Privacy Policy

§1 Data Controller

  1. The data controller is Tom Toms Bakery, conducting business under the name Tom Toms Bakery Portrush Co. Antrim BT56 8AB. The business is registered in the Central Register and Information on Business Activity under tax identification number ID: 569100494743.
  2. Contact with the person supervising personal data processing in the organization is possible electronically at e-mail: contact@tomtomsbakery.uk, in writing to the Controller's address, or by phone at 028 708 24 614.
  3. This Policy contains rules regarding the processing of personal data by the Controller in the Service, including the grounds, purposes, and scope of personal data processing, as well as the rights of data subjects.
  4. Personal data are processed by the Controller in accordance with applicable law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Official text of the GDPR Regulation: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679.
  5. User rights are not absolute and do not apply to all personal data processing activities.

§2 Definitions

  • Controller - Tom Toms Bakery, conducting business under the name Tom Toms Bakery Portrush Co. Antrim BT56 8AB. The business is registered in the Central Register and Information on Business Activity under tax identification number ID:569100494743 .
  • Personal Data - information about an identified or identifiable natural person through one or more specific factors determining physical, physiological, genetic, mental, economic, cultural or social identity, including device IP, online identifier and information collected via cookies and other similar technology.
  • Policy - this Privacy Policy.
  • Profiling - automated processing of personal data consisting of analyzing and predicting user behavior.
  • GDPR / GDPR Regulation - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
  • Service - website operated by the Controller at https://tomtomsbakery.uk/.
  • User - any natural person visiting the Service or using one or more services or functionalities described in the Policy.

§3 Security

  1. The Controller has implemented appropriate technical and organizational measures ensuring the security of personal data processing, and in particular is responsible and ensures that the data collected by them:
    • are processed lawfully;
    • are collected for specified, legitimate purposes and not further processed in a manner incompatible with those purposes;
    • are substantively correct and adequate in relation to the purposes for which they are processed;
    • are stored in a form enabling identification of data subjects for no longer than necessary to achieve the processing purpose; and
    • are processed in a manner ensuring appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.

§4 Purposes and Legal Bases for Data Processing

  1. Based on Art. 6(1)(a) GDPR (consent), personal data may be processed for purposes:
    • Retargeting and behavioral advertising, including displaying personalized ads based on user activity history in the Service and on other websites.
    • Sending the Newsletter.
    • Operating and maintaining user account in the Service.
    • Contact via remote communication tools.
    • Content moderation.
    • Content personalization.
    • Marketing of Controller's and Controller's partners' products and services.
    • Participation in webinars or online training.
    • Participation in contests and loyalty programs.
    • Invitations to participate in surveys and market research.
  2. Based on Art. 6(1)(b) GDPR (contract performance), personal data may be processed for purposes:
    • Managing user account.
    • Performing sales contract or service contract or taking actions at the data subject's request before concluding such contract or after its conclusion, in particular: warranty rights, complaint handling.
    • Complaint or withdrawal from distance contract.
  3. Based on Art. 6(1)(c) GDPR (legal obligation of the Controller), personal data may be processed for purposes:
    • Issuing and storing invoices, bills or fulfilling other obligations resulting from tax and accounting regulations (archiving obligation regarding accounting documents).
    • Cooperation with law enforcement and public institutions.
    • Creating registers and other documentation required by GDPR provisions.
  4. Based on Art. 6(1)(f) GDPR (legitimate interest of the Controller), personal data may be processed for purposes:
    • Operating the Service https://tomtomsbakery.uk/.
    • Storing data necessary for proper functioning of the Service in cookies according to the Cookies Policy.
    • Maintaining accounts on Facebook, Instagram, TikTok platforms and interacting with Users of these platforms.
    • Securing the Service's security, managing the Service and its proper functioning.
    • Conducting statistics and traffic analysis in the Service.
    • Direct marketing.
    • Establishing claims submitted by or against the Controller.
    • Contact with the User.
  5. Personal data may also be processed for other purposes if the Controller has an appropriate legal basis for this, in particular resulting from Art. 6 GDPR, provided that such purpose does not violate the User's rights and freedoms. In such case, the User will be informed about the new processing purpose before processing begins for that purpose.

§5 Profiling

  1. The Controller uses profiling for marketing purposes, consisting of analyzing User activity in the Service using cookies and similar technologies.
  2. Profiling may include:
    • Personalization of ads based on browsing history,
    • Analysis of User interaction with content in the Service,
    • Adjustment of displayed advertising content on external websites (e.g., Google Ads, Facebook).
  3. Profiling is conducted solely based on User consent.
  4. The User may withdraw consent to profiling at any time by changing settings or contacting the Controller at e-mail: contact@tomtomsbakery.uk.

§6 Personal Data Processing Period

  1. The processing period of data by the Controller depends on the type of service provided and the processing purpose. As a rule, data are processed for the duration of the service, until withdrawal of given consent or effective objection to data processing in cases where the legal basis for data processing is the Controller's legitimate interest.
  2. The processing period may be extended if processing is necessary to establish and pursue possible claims or defend against claims, and after that time only when and to the extent required by law. After the processing period, data are irreversibly deleted or anonymized.
  3. Detailed storage periods depending on purpose, e.g.:
    • Data related to contract performance - stored for the duration of the contract, then until the statute of limitations expires (3 or 6 years).
    • Accounting and tax data - stored for the period required by tax law (currently 5 years).
    • Data obtained based on received consent - stored until consent is withdrawn.
    • Data related to user inquiries - stored for up to 12 months from correspondence termination.

§7 User Rights

  1. The User has the following rights regarding their personal data:
    • Access to their personal data,
    • Rectification of personal data at any time,
    • Erasure of their personal data at any time,
    • Receiving a copy of their data,
    • Restriction of personal data processing,
    • Objection to personal data processing,
    • Data portability,
    • Withdrawal of consent; withdrawal does not affect lawfulness of processing based on consent before its withdrawal,
    • Objection to personal data processing based on Controller's legitimate interest for marketing purposes, direct marketing, and for purposes other than marketing,
    • Lodging a complaint with a supervisory authority.
  2. To exercise the above rights, the User may contact the Controller by sending a message to e-mail contact@tomtomsbakery.uk or correspondence to the Controller's registered address. The Controller undertakes to consider the request within 30 days of receipt.
  3. In some cases, the Controller may refuse to fulfill the User's request if legal provisions impose an obligation to further process data.

§8 Recipients of Personal Data

  1. For proper operation of the Service, the Controller transfers User's personal data to other external entities, in particular: hosting company, courier companies, payment operators.
  2. The Controller reserves the right to disclose personal data when required by applicable law, including the obligation to provide information to appropriate administrative authorities or law enforcement.

§9 Personal Data Security

  1. The Controller continuously conducts risk analysis to ensure that Personal Data are processed by them securely. Through their actions, they primarily ensure that only authorized persons have access to data and only to the extent necessary for their tasks.
  2. The Controller is obliged to take all legally permitted actions to ensure that all operations on Personal Data are recorded and performed only by authorized entities.
  3. The Controller is also obliged to ensure that other entities cooperating with the Controller provide guarantees of applying appropriate security measures whenever they process Personal Data on behalf of the Controller.
  4. The Controller applies technical safeguards such as data transmission encryption (SSL/TLS), access restriction to systems, and procedures protecting against unauthorized data access.

§10 Privacy Policy Changes

  1. The Policy is regularly reviewed and updated.
  2. The current version of the Policy was adopted and is effective from 19.01.2026.