Your Data Rights
Your Data, Your Rights
Under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018, you have specific rights over your personal data. This page explains each right and how to exercise it with iLoveHACCP.
#1Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the HACCP plan generation service you signed up for.
- Legitimate interest (Art. 6(1)(f)): Analytics on platform usage to improve service quality (never on the content you create).
- Consent (Art. 6(1)(a)): Marketing emails and non-essential cookies — you can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): Retaining payment records as required by tax and accounting regulations.
Plain English SummaryWe only process data when we have a clear legal reason: to deliver the service, improve the platform, or because you gave consent.
#2Right of Access (Art. 15)
You can request a complete copy of all personal data we hold about you, including your account details, generated plans, drafts, and payment history. We will provide this in a structured, commonly used format (JSON or CSV) within 30 days of your request.
Plain English SummaryAsk us for a copy of everything we know about you. We'll send it within 30 days.
#3Right to Rectification (Art. 16)
If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. You can update most information directly from your account settings, or contact us for changes that require manual processing.
Plain English SummarySpotted an error in your data? Fix it in your settings or ask us to correct it.
#4Right to Erasure (Art. 17)
You can request the permanent deletion of your account and all associated data — the “right to be forgotten.” Upon receiving your request:
- Your account and profile data are immediately logically deleted.
- Your generated plans, drafts, and builder responses are permanently purged.
- Backup copies are fully removed within 30 days.
- Payment records may be retained where required by law (e.g. tax obligations), but are anonymised.
Plain English SummaryAsk us to delete everything. It's gone immediately, with backups purged within 30 days.
#5Right to Data Portability (Art. 20)
You can request your personal data in a structured, machine-readable format (JSON or CSV). This includes your account information and all generated HACCP plans. You can also request that we transmit this data directly to another service provider where technically feasible.
Plain English SummaryWant to take your data elsewhere? We'll export it in a standard format you can use anywhere.
#6Right to Restrict Processing (Art. 18)
You can request that we temporarily stop processing your data while we resolve a dispute about data accuracy, or if you have objected to processing and we are evaluating your request. During restriction, your data is stored but not actively processed.
Plain English SummaryYou can pause how we use your data while we sort out any concerns.
#7Right to Object (Art. 21)
You can object to the processing of your personal data based on our legitimate interests. If you object, we will stop processing your data unless we can demonstrate compelling legitimate grounds. You can object to marketing communications at any time by clicking the unsubscribe link in any email or contacting us directly.
Plain English SummaryDon't want us using your data for a particular purpose? Tell us and we'll stop.
#8Data Protection Officer
For any data rights requests or questions about how we handle your data, contact our Data Protection Officer:
- Email: support@ilovehaccp.com
- Subject line: “GDPR Request”
We respond to all valid requests within 30 days. If your request is complex, we may extend this by a further 60 days, but we will notify you of any extension within the initial 30-day period.
Plain English SummaryEmail support@ilovehaccp.com with 'GDPR Request' in the subject. We'll respond within 30 days.
#9Supervisory Authority
If you believe your data protection rights have not been adequately addressed, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or the relevant supervisory authority in your EU member state.