Privacy Policy
This Privacy Policy explains how Starlight Feast Catering ("we", "us", or "our") collects, uses, discloses, and protects your personal data when you use our catering services, visit our website, interact with us on social media, or otherwise communicate with us. We are committed to protecting your privacy and handling your personal data in accordance with applicable data protection laws in England, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- Who We Are Starlight Feast Catering is a catering service provider operating in England. We act as the data controller for the personal data we process about our clients, prospective clients, suppliers, website visitors, and other individuals who interact with us.
If you have any questions about this Privacy Policy or our data protection practices, you can contact us using the contact details provided in section 12 of this Policy.
- What Personal Data We Collect The personal data we collect depends on how you interact with us and the services we provide. We may collect and process the following categories of personal data:
2.1 Identification and Contact Details
- Full name
- Address and postcode
- Email address
- Telephone number or mobile number
- Company name and role (for corporate clients)
2.2 Booking and Service Information
- Event date, time, and location
- Type of event (e.g. wedding, corporate event, private party)
- Number of guests
- Catering preferences and requirements
- Budget and payment preferences
2.3 Dietary and Special Requirements
- Dietary preferences (e.g. vegetarian, vegan)
- Food allergies and intolerances
- Religious or cultural dietary restrictions We collect this information only to the extent necessary to provide safe and appropriate catering services. As some of this may be considered special category data (e.g. information that may reveal religious beliefs or health conditions such as allergies), we process it with additional safeguards and only with your explicit consent or where otherwise permitted by law.
2.4 Payment and Financial Data
- Limited payment details needed to process transactions (e.g. partial card details, billing address) We typically use secure third-party payment processors and do not store full payment card details on our systems.
2.5 Communication and Correspondence
- Records of inquiries, complaints, feedback, and other communications
- Emails, messages via our website contact forms, and social media messages
2.6 Website and Usage Data When you visit our website, we may automatically collect certain information, including:
- IP address
- Browser type and version
- Device type and operating system
- Referring pages and URLs
- Pages visited, time and date of visit, and time spent on pages This data is typically collected via cookies and similar technologies. For more details, please refer to our Cookie Policy (if applicable).
- How We Use Your Personal Data We use your personal data for the following purposes and on the legal bases set out below:
3.1 To Provide and Manage Our Services
- To process inquiries and bookings
- To plan and deliver catering services
- To manage events and coordinate logistics
- To communicate with you about your bookings Lawful basis: performance of a contract or steps taken at your request prior to entering into a contract; legitimate interests.
3.2 To Process Payments and Invoicing
- To process payments for services
- To issue invoices and receipts
- To manage refunds and billing queries Lawful basis: performance of a contract; legal obligation (e.g. accounting and tax requirements).
3.3 To Manage Dietary Requirements and Allergies
- To provide safe and appropriate menu options
- To avoid ingredients that could cause allergic reactions Lawful basis: explicit consent; vital interests; or other legal bases permitted under UK data protection law for special category data.
3.4 Customer Support and Communication
- To respond to questions, requests, and complaints
- To send important service messages, such as changes to bookings or terms Lawful basis: performance of a contract; legitimate interests.
3.5 Marketing and Promotions
- To send you information about our services, offers, and events, where permitted
- To conduct surveys, gather feedback, and improve our services Lawful basis: consent (where required); legitimate interests (in promoting and developing our business, where local law allows). You can opt out of marketing communications at any time by following the unsubscribe instructions in our messages or by contacting us.
3.6 Website Administration and Improvement
- To operate, maintain, and improve our website and services
- To monitor usage and analyse trends
- To ensure the security of our systems Lawful basis: legitimate interests (in running and improving our business and website; maintaining security).
3.7 Legal and Regulatory Compliance
- To comply with applicable laws and regulations
- To respond to lawful requests from authorities
- To establish, exercise, or defend legal claims Lawful basis: legal obligation; legitimate interests.
- Cookies and Similar Technologies
We may use cookies and similar technologies on our website to:
- Remember your preferences
- Analyse website traffic and usage patterns
- Improve user experience and website performance
Where required by law, we will ask for your consent before placing non-essential cookies on your device. You can manage your cookie preferences through your browser settings or our cookie management tool (if available). Disabling some cookies may affect the functionality of our website.
- How We Share Your Personal Data We do not sell your personal data. We may share your data with the following categories of recipients, but only where necessary and with appropriate safeguards:
5.1 Service Providers and Business Partners
- Payment processors
- IT and hosting providers
- Email and communication platforms
- Event venues or coordinators involved in your booking
- Professional advisers (e.g. accountants, legal advisers)
These third parties may only process your personal data on our instructions and are required to keep it secure and confidential.
5.2 Legal and Regulatory Recipients We may disclose personal data if required to do so by law, or if we reasonably believe that such action is necessary to:
- Comply with a legal obligation
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing
- Protect the personal safety of clients or the public
5.3 Business Transfers In the event of a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to a new owner or successor business, subject to appropriate confidentiality safeguards and continued protection in line with this Privacy Policy.
-
International Data Transfers We primarily process personal data within the United Kingdom. If we transfer your personal data outside the UK (for example, because a service provider is located in another country), we will ensure that an adequate level of protection is in place, in accordance with UK data protection law. This may include:
- Transfers to countries that have been deemed to provide an adequate level of protection by the UK government
- Using standard contractual clauses approved by the UK authorities
- Implementing other appropriate safeguards
-
Data Retention We only keep your personal data for as long as is reasonably necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
In determining appropriate retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which we process it
- The potential risk of harm from unauthorised use or disclosure
- Applicable legal obligations and limitation periods for claims
Once personal data is no longer required, we will securely delete, anonymise, or destroy it.
- How We Protect Your Personal Data
We take appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include:
- Access controls and authentication
- Secure networks and encryption where appropriate
- Regular backup and system monitoring
- Staff training and confidentiality obligations
However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
- Your Data Protection Rights Under the UK GDPR and related laws, you have certain rights regarding your personal data. These may include:
9.1 Right of Access You can request confirmation as to whether we process your personal data and, where we do, request a copy of the data and certain information about how it is used.
9.2 Right to Rectification You can ask us to correct inaccurate or incomplete personal data that we hold about you.
9.3 Right to Erasure In certain circumstances, you can ask us to delete your personal data, for example where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent (where consent was the legal basis).
9.4 Right to Restriction of Processing You can ask us to restrict the processing of your data in certain circumstances, such as where you contest its accuracy or object to our use of it.
9.5 Right to Data Portability Where we process your personal data on the basis of consent or a contract and by automated means, you can request that we provide your data in a structured, commonly used, and machine-readable format or that we transmit it to another controller where technically feasible.
9.6 Right to Object You can object, on grounds relating to your particular situation, to our processing of your personal data where we rely on legitimate interests. You also have the right to object at any time to processing for direct marketing purposes.
9.7 Rights in Relation to Automated Decision-Making We do not typically use your personal data for automated decision-making that produces legal or similarly significant effects. If this changes, we will inform you and explain your related rights.
9.8 Right to Withdraw Consent Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing carried out before consent was withdrawn.
To exercise any of your rights, please contact us using the details in section 12. We may need to verify your identity before responding to your request.
-
Children’s Privacy Our services are generally intended for adults. We do not knowingly collect personal data from children under 13 without appropriate parental or guardian consent. If you believe that a child has provided us with personal data without such consent, please contact us and we will take steps to delete such information where required.
-
Links to Other Websites Our website may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices or the content of such third-party sites. We encourage you to read the privacy policies of any third-party sites you visit.
-
Contact Details If you have any questions about this Privacy Policy, our data practices, or if you wish to exercise your data protection rights, you can contact us at:
Starlight Feast Catering Data Protection Enquiries: [Insert contact email or address]
Please include enough information to identify yourself and the nature of your request.
- Complaints and Your Right to Contact the ICO If you are unhappy with how we handle your personal data, please contact us first so we can try to resolve your concerns. You also have the right to lodge a complaint with the UK data protection authority:
Information Commissioner’s Office (ICO) Website: https://www.ico.org.uk Telephone: +44 (0)303 123 1113
- Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this document and, where appropriate, notify you by email or by a notice on our website.
Please review this Privacy Policy periodically to stay informed about how we protect your personal data.