What is this notice for?
This notice explains what we do with your personal data and the steps we take to keep it secure. It explains when and how we collect personal data, who we share it with, how we process it and what your rights are in respect of the personal data processing we carry out.
Who is Greene King?
As the country's leading pub retailer and brewer, Greene King welcomes customers into our 3,000 pubs, restaurants and hotels across the UK and brews a range of award-winning ales. Our products and services trade under a wide range of well-known brands, including Greene King, Hungry Horse, Farmhouse Inns, Chef & Brewer, Flaming Grill, Old English Inns, Greene King IPA and Old Speckled Hen. More information about all of our brands can be found on our home page.
When we say ‘we’, ‘us’ or ‘our’ in this notice, we are referring to Greene King Brewing and Retailing Limited. We are the data controller in respect of this website. Our ICO registration number is ZA054235.
When do we use your personal data?
We process some of your personal data in the following circumstances:
- when you use this website
- when you contact us with potential sites for us to consider
- if we pay you a finder’s fee
We don’t keep your personal data for any longer than we need it. See our section on retention periods below for more details.
Sometimes we need to share your personal data with other Greene King companies or with other organisations that help us provide our products and services to you. We will not sell your personal data and we do not allow these organisations to use your personal data for anything that’s not described in this notice. We might also need to share your personal data to uphold your rights, our rights or the rights of other people and we may need to share your personal data to meet some of our legal obligations. See the data sharing section for more details.
You can find out more about how we meet our data protection law obligations below. This section also explains what rights you have in respect of the personal data processing we do, and how you can exercise them.
How can you contact us?
If you want to discuss how we use your personal data
- Write to us at Guest Relations, Greene King, Sunrise House, Ninth Avenue, Burton-upon-Trent, Staffordshire, DE14 3JZ
- Send an email to email@example.com
- Call us on 01283 498400
If you want to contact our Data Protection Officer
- Write to the Data Protection Officer, Greene King, Westgate Brewery, Bury St Edmunds, Suffolk, IP33 1QT
- Send an email to firstname.lastname@example.org
- Call us on 01284 763222
How do we use your personal data?
When you use our website
When you contact us with potential sites for us to consider
We will ask for your name, telephone number and email address so that we can liaise with you further about your suggestion and so that we can get in touch again if we agree to pay you a finder’s fee. We will also ask for details of the site you are proposing and your relationship with it.
When we pay you a finder’s fee
We will need your bank details to be able to pay a finder’s fee.
How long do we keep your personal data for?
|Information about||Is kept until|
|When you use our website||
|When you contact us with potential sites for us to consider||
For one month from your initial contact or, if it is a site we are interested in, in accordance with the time period below.
|If we pay you a finder’s fee||
For 6 years from the date of payment.
Who do we share your personal data with?
Other Greene King companies
Any of the information we collect from you may be shared with other companies within the Greene King group:
|Greene King plc||
This is the holding company in the Greene King group
Westgate Brewery, Bury St Edmunds, Suffolk IP33 1QT
|Greene King Services Limited||
This company employs the group’s employees who may be dealing with your proposal
Each of these companies is bound by the terms of this privacy notice and they are also required to comply with our data protection policies. They are not permitted to use your personal data for their own purposes.
Organisations who help us to provide our products and services
We work with a number of third-party suppliers and service providers. Many of these organisations process personal data in order to provide products or services to us or on our behalf. See the third-party data sharing list below for more details.
|Organisation||Contact details||Data shared||Reason for sharing||International data transfers|
Whitestone Retail and Leisure Limited
Egerton House, 55 Hoole Road, Chester, CH2 3NJ
Name, telephone number, email address, and details of the site you are proposing
To help find sites that may be of interest to us for development
These organisations are bound by the terms of this privacy notice and they are also required to comply with our data protection policies. They are not permitted to use your personal data for their own purposes.
International data transfers
Some of the third parties we work with have operations in countries outside of the European Union or the European Economic Area. Before your personal data is transferred outside of these regions, we implement at least one of the following safeguards:
- We check whether the personal data is being transferred to a country that has been deemed to provide an adequate level of protection by the European Commission.
- Where we use third parties based in the United States, we check if they have signed up to the Privacy Shield framework. This framework requires signatories to provide a similar level of protection to personal data as would be the case if the personal data remained within the European Union or European Economic Area.
- We may use specific contracts approved by the European Commission which give personal data the same protection as it has in the European Union and European Economic Area.
- If we are unable to apply any of the first three safeguards, we will try to contact you to ask for your consent before we transfer your personal data.
Other situations that may require us to share your personal data
We will share your personal data if we are required to do so by law or by a regulatory authority. For example, we may have to share your personal data for the detection or prevention of crime, fraud or money laundering, or to allow a regulator or ombudsman to investigate a complaint you have submitted to them.
We will share your personal data if we need to do so to protect our business interests, such as to enforce the terms of a contract, pursue an overdue debt or defend our legal rights.
As we develop our business, we might sell or buy group companies or other businesses. This might involve transferring customer information to the person buying the businesses. If this happens, the new owner will be bound by the terms of this privacy notice.
Occasionally, we may need to share your data to protect the rights of other organisations or people. In these cases, we will try to contact you to seek your consent first but this may not be possible, especially in the event of a medical or other emergency.
How do we comply with data protection law?
We have adopted the measures that we believe are necessary to comply with the Data Protection Act 1998 and we are preparing for the act’s replacement, which will fully embed the General Data Protection Regulation into UK law.
We have also adopted the measures that we believe are necessary to comply with the Privacy and Electronic Communications Regulations 2003. This law sets out an additional set of rules that we must follow whenever we communicate with you via any of our websites and apps, or by telephone, fax, email or text message.
Protecting your data
We protect the personal data we hold from theft, accidental loss, corruption and other threats that would have a negative impact on our customers. These protective measures include:
- Not collecting personal data that we don’t really need
- Destroying or anonymising personal data securely when we don’t need it any more
- Only allowing our staff and our suppliers to process the personal data they need to carry out their duties
- Encrypting personal data to render it useless to anyone who is not authorised to access it
- Making sure that staff are trained on how to handle personal data safely and securely and are fully aware of their personal responsibilities
- Binding our suppliers and partners to the same standards and duties of care that we hold ourselves to
- Protecting our websites, networks and IT systems from unauthorised access and from threats such as denial of service attacks, viruses and malware
- Making periodic checks that all of these measures are working well and making improvements to them when we think we can do better
Being accountable for what we do
As well as the security measures mentioned above, we have a team of people whose job it is to make sure that Greene King does the right thing the right way whenever we’re processing personal data. This team includes a Data Protection Officer, who can be contacted using the contact details set out above.
There are a set of checks we apply to make sure we process personal data fairly and transparently. These include:
- Providing you with clear and accurate information about why we need your personal data, what we do with it and how long we keep it for
- Checking that our business interests don’t unfairly or unreasonably impact upon you or your rights
- Identifying personal data processing risks and reducing them to an acceptable level
- Responding honestly, clearly and promptly to enquiries we receive from you or from the Information Commissioner’s Office
Making sure our processing respects the law
The ICO have published a helpful guide to lawful bases for the general public which you can find on their website – www.ico.org.uk . The lawful bases we rely on for the processing we do are shown in bold typeface in this table:
|When you use our website||
We process this personal data because it is in our legitimate interests to provide a fully-functioning, accessible and useful website to our customers.
|When you contact us with a potential site for us to consider||
We do this because it is in our legitimate interests to obtain information from you about sites that may be of interest to us.
|If we pay you a finder’s fee||
This processing is carried out in accordance with a contract with you
Data protection laws give you certain rights and as a responsible data controller, we are committed to uphold these for you:
|Name of right||Description||How to make a request|
You have the right to know what we want your personal data for, what we will do with it, who we share it with and how long we keep it for. This is the primary reason for publishing this notice.
Send any questions you have about our privacy notices to email@example.com
You have the right to be sent information about the personal data we have about you and a description of what we are using it for. This is also known as a ‘subject access request’, ‘SAR’ or ‘DSAR’.
Send your request to firstname.lastname@example.org
You have the right to ask us not to process inaccurate personal data or to ask us to correct it.
Send your request to our email@example.com
Some conditions and limits apply to these rights: you can find out more about these on the ICO website.
|Erasure (‘right to be forgotten’)||
You have a right in certain situations to ask us to delete your personal data.
You have a right in certain situations to ask us not to process your personal data.
|Object to processing||
You have the right in certain circumstances to object to the fact that we are processing some of your personal data.
You have the right in certain circumstances to ask us to pass some of your personal data to another data controller on your behalf.
You have a right to lodge a complaint with the UK Information Commissioner’s Office or in some situations, another European Union data protection authority.
Send your complaint to the ICO.
Most of the personal data processing we do does not rely on your consent to make it lawful but any consent that we are relying on can be withdrawn by you if you decide you wish to do so.
Follow the unsubscribe instructions in any of the marketing messages we have sent you or send your request to firstname.lastname@example.org
Detailed information about all of these rights can be found on the ICO website.
Responding to your questions
When you notify us that you want to exercise any of your rights, we will acknowledge your request as soon as possible and ask for any information we may need to verify your identify: if we don’t already know who you are, we will ask you to send us a copy of your passport or photo-card driving licence, so that we can check your name, address and signature.
Once we have confirmed your identity, we will validate your request then gather together the information we need to be able to respond fully to it.
Whilst we always try to carry out this work as quickly as possible, it may take us up to 30 days to respond to you in full. If your request is particularly difficult to respond to, we may ask you for any further information that will help us respond more quickly, or ask you if there is some information that you want particularly urgently. We may also respond to your request in phases, as relevant information becomes available.
If we cannot satisfy your request within 30 days, we will write to you to tell you why, and when we expect to be able to provide you with a full response. If for any reason we decide that we should not respond in the way you have asked us to, we will provide you with our decision and our reasons for reaching it within 30 days.
Changes to this privacy notice