1 Scope of this notice
1.1 Fodafilment (Fodafilment, we, us or our), part of FodaBox Limited, is committed to respecting and protecting your privacy. This Privacy Notice sets out what we do with the personal data we process about you.
1.2 This Privacy Notice applies only to the personal data that we process of users (you, your) of (i) Fodafilment.com (Website), and (ii) the cloud-based platform we call our “Portal” which we make available to customers who use our fulfilment services (Portal). However, we have also included information about how we process the personal data of customers of our direct customers (end customers) on our Portal where that information is provided by our direct customers in connection with our services.
1.3 This Privacy Notice does not extend to any other websites we might link to. For information about how our customers or partners process personal data of their customers, please visit their websites directly.
2 Our Role
2.1 We are Fodafilment (trading as FodaBox Limited), a company registered in England and Wales under company registration number 07591686. Our registered office is at Unit 10, Quadrant Park, Welwyn Garden City, Hertfordshire AL7 1FS. We are registered with the Information Commissioner’s Office with registration number ZB028821.
2.2 For the purpose of the Data Protection Act 2018 and the General Data Protection Regulation (EU) 2016/679 (the GDPR, as and to the extent it forms part of domestic law in the United Kingdom), Fodafilment is the controller of the personal data it processes about you. Where we process the personal data of end customers, to whom we make deliveries of our customers’ products, this will be personal data provided to us by our customers and we do this as data processors. In relation to such personal data, our customers are data controllers and they are required to provide data privacy information when they collect it.
2.3 We have appointed a data protection officer who has responsibility for advising us on our data protection obligations. You can contact the data protection officer at: firstname.lastname@example.org
3 The personal data we collect
3.1 personal data is any information relating to an identified or identifiable living person.
3.2 The persons to which this privacy notice applies may be registered companies, sole traders or partnerships. Where they are a registered company, we will process personal data in relation to our contact at that company.
3.3 The personal data we process of users of the Website will be the following details provided by individuals who would like to receive information about our services:
· email address
· phone number
We also process the following personal data of individuals who are customers or our customers and who contact us via the Website:
· email address
· phone number
· order details
· IP address
3.4 The personal data of our customers (who are users of the Portal) that we process will be:
· contact information such as email addresses and telephone numbers
· IP address (automatically collected by cookies)
In relation to end customers, we receive order details from our customers and will process the following personal data of those individuals in connection with processing and delivering orders:
· email address
· phone number
· order details
4 What we do with the personal data we collect
4.1 We use personal data for the following purposes:
4.1.1 if you are enquiring about our services, to contact you with information you may need;
4.1.2 if you are a point of contact at one of our customers, to run and manage the customer account including providing support to you in using our services and to answer any questions you may have, including dealing with complaints or other feedback;
4.1.3 if you are an end customer, to fulfil orders that you place for goods and services purchased from our customers;
4.1.4 if you are our customer or an end customer, to provide support to you in using our services and to answer any questions you may have, including dealing with complaints or other feedback;
4.2 Where we contract directly with a customer, we need certain personal data to perform our contract. Where you are an end customer and we are engaged to complete a delivery to you, we do not have a contract with you, but we will need your personal data to complete your delivery. We obtain this data from our customers, with whom you have transacted. If you do not provide the necessary personal data, we will not be able to make the delivery. When end customer data is collected for the purposes of deliveries, our customer (the company you have ordered from) must tell you which personal data is mandatory for you to provide and how your personal data will be processed.
5 Our legal basis for processing your personal data
5.1 In accordance with applicable data protection laws including the GDPR, we are only permitted to process your personal data if we have a legal basis for doing so. The table below details the legal basis is in relation to each of the purposes set out above.
|Purpose||Personal data processed||Legal basis|
|To respond to requests for information about our services and becoming a customer||The contact details provided by you||We process this personal data on the basis that we have your consent to do so as you have provided your contact details to use for responding with information you may need|
|To pass on your information to selected third parties if you have expressed an interest in hearing more from them via our website||The contact details provided by you||We process this personal data on the basis that we have your consent to do so because you have provided your contact details for us to pass on to the relevant third party so that they can respond to you|
|To use your personal data to set up a service from a selected third party||The personal data provided by you||We process this personal data on the basis that we have your consent to do so because you have provided your contact details for us to set this up on your behalf|
|To run and manage our customer accounts||Your name and contact details including address, telephone number and email address||We process this personal data on the basis that it is necessary to enable us to fulfil the contract that we have with our customers to deliver our services (where we liaise directly with the customer) and where we liaise with a representative from the customer, on the basis that we have a legitimate interest in such processing (which is to fulfil the contract with our customer which will usually be your employer)|
|To fulfil orders that you (as an end customer) place with 3rd party platforms (for example, eBay, Shopify or Amazon) or direct with traders for goods and services||Your name, address, telephone number, email address, order information and any other information provided to us by our customer||We process this personal data on the basis that it is necessary for the purpose of our legitimate interest, which is us delivering your order to you and satisfying the requirements of our contract with our customer|
|To provide support to you in using our services and to answer any questions you may have||Your name, address, telephone number and email address||We process this personal data for these purposes on the basis that we have a legitimate interest in ensuring that we can assist with your query|
|To deal with complaints or other feedback||Your name, address, telephone number and email address||We process this personal data on the basis that we have a legitimate interest in ensuring that we can assist with your complaint or use your feedback to make improvements to our business and provide the best possible service for our customers and end customers|
5.2 In accordance with the GDPR, we will only retain personal data for as long as is necessary in light of the reason we are processing it. For example, if we are delivering a parcel to you, we will need to retain your name and address from when the order is received until a reasonable period after the order has been delivered to ensure that we can deal with any queries in relation to a delivery. We will also need to process personal data relating to our customers for the duration of their account with us being active, and for a reasonable period afterwards for our record keeping purposes.
5.3 All personal data we process is stored securely in accordance with the technical and organisational security measures we have implemented to meet the requirements of the GDPR.
5.4 We do not use personal data of our customers or end customers for activities unrelated to the fulfilment services we operate.
6. Sharing your personal data
6.1 We share your personal data with third parties where it is necessary for us to do so to meet our obligations under our contracts with customers. These are selected third parties who provide courier services to deliver goods to end customers and other third parties who provide services to us as part of managing and operating our business, such as operating an IT system.
6.2 We will also share your personal data with selected third parties who provide other specific services, if you have expressed an interest in hearing more from them about their services, or to set up a service from a selected third party.
6.3 Finally, we share personal data where we are required to do so in order to comply with a regulatory or legal provision.
6.4 We will never sell your personal data for direct marketing.
6.5 We only allow third parties to handle your personal data if we are satisfied they take appropriate measures to protect your personal data. Any third party with which we share your personal data is authorised to use it only to the extent required to perform the task we have engaged them as our processor to do. Any use for other purposes is strictly prohibited.
6.6 We will disclose your personal data where we are legally required to do so, for example to tax authorities, or where we need to share your personal data for the purposes of preventing or detecting crime, in connection with legal proceedings, for the purpose of obtaining legal advice or otherwise for the purposes of establishing, exercising or defending legal rights or claims.
7 Where personal data is stored and transferred
7.1 The personal data that we collect will not ordinarily be transferred to, or stored at, a destination outside the UK or the European Economic Area (EEA).
7.2 However, if we do need to transfer your personal data outside the UK or the EEA we will take all steps reasonably necessary to ensure that any such transfer is made securely and that there is adequate protection in place in order to protect your personal data.
7.3 We will also comply with applicable UK and EEA laws designed to ensure the privacy of personal data.
7.4 Please contact us if you wish to find out more; if we ever transfer your personal data outside the UK or the EEA you can ask us for a copy of the relevant safeguards implemented in relation to the transfer.
8 Changes of Business Ownership and Control
8.1 From time to time our business will change and this may involve us selling some or part of that business. If this happens, your details may be disclosed to our advisers and to prospective purchasers or joint venture partners and their advisers.
8.2 The personal data we process may, if it is appropriate, be transferred to any new owner but always under the terms of this Privacy Notice and they will only be allowed to use that Data for the same purposes for which you supplied it to us.
9 Your rights
9.1 You have a number of rights under data protection law. These rights and information about how you can exercise them are set out in this section. We may need to ask you for proof of your identity before we can respond to a request to exercise your rights detailed in this section and we may need to ask you for more information, for example, to help us to identify the personal data that your request relates to. If you seek to exercise your rights we will explain to you whether or not the right applies to you as these rights do not apply in all circumstances.
9.2 We will respond to any requests to exercise your rights as soon as we can and in any event within one month of receiving your request and any necessary proof of identity or further information. If your request is particularly complex, or if you have made numerous requests, we may extend the time we take to respond by up to an additional two months. If this is the case we will let you know as soon as we can and explain why we need to take longer to respond.
9.3 If you would like to exercise any of these rights, please contact us using the details provided in 2.3 above.
9.4 A right to access your personal data – You have a right to ask us for copies of the personal data that we hold about you (subject to some exceptions).
9.5 A right to have inaccurate personal data corrected – You have a right to ask us to correct inaccurate data that we hold about you. If we are satisfied that the new data you have provided is accurate, we will correct your personal data as soon as possible.
9.6 A right to object to us processing your personal data – You have a right to object to us processing any personal data where we are relying on legitimate interests as the legal basis of our processing (as set out in Section 5 above). If you make a request to exercise your right to object but we have compelling legitimate grounds to carry on processing your personal data, we will be able to continue to do so. Otherwise, we will cease processing your personal data.
9.7 A right to have your personal data erased – You have a right to ask us to delete your personal data in certain circumstances, for example, if we have processed your data unlawfully or if we no longer need the data for the purposes set out in this Privacy Notice.
9.8 A right to ask us not to market to you – You can ask us not to send you direct marketing. You can do this by following the “unsubscribe” instructions in any marketing emails we send; by changing your account settings; or by contacting us using the details above.
9.9 A right to have the processing of your personal data restricted – You can ask us to restrict the processing of your personal data in some circumstances, for example, if you think the personal data is inaccurate and we need to verify its accuracy, or if we no longer need the data but you require us to keep it so that you can exercise your own legal rights. Restricting your personal data means that we only store your personal data and don’t carry out any further processing of it unless you consent or we need to process the data to exercise a legal claim or to protect a third party or the public.
10.1 You are important to us, and so is protecting your personal data. We have high standards when it comes to collecting and using personal data. For this reason, we take any complaints we receive from you about our use of your personal data very seriously and request that you bring any issues to our attention by contacting us at email@example.com.
10.2 You also have the right to lodge a complaint with:
· the Information Commissioner’s Officer (which regulates data protection compliance in the UK and provides information for this purpose on its website at www.ico.org.uk); or, if applicable
· a relevant data protection supervisory authority in the EEA state of your habitual residence, place of work or of an alleged infringement of data protection laws in the EEA.
Changes to this Privacy Notice
We may change this Privacy Notice as we decide from time to time or as may be required by law. If we make any changes they will be posted on our website.