Data Protection Policy
UK GDPR and Data Protection Act 2018 | Last updated: 10 June 2026
This Data Protection Policy sets out how Mintro B Ltd, trading as Mintro, meets its responsibilities under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It explains the standards we hold ourselves to and the rules everyone working for or with us must follow when handling personal information.
1. Purpose and scope
The purpose of this policy is to make sure we collect, use, store, and dispose of personal information lawfully, fairly, and securely, and that we respect the rights of the people whose information we hold. It applies to all personal information we process, whether about customers, staff, suppliers, or others, and in any format, whether on paper, electronically, or as images such as CCTV.
This policy applies to all directors, employees, workers, contractors, and volunteers of Mintro. Everyone covered by this policy must read, understand, and follow it. Breaking it may lead to disciplinary action and, in serious cases, may be a criminal offence.
2. Key terms
-
Personal data: any information relating to an identified or identifiable living person, such as a name, address, photograph, or device identifier.
-
Special category data: more sensitive information, such as health, which needs extra protection. We avoid collecting special category data unless there is a clear lawful reason.
-
Processing: anything we do with personal data, including collecting, storing, using, sharing, and deleting it.
-
Data subject: the living person the personal data is about.
-
Controller: the organisation that decides how and why personal data is processed. Mintro is the controller.
-
Processor: a third party that processes personal data on our behalf, following our instructions.
3. Our data protection principles
We follow the principles set out in the UK GDPR. Personal data must be:
-
Processed lawfully, fairly, and in a transparent way.
-
Collected only for specified, explicit, and legitimate purposes, and not used in a way that is incompatible with those purposes.
-
Adequate, relevant, and limited to what is necessary.
-
Accurate and, where needed, kept up to date.
-
Kept in a form that identifies people for no longer than necessary.
-
Processed securely, with protection against unauthorised processing, loss, or damage.
We are accountable for meeting these principles and for being able to demonstrate that we meet them.
4. Lawful basis for processing
We identify and record a lawful basis before we process personal data. The bases we rely on are performance of a contract, compliance with a legal obligation, our legitimate interests, and consent. Where we rely on consent, we make sure it is freely given, specific, informed, and recorded, and we make it easy to withdraw. Our Privacy Policy explains to customers which bases we rely on for each purpose.
5. Special category data
We do not seek to collect special category data in the normal course of business. If we ever need to, we will identify an additional condition for processing it under the UK GDPR and the Data Protection Act 2018 before doing so, and we will apply extra safeguards.
6. Roles and responsibilities
Overall responsibility for data protection rests with the directors of Mintro B Ltd. Day to day responsibility for monitoring compliance with this policy is assigned to a named person within the business, who handles data protection queries, requests from individuals, and any reported breaches. We are not currently required to appoint a statutory Data Protection Officer, but we keep this under review as the business grows. Every member of staff is responsible for handling personal data correctly and for following this policy.
7. The rights of individuals
We respect the rights individuals have over their personal data. These are the right to be informed, the right of access, the right to correction, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights relating to automated decision making. We do not carry out automated decision making that produces legal or similarly significant effects on individuals.
When we receive a request from an individual to exercise a right, we acknowledge it promptly, confirm the person's identity, and respond within one month. We may extend this by up to two further months for complex requests, telling the person why. We keep a record of requests and how we handle them. Requests should be directed to stockport@mintro.co.uk.
8. Data security
We protect personal data with appropriate technical and organisational measures, proportionate to the risk. These include controlling who can access information, using secure systems and strong access credentials, locking away physical records, securing devices, disposing of records securely, and limiting access to personal data to those who need it for their role. CCTV and identification records are held with particular care. We review our security measures regularly.
9. Working with processors and third parties
Before we allow a third party to process personal data on our behalf, we satisfy ourselves that they can keep it secure, and we put a written contract in place requiring them to protect the data, to process it only on our instructions, and to assist us in meeting our obligations. Our processors include our payment providers, point of sale software provider, website provider, couriers, and IT and email providers.
10. Data retention
We keep personal data only for as long as we need it for the purpose we collected it, or for as long as the law requires. Transaction and identification records are kept for at least six years to meet tax and anti money laundering duties, and longer where needed for legal claims or fraud prevention. CCTV footage is kept for a short period unless needed for an investigation. We securely delete or anonymise personal data when it is no longer needed, following a retention schedule that we review periodically.
11. Personal data breaches
A personal data breach is a security incident that leads to the loss, theft, unauthorised access, alteration, or destruction of personal data. Anyone who becomes aware of an actual or suspected breach must report it immediately to the person responsible for data protection. We will investigate without delay, take steps to contain and recover, and assess the risk to individuals.
Where a breach is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk to individuals is high, we will also tell the affected individuals without undue delay. We keep a record of all personal data breaches, including those we do not report.
12. CCTV
We operate CCTV for the safety of people and the protection of property, and for the prevention and detection of crime. We display clear signage where CCTV is in use, hold footage securely, keep it only as long as needed, and share it only where appropriate, for example with the police.
13. Direct marketing
We follow the UK GDPR and the Privacy and Electronic Communications Regulations (PECR) when sending direct marketing. We send electronic marketing only to people who have agreed to receive it, we keep clear records of consent, and we give people an easy way to opt out in every message and honour opt outs promptly.
14. Records of processing and accountability
We keep a record of our processing activities, describing the personal data we hold, why we hold it, who we share it with, and how long we keep it. We carry out a data protection impact assessment where a new activity is likely to result in a high risk to individuals. These records help us demonstrate that we meet our obligations.
15. Training and awareness
We make sure that everyone who handles personal data understands their responsibilities. New staff receive data protection guidance as part of their induction, and we provide refresher guidance as needed, particularly around identification checks, customer information, and spotting and reporting breaches.
16. Review
We review this policy regularly, and whenever there is a significant change in the law or in how we work, to make sure it remains accurate and effective. Questions about this policy should be directed to stockport@mintro.co.uk.
Mintro B Ltd, trading as Mintro. Registered in England and Wales, company number 12461362. Registered office: Regency Court, 62-66 Deansgate, Manchester, M3 2EN. ICO registration ZA786421.