Back to Login

Privacy Notice

Last updated: March 2026

1. Who We Are

The Original Baker Ltd ("The Original Baker", "we", "us") is the data controller for the personal data processed through this CRM system. We are part of the Olidor Group of companies.

If you have any questions about how we handle your data, please contact:

Data Protection Queries
The Original Baker Ltd
Email: info@theoriginalbaker.co.uk

2. What Data We Collect

When you use this CRM system, we process the following personal data:

  • Account information — your name, email address, and role within the organisation
  • Authentication data — login credentials (passwords are stored in hashed form only)
  • Activity logs — records of your actions within the system, including login times, pages visited, and changes made
  • Business data you enter — customer records, contacts, opportunities, notes, and other CRM data created as part of your job duties
  • Technical data — IP address, browser type, and session information

3. Why We Process Your Data

We process your personal data on the following legal bases under UK GDPR:

Performance of a contract (Article 6(1)(b))

Processing your account and authentication data is necessary for us to provide you with access to the CRM as part of your employment or engagement with us.

Legitimate interests (Article 6(1)(f))

We log activity data for security monitoring, system integrity, and to maintain accurate business records. Our legitimate interest is the secure and effective operation of our business systems.

Legal obligation (Article 6(1)(c))

Certain records are retained to comply with legal and regulatory requirements, including financial record-keeping obligations.

4. How Long We Keep Your Data

  • Account data — retained for the duration of your employment or engagement, and for up to 12 months after your account is deactivated
  • Activity logs — retained for up to 24 months for security and audit purposes
  • Business records — retained in accordance with our data retention policy and applicable legal requirements (typically 6 years for financial records)

5. Who We Share Your Data With

Your personal data may be shared with:

  • Other Olidor Group companies — where necessary for group-wide business operations
  • Hosting providers — our CRM is hosted on secure cloud infrastructure
  • IT support — authorised personnel who maintain and support the system

We do not sell your personal data or share it with third parties for marketing purposes. Where we use third-party processors, appropriate data processing agreements are in place.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted connections (HTTPS/TLS) for all data in transit
  • Hashed password storage using industry-standard algorithms
  • Role-based access controls limiting data visibility
  • Regular security reviews and monitoring
  • Account lockout protections against brute-force attacks

7. Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate personal data
  • Right to erasure — request deletion of your personal data (subject to legal retention requirements)
  • Right to restrict processing — request that we limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests

To exercise any of these rights, please contact info@theoriginalbaker.co.uk.

8. Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Website: ico.org.uk
Telephone: 0303 123 1113

9. Changes to This Notice

We may update this privacy notice from time to time. Any changes will be reflected on this page with an updated revision date. We encourage you to review this notice periodically.

© 2026 The Original Baker