GDPR Compliance Policy
Last Updated: April 03, 2026
1. Introduction
Yummyplateworld (the “Company”, “we”, “our”, or “us”) is committed to protecting the privacy and personal data of our users and visitors in accordance with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679) and applicable national laws. This policy explains what personal data we collect, why we process it, how we protect it, and your rights as a data subject.
2. Data We Collect
- Email addresses: Collected when you register for an account, subscribe to newsletters, or place an order.
- Cookies: We use first‑party and third‑party cookies to enhance your browsing experience, remember your preferences, and analyze site usage.
- Analytics data: We employ services such as Google Analytics to collect anonymous usage statistics, which help us improve our website and services.
3. How We Protect Your Data
We implement robust technical and organisational measures to safeguard your personal data:
- SSL/TLS encryption: All data transmitted between your browser and our servers is encrypted using HTTPS.
- Secure servers: We host data on reputable, geographically diverse data centres with redundant power, fire suppression, and physical access controls.
- Limited retention: Personal data is retained only as long as necessary to fulfil the purposes for which it was collected, or as required by law.
- Access controls: Only authorised personnel with a legitimate business need may access personal data. All staff undergo regular privacy and security training.
4. Legal Basis for Processing
We process personal data on one or more of the following lawful bases:
- Consent: When you explicitly opt‑in to receive marketing communications or provide data for account creation.
- Legitimate interest: For improving our services, ensuring website security, and complying with legal obligations.
5. Your GDPR Rights
Under the GDPR, you have the following rights with respect to your personal data. We will respond to any request within 30 days of receipt.
- Right to Access: You may request a copy of the personal data we hold about you, including the purpose of processing, categories of data, and recipients.
- Right to Rectification: You can request correction of inaccurate or incomplete data. We will verify the request before updating.
- Right to Erasure: Also known as the “right to be forgotten”, you may ask us to delete your personal data, provided no legal obligations prevent it.
- Right to Restrict Processing: You may request that we temporarily suspend processing of your data, for example while we verify its accuracy.
- Right to Data Portability: You can obtain your personal data in a structured, commonly used format and transfer it to another controller.
- Right to Object: You may object to the processing of your data for direct marketing, profiling, or other purposes, and we will cease processing unless we have a compelling legitimate interest.
- Right to Withdraw Consent: You may withdraw any previously given consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
6. How to Exercise Your Rights
To exercise any of the rights listed above, please contact our Data Protection Officer via email at [email protected]. In your message, specify:
- Your full name and contact details.
- The specific right you wish to exercise.
- Any supporting documentation that verifies your identity.
We will acknowledge receipt of your request within 5 business days and provide a response within 30 days, unless the request is complex, in which case we may extend the period by an additional 30 days, with a maximum total of 60 days.
7. Data Retention
We retain personal data for the period necessary to fulfil the purposes for which it was collected, including:
- Account maintenance and transaction records – up to 7 years.
- Marketing communications – until consent is withdrawn.
- Legal and regulatory compliance – as required by law.
8. Contact Information
If you have any questions about this policy or wish to lodge a complaint with a supervisory authority, please contact us:
Email: [email protected]
Address: Yummyplateworld Ltd., 123 Flavor Street, Culinary City, 45678, United Kingdom
9. Updates to This Policy
We may update this policy from time to time to reflect changes in our data practices or legal requirements. The “Last Updated” date at the top of this page indicates the most recent revision. We encourage you to review this policy periodically.