Logo header

Data Protection Policy

1. Purpose

This UK GDPR & Data Protection Policy sets out how FOUGITO FRANCHISE LTD ("FOUGITO", "we", "our", or "us") complies with the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK privacy legislation.

FOUGITO is a Software-as-a-Service (SaaS) technology provider delivering cloud-based EPOS software, online ordering platforms, hospitality technology, merchant management systems, payment integrations and related digital services.

This policy establishes the organisational and technical measures implemented by FOUGITO to ensure that personal data is processed lawfully, fairly, securely and transparently.

2. Scope

This policy applies to:

  • All employees;
  • Directors;
  • Contractors;
  • Consultants;
  • Temporary workers;
  • Agency staff;
  • Franchisees (where applicable);
  • Third-party processors acting on behalf of FOUGITO; and
  • All processing of personal data undertaken by FOUGITO.

This policy covers personal information relating to:

  • Customers;
  • Merchants;
  • Restaurant operators;
  • Hospitality businesses;
  • Suppliers;
  • Employees;
  • Contractors;
  • Applicants;
  • Website users; and
  • Business contacts.

3. Data Protection Principles

FOUGITO processes personal data in accordance with the seven UK GDPR principles. Personal data shall be:

  • Processed lawfully, fairly and transparently;
  • Collected for specified, explicit and legitimate purposes;
  • Adequate, relevant and limited to what is necessary;
  • Accurate and kept up to date;
  • Retained only as long as necessary;
  • Processed securely using appropriate technical and organisational measures; and
  • Processed in a manner that demonstrates accountability.

4. Roles and Responsibilities

The Board of Directors has overall responsibility for ensuring compliance with data protection legislation.

Management is responsible for:

  • Implementing this policy;
  • Ensuring staff compliance;
  • Maintaining appropriate security controls;
  • Monitoring legal developments; and
  • Ensuring sufficient resources are available for compliance.

Employees are responsible for:

  • Handling personal data securely;
  • Following company procedures;
  • Reporting suspected breaches immediately;
  • Protecting confidential information; and
  • Completing mandatory data protection training.

5. Categories of Personal Data

FOUGITO may process:

Customer Data

  • Names;
  • Contact details;
  • Delivery addresses;
  • Order history;
  • Communication records.

Merchant Data

  • Business information;
  • Contact details;
  • Banking information;
  • Subscription information;
  • Commercial agreements.

Employee Data

  • Payroll information;
  • Employment records;
  • Right-to-work documentation;
  • Pension information;
  • Emergency contacts.

Technical Data

  • IP addresses;
  • Browser information;
  • Device identifiers;
  • Audit logs;
  • Login history;
  • Security logs.

6. Lawful Bases for Processing

FOUGITO relies upon one or more lawful bases under Article 6 UK GDPR. These include:

Contract

Processing necessary to provide SaaS services, EPOS systems and platform functionality.

Legal Obligation

Compliance with:

  • Tax legislation;
  • Employment law;
  • Accounting requirements;
  • Regulatory obligations; and
  • Lawful requests from public authorities.

Legitimate Interests

Including:

  • Improving software;
  • Fraud prevention;
  • Cyber security;
  • Customer support;
  • Business administration;
  • Network monitoring;
  • Service optimisation.

Consent

Where required for:

  • Marketing communications;
  • Optional cookies;
  • Promotional campaigns.

Consent may be withdrawn at any time.

7. Special Category Data

FOUGITO does not intentionally process Special Category Data unless:

  • Legally required;
  • Necessary for employment purposes;
  • Required for accessibility or support services; or
  • Explicit consent has been obtained.

Where Special Category Data is processed, additional safeguards will apply.

8. Data Controller and Data Processor Responsibilities

FOUGITO acts as a Data Controller when determining the purposes and means of processing personal data, including its own business operations.

FOUGITO acts as a Data Processor where it processes personal data solely on behalf of merchant customers using its software platform.

Appropriate Data Processing Agreements (DPAs) will be entered into where required under Article 28 UK GDPR.

9. Data Minimisation

Only personal information necessary for legitimate business purposes will be collected and processed.

Access to personal information is restricted using role-based access controls.

10. Accuracy

Reasonable steps will be taken to ensure that personal data remains accurate and current.

Users may request correction of inaccurate information at any time.

10. Accuracy

Reasonable steps will be taken to ensure that personal data remains accurate and current.

Users may request correction of inaccurate information at any time.

11. Data Retention

Personal information will only be retained for as long as necessary. Retention periods are determined by:

  • Legal obligations;
  • Contractual requirements;
  • Regulatory requirements;
  • Operational necessity;
  • Limitation periods for legal claims.

Secure deletion procedures are applied once retention periods expire.

12. Information Security

FOUGITO maintains appropriate technical and organisational security measures, including:

  • Encryption in transit and at rest where appropriate;
  • Role-based access controls;
  • Strong authentication mechanisms;
  • Secure cloud hosting;
  • Audit logging;
  • Vulnerability management;
  • Regular software updates;
  • Penetration testing where appropriate;
  • Malware protection;
  • Network monitoring;
  • Disaster recovery planning;
  • Secure backups; and
  • Business continuity procedures.

13. International Transfers

Where personal data is transferred outside the United Kingdom, FOUGITO will ensure appropriate safeguards are implemented, including:

  • UK International Data Transfer Agreements (IDTAs);
  • The UK Addendum to the EU Standard Contractual Clauses;
  • Adequacy regulations; or
  • Other lawful transfer mechanisms recognised under UK GDPR.

14. Data Subject Rights

Individuals have the right to:

  • Be informed;
  • Access their personal data;
  • Rectify inaccurate information;
  • Erase personal information where applicable;
  • Restrict processing;
  • Object to processing;
  • Data portability;
  • Object to automated decision-making where applicable; and
  • Withdraw consent.

Requests should be submitted to:

privacy@FOUGITO.com

Requests will normally be answered within one calendar month.

15. Subject Access Requests (SARs)

FOUGITO maintains documented procedures for handling Subject Access Requests. Requests will be:

  • Verified;
  • Logged;
  • Assessed;
  • Responded to within statutory deadlines; and
  • Securely delivered.

16. Personal Data Breaches

Any employee becoming aware of a suspected personal data breach must immediately notify management.

FOUGITO will:

  • Investigate the incident;
  • Assess risks to individuals;
  • Contain the breach;
  • Maintain breach records;
  • Notify the Information Commissioner's Office (ICO) where legally required within 72 hours; and
  • Notify affected individuals where there is a high risk to their rights and freedoms.

17. Data Protection Impact Assessments (DPIAs)

A DPIA will be undertaken where processing is likely to result in a high risk to individuals, including where new technologies or large-scale processing activities are introduced.

18. Records of Processing Activities (ROPA)

FOUGITO maintains Records of Processing Activities documenting:

  • Categories of processing;
  • Purposes of processing;
  • Lawful bases;
  • Recipients
  • Retention periods;
  • International transfers; and
  • Security measures.

ROPA records will be reviewed regularly.

19. Third-Party Processors

All third-party processors engaged by FOUGITO must:

  • Provide sufficient guarantees of UK GDPR compliance;
  • Enter into written Data Processing Agreements;
  • Implement appropriate security measures;
  • Process personal data only on documented instructions; and
  • Assist FOUGITO in meeting its legal obligations where required.

20. Training and Awareness

Employees handling personal data shall receive appropriate training on:

  • UK GDPR;
  • Cyber security;
  • Confidentiality;
  • Phishing awareness;
  • Incident reporting;
  • Acceptable use; and
  • Secure handling of personal information.

Training will be refreshed periodically.

21. Monitoring and Compliance

Compliance with this policy will be monitored through periodic reviews, internal audits, security assessments and updates to reflect changes in legislation or business operations.

22. Complaints

Individuals who have concerns about the processing of their personal information should contact FOUGITO in the first instance.

If concerns cannot be resolved, individuals may lodge a complaint with the Information Commissioner's Office (ICO).

23. Policy Review

This policy shall be reviewed at least annually or sooner if required due to changes in:

  • Legislation;
  • Regulatory guidance;
  • Business operations;
  • Technology;
  • Security risks; or
  • Organisational structure.

Empowering a greener tomorrow

Discover our vision through Fougito's tech innovations

Learn more