Legal
Privacy Policy
This Privacy Policy explains how Norfolk Stores Group collects, uses, and protects personal information across all of our websites and physical locations. We are committed to protecting your privacy and handling your data in an open and transparent manner, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Norfolk Stores Group is a family-owned business operating a portfolio of community retail and financial service locations across Norfolk and the Isle of Wight. Our sites include:
- Massingham Stores & Post Office, 14 Station Road, Great Massingham, Norfolk, PE32 2HY
- Fakenham Post Office, 34 Upper Market, Fakenham, Norfolk, NR21 9BX
- Brancaster Post Office & Stores, Brancaster, Norfolk
- Holt Banking Hub, 16 High Street, Holt, Norfolk, NR25 6BQ
- Wymondham Banking Hub, 45 Market Street, Wymondham, Norfolk, NR18 0AL
- Ryde Banking Hub, 10 Lind Street, Ryde, Isle of Wight, PO33 2NQ
For the purposes of data protection law, Norfolk Stores Group is the data controller for personal data collected through our websites and in our stores. Our websites are operated under the norfolkstores.co.uk domain and its affiliated subdomains.
We are not required to register with the Information Commissioner's Office (ICO) unless we process personal data that triggers registration requirements, but we are fully committed to upholding the principles of the UK GDPR.
2. What Information We Collect
Information you provide to us
We may collect the following types of personal information when you interact with us:
- Contact information: name, email address, telephone number, and postal address, when you contact us via our websites, by phone, or by email
- Enquiry details: the content of messages you send us through contact forms or email
- Booking information: for holiday accommodation at The Hideaway (Massingham), we collect names, contact details, and payment information via our booking platform
- Chatbot interactions: where an AI-powered chat assistant is available on a site, conversation content may be processed to respond to your query
Information collected automatically
When you visit our websites, we may automatically collect:
- Usage data: pages visited, time spent on pages, links clicked, referral source
- Device and browser information: browser type, operating system, screen resolution, and device type
- IP address: used to understand geographic location at a country/region level and to prevent fraud
- Cookies: small files stored on your device. See Section 5 for details
Information from third parties
We do not purchase or obtain personal data from data brokers. We may receive basic contact information when someone is referred to us by a partner organisation (such as Cash Access UK or Post Office Ltd) in connection with our banking hub or post office services.
3. How We Use Your Information
We use the personal information we collect for the following purposes:
- To respond to your enquiries and provide customer service
- To process holiday accommodation bookings and manage your reservation
- To operate and improve our websites and services
- To send you information about our services where you have asked us to
- To comply with legal and regulatory obligations
- To monitor and analyse website usage in aggregate to improve our online presence
- To protect the security and integrity of our websites and prevent fraud
We do not use your personal data for automated decision-making or profiling, sell your data to third parties, or use it for direct marketing without your explicit consent.
4. Our Legal Basis for Processing
Under UK GDPR, we rely on the following lawful bases to process your personal data:
- Legitimate interests (Article 6(1)(f)): for website analytics, responding to general enquiries, and improving our services, where we have assessed that our interests do not override your rights
- Contract (Article 6(1)(b)): where we need to process your data to fulfil a booking or service agreement with you
- Legal obligation (Article 6(1)(c)): where we are required by law to retain or process certain information
- Consent (Article 6(1)(a)): where we ask for your permission before using your data for a specific purpose (e.g. marketing emails). You may withdraw consent at any time
7. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes set out in this policy:
- Enquiry and contact data: up to 2 years after your last contact with us
- Booking data: up to 7 years for accounting and legal compliance purposes
- Website analytics data: in anonymised, aggregate form, retained indefinitely as it cannot be used to identify you
- Legal obligation data: as long as required by applicable law
When data is no longer required, it is securely deleted or anonymised.
8. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data. You can exercise these rights free of charge by contacting us (see Section 13):
- Right of access: to request a copy of the personal data we hold about you
- Right to rectification: to ask us to correct inaccurate or incomplete data
- Right to erasure (‘right to be forgotten’): to ask us to delete your data, subject to legal retention requirements
- Right to restrict processing: to ask us to limit how we use your data
- Right to data portability: to receive your data in a structured, machine-readable format
- Right to object: to object to processing based on legitimate interests
- Right to withdraw consent: where processing is based on your consent, you can withdraw it at any time
We will respond to your request within 30 days. If you are dissatisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection: ico.org.uk / 0303 123 1113.
9. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. These include:
- Secure HTTPS connections on all our websites
- Access controls limiting who can access personal data within our organisation
- Regular review of our data handling practices
- Use of reputable, security-vetted third-party services
While we take all reasonable steps to protect your data, no method of transmission over the internet is 100% secure. If you have concerns about a specific security issue, please contact us immediately.
10. Third-Party Links
Our websites may contain links to third-party websites, including Cash Access UK, Post Office Ltd, and local partners. This Privacy Policy applies only to our own websites. We encourage you to read the privacy policies of any third-party sites you visit, as we have no control over their practices.
11. Children's Privacy
Our websites are not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make significant changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of our websites after changes are made constitutes acceptance of the updated policy.
13. How to Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights, or have a complaint about how we handle your data, please contact us:
Norfolk Stores GroupNorfolk, United Kingdom
Email: info@norfolkstores.co.uk
We aim to respond to all privacy-related requests within 30 days.