1. Purpose
This UK GDPR & Data Protection Policy sets out how FOUGITO FRANCHISE LTD ("FOUGITO", "we", "our", or "us") complies with the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK privacy legislation.
FOUGITO is a Software-as-a-Service (SaaS) technology provider delivering cloud-based EPOS software, online ordering platforms, hospitality technology, merchant management systems, payment integrations and related digital services.
This policy establishes the organisational and technical measures implemented by FOUGITO to ensure that personal data is processed lawfully, fairly, securely and transparently.
2. Scope
This policy applies to:
- All employees;
- Directors;
- Contractors;
- Consultants;
- Temporary workers;
- Agency staff;
- Franchisees (where applicable);
- Third-party processors acting on behalf of FOUGITO; and
- All processing of personal data undertaken by FOUGITO.
This policy covers personal information relating to:
- Customers;
- Merchants;
- Restaurant operators;
- Hospitality businesses;
- Suppliers;
- Employees;
- Contractors;
- Applicants;
- Website users; and
- Business contacts.
3. Data Protection Principles
FOUGITO processes personal data in accordance with the seven UK GDPR principles. Personal data shall be:
- Processed lawfully, fairly and transparently;
- Collected for specified, explicit and legitimate purposes;
- Adequate, relevant and limited to what is necessary;
- Accurate and kept up to date;
- Retained only as long as necessary;
- Processed securely using appropriate technical and organisational measures; and
- Processed in a manner that demonstrates accountability.
4. Roles and Responsibilities
The Board of Directors has overall responsibility for ensuring compliance with data protection legislation.
Management is responsible for:
- Implementing this policy;
- Ensuring staff compliance;
- Maintaining appropriate security controls;
- Monitoring legal developments; and
- Ensuring sufficient resources are available for compliance.
Employees are responsible for:
- Handling personal data securely;
- Following company procedures;
- Reporting suspected breaches immediately;
- Protecting confidential information; and
- Completing mandatory data protection training.
5. Categories of Personal Data
FOUGITO may process:
Customer Data
- Names;
- Contact details;
- Delivery addresses;
- Order history;
- Communication records.
Merchant Data
- Business information;
- Contact details;
- Banking information;
- Subscription information;
- Commercial agreements.
Employee Data
- Payroll information;
- Employment records;
- Right-to-work documentation;
- Pension information;
- Emergency contacts.
Technical Data
- IP addresses;
- Browser information;
- Device identifiers;
- Audit logs;
- Login history;
- Security logs.
6. Lawful Bases for Processing
FOUGITO relies upon one or more lawful bases under Article 6 UK GDPR. These include:
Contract
Processing necessary to provide SaaS services, EPOS systems and platform functionality.
Legal Obligation
Compliance with:
- Tax legislation;
- Employment law;
- Accounting requirements;
- Regulatory obligations; and
- Lawful requests from public authorities.
Legitimate Interests
Including:
- Improving software;
- Fraud prevention;
- Cyber security;
- Customer support;
- Business administration;
- Network monitoring;
- Service optimisation.
Consent
Where required for:
- Marketing communications;
- Optional cookies;
- Promotional campaigns.
Consent may be withdrawn at any time.
7. Special Category Data
FOUGITO does not intentionally process Special Category Data unless:
- Legally required;
- Necessary for employment purposes;
- Required for accessibility or support services; or
- Explicit consent has been obtained.
Where Special Category Data is processed, additional safeguards will apply.
8. Data Controller and Data Processor Responsibilities
FOUGITO acts as a Data Controller when determining the purposes and means of processing personal data, including its own business operations.
FOUGITO acts as a Data Processor where it processes personal data solely on behalf of merchant customers using its software platform.
Appropriate Data Processing Agreements (DPAs) will be entered into where required under Article 28 UK GDPR.
9. Data Minimisation
Only personal information necessary for legitimate business purposes will be collected and processed.
Access to personal information is restricted using role-based access controls.
10. Accuracy
Reasonable steps will be taken to ensure that personal data remains accurate and current.
Users may request correction of inaccurate information at any time.
10. Accuracy
Reasonable steps will be taken to ensure that personal data remains accurate and current.
Users may request correction of inaccurate information at any time.
11. Data Retention
Personal information will only be retained for as long as necessary. Retention periods are determined by:
- Legal obligations;
- Contractual requirements;
- Regulatory requirements;
- Operational necessity;
- Limitation periods for legal claims.
Secure deletion procedures are applied once retention periods expire.
12. Information Security
FOUGITO maintains appropriate technical and organisational security measures, including:
- Encryption in transit and at rest where appropriate;
- Role-based access controls;
- Strong authentication mechanisms;
- Secure cloud hosting;
- Audit logging;
- Vulnerability management;
- Regular software updates;
- Penetration testing where appropriate;
- Malware protection;
- Network monitoring;
- Disaster recovery planning;
- Secure backups; and
- Business continuity procedures.
13. International Transfers
Where personal data is transferred outside the United Kingdom, FOUGITO will ensure appropriate safeguards are implemented, including:
- UK International Data Transfer Agreements (IDTAs);
- The UK Addendum to the EU Standard Contractual Clauses;
- Adequacy regulations; or
- Other lawful transfer mechanisms recognised under UK GDPR.
14. Data Subject Rights
Individuals have the right to:
- Be informed;
- Access their personal data;
- Rectify inaccurate information;
- Erase personal information where applicable;
- Restrict processing;
- Object to processing;
- Data portability;
- Object to automated decision-making where applicable; and
- Withdraw consent.
Requests should be submitted to:
privacy@FOUGITO.com Requests will normally be answered within one calendar month.
15. Subject Access Requests (SARs)
FOUGITO maintains documented procedures for handling Subject Access Requests. Requests will be:
- Verified;
- Logged;
- Assessed;
- Responded to within statutory deadlines; and
- Securely delivered.
16. Personal Data Breaches
Any employee becoming aware of a suspected personal data breach must immediately notify management.
FOUGITO will:
- Investigate the incident;
- Assess risks to individuals;
- Contain the breach;
- Maintain breach records;
- Notify the Information Commissioner's Office (ICO) where legally required within 72 hours; and
- Notify affected individuals where there is a high risk to their rights and freedoms.
17. Data Protection Impact Assessments (DPIAs)
A DPIA will be undertaken where processing is likely to result in a high risk to individuals, including where new technologies or large-scale processing activities are introduced.
18. Records of Processing Activities (ROPA)
FOUGITO maintains Records of Processing Activities documenting:
- Categories of processing;
- Purposes of processing;
- Lawful bases;
- Recipients
- Retention periods;
- International transfers; and
- Security measures.
ROPA records will be reviewed regularly.
19. Third-Party Processors
All third-party processors engaged by FOUGITO must:
- Provide sufficient guarantees of UK GDPR compliance;
- Enter into written Data Processing Agreements;
- Implement appropriate security measures;
- Process personal data only on documented instructions; and
- Assist FOUGITO in meeting its legal obligations where required.
20. Training and Awareness
Employees handling personal data shall receive appropriate training on:
- UK GDPR;
- Cyber security;
- Confidentiality;
- Phishing awareness;
- Incident reporting;
- Acceptable use; and
- Secure handling of personal information.
Training will be refreshed periodically.
21. Monitoring and Compliance
Compliance with this policy will be monitored through periodic reviews, internal audits, security assessments and updates to reflect changes in legislation or business operations.
22. Complaints
Individuals who have concerns about the processing of their personal information should contact FOUGITO in the first instance.
If concerns cannot be resolved, individuals may lodge a complaint with the Information Commissioner's Office (ICO).
23. Policy Review
This policy shall be reviewed at least annually or sooner if required due to changes in:
- Legislation;
- Regulatory guidance;
- Business operations;
- Technology;
- Security risks; or
- Organisational structure.