This policy relates to the privacy of your personal data at Catering Management Consultants Limited (CMC).

CMC are the Data Controller.

As we set the rules and reasons for collecting data from you, we are classed as the Controller of your personal data. This means it is our responsibility to ensure that the data we collect is controlled effectively, and protected at all times. Should you have any questions about the processing of your data contact our Data Compliance Manager, Sue Pawley, directly using the following methods:

Mrs S Pawley, CMC, 111 Avondale Road, Darwen, Lancashire BB5 3PN
sue@cmcschoolfood.co.uk

Why we need your personal data and what we need to do with it.

Website Visitors

How we use Cookies, Cookies are very small text files that are stored on your computer when you visit some websites.

We only use cookies to: Track the pages you visit via Google Analytics and to remember your login details for the system to operate correctly.

The CMC website will not share any personal information with third parties.

CMC TRACKER

Our in-House operations system covering all legal and financial systems will store client and catering staff information relevant to the use of the system. 

Data and personal information used in this system is stored in the United Kingdom.

CMC TRACKER will not share any personal information with third parties.

Safety Culture & EdApp Software

CMC use the software provided by “Safety Culture” to compile client audits and “EdApp” to supply a training platform used by school staff. These systems will therefore store client and catering staff information relevant to the use of the system. 

Data and personal information used in this system is stored in the United States we ensure a lawful transfer mechanism applies. The recipient is certified to the UK-US data bridge.

Food Safety Training 

CMC staff use personal information of school staff to deliver Food Safety Training. We work in partnership with Highfield Training to deliver this training and in the process share this information.

Data and personal information used by CMC staff is stored in the United States we ensure a lawful transfer mechanism applies. The recipient is certified to the UK-US data bridge.

Data and personal information passed to Highfield Training is stored in the United Kingdom using processes at least on a par with that of CMC.

Primary Authority Partnership (PAP)

CMC work in partnership with City of Wolverhampton Council, Environmental Health to deliver Primary Authority Partnership. PAP is an agreement between a business and a single local authority to provide a single point of contact to ensure consistent regulation and enforcement in all CMC schools. In order to achieve this client / school information needs to be shared.

Data and personal information used by CMC staff is stored in the United States we ensure a lawful transfer mechanism applies. The recipient is certified to the UK-US data bridge.

Data and personal information passed to City of Wolverhampton Council, Environmental Health is stored in the United Kingdom using processes at least on a par with that of CMC.

Personal Data

Your personal data will be managed in accordance with the UK General Data Protection Regulation (UK GDPR) under the following principles:

1. Lawfulness, Fairness and Transparency:

We are required to process your personal data as part of the performance of your contract with CMC.

2. Purpose Limitation:

Your data will only be collected for specified, contractual and legitimate purposes meaning that as well as using the data to perform your contract, we may use it for:

      • CMC Focus updates
      • Marketing Purposes – as a reference contact for potential customers, in case studies with your approval or on social media with your approval, unless you tell us not to do so.
      • Other products/services provided by CMC that we may offer to you unless you tell us not to do so

3. Data Minimisation:

We will not ask for more information than we need for the purposes for which we are collecting it.

4. Data Accuracy:

We will update our records when you inform us that your details have changed.

5. Storage Limitation:

We keep personal data only as long as necessary for the purposes collected. Certain records (e.g., finance/tax) are kept for six years to meet legal duties.

6. Integrity and Confidentiality:

We have implemented  processes to protect the integrity and confidentiality of your personal data

Policies and processes we have to protect your rights as the ‘Data Subject’ 

Under UK GDPR you have a number of ‘rights’ which you can exercise at any time.  Should you wish to do so, please contact the person named at the end of this Notice. These rights might include:

  • the right to access all of the data we process on you. This will be supplied to you within 30 days from the request being received.
  • the right for any inaccurate data we hold on you to be corrected. We will make your amendments without undue delay
  • Where the contract has ended but consent has been obtained to process your data, you may have the right to be forgotten and your personal data to be erased without undue delay. Where we require your data (for contractual reasons), your data will be removed once the term of the contract has expired
  • the right to restrict us from processing your personal data, which can be reversed by you
  • the right in certain circumstances to object to automated decision making, whereby we may use your data for profiling purposes to make a decision.

Transferring personal data 

Due to the nature of the business, we work with a variety of UK GDPR compliant businesses who act as our processors which store and process your personal data on our instructions. Below is a list of the types of processors that we share your data with:

  • Website hosting companies
  • Produce and product suppliers
  • Training companies
  • Information Technology companies
  • Software Companies
  • Secured servers

International Transfers

Where we transfer data outside the UK, we’ll ensure a lawful transfer mechanism. For the US, we transfer only to recipients certified under the UK-US data bridge (UK extension to the EU-US DPF)

Talking to us about your rights or this Notice

Should you wish to speak to us about the way we process your data, or wish to exercise your rights as listed above, please contact our Data Compliance Manager, Sue Pawley, directly using the following methods: 

Mrs S Pawley, CMC, 111 Avondale Road, Darwen, Lancashire BB3 1NT

sue@cmcschoolfood.co.uk