PRIVACY RIGHTS AND DATA PROTECTION COMPLAINTS

Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0

1. About This Page

You may use this page to:

NibbleKit is operated by Paul Hepple, a sole trader trading as DarkByte Creations. In this page, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.

You do not have to use this form. A valid rights request or data-protection complaint may also be made by email, post or another contact method through which it reasonably reaches us.

You do not need to quote legislation or use legal terminology. Please explain, in your own words, what you would like us to do or what you believe has gone wrong.

2. DarkByte and Merchant Privacy Roles

NibbleKit is a white-label technology platform used by participating food businesses and other sellers, referred to as Merchants.

DarkByte is normally a controller for personal data used for its own purposes, such as:

A Merchant is normally a separate controller for personal data it uses to:

DarkByte may act as a processor where it stores, transmits or otherwise handles personal data only on a Merchant's documented instructions.

DarkByte and a Merchant may therefore hold or use some of the same information for different purposes and in different legal roles. Each party is responsible for responding in relation to processing for which it is a controller.

If your request concerns a particular Merchant, order or Merchant-branded account, please identify the Merchant where possible. We will determine which party is responsible for the relevant processing.

3. Rights Requests and Complaints Are Different

A rights request asks an organisation to take an action provided for by data-protection law, such as giving access to personal data, correcting it or deleting it.

A data-protection complaint expresses dissatisfaction with how personal data has been handled or with the way a previous privacy request was dealt with.

You may make both at the same time. Where a submission contains both a rights request and a complaint, we will identify and handle each part under the appropriate process and timetable.

An order complaint about missing food, delivery, product quality, allergens, refunds or another Merchant service is not automatically a data-protection complaint. Order complaints should normally be submitted to the Merchant identified at checkout or in the order confirmation.

You may nevertheless use this page where an order issue also concerns the use, disclosure, accuracy, security or retention of personal data.

4. Data-Protection Rights

Depending on the circumstances and the law that applies, you may have the right to:

4.1 Access personal data

You may ask whether we process your personal data and request a copy of that data together with relevant information about its use.

4.2 Correct inaccurate or incomplete data

You may ask us to correct personal data that is inaccurate or complete data that is incomplete.

4.3 Request deletion

You may ask us to delete personal data where the applicable legal conditions are met.

The right to deletion is not absolute. Some information may need to be retained for reasons such as:

Where we cannot delete particular information, we will explain the applicable reason unless the law prevents us from doing so.

4.4 Restrict processing

You may ask us to restrict the use of personal data in circumstances provided for by law, including while its accuracy or the lawfulness of its use is being considered.

Restriction normally means that the data is stored but not otherwise used except for permitted purposes.

4.5 Receive or transfer certain data

You may request certain personal data in a structured, commonly used and machine-readable format where the right to data portability applies.

Where technically feasible and legally appropriate, you may ask for that data to be transmitted directly to another controller.

4.6 Object to certain processing

You may object to processing based on legitimate interests or another applicable ground. We will consider the objection in light of the purpose, our grounds for continuing and the effect on your rights.

You have an absolute right to object to processing for direct-marketing purposes. Where a valid direct-marketing objection is received, the relevant marketing use will stop.

Where processing is based on consent, you may withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal. It may also be necessary to retain a limited record of the consent and its withdrawal so that we can demonstrate compliance and respect your choice.

4.8 Ask about certain automated decisions

Where applicable, you may ask for information about safeguards relating to a decision made solely by automated processing that has a legal or similarly significant effect on you. You may also have rights to make representations, contest the decision or request human involvement.

NibbleKit profile warnings, order prompts or content filters do not necessarily amount to decisions of this kind.

5. Account Deletion

Account deletion is separate from deleting every record connected with an account.

A request to delete a NibbleKit account normally means that:

Account deletion may not immediately remove:

Where account creation is supported in a mobile app, the app will provide a way to initiate deletion from within the app at the user/profile screen menu using Delete Account.

A public account-deletion route is also available at the public Data Request page at https://nibblekit.com/policies/data-request/.

Deleting an app from a device does not by itself delete the account.

6. How to Submit a Request or Complaint

You may submit a request or complaint:

Using the form may help us route the matter, but it is not compulsory.

Where your submission concerns a Merchant, you may also contact that Merchant directly using the details shown at checkout, in the order confirmation or in the Merchant-branded service.

7. Information to Include

Please provide enough information for us to understand the matter and identify the relevant records.

Useful information may include:

Do not send:

We will ask separately if further information is genuinely required.

8. Privacy Form

Use this form to submit a privacy rights request, account-deletion request or data-protection complaint to DarkByte. Do not include passwords, full payment card details or identity documents in this form.

Use an email address through which we can communicate securely about the request.

Do not enter payment card details.

For a complaint, identify the processing you are concerned about, when you became aware of it, any previous contact and the outcome you are seeking.

If you act for someone else, explain your authority. We may ask for proportionate evidence before disclosing personal data or acting on the request.

After submission, the confirmation page will show the submission date and any generated reference included in the redirect. DarkByte may later classify the submission as a rights request, data-protection complaint, both or another privacy enquiry after review.

9. Identity Verification

We must take reasonable steps to ensure that personal data is not disclosed to the wrong person.

We will request identity evidence only where it is reasonably necessary and proportionate, taking account of:

Where possible, we will verify identity using information already associated with the account or a secure account-based process.

We will not routinely require a passport, driving licence or other formal identity document merely because a rights request has been made.

Where additional evidence is necessary:

The applicable response period begins when we have received sufficient information reasonably required to verify identity.

10. Requests Made by Representatives

A representative may make a request on behalf of another person.

Before disclosing personal data or taking action, we may ask for evidence that:

Where appropriate, we may contact the person concerned directly to confirm authority or to determine how they would like the response delivered.

We will not provide a representative with more information than they are authorised to receive.

11. How We Handle Rights Requests

We will:

We normally respond without undue delay and no later than one month after receiving a valid request.

Where a request is complex or you have made a number of requests, the response period may be extended by up to two further months. If an extension is required, we will normally tell you within the initial one-month period and explain the reason.

A request is not treated as complex merely because it is inconvenient or because information is held in more than one ordinary platform system.

If we do not take the requested action, we will explain the reason and provide information about available complaint rights, unless the law prevents us from doing so.

12. How We Handle Data-Protection Complaints

A data-protection complaint may concern, for example:

When we receive a data-protection complaint, we will:

We will identify the matters complained about, any related rights request and the processing roles involved.

We will acknowledge receipt within 30 days of receiving the complaint. Where we can investigate and provide the outcome within that period, the acknowledgement and outcome may be provided together.

The acknowledgement will normally include a complaint reference, the date received and information about how to contact us regarding the case.

Depending on the complaint, this may include reviewing account, order, access, consent, support, security or audit records; checking provider records; speaking to relevant personnel; or seeking information from a Merchant.

We may ask the complainant, a Merchant or another relevant party for information reasonably needed to understand and investigate the complaint.

Where the investigation cannot be completed promptly, we will provide appropriate progress information without undue delay. Updates will explain the current position and, where reasonably possible, the next step.

Once the investigation is complete, we will explain the outcome without unjustifiable or excessive delay.

The outcome will normally:

There is no requirement to wait for our investigation to finish before contacting the Information Commissioner's Office.

13. Requests or Complaints Involving a Merchant

Where a submission concerns processing controlled by a Merchant, we may:

We will inform you where we forward or refer a matter, unless doing so would be unlawful or would create a material security risk.

Forwarding a request does not make DarkByte responsible for a Merchant's independent processing. It also does not remove any responsibility DarkByte has for its own processing or conduct.

Where DarkByte is acting solely as processor, the Merchant normally decides how the relevant rights request is resolved. DarkByte will provide the Merchant with reasonable assistance required by the applicable data-processing agreement and data-protection law.

Where both DarkByte and the Merchant are controllers for different purposes, each party will handle the part relating to its own processing.

14. Fees, Repetitive Requests and Refusals

There is normally no charge for making a rights request or data-protection complaint.

Where data-protection law permits, we may charge a reasonable fee or refuse to act on a rights request that is manifestly unfounded or manifestly excessive. This threshold is high, and each request will be considered on its own circumstances.

We will not treat a request as unfounded or excessive merely because:

Where we charge a fee or refuse to act, we will explain the decision and the available complaint rights unless the law prevents us from doing so.

A complaint will not be rejected merely because it is submitted through a channel other than this form.

15. Secure Delivery of Responses

We will take reasonable steps to deliver personal data securely.

Depending on the sensitivity and volume of the information, we may use:

We may redact or withhold information where disclosure would adversely affect another person's rights, reveal protected confidential information or fall within another lawful exemption.

We will not send passwords, full payment card information or another person's unrestricted personal data in a rights response.

16. Complaining to the Information Commissioner's Office

You may complain to the Information Commissioner's Office, the UK supervisory authority for data protection.

You may contact the Information Commissioner's Office at any point. You do not have to complete DarkByte's complaints process first.

Information about making a complaint is available through the Information Commissioner's Office website.

Where you remain dissatisfied after receiving our outcome, it may help to provide the Information Commissioner's Office with:

17. Contact Details

NibbleKit is operated by:

Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com

Privacy rights and complaints contact:

privacy@darkbyte.uk

This page should link to:

19. Changes to This Page

We may update this page to reflect changes in data-protection law, guidance, platform functions or our request-handling process.

The current version will show its last-updated date and version number.

A change to this page will not reduce rights that apply under data-protection law or retrospectively change the way a request or complaint already received must be handled.

Previous material versions are available on reasonable request from support@nibblekit.com.