In very basic terms we respect your personal information and will only ask you for what information we really need from you. We will only share it with others where we need their help for us to deliver our service to you (for example our professional printing laboratory who may need your name and address to post your purchases). We will never share your information in any other circumstances, nor will we sell it on elsewhere.
The Data We Collect
As a data controller we collect a variety of data in order to deliver our services, and we will manage your personal data transparently, fairly and securely.
We may ask you to provide us the following data:
- First and Last Name
- Postal Address and post code
- Telephone number
- Email address
We will also record a date of birth for all persons we photograph under the age of 13 and require the parent or a legal guardian to consent to photography
Obviously being a photographic business we also create and manage images as per our contractual agreement(s).
We use the above data to deliver our service to you, to personalise your experience and for marketing purposes. We also use the above data to fulfil our financial record-keeping obligations as required by law.
We collect this data on the lawful basis:
- To fulfil our contract with you for your booking
- To meet our legal obligations
- Where consent is given by you
When you visit our website we also collect cookies. These are small pieces of data that websites send to a user’s computer and are stored on the user’s web browser. They are designed to enable the website to remember information, such as what a user might have put in a shopping cart. This helps us deliver our service to you and to personalise your experience.
What third parties do we share personal data with?
We share data with the following third parties:
- Our chosen printing laboratories. Data is not transferred outside of the European Economic Area
- Our accountant. Data is not transferred outside of the European Economic Area
- Gmail as our email provider, where emails are sent to/from us. Data is transferred outside of the European Economic Area to the United States under the protection of EU/US privacy shield
- Google Analytics. Data is transferred outside of the European Economic Area to the United States under the protection of EU/US privacy shield
- Our website host. Data is transferred outside of the European Economic Area to the United States under the protection of EU/US privacy shield
- GoCardless for direct debit payment processing. Data is not transferred outside of the European Economic Area
- Stripe and Paypal for credit/debit card processing. Data is not transferred outside of the European Economic Area
- Computer Back Up Providers. Data is not transferred outside of the European Economic Area
- Mailerlite for email newsletters. Data is transferred outside of the European Economic Area to the United States under the protection of EU/US privacy shield
- Suitedash for my client portal. Data is transferred outside of the European Economic Area to the United States under the protection of EU/US privacy shield
There are also certain situations in which we may share access to your personal data without your explicit consent, for example if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation
Why do we share your personal data with the above?
We share your data in order to deliver our service to you, for marketing purposes and to comply with our legal and financial record-keeping obligations
We may transfer personal data to a country outside of the European Economic Area (EEA) if necessary e.g. if a third party we utilise could have servers located outside of the EEA. If this is the case, we will either obtain your consent or otherwise ensure that the transfer is legal and your data is secure by following the EU’s guidelines.
How do we keep your personal data secure?
We keep your data secure by following internal policies or best practice and training for staff, by using Secure Socket Layer (SSL) technology when information is submitted to us online, by using password protected booking systems.
In the unlikely event of a criminal breach of our security we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we will also inform you.
You have the following rights:
- The right to be informed about the collection and use of your personal data
- The right of access to your personal data and any supplementary information
- The right to have any errors in your personal data rectified
- The right to have your personal data erased
- The right to block or suppressing the processing of your personal data
- The right to move, copy or transfer your personal data from one IT environment to another
- The right to object to processing of your personal data in certain circumstances, and
- Rights related to automated decision-making (e.g. where no humans are involved) and profiling (e.g. where certain personal data is processed to evaluate an individual)
We also give you the option to manage your data via email to firstname.lastname@example.org telephone 07930 337914 or in writing to 15 Rushton Road, Wilbarston, Market Harborough, LE16 8QL
While we do not hold personal data any longer than we need to, the duration will depend on your relationship with us, and whether it is ongoing. We may keep some of your personal data for up to 7 years after our working contract with you has finished for tax legislation purposes. After this time we will archive your photographs indefinitely along with your relevant details and consent forms. This is due to replacement images being made several years after being taken