The Goat — www.thegoat-llandudno.co.uk
Last updated: 27 August 2026
The website, www.thegoat-llandudno.co.uk, is operated by Morgans Holding Ltd, a company registered in England and Wales with VAT registration number 357486849, with its registered office at The Esplanade Hotel, Glan y Mor Parade, Llandudno, LL30 2LL. We trade as "The Esplanade Hotel" and "The Goat".
We are the "data controller" of the personal data collected through this Website. This means we are responsible for deciding how and why your personal data is used, and for keeping it safe.
We are registered with the Information Commissioner’s Office (ICO) under registration number ZC230151.
Contact for data protection matters:
This policy explains what personal data we collect from you when you use this Website, why we collect it, the legal grounds we rely on, who we share it with, how long we keep it, and the rights you have over it. It covers data collected digitally through the Website, including forms, booking systems, cookies and similar technologies.
It applies alongside our cookie information in section 7 and, where you make a booking or purchase, our Terms & Conditions (www.thegoat-llandudno.co.uk/terms).
This policy does not cover personal data we collect offline (for example, in person at the restaurant or over the phone), except where stated.
We collect personal data in the following ways.
When you submit a contact, enquiry or feedback form, we collect: your name, email address, phone number, and the content of your message, plus any other information you choose to include.
When you book accommodation through our online booking engine we collect: your name, email address, phone number, postal address, arrival and departure dates, guest details (including the names of others in your party, where provided), payment card details, and any preferences or special requirements you tell us about (for example accessibility or dietary needs — see section 4 on special category data). Our booking engine is provided by Guestline, which processes this personal and payment data securely on our behalf. Payments are processed securely through Guestline; we do not store your full card details on this Website.
When you reserve a table or book an event through our online reservation system, we collect your name, email address, phone number, party size, the date and time of your reservation, and any dietary requirements, allergies, or special requests you provide. Our reservation system is provided by ResDiary, which processes this personal data and any payment or deposit details securely on our behalf.
When you sign up to our mailing list, we collect your name and email address. Our email marketing is managed through Mailchimp, which processes this data on our behalf. We record when and how you consented.
When you connect to the guest Wi-Fi at the restaurant, you are asked to provide your name and email address to log in. Our guest Wi-Fi service is provided by Beambox, a third-party provider that collects and processes this data on our behalf. The contact details you provide are added to our marketing list, which is stored in Mailchimp, and may be used to send you marketing emails in line with section 6. You can opt out at any time using the unsubscribe link in any email or by contacting us at data@greyhive.co.uk.
When you visit the Website, we automatically collect certain technical data, including: your IP address, browser type and version, device type, operating system, referral source, pages viewed, time spent on pages, and how you navigate the Website. This is collected via cookies and similar technologies — see section 7.
We do not intentionally collect special category (sensitive) personal data through this Website, except where you voluntarily provide it — for example, dietary requirements or allergy information that may reveal health or religious information, or accessibility requirements when booking. Where you provide this, we use it only to accommodate your needs and rely on your explicit consent, which you may withdraw at any time.
UK data protection law requires us to have a lawful basis for using your personal data. Our purposes and the corresponding lawful bases are:
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded they are not overridden. You can request a copy of our assessment using the contact details in section 1.
We will only send you marketing communications by email where you have either (a) consented, or (b) previously made a purchase or booking with us and not opted out, in which case we may tell you about similar products and services (the "soft opt-in" permitted under UK e-privacy rules).
Every marketing email we send contains an unsubscribe link. You can also opt out at any time by contacting us at data@greyhive.co.uk. Opting out of marketing will not affect service communications we need to send you, such as booking confirmations.
We may use your hashed email address to show you relevant advertising on platforms such as Meta and Google, and to create audiences of people with similar interests. We only do this where you have consented to advertising cookies. You can object at any time.
We do not sell your personal data to third parties.
This Website uses cookies and similar technologies. When you first visit, you will see a cookie banner that lets you accept or reject non-essential cookies. Essential cookies (needed for the Website to function, such as those supporting the booking process) do not require consent.
The categories we use are:
You can change or withdraw your cookie preferences at any time by re-opening the cookie banner on the Website or through your browser settings.
We share personal data with trusted third parties who help us run the Website and our business. They act under contract, only on our instructions, and must keep your data secure. These include:
We may also disclose personal data where required by law, to professional advisers, in connection with a sale or restructuring of our business, or to protect our legal rights.
We keep personal data only as long as necessary for the purposes described in this policy, and then securely delete or anonymise it. Our standard retention periods are:
Some of our service providers — including Mailchimp, Meta, Google and Webflow — may store or process personal data outside the UK, including in the United States. Where they do, we ensure appropriate safeguards are in place, such as the UK Extension to the EU–US Data Privacy Framework, UK adequacy regulations ("data bridges"), or the ICO’s International Data Transfer Agreement / Addendum, so that your data receives protection not materially lower than it would in the UK.
We use appropriate technical and organisational measures to protect your personal data, including encryption in transit (HTTPS/SSL across the Website), access controls limiting who can view your data, and reputable, security-accredited service providers. All data we collect through any of our software systems — whether personal or financial — is accessible to authorised members of staff only via a two-factor authentication (2FA) process; this includes our booking and reservation systems, Guestline and ResDiary. While no online transmission is completely secure, we work to protect your data and require the same of our suppliers. If a data breach occurs that is likely to result in a risk to your rights, we will notify the ICO and, where required, affected individuals, in line with our legal obligations.
Under UK data protection law, you have the right to:
To exercise any of these rights, contact us using the details in section 1. We will respond within one month (this may be extended for complex requests, in which case we will let you know). We may need to verify your identity first. These rights are free to exercise in most circumstances.
You have a legal right to complain to us if you believe we have not handled your personal data in line with data protection law, and we have a formal process for dealing with such complaints.
How to complain to us: You can submit a data protection complaint by email to data@greyhive.co.uk, or by post to The Goat, Glan y Mor Parade, Llandudno, LL30 2LL.
What happens next: We will acknowledge your complaint within 30 days of receiving it, investigate it promptly and appropriately (led by our General Manager), keep you informed of progress, and tell you the outcome without undue delay.
Escalation: If you are not satisfied with our response, or at any time, you can complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO): Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint
We would, however, welcome the chance to resolve your concerns directly first.
This Website is not directed at children, and we do not knowingly collect personal data from anyone under 18 through it. Where you provide details of children in your party as part of a booking, we use this only to manage your stay. If you believe a child has provided us with personal data, please contact us, and we will delete it.
This Website may contain links to third-party websites (for example, social media platforms, review sites, or partner attractions). We are not responsible for the privacy practices of those sites — please check their own privacy policies.
We may update this policy from time to time. The latest version will always be published on this page with the "last updated" date shown at the top.
Questions about this policy or your personal data should be directed to:
Morgans Holding Ltd (trading as The Goat)
The Goat, Glan y Mor Parade, Llandudno, LL30 2LL
data@greyhive.co.uk
01492 353 189