Legal
Privacy Policy
Last updated: 26 August 2026
This notice explains how Oak & Ivy Coffee House (“we”, “us”) handles personal data. It is written for a small café website in Northern Ireland under the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). It is general information, not legal advice. Please replace the contact email if you use a different address.
1. Who we are
The data controller is Oak & Ivy Coffee House, 6a Tobermore Rd, Draperstown, Magherafelt BT45 7AG, Northern Ireland.
Website: oakivycoffeehouse.com
Privacy enquiries: visit us in person during opening hours, write to the address above, or message us on Instagram or Facebook. If you add a dedicated email, use that as the main contact for data rights requests.
We do not have a statutory Data Protection Officer. The owners deal with privacy requests.
2. The data we collect
This website is a brochure site. We do not run accounts, online checkout or a contact form at present. We may still process limited personal data:
- Website use. Technical data such as IP address, browser type and pages viewed, if you allow optional tools (see Cookies Policy) or if our hosting provider keeps standard server logs for security.
- Cookie choice. A record on your device that you accepted, rejected or customised optional tools.
- In-person custom. If you pay by card in the café, the card terminal provider processes payment data. We may see a truncated card receipt. We do not store full card numbers.
- Enquiries. Name, contact details and message content if you email, phone, message on social media, or speak to us about bookings, allergens, jobs or complaints.
- Reviews. If you leave a public Google, Facebook or Instagram review, that platform is the controller of that content.
- CCTV. If CCTV is used on the premises for security, signs will be displayed. Recordings are kept only as long as needed for that purpose.
We do not intentionally collect special category data through the website. Please do not send health or allergy details through public social media; tell staff in person if you need us to know.
3. Why we use data and the lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Running this website and remembering your cookie choice | Legitimate interests (operating a public site); consent where PECR requires it for optional tools |
| Serving you in the café, taking orders and payments | Contract; legal obligation for tax records |
| Answering messages and complaints | Legitimate interests; contract if we are arranging something for you |
| Loading Google Fonts or Google Maps | Consent (PECR / UK GDPR) |
| Security of the premises (if CCTV is used) | Legitimate interests |
| Keeping invoices and similar records | Legal obligation |
We do not sell personal data. We do not use the website for automated decision-making or profiling.
4. Cookies and similar technologies
Optional tools are off until you choose. Necessary storage only remembers that choice. Full detail is in the Cookies Policy. You can change your mind at any time via Cookie settings.
5. Who we share data with
- Hosting / domain provider — to keep the site online.
- Google — only if you consent to fonts or the map embed. Google’s own terms and privacy notice then apply. Google may process data in the United States under its transfer tools.
- Meta (Instagram / Facebook) — if you follow or message those pages.
- Card payment providers — for in-café card payments.
- Professional advisers and authorities — if the law requires it or we need to defend a claim.
We do not run Google Analytics or advertising pixels on this site.
6. International transfers
The site is aimed at visitors in the UK. If you allow Google Fonts or Maps, information (including IP address) may be processed outside the UK. Google states that it uses approved transfer mechanisms. You can refuse those tools and still use the rest of the site.
7. How long we keep data
- Cookie choice: up to 6 months on your device, then we ask again.
- Server logs: typically up to 90 days, unless needed for security.
- Enquiry messages: up to 12 months after the matter is closed.
- Till / tax records: usually 6 years, as required for UK tax law.
- CCTV (if used): the shortest period that still meets the security purpose, often around 30 days unless an incident is being reviewed.
8. Your rights
Under UK GDPR you can ask to access, correct, erase or restrict your data, object to processing based on legitimate interests, and (where we rely on consent) withdraw consent. You may also complain to the Information Commissioner’s Office. These rights are explained on our GDPR & Your Rights page.
9. Children
The site is for a general audience. We do not knowingly collect children’s data through the website. The café welcomes families; any children’s meal orders are taken from the accompanying adult.
10. Security
We use HTTPS on the website and limit who can access business records. No method of transmission is completely secure. Please do not send card details by email or social media.
11. Changes
If we add a contact form, bookings, email marketing or analytics, we will update this notice and, where required, ask for consent again.
12. How to contact us or the ICO
Oak & Ivy Coffee House, 6a Tobermore Rd, Draperstown, Magherafelt BT45 7AG. Open Monday–Saturday 9:00–15:30.
Information Commissioner’s Office: ico.org.uk · Helpline 0303 123 1113.
