Transparency is important to us. It's why our chicken is traceable and responsibly produced, and why we want you to understand how we use personal data to run our website and Colonel's Club app, show you relevant ads and serve you in our stores. It's also why we want you to know the rights you have over your personal data – to opt-out of marketing, to ask us for a copy of your data, to object to our use of it, and, occasionally, to ask us to delete it.
SCOPE OF THIS NOTICE?
Us. We're Kentucky Fried Chicken (Great Britain) Limited – but in this Notice we call ourselves "we", "us" or "KFC". We are responsible (the data controller in technical lingo) for our website, Colonel's Club app, any newsletters and marketing you've signed up for, and some KFC stores in the UK and Ireland, which we own and operate. This Notice describes how we use your data to do this.
Not our franchisees. Other stores are run by franchisees, who are independent business owners and therefore independent data controllers (yep, technical terms again). As a result, each franchisee is responsible for its own data protection compliance. If you would like to talk to any of our franchisees about their privacy practices, please contact that them directly.
WHAT DATA DO WE COLLECT AND HOW DO WE USE IT?
From our website. We use your data to operate and improve your experience on our website.
For some of the features on our website to work, we need to remember you. For example, when you're browsing our menu to order, we need to remember what you've already selected so that we don't just give you the last item you picked. As this is an inherent part of what you ask us to do when you order online, we don't ask your consent.
If you use our 'store locator' feature, you can agree to share your location so that you can more easily find the nearest store.
We also keep track of visitors to our website to help us understand how they use the site so we can make it work smoothly and look cooler. For example, we keep track of which pages are visited most, how long visitors spend on our site, what websites they visit before and after ours, and where our visitors come from.
We're able to do this by using cookies and other technical information your device automatically sends to us. Except for the uses that are inherent to the service, we ask your consent to collect this information by way of the cookie banner you saw when you first visited our website.
From your online orders. When you place an order directly with us or another online delivery company, you will be asked to provide data to process your transaction and deliver your order. None of this should be surprising payment details, contact details and delivery location are needed to get your food to your doorstep.
From our stores. When you visit our stores, if you pay for your order by payment card, then we need to process this data – but we don't use it for any other purposes.
We also provide WiFi services in some stores. If you use our WiFi, we obtain information about you connection and device, such as the type of phone you use and your IP address, which we use for our legitimate interests of better understanding our customers. If you consent, we also receive your email address to send you promotional material. For further information on what data we collect from you and what we do with it when you use our WiFi in our stores, please visit our WiFi privacy notice.
From our Colonel Club app. Our Colonel's Club app gives you the chance to win rewards by scanning you’re app every time you order from us. If you sign up for the app, we ask for the type of information we need to allow you to sign (e.g. name, email address, etc.) and we collect information about your past orders as needed to let us allocate rewards.
From social media. If you interact with our Facebook page, Twitter page, Instagram, or other social media presence, we use the information you provide to respond to questions or comments you leave us. We also use these social media services to show you advertising and special offers via social media, which, in some cases, will be targeted to you based on your interests and online browsing (including our website).
For marketing. It's no secret, we use data you give us to promote our delicious recipes and let you know about special offers. We collect your email address and other contact details when you create an account or sign up for newsletters, competitions and other promotional events. We always ask your consent to receive our promotional material.
We also store information about your preferences, like whether you've decided to opt-in to marketing emails, what types of products you seem to be interested in and how often you open the emails we send to further our interest in providing you the most relevant advertising.
Responding to enquiries. If you contact us for any reason, we will use the data you provide us to respond to your question. We see good customer service as a necessary part of the KFC experience.
We also want to learn from your feedback so that we can keep getting better. We use the information for these legitimate business purposes, provided that we don't do this in a way that infringes on your data protection rights.
For legal and standard business reasons. Okay, here comes the legal jargon. We've lumped it all into one section because most of this only happens occasionally or in exceptional circumstances.
Where the law requires it or where we believe it is necessary to protect our legal rights, interests and the interests of others, we use personal data in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a business.
We also use personal data for safety and security, to verify accounts and activity, to monitor suspicious or fraudulent activity and to identify violations of our policies.
WHO DOES KFC SHARE MY INFORMATION WITH?
Your personal data will be shared with companies providing services under contract to us for all the reasons described above, such as payment processing providers (e.g. Worldpay and Ingenico), application developers (e.g. Sideshow), delivery companies (e.g. Just Eat and Deliveroo), data analysts (e.g. Adjust and Atlas Systems), customer care service providers (e.g. Ascensos) and research companies (e.g. Conquest Research) who help to give us an insight into how we can better serve you and all of our other customers, professional advisors, and information technology providers such as Microsoft located in the US, EE located in the UK, Amazon Web Services located in in the US and throughout Europe, and Salesforce which has datacentres in Frankfurt, Paris, London and the US. If you contact us for whatever reason, you'll most likely speak to agents from a company called Ascensos that assists us in responding to your queries and addressing any complaints. If your query relates to one of our franchisees, we may share your details with the relevant franchisee to enable them to resolve your concern and to follow up with you directly.
Your personal data will be processed in or accessed from the United States by some of the third parties to whom we share your personal data. We rely on the EU-U.S. Privacy Shield Framework to transfer your personal data to Yum! Brands, Inc. in the United States. For further information, including to obtain a copy of the documents used to protect your information, please contact us as described in the Contact Us section below.
HOW CAN I STOP RECEIVING NOTICES ABOUT FUTURE OFFERS?
If you no longer want to receive details of our fantastic products and offers, please let us know by completing a form available at www.kfc.co.uk/contact or the address given at the bottom of this Notice. Please make sure that you tell us your full name and address or email address.
Alternatively, you can click on the unsubscribe link at the bottom of any of the email or SMS messages we have sent to you.
WHAT OTHER RIGHTS DO I HAVE?
You have the right to ask us for a copy of your personal data; to correct, delete or restrict processing of your personal data; and to obtain the personal data you provide in a structured, machine readable format. In addition, you can object to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement or compelling interest). Where we have asked for your consent, you may withdraw consent at any time. If you ask to withdraw your consent to us processing your data, this will not affect any processing which has already taken place at that time.
These rights may be limited, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep. If you have unresolved concerns, you have the right to complain to the data protection authority in the country you reside, where you work, where you think the alleged breach is located.
HOW LONG DO YOU KEEP MY DATA FOR?
We will retain your personal data only for as long as we need it for our legitimate interest in accordance with applicable law, after such time, we will either delete or anonymize your information or, if this is not possible (for example, because the information has been stored in backup archives), then we will securely store your information and isolate it from any further use until deletion is possible. Below, we describe how long we keep it:
• Marketing information: If you have elected to receive marketing emails from us, we will retain information about your marketing preferences for three years from the date that you last express interest in our products and services, such as when you last open an email from us. We will retain information derived from cookies and other tracking technologies for 13 months from the date such information was created.
• In-store purchases and online orders: We retain individual records about purchases in our stores for six years after the purchase.
• Customer service: We retain records from any interactions you have with us or our customer service representatives for 6 years from when you last interact with us. If the information you provided us relates to health and safety, we may retain it for longer as required by law.
• Colonel's Club app: We retain information we collect from your use of the Colonel's Club app for three years from when you disable your account. If you stop using the app but do not disable your account, we will disable it for you after four years from the last time you sign on.
COOKIE AND SIMILAR TECHNOLOGIES
It's no secret we specialise in chicken, not computers, so most of the cookies we use are provided by other companies (they're known as third-party cookies). We use the following types of cookies and similar technologies:
• Strictly necessary cookies. These are cookies that are required for the operation of our websites or apps. They include, for example, cookies that enable you to log into secure areas of our website or use a shopping cart.
• Analytics cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our websites and apps when they are using them. This helps us to improve the way our website and app work, for example, by ensuring that users are finding what they are looking for easily.
• Functionality cookies. These are used to recognise you when you return to our website or app and to personalise our content for you, for example, by remembering your preferences.
• Advertising cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website or app and the advertising displayed on them more relevant to your interests. We may also share this information with third parties for this purpose.
• Social media cookies. We use these cookies when you share information using a social media sharing button or “like” button on our website to keep track of the way customers engage with and share our content. The social network will record that you have done this. This information may be linked to targeting/advertising activities.
Withdrawing consent. You can opt out from the different cookies though your browser settings and via the table below.
HOW DO I CONTACT KFC?
If you have any questions about our Notice or the use of your personal data, please contact by (i) post: KFC Care Squad, 250 Airbles Road, Motherwell ML1 3AT or (ii) complete a form at www.kfc.co.uk/contact.