Privacy Policy & Data Protection Declaration
Effective Date: May 12, 2026. Version 4.1 (UK Compliance Bundle)
1. Data Stewardship Principle
ZENOBIA STREET FOOD LTD ("the Company", "we", "us") operates under a principle of radical transparency regarding user data. In accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we act as both the Data Controller and Data Processor for information collected through this portal and our physical points of sale at Hoults Estate.
2. Information Collection & Justification
We process personal data only when a clear legal basis exists. This includes: (a) Contractual Necessity: Processing your address and payment details to deliver food. (b) Legal Obligation: Retaining financial records for HMRC (7 years). (c) Consent: Opting into our Gastronomy Journal. (d) Legitimate Interest: Analyzing anonymized heatmaps of Newcastle delivery zones to optimize our electric vehicle routes.
3. Technical & Organizational Measures (TOMs)
Our servers utilize AES-256 encryption at rest. All payment processing is outsourced to PCI-DSS Level 1 certified gateways (Stripe/PayPal), meaning Zenobia personnel never see or store your full card details. We conduct bi-annual penetration tests on our Unit 5 infrastructure to ensure the Newcastle hub is a digital fortress.
4. Your Statutory Rights
Under UK law, you possess the Right to Access (Subject Access Request), the Right to Rectification, the Right to Erasure ("Right to be Forgotten"), and the Right to Data Portability. To exercise these rights, email our Data Protection Officer at info@geelongwealth.sbs with the subject "SAR - [Your Name]". We resolve all requests within 30 calendar days at no cost to the subject.
... [Document continues with further 1000+ words on international transfers, cookies, and liability limits] ...