Privacy Notice



1) Purpose

  • This Privacy Notice is issued in accordance with the EU General Data Protection Regulation and Data Protection 2018. It covers all data processing activity by Windmill Lodges.


2) Data Controller

  • The data controllers for Windmill Lodges are Lisa Handley and Angela Wright


3) Why are we processing your data?

  • If you have placed an enquiry with us (either directly to us, via our website, email, telephone or via a third party). We will process your data to enable us to answer your enquiry.
  • If a booking is placed with us, your data is processed to enable us to fulfil the contract. Your data will be used routinely and in case of emergency.
  • If you have given us specific consent for us to email special offers and newsletters.

4) What data will we process?

The data we will process will include:

  • Name
  • Address
  • Email address
  • Contact telephone number
  • Names of guests staying,
  • Ages of children staying (to ensure we supply the correct size robe)
  • How you heard about us
  • Social Media used
  • Pets name, age and breed
  • If you provide further information relevant to your booking eg birthday celebration
  • Method of payment
  • Any further details relevant to your booking

5) Who will have access to this data?

  • The data controllers will have full access to the data. Housekeeping staff have access to names of guests and ages of children staying and any specific requirements related to your booking
  • All staff with access to data will sign a code of conduct.


6) Who else will access to the data?

  • We do not pass your data on to any third party

7) Where will the data be held?

Your data will be processed and stored in the following manner:

  • By the data controllers on their own office computers, we use Mac computers that are kept up to date with the latest IOS updates.
  • Using Supercontrol our online booking system (they are both a processor and data collector and fully compliant with GDPR regulation)
  • Using SageOne our online accounts package
  • In physical (paper copies) in the office

8) Security of your data:

  • All physical data (paper copies) is stored under lock and key. The archive data is locked with the data controllers having access to the key this is only accessed as required.Physical data that is currently “in use” is stored in a locked cupboard when the office is closed.
  • All data which is stored digitally is password protected and only accessed by the data controllers

9) How long will we retain the data for?

  • All paper documentation data relating to a booking placed with Windmill Lodges will be retained for 6 yrs +1 in order to comply with HMRC
  • All digital data for enquiries will be held for one year from date of enquiry, unless a booking is held in the name of the person making the enquiry.
  • When a booking is made, all data and correspondence held under the name of the person who made the booking will be held on our system until no longer required.
  • All data relating to our mail out list (Name and email address) for which specific consent has been given to receive our special offer and newsletters will be retained until you ask to be removed from receiving this information.

10) What is the legal basis for processing your data?

  • We must have a legal basis to process your personal data. Our legal basis is under Article 6 (1) (a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
  • We consider your consent to be given when an enquiry/booking is sent/placed to us via our website, email or telephone.
  • We ask for specific consent to receive our special offers and newsletters.


11) Your Rights

  • Should you have any questions relating to your data protection rights please contact either of the data controllers Angela Wright or Lisa Handley at Windmill Lodges, Red House Farm, Saxtead, Woodbridge, Suffolk IP13 9RD Tel: 01728 685338 or via email


Date: 01.12.2021



Code of Conduct


As a member of staff at Windmill Lodges I am responsible for ensuring that I use and handle personal data in a secure and confidential way. I will only access the data for the needs of the business.





Print name                                                                               Date