Data Protection


VERSION: April 2020

To be Brief.
We will not record and keep any information about you without your permission. We will not share your information with any other companies. You will have an opportunity to unsubscribe whenever we communicate with you.

  1. About the Processing of Your Personal Data

This data protection notice serves to inform you that Tilly Confectionery Ltd t/a Mrs Tilly’s and Mrs Tilly’s Direct (below “we”, “us” or “our”)  will process personal data relating to you as a representative of your company who is a contact to us.

  1. We are the data controller

Your privacy is important to us. Under the EU General Data Protection Regulation 2016/679 and associated and applicable EU legal acts, from time to time (below “EU Data Protection Law”), we are the ‘data controller’ in relation to you.

As the data controller, we determine the means and purposes of collection and use of your personal data and we are obliged to provide the individual whose personal data is being processed (you) with certain information about the processing. This notice serves as such information. This notice is not intended to replace any other separate or more detailed privacy notices or further information that we may provide you.

  1. Sources of Personal Data

We will process personal data about you gathered from the following sources:

(1) Personal data that you provide (or have provided) to us, such as name, title, e-mail address and telephone number.

(2) Personal data that arise as a result of you or your company as a customer or supplier to us, such as customer or supplier number and delivery history.

  1. Purpose and Legal Basis for the Processing of Your Personal Data

The processing of your personal data is necessary for us in order to pursue our legitimate interests of providing our services to your company and for internal administrative purposes within Tilly Confectionery Ltd. Specifically, your personal data is processed for the following purposes: customer and supplier management, billing, delivery, advertising, information relating to our products, solutions and customer segmentation, which may e.g. lead to customised advertising and invitations.

If you do not provide your personal data we may not able to properly fulfil our contractual obligations towards yourself or company.

  1. How Your Personal Data is Processed

For the above described purposes, your personal data will be collected, processed and transmitted electronically to us inside or outside the EU.

Appropriate technical and organisational measures and safeguards protect your personal data and all data processing operations handled by us. Such measures include traceability and access control and other suitable IT and information security measures in accordance with industry practice, as well as data processing agreements and other arrangements as appropriate ensuring protection of your rights as a data subject and ensuring that your personal data is only used for the purposes for which it is collected, as described above.

We will not disclose or share your personal data with any third party. We may however need to disclose your personal data to relevant public authorities, if required by law.

  1. Retention Period

Your personal data will be stored for as long as necessary to meet the purposes described herein. This means that your personal data is generally stored for as long as you are a representative for your company who is a customer or supplier to us, unless otherwise required or permissible under EU Data Protection Law or local law. When your personal data is no longer necessary for us to retain for the purposes of the processing it will be deleted or rendered anonymous in such a manner that the data will no longer identify you.

  1. Marketing Choices regarding your personal information

Mrs Tilly’s may send you marketing communications by email about products and services that we feel may be of interest to you. You can ‘opt-out’ of such communications if you would prefer not to receive them in the future by using the “unsubscribe” facility provided in the communication itself or you can update your preferences by using the contact us link.

  1. Your Rights

As a data subject you have certain mandatory rights under EU Data Protection Law in regards to our processing of your personal data:

  1. a) Right to access – You have the right to receive written confirmation as to whether or not personal data concerning you is being processed, and, if personal data is processed, access to the personal data.
  2. b) Right to object – You have the right to object to our processing of your personal data, and we are then obliged to re-examine whether our legitimate interests to perform the processing still outweigh your interests and objection. If you object to processing for direct marketing purposes, we will no longer process your personal data for such purposes.
  3. c) Right to rectification and restriction – You have the right to have inaccurate or incomplete personal data corrected and under certain circumstances, you have the right to request restriction of the processing.
  4. d) Right of erasure – Under certain specific circumstances, e.g. your personal data is no longer necessary for the purposes set out herein; you have the right to request that your personal data is erased.
  5. e) Right to lodge a complaint – If you believe that we illegally process your personal data, and if you are an EU citizen, you can lodge a complaint to the Information Commissioner’s Office, ICO.
  6. When we need to update this policy

We will need to change this policy from time to time in order to make sure it stays up to date with the latest legal requirements and any changes to our privacy management practices.

A copy of the latest version of this policy will always be available on this page.

  1. Competitions

Tilly Confectionery make indulgent treats – and know that our products can be a fun indulgence. We aim to provide a mix of fact and fun on our website and on our packs. We will offer competitions, promotions and surveys with a reward for completion. The content for each is different (and we are always pleased to hear any good suggestions for more).
We do ask for contact information when you enter the competition – because we need to be able to contact you if you win!
This type of information is only held as a temporary record until the advertised close of the competition when we contact the winners and delete the information.
We may share non-personal survey information with others, such as our retailers, but only in aggregate anonymous form, which means that the information will not contain any personally identifiable information about you.

  1. Shopping online with us.

If you shop online with us, your address detail and contact information is requested and required to enable us to fulfill your order. We use Shop Pay security for protecting your online financial transaction or you may elect to pay with paypal.

Our data is kept and backed up in secure premises and the server has appropriate firewall and other technical support added. We endeavour to take all appropriate measures to prevent unauthorised access or inaccuracy.

  1. Refund Policy

If for any reason, you are not happy with any of our products, we will happily exchange or refund your purchase.

  1. Contact Details

If you wish to exercise your mandatory rights under EU Data Protection Law, as set forth above, please send a written and duly signed request to Tilly Confectionery Ltd, 5 Central Park, Central Boulevard, Larbert, Stirlingshire, FK5 4RU.

If you have questions regarding the processing of your personal data under this notice, you can contact our data protection officer at