1. Who we are and how to contact us
This Privacy Policy explains how Orsman Butchers (“we”, “us”, “our”) collects, uses, shares and protects your personal data when you visit and use our website at https://www.orsmanbutchers.co.uk and when you interact with us in relation to our online services. We are the data controller for the personal data we process about you.
If you have questions about this notice, your personal data, or wish to exercise your rights, please contact our privacy team using the details in section 12.
2. The data we collect
We collect the following categories of personal data, depending on how you interact with us:
- Information you provide to us: name, contact details (such as email address and telephone number), delivery/collection information, order details, account login details (if you create an account), messages you send us (e.g., via forms or email), marketing preferences, and any information you choose to provide in surveys, feedback, or job applications.
- Transaction and payment information: details of products you purchase, purchase amounts and dates, and your chosen payment method. Payment card details are processed by our external payment processor; we do not store full card numbers.
- Device and usage data: IP address, device identifiers, browser type and settings, pages visited, time and date of visits, referring and exit pages, and interactions with our website. This information may be collected via cookies and similar technologies (see section 4).
- Information from third parties: we may receive data from service providers (e.g., payment processors, analytics providers), delivery partners, and publicly available sources to help prevent fraud, deliver orders, and improve our services.
3. Purposes and legal bases for processing
We process your personal data only when we have a legal basis to do so under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The purposes and legal bases are:
- Providing our services and fulfilling contracts (Article 6(1)(b)): to take and manage orders, process payments, provide customer accounts, arrange delivery or collection, and communicate with you about your orders or queries.
- Customer support and service improvement (Article 6(1)(f) – legitimate interests): to respond to enquiries, troubleshoot issues, improve the functionality and user experience of our website and services, and train our staff. Our legitimate interests are to run an effective business and provide a high-quality service.
- Marketing communications (Article 6(1)(a) – consent, or Article 6(1)(f) – legitimate interests, including soft opt-in where permitted by PECR): to send you news, offers, and updates. You can opt out at any time. Where required by law, we will seek your consent before sending electronic marketing.
- Analytics and performance measurement (Article 6(1)(a) – consent): to understand how our website is used, measure the effectiveness of content, and improve our services. Non-essential cookies/analytics will only run with your consent.
- Security, fraud prevention, and misuse detection (Article 6(1)(f) – legitimate interests; Article 6(1)(c) – legal obligation): to protect our website, systems and customers, and to comply with legal requirements.
- Legal and regulatory compliance (Article 6(1)(c) – legal obligation): to comply with tax, accounting and other legal obligations, and to respond to lawful requests from authorities.
- Recruitment (Article 6(1)(b)/(f)): to process job applications and assess candidates.
4. Cookies and similar technologies
Cookies are small files placed on your device when you visit our website. We use:
- Strictly necessary cookies: required for the site to function (e.g., page navigation, security, load balancing). These cannot be switched off.
- Performance/analytics cookies: help us understand how visitors use our site so we can improve it. We only set these with your consent.
- Functional cookies: remember choices you make (e.g., preferences) to provide enhanced features, set with your consent where required.
You can manage cookie preferences via your browser settings and, where provided, our on-site cookie controls. Blocking some cookies may affect site functionality. We do not currently respond to browser “Do Not Track” signals.
5. Who we share your data with
We do not sell your personal data. We may share your data with:
- Service providers (processors): companies that provide hosting, IT support, payment processing, analytics, email/SMS distribution, and customer support tools. They are bound by contracts to protect your data and only process it on our instructions.
- Delivery and logistics partners: to deliver orders and communicate delivery updates.
- Professional advisers: accountants, auditors, insurers and lawyers, where necessary for our legitimate interests and legal obligations.
- Authorities and regulators: where required by law, to comply with lawful requests, or to protect our rights or the rights of others.
- Business transfers: in connection with a merger, acquisition, restructuring or sale of assets, your data may be transferred as part of that transaction, subject to appropriate protections.
6. International transfers
Some of our service providers may be located outside the UK. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, such as:
- An adequacy decision by the UK government for the destination country; and/or
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, including additional safeguards where appropriate; and/or
- Participation in approved transfer frameworks (for example, the UK extension to the EU–US Data Privacy Framework, where applicable).
You can request a copy of the relevant safeguards by contacting us (see section 12). Please note that some details may be redacted for confidentiality.
7. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, and to meet legal, accounting or reporting requirements. Typical retention periods are:
- Orders and transaction records: 6 years from the end of the financial year in which the transaction occurred (or longer if required by law).
- Customer accounts: for as long as the account is active; if closed, core records are retained for up to 6 years, with residual logs retained for security and compliance.
- Customer service enquiries: up to 2 years after resolution.
- Marketing subscriptions: until you unsubscribe; we maintain a suppression list indefinitely to honour opt-outs.
- Job applications: typically up to 6 months after the recruitment process ends, unless you consent to a longer period or a role is offered.
- Website analytics data: according to the lifespan of the cookies or tools in use and any consent you have provided.
8. Your rights
Under the UK GDPR, you have the following rights (subject to conditions and exemptions):
- Access: request a copy of your personal data.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure: request deletion of your data in certain circumstances.
- Restriction: request that we limit how we use your data.
- Portability: receive your data in a structured, commonly used, machine-readable format and request we transfer it to another controller where feasible.
- Object: object to processing based on legitimate interests, including profiling; and object at any time to direct marketing.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time (this does not affect processing before withdrawal).
To exercise your rights, contact us using the details in section 12. We may need to verify your identity. We aim to respond within one month, or notify you if more time is needed due to complexity or volume.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO). Contact details: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113.
9. Data security
We implement appropriate technical and organisational measures to protect personal data, including secure hosting, access controls, encryption in transit (TLS), staff training, data minimisation, and regular review of our security practices. While no system is completely secure, we work to prevent unauthorised access, disclosure, alteration or destruction of your data. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO where required by law.
10. Children’s privacy
Our website and services are intended for adults. We do not knowingly collect personal data from children under 13 years of age. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
11. Automated decision-making
We do not use your personal data to make decisions based solely on automated processing that produce legal or similarly significant effects about you.
12. Controller and DPO contact details
Data controller: Orsman Butchers.
Data Protection Officer (DPO) contact: We are not required to appoint a statutory Data Protection Officer. However, you can contact our Data Protection Contact for all privacy-related queries at: privacy@orsmanbutchers.co.uk
13. Third-party websites
Our website may contain links to third-party websites or services. Those sites are not governed by this Privacy Policy, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party services you use.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will post the updated version on our website and adjust the “Last updated” date below.
Last updated: 28 December 2025