After a busy summer, we’ll be taking a short Bank Holiday break. We’ll be closed on Monday 31st August, reopening at 11am on Tuesday 1st September. Enjoy the Bank Holiday, however you spend it!
At Nicholas Hythe Ltd, we take the protection of personal information seriously. This policy explains the principles we follow when collecting, using, sharing, storing and deleting personal data.
We are committed to complying with UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to personal data relating to customers, prospective customers, employees and other individuals whose information we process in the course of our business.
Nicholas Hythe Ltd is the Data Controller and is responsible for ensuring that personal data is handled appropriately.
Ross Halliday is our Data Protection Lead. Any questions, concerns, data protection requests or suspected data breaches should be reported to:
Email: info@nicholashythe.co.uk
All employees and other authorised users of our systems are responsible for handling personal data in
accordance with this policy.
Depending on the circumstances, we may collect and process information including:
• names, addresses, email addresses and telephone numbers;
• project and property information;
• kitchen design requirements;
• design, quotation and order information;
• payment, invoice and accounting information;
• communications and notes relating to an enquiry or project;
• information generated through the use of our business systems;
• CCTV footage; and
• other information reasonably required to provide our services or administer our business.
We should only collect and use personal data that is reasonably necessary for the relevant purpose.
We may use personal data to:
• respond to enquiries;
• arrange consultations;
• prepare and manage kitchen designs, estimates and quotations;
• take steps requested by a prospective customer before entering into a contract;
• process and fulfil customer orders;
• manage kitchen installations and associated services;
• communicate with customers throughout their project;
• administer payments, accounts and invoices;
• undertake appropriate marketing activities;
• manage and improve our business, website and customer service;
• maintain the security of our premises, people and systems; and
• comply with legal, regulatory, accounting and other business obligations.
We must have an appropriate lawful basis whenever we process personal data. Depending on the circumstances, this may include performance of a contract or steps before entering into a contract, compliance with a legal obligation, our legitimate interests or consent where required.
We do not sell personal data.
Personal data may be stored and processed using approved business systems, including Microsoft 365, Xero and our quotation and commercial workflow platform.
Access to these systems must be limited to authorised users and appropriate security measures must be
maintained.
We may share personal data where reasonably necessary to provide our services, administer our business or
comply with legal obligations. This may include:
• suppliers and manufacturers;
• installers and subcontractors;
• delivery providers;
• professional advisers, accountants and insurers;
• IT, software, hosting and cloud service providers;
• approved marketing and website service providers; and
• regulatory, legal or other authorities where required.
Where another organisation processes personal data on our behalf, appropriate data processing, confidentiality and security arrangements must be in place.
Personal data must not be transferred outside the UK unless appropriate safeguards required by UK data
protection law are in place.
Nicholas Hythe Ltd may use approved artificial intelligence-assisted tools within its business systems to assist with tasks such as preparing or refining quotation content, product information and customer communications.
AI tools are intended to support our employees and do not replace appropriate human judgement or review.
When using an approved AI-assisted tool:
• only information reasonably necessary for the particular task should be processed;
• unnecessary customer-identifying information should not be provided to an AI service;
• personal data must only be processed through AI services approved by Nicholas Hythe Ltd;
• employees must not enter customer or company information into unapproved public AI tools;
• AI-generated information must be checked for accuracy and appropriateness; and
• customer-facing quotations, documents or communications produced or assisted by AI must be reviewed by an authorised member of staff before being issued.
Where an external AI provider processes personal data on our behalf, appropriate contractual, security and data protection arrangements must be in place.
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet our legal, accounting, warranty and regulatory obligations.
Customer and project information will usually be retained for up to seven years after completion of the project for accounting, contractual or legal reasons.
Enquiry and quotation information relating to prospective customers who do not proceed will normally be retained for 12 months from the last meaningful contact, after which it will be securely deleted or anonymised unless there is a legitimate reason to retain it for longer. Information must be securely deleted or disposed of when it is no longer required.
Individuals have rights under UK data protection law which may include the right to:
• access their personal data;
• request correction of inaccurate information;
• request deletion of personal data;
• restrict certain processing;
• object to certain processing;
• request data portability in appropriate circumstances; and
• withdraw consent where processing is based on consent.
Requests should be referred promptly to the Data Protection Lead at info@nicholashythe.co.uk.
We will normally respond to requests within one month, subject to the requirements and permitted exceptions
under data protection law.
We use appropriate technical and organisational measures to protect personal data.
These may include:
• access restricted to authorised users;
• strong passwords and multi-factor authentication where appropriate;
• role-based access permissions;
• encryption and secure communications;
• appropriate backup and recovery arrangements;
• security updates and system maintenance;
• confidentiality requirements for staff and service providers; and
• audit trails and system logging where appropriate.
Employees must take reasonable care when accessing, sharing or handling personal data and must not
disclose it to anyone who is not authorised to receive it.
Any actual or suspected loss, accidental disclosure, unauthorised access or other potential personal data breach must be reported immediately to the Data Protection Lead.
Employees, contractors and other users must not attempt to investigate or resolve a suspected breach independently unless instructed to do so.
The Data Protection Lead will assess and record the incident and follow the company’s Data Protection Breach Procedure, including notification to the Information Commissioner’s Office (ICO) and affected individuals where required.
Nicholas Hythe Ltd uses CCTV cameras at its premises for the purpose of protecting the safety and security of staff, visitors and property; deterring and detecting crime; and supporting the investigation of incidents. Cameras are positioned only where necessary and proportionate and are not used to monitor staff conduct or performance.
CCTV processing is carried out under the lawful basis of legitimate interests (Article 6(1)(f) UK GDPR) in protecting the company’s premises, people and assets.
A Legitimate Interests Assessment (LIA) has been completed and is available on request.
Live feeds and recordings are only accessible to authorised personnel responsible for security and management.
Recorded footage is stored securely and retained for no longer than 14 days, unless longer retention is required for the investigation of a specific incident or disclosure to law enforcement or insurers.
Clear signage is displayed at each camera location informing individuals that CCTV is in operation and providing the purpose of monitoring.
Further information is available on request from the Data Protection Lead.
Any individual recorded by CCTV has the right to request access to footage in which they appear through a Subject Access Request (SAR).
Where footage contains third parties, we will take reasonable steps to protect their identity where required before disclosure.
CCTV use is reviewed periodically to ensure that it remains necessary and proportionate.
Any expansion or significant change to CCTV use will not take place without first considering the data protection implications and updating relevant documentation where necessary.
This policy will be reviewed regularly and whenever there is a significant change to the way Nicholas Hythe Ltd collects or processes personal data, including the introduction of significant new technology or systems.
Approved by: __________________________
Position: Director
Date approved: ________________________
Effective date: August 2026
Version: 1.2
We warmly invite you to explore our displays and speak with our team in person at either of our showrooms. If you would prefer to arrange a dedicated consultation, appointments are also available. Please call St Ives: 01480 468598 or Ely: 01353 786598, or click the ‘Contact Us’ button below.