Privacy Policy

Souter Bros Limited: Privacy Notice 

Who we are

1.1 This privacy notice (the “Privacy Notice”) applies to all personal information processing activities carried out by Souter Bros Limited (Souter Bros). Souter Bros was set up as a premium coffee and café business in 2020.

1.2 The company operates café’s, events, wholesale and convenience services and leases equipment to industry partners

1.3 The objectives of the Souter Bros are:

  • To provide high-quality, premium coffee products and catering services to our customers.
  • To engage and listen to our customers, and proactively seek their feedback, ensuring we provide varied and culturally aligned service offers that satisfy our customers and meet their needs.
  • To ensure we provide accessible services and take proactive steps to remove barriers to our services.
  • To build lasting relationships with our customer base, and market loyalty and promotional schemes to improve their experience and increase our value proposition. 

1.5.  In order to carry out our objectives, we collect, process and store personal and sensitive data on an ongoing basis. Our lawful basis for processing personal data is, to carry out our public task set out above. Exceptions to this will be on the lawful basis of consent from our customers. We have a responsibility to protect this information and ensure its confidentiality, integrity and availability.

1.8. This privacy statement describes why and how we collect and use personal data. We may use personal data provided to us for any of the purposes described in this privacy statement or as otherwise stated at the point of collection.

1.9. Souter Bros is a data controller in respect of personal information that we process in connection with our business. In this notice, references to “we”, “us” or “our” are references to Souter Bros.

1.11. Our principal address is XXXXXX and further contact details are found at; info@souterbros.co.uk or, if you have a query or request as a data subject (under the General Data Protection Act); DPO@souterbros.co.uk  

More information about Souter Bros can be found at: www.souterbros.co.uk 

1.12. We respect individuals’ rights to privacy and to the protection of personal information. The purpose of this Privacy Notice is to explain how we collect and use personal information in connection with our business. “Personal information” means information about a living individual who can be identified from that information (either by itself or when it is combined with other information).

1.13. We may update our Privacy Notice from time to time. When we do we will communicate any changes to you and publish the updated Privacy Notice on our website. We would encourage you to visit our website regularly to stay informed of the purposes for which we process your information and your rights to control how we process it.

2. How we obtain and process information

2.1. Personal data – means any information relating to an identifiable living person who can be directly or indirectly identified in particular by reference to an identifier. This definition provides for a wide range of personal identifiers to constitute personal data, including name, identification number, location data or online identifier, reflecting changes in technology and the way organisations collect information about people.

2.2. Your information is made up of all the personal information we hold about you. It includes:

  • information you give us – you may give us information by filling in survey or forms on our site or by corresponding with us by phone, email or otherwise, the information you give us may include your name, address, email address and phone number
  • information collected by suppliers, or subcontractors who work on our behalf, or with us.
  • information that we learn about you through our relationship with you.

2.3. Information we gather from the technology which you use to access our services, for example;

  • Location data from your mobile phone, an Internet Protocol (IP) Address used to connect your device to the internet, your login information, browser type and version, operating system and platform.
  • Full Uniform Resource Locators (URL) clickstream to, through and from our site, items viewed or searched for on our site, page response times, length of visit or page interaction information.

2.4. “Sensitive” and “Special Categories” of personal information.

  • In this Notice we also talk about “Sensitive” and “Special Categories” of personal information. This means personal information that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic information, biometric information for the purpose of uniquely identifying someone, information concerning health or information concerning someone’s sex life or sexual orientation.
  • Under data protection law, these types of information are treated differently because they are so sensitive. Under UK law, it is also expected that information relating to criminal convictions and offences or related security measures will also be treated as if it is sensitive/special category information.
  • We take steps to minimise the collation of special category data, however, with your consent, we may collect information about your ethnicity in order to provide quantitative and qualitative insight on our service for our own use – in this case, we anonymise the data so that personal data is not shared, and you cannot be identified.
  • Our lawful basis for collecting special category data comes under research purposes Schedule (1) Part 1 (4) for research purposes. Where we also commission services we will process special category data under (8) Equality of opportunity or treatment.

3. Your rights

3.1. We want to make sure you are aware of your rights in relation to the personal information we process. We have described those rights and the circumstances in which they apply below. If you wish to exercise any of these rights, if you have any queries about how we use your personal information that are not answered here, or if you wish to complain to our Data Protection Officer, please email us at DPO@souterbros.co.uk or call on XXXXX.

3.2. Access – You have a right to get access to the personal information we hold about you. If you would like a copy of the personal information we hold about you, please write to: Data Protection Officer, Souter Bros XXXXXX or call on XXXX 

3.3. For more information on how to get access to your information and the documents we need you to submit, please complete a Subject Access Request (PDF, 162KB) and submit either via email: DPO@Souterbros.co.uk or by post to: XXXX

3.4. Rectification – You have a right to rectification of inaccurate personal information and to update incomplete personal information. If you believe that any of the information that we hold about you is inaccurate, you have a right to request that we restrict the processing of that information and to rectify the inaccurate personal information.

3.5. Erasure – You have a right to request that we delete your personal information. You may request that we delete your personal information if you believe that;

  • we no longer need to process your information for the purposes for which it was provided
  • we have requested your permission to process your personal information and you wish to withdraw your consent or
  • we are not using your information in a lawful manner.

3.6. Restriction – You have a right to request us to restrict the processing of your personal information. You may request us to restrict processing your personal information if you believe that;

  • any of the information that we hold about you is inaccurate
  • we no longer need to process your information for the purposes for which it was provided, but you require the information to establish, exercise or defend legal claims or
  • we are not using your information in a lawful manner.

3.7. Objection – You have a right to object to the processing of your personal information. You have a right to object to us processing your personal information (and to request us to restrict processing) for the purposes described in Schedule A – Purposes of Processing (below), unless we can demonstrate compelling and legitimate grounds for the processing, which may override your own interests or where we need to process your information to investigate and protect us or others from legal claims. Depending on the circumstances, we may need to restrict or cease processing your personal information altogether, or where requested, delete your information.

3.8. Withdraw consent – You have a right to withdraw your consent. Where we rely on your permission to process your personal information, you have a right to withdraw your consent at any time. We will always make it clear where we need your permission to undertake specific processing activities.

3.9. Lodge complaints – You have a right to lodge a complaint. If you wish to raise a complaint on how we have handled your personal information, you can contact our Data Protection Officer who will investigate the matter and report back to you.

Email: DPO@Souterbros.co.uk

Post: XXXX

Telephone: XXXX 

We hope that we can address any concerns you may have, but you can always contact the Information Commissioner’s Office (ICO). For more information, visit ico.org.ukOpens in a new window

4. Changes to this notice

4.1. We may change this notice from time to time, in whole or part, at our sole discretion or to fulfil a legal obligation. We encourage you to check our website to view the most recent version of this notice. You may also request a copy of the most recent version by contacting us.

5. How we use and share your information

5.1. We will only use and share your information where it is necessary for us to lawfully carry out our business activities. We want to ensure that you fully understand how your information may be used. We have described the purposes for which your information may be used in detail in Schedule A – Purposes of Processing.

5.2. We share your personal information with other organisations within the Souter Bros Group, all of which provide the same high level of security and protection. We have group-wide policies to make sure your personal information is protected, no matter which organisation in the Souter Bros Group holds that information.

5.3. We collect personal data so that we can understand your situation and provide you with personalised information and guidance. We use the data that we store to help us to ensure that we continually give a high-quality service that is accurate and clear and in line with the current UK and/or EU legislation; and provide quantitative and qualitative insight on our service for our own use and third parties.

5.4. If you want us to stop using personal information we’ve collected via cookies on our websites, you should change your cookie settings. In some cases, we might decide to keep information, even if you ask us not to. This could be for legal or regulatory reasons, so that we can keep providing our products and services. We will always tell you why we keep the information.

6. Sharing with third parties

6.1. We will not share your information with anyone outside Souter Bros except;

  • where we have your permission
  • where we are using an external processor for data analysis for quality assurance purposes
  • where we are required by law and to law enforcement agencies or government entities
  • where required for a reorganisation, transfer or other transaction relating to our business
  • in anonymised form as part of statistics or other aggregated data shared with third parties or
  • where permitted by law, it is necessary to fulfil our statutory objectives or those of a third party, and it is not inconsistent with the purposes listed above.

6.2. We will only share your information with third parties on a limited basis following due diligence and in accordance with our internal procedures.

6.3. Souter Bros will not share your information with third parties for their own marketing purposes.

7. Communications with you

7.1. We will contact you with information relevant to Souter Bros (including updated information about how we process your personal information), by a variety of means including via email, post and/or telephone. If at any point in the future, you change your contact details you should tell us promptly about those changes.

7.2. If you change your mind about how you would like us to contact you or you no longer wish to receive this information, you can tell us at any time by emailing us at DPO@Souterbros.co.uk 

7.3. We may monitor or record calls, emails, text messages or other communications in accordance with applicable laws for the purposes outlined in Schedule A – Purposes of Processing.

8. How long we keep your information

8.1. When using our services, we create records that contain your information. Records can be held on a variety of media (physical or electronic) and formats.

8.2. We manage our records to help us to serve our customers well (for example for operational reasons, such as dealing with complaints or financial transactions) and to comply with legal and statutory requirements. Records help us demonstrate that we are meeting our responsibilities and to keep as evidence of our business activities.

8.3. Retention periods for records are determined based on the type of record and the nature of the activity. We normally keep customer account records for up to five years after your relationship with The Souter Bros ends, whilst other records are retained for shorter periods, for example 90 days for CCTV records or 12 months for call recordings captured on voicemail. Retention periods may be changed from time to time based on business or legal and regulatory requirements.

8.4. We may on exception retain your information for longer periods, particularly where we need to withhold destruction or disposal based on an order from the courts or an investigation by law enforcement agencies. This is intended to make sure that the organisation will be able to produce records as evidence, if they’re needed.

8.5. If you would like more information about how long we keep your information, please contact us at DPO@Souterbros.co.uk 

9. Security

9.1. We are committed to maintaining and enhancing the privacy and confidentiality of your personal data. We take various steps to protect the information you provide from loss, misuse, and unauthorised access or disclosure by; ensuring only authorised persons can access your data and running website scanning and penetration test activities. These steps take into account the sensitivity of the information we collect, process and store, and the current state of technology.

9.2. Your data is stored inside the European Economic Area (EEA) and will not be transferred outside the EEA.

9.3. If a security breach causes an unauthorised intrusion into our system that materially affects you or the privacy of your data we will notify you as soon as possible. We will also notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach.

9.4. We are committed to ensuring that your information is secure with us and with the third parties who act on our behalf. For more information about the steps we are taking to protect your information please contact us at DPO@Souterbros.co.uk.

10. Schedule A – Purposes of Processing

10.1. We will only use and share your information where it is necessary for us to carry out our lawful business activities. Your information may be shared with and processed by members of the Souter Bros Group (Souter Bros).


10.2. We will process your information where we have the legal basis to do so and without prejudicing your interests or fundamental rights and freedoms. We want to ensure that you fully understand how your information may be used. We have described the purposes for which your information may be used in detail below:

We’ll send you information about the services we provide by phone, post, email or text message. We also use the information we have about you to personalise these messages wherever we can as we believe it is important to make them relevant to you. We also check that you are happy for us to send you information by text or email before we do so. In each message we send, you also have the option to opt out. This includes processing your information to;

  • Develop, test, monitor and review the performance of services, internal systems and security arrangements offered by Souter Bros.
  • Assess the quality of our service to customers and to provide staff training.
  • Comply with legal and statutory obligations.
  • Provide you with information on our service and promotions (e.g. newsletters).
  • Issue surveys to assist with stakeholder feedback for Financial Capability evaluation and programme improvements
  • We’ll use your personal information to create aggregated and anonymised information. Nobody can identify you from that information. We’ll use it to run management and corporate reporting, research and analytics, to improve the services we provide; and provide other organisations with aggregated and anonymous reports.

10.3. To develop our service(s) and build a better understanding of what our customers want. This means we’ll;

  • Maintain, develop and test our network (including managing the traffic on our network), products and services, to provide you with a better service.
  • Train our people and suppliers to provide you with services (but we make the information anonymous beforehand wherever possible).
  • Create a profile about you to better understand you as our customer.
  • Share personal information within the Souter Bros Group for administrative purposes, such as sharing contact details, so we can get in touch with you.
  • Run surveys and market research.

If you need to get in touch: dpo@souterbros.co.uk