and affected individuals in accordance with GDPR requirements.
8. Data Retention
Personal data will be retained only for as long as necessary for the purposes for which it was collected, in line with Carma’s data retention policy and GDPR requirements.
9. Policy Review and Updates
This policy will be reviewed and updated regularly to reflect changes in legal requirements, industry practices, and Carma’s operations. Any changes to the policy will be communicated to stakeholders in a timely manner.
10. Contact Information
For any inquiries or requests related to personal data protection, please contact Carma’s Data Protection Officer at [DPO Contact Information].
This GDPR policy serves as a comprehensive guide to ensure Carma’s compliance with data protection laws while respecting the privacy and rights of our users. It reflects Carma’s commitment to transparency, accountability, and continuous improvement in data protection practices.