WEBSITE PRIVACY POLICY
This Website Privacy Policy explains how: (i) Pilgrim’s Food Masters UK Limited and/or Pilgrim’s Food Masters Ireland Limited (‘we’, ‘us’, ‘our’) handle and use information collected about you as data controller.
This policy (together with our website terms of use and any other documents referred to in it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. This website is not intended for children and we do not knowingly collect data relating to children.
We will comply with our obligations under the relevant data protection laws, including the: (i) EU General Data Protection Regulation ((EU) 2016/679) (‘EU GDPR’; (ii) UK General Data Protection Regulation (as defined in The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019) (‘UK GDPR’); and (iii) Data Protection Act 2018, and any subsequent legislation when handling your personal data (the ‘Data Protection Law’).
Overall responsibility for this Website Privacy Policy is Group Privacy Officer who can be contacted at gpo@pilgrimssharedservices.com
Information we collect about you
We may collect, store and process the following data about you when you use our website, contact us or enter into any contractual arrangement with us:
How do we gather the data we hold about you?
Directly from you- the majority of the data we hold about you will have been provided to us by you during your interactions and communications with us and with our website.
Automatic Collection – as you use our website we may automatically collect Technical Data as stated above by using server logs and cookies.
Cookies – our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. For detailed information on the cookies we use and the purposes for which we use them see our Cookie Policy [www.moypark.com/footer/our-cookie-policy].
Third Parties and Publicly available sources – this is the information we receive about you if you use any of the other websites we operate or the other services we provide (including, without limitation, our pages on Facebook and Twitter and any other social media services from time to time). We are working closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies). We will receive personal data about you from various third parties and public sources as set out below:
Use and lawful basis of processing of the information
Generally we will use the information we gather about you in accordance with the following lawful bases of processing
Processing of Special Category Data
In the rare circumstances that you have provided us with special category data for example relating to your health or medical conditions, we will use this information to ensure we comply with our health and safety obligations or where it is required in relation to any legal or insurance claims relating to you.
Information that may be shared with third-parties.
Your personal data will be accessed by authorised staff who need to have access to that information. In order to pursue the above purposes your personal data may be made available to recipients providing relevant services to us, such as IT software providers, insurers and legal advisers or government authorities as required by law. Such service providers will only process the personal data in accordance with our instructions.
We utilise the services of Pilgrim’s Shared Services Ltd (PSSL) to provide IT, accounts and payments and other key function services which means that we may share your information with PSSL who are bound by terms of confidentiality and must meet the our standards in regards data protection. PSSL will acting as the data processor for the us in this respect. We will also share your information as necessary with our UK based sister companies including Pilgrim’s Pride Limited, Pilgrim’s Food Masters Limited and Pilgrim’s Food Masters Ireland Limited and their affiliates.
We may also disclose your personal data to third parties if we are under a duty to disclose or share your personal data in order to comply with any legal obligation; or in order to defend or make any legal claim; or to protect the rights, property or safety of the business, employees, customers or others. Personal data may also be disclosed to external parties in connection with any external third party regulatory or customer audits, sale or purchase of the business or assets, as well as to parties you authorise us to disclose your personal data to. We will not sell your personal data to any third party.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
We may transfer the personal data we collect about you outside of the UK or EEA to a country that may have privacy protections less stringent than in the EEA or UK. For instance, we may transfer your personal data to our parent company, Pilgrim’s Pride Corporation (‘PPC’), and its majority shareholder, JBS USA, (both based in the United States of America) in order to: (i) perform our contract with you including processing invoices and making payments and contract administration: (ii) as part of our regular reporting activities on company performance; (iii) for system maintenance support and hosting of data; (iv) IT and website support.
Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us using the details at the bottom of this policy if you want further information, or copies, on the specific mechanism used by us when transferring your personal data out of the UK.
We provide access to an ethical helpline which offers an outlet for any concerns you might have in relation to our operations that you cannot or do not feel able to raise in other ways. In order to provide an element of confidentiality, this ethics line is operated by a third-party processor. The third-party processor providing the ethics line is currently based in the EEA but the helpline is administered PPC and JBS USA acts as the Data Controller and should you choose to use this service you will be provided with privacy information relating to the use of that service when logging your concern.
You will appreciate that in order to investigate and deal with some cases it will be necessary for the information you provide, which may include personal data, to be provided to us or other companies in our group. We will use the data in the investigation of the matters to which it relates and will handle your data during such investigations in accordance with this privacy policy.
How long we store your data
Data will be retained only as long as is necessary and in accordance with the personal data retention periods set out in our Retention Guidelines. Please contact us using the details at the bottom of this policy if you would like further information on how we retain data.
Automated decision making
Automated decision-making takes place when an electronic system uses personal data to make a decision without human intervention. You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making unless we have a lawful basis for doing so. Where your data is subjected to automated processing, we will inform you in advance.
Your rights
Under certain circumstances, by law you have the right to:
In addition, in the limited circumstances where you may have provided your Consent to the processing of your personal information, you have the right to withdraw your Consent at any time. This will not affect your contractual relationship with us.
Some of these rights are not automatic, we reserve the right to discuss with you why it might not comply with a request. If you want to exercise one of the above rights, please contact us using the details at the bottom of this policy.
Complaints
You retain the right to lodge a complaint about our management of your personal data to the relevant supervisory authority, including:
Changes to our privacy policy
Any changes we make to our privacy policy in the future will be posted on this page. Please check back frequently to see any updates or changes to our privacy policy.
Contact us
Questions, comments, concerns and requests regarding this privacy policy or our collection or use of your information are welcomed and should be addressed to the Group Privacy Officer at gpo@pilgrimssharedservices.com or by post to Seton House, Warwick Technology Park, Gallows Hill, Warwick, CV34 6DA.
As part of our customer and supplier due diligence , you may be asked to complete a Supplier Completion Form- Compliance, a Business Intermediary Due Diligence Request Form or a Due Diligence Questionnaire and provide associated information as a potential customer or supplier (“ Due Diligence Information”) to a company in the Moy Park and Pilgrims Group including Moy Park Limited, Kitchen Range Foods Limited, Pilgrim’s Pride Ltd, Pilgrim’s UK Lamb Limited, Pilgrim’s Shared Services Ltd, Pilgrim’s Food Master’s UK Limited, Pilgrim’s Food Masters Ireland Limited, Oakhouse Foods Limited, Rollover Limited, Albert Van Zoonen BV, Moy Park France SAS and Moy Park Beef Orleans SARL and their affiliated companies (each described as “ we/ the Company” individually and collectively as “the Group”).
The particular Group company that you are establishing a business relationship with will be the “Data Controller” and you will be the “Data Subject” as defined under EU and UK GDPR of any personal data you provide in response to the Due Diligence Information and in response to any other information provided to us as part of the Company customer and supplier set up process.
The Company will comply with our obligations under the relevant data protection laws, including the: (i) EU General Data Protection Regulation ((EU) 2016/679) (‘EU GDPR’; (ii) UK General Data Protection Regulation (as defined in The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019) (‘UK GDPR’); and (iii) Data Protection Act 2018, and any subsequent legislation (together the ‘Data Protection Law’) when handling your personal data ( as defined by the Data Protection Law).
Overall responsibility for monitoring compliance with data protection sits with the Privacy Steering Group, the main contact of which is the Group Privacy Officer (who can be contacted at gpo@pilgrimssharedservices.com).
Due Diligence Information that you have provided to the Company by completing the due diligence forms or as part of any associated tender or other pre-contract processes, communication, correspondence, or enquiries. We may also gather information about you from other third parties such as credit refence agencies and third party agencies that we use as part of our due diligence and compliance processes for example to screen against international sanctions lists and to complete appropriate due diligence in compliance with our Anti-Bribery and Anti-Corruption Policy and all applicable anti-bribery and anti-corruption laws and guidance. Occasionally we may sometimes collect additional information from publicly available sources, such as Companies House or publicly available internet and social media sites. To the extent that the information gathered falls into the category of personal data, this is collectively referred to as your personal data in the notice.
The Due Diligence Information will be used by the Company to help achieve compliance with anti-corruption laws including the UK Bribery Act 2010 and the United States Foreign Corrupt Practices Act. The questions have been tailored to seek only information that is relevant to the Group’s anti-corruption compliance efforts. The lawful basis for processing this data is to comply with our legal obligations and for our legitimate business interests of the Company which include ensuring that we complete appropriate due diligence on customers and suppliers to ensure we comply with our internal compliance processes and policies, and we believe that these legitimate business interests are not incompatible with your rights and freedoms.
We will not normally process Special Category Personal Data or data relating to criminal offences save for in the following circumstances:
We will use information about you to determine your suitability to become an approved customer or supplier to the Company in compliance with our legal obligations and internal compliance processes.
The provision of any personal data as part of the Due Diligence Information is required for us to complete our customer and supplier due diligence processes prior to entering into a contract with you as a customer or supplier. You do not have to supply the information but a refusal to provide this personal data may prevent us from being able to process your enrollment onto our systems as a customer or supplier which may prevent us from entering into a contract with you.
Automated decision-making takes place when an electronic system uses personal data to make a decision without human intervention. You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making unless we have a lawful basis for doing so. Where your data is subjected to automated processing, we will inform you in advance.
Your personal data will be accessed by authorised staff at the Company who need to have access to that information to complete customer and supplier due diligence checks which will include relevant members of the supply chain, finance, commercial, legal and compliance teams.
The Company utilises the services of Pilgrim’s Shared Services Ltd (PSSL) to provide IT, finance, supply chain and legal and compliance support and other key function services which means the Company shares your information with PSSL who are bound by terms of confidentiality and must meet the Company standards in regards data protection. PSSL will be acting as the data processor for the Company in this respect. We will also share your information as necessary with our UK based sister companies.
We may also have to share your data with third parties, including third-party service providers and other entities in the group or where required by law, where it is necessary to administer the working relationship with you or where we have another legitimate interest in doing so. The following activities are carried out by third-party service providers:
We require third parties to respect the security of your data, to take appropriate security measures and to treat it in accordance with the law. We only permit third parties to process your personal data for specified purposes and in accordance with our instructions.
We may transfer the personal data we collect about you outside of the UK or EEA to a country that may have privacy protections less stringent than in the EEA or UK. For instance, we may transfer your personal data to our parent company, Pilgrim’s Pride Corporation (‘PPC’), and its majority shareholder, JBS USA, (both based in the United States of America) in order to complete due diligence checks on you and to report on our compliance with Anti-Bribery and Anti-Corruption laws or any related audit. We also use third-party processors to carry out due diligence and profile checks on potential customers and suppliers who are based in the United States of America.
In the absence of an adequacy decision from the EU Commission or UK Parliament, we will implement measures to ensure that your personal data receives an adequate level of protection, such as EU standard contractual clauses or UK International Data Transfer Agreement, together with technical and organizational safeguards to ensure that your personal data is treated in a way that is in compliance with and which respects the EU and UK laws on data protection. For further information, or to request copies, about the data transfer agreement or the safeguards in place please contact the Group Privacy Officer.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected the personal data for, including for the purposes of satisfying any legal, accounting, or reporting requirements. For further information, please see our Retention Guidelines available from the Group Privacy Officer.
For further information on how the Company uses, handles and stores your data and your rights as a data subject please see the Company general Privacy Notice available on the Company internet site, copies of which are available from the Group Privacy Officer.
If you have any concerns or queries about our use of your personal data, please contact the Group Privacy Officer at gpo@pilgrimssharedservices.com.