• Gold Instagram Logo
  • Gold Facebook Logo
13 Stone Bridge Lane
Oswaldtwistle
Lancashire
BB5 3HX

Privacy Policy & GDPR

This policy was created on Monday 17th December 2018

In the most basic of terms, I respect, throughout our relationship, your personal information. I only ask for personal information that is needed for me to operate this business smoothly and your details are encypted when stored on any of my electronic devices to minimise any data breaches. I look after your personal details with the same level of respect that I treat my own and never pass them onto any other party unless it is needed for the running of my business. Those exact parties are named in section 2 of this privacy policy and includes the likes of my printing lab who may request your name and address if the product is being sent directly to you.

Introduction

Photography by Andrew James takes your privacy very seriously. This privacy policy has been prepared in line with the EU’s General Data Protection Regulation (GDPR), which promotes fairness and transparency for all individuals in respect of their personal data. This privacy policy applies to all data I process, and by using Photography by Andrew James you consent to the collection and use of such data.

1. The Data I collect

 

As a data controller I collect a variety of data in order to deliver my services, and I will manage your personal data transparently, fairly and securely.

I may ask you to provide the following data –

  • First and Last Names

  • Addresses & Postcodes

  • Telephone Numbers

  • Email Addresses

  • Names of some key members of your family (for group photographs)

Obviously being a photographic business I also create and manage images as per our contractual agreement.

I use the above data -

  • To deliver my service to you

  • For marketing purposes

  • To personalise your experience

I collect this data on the following lawful basis -

  • To arrange or fulfil a Contract

  • To meet a legal obligation other than a Contract

When you visit my website I also collect Cookies. These are small pieces of data that websites send to a user's computer and are stored on the user's web browser. They are designed to enable the website to remember information, such as what a user might have put in a shopping cart for example. This helps me-

  • Personalise your experience

  • Deliver my service to you

  • For Marketing Purposes

 

2. Which third parties do I share Personal Data with?

 

I share personal data with the following third parties -

  • G Suite (my email provider) - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.

  • Mailchimp (my newsletter provider service) - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.

  • My Accountant for tax and accounting purposes - Data is not transferred outside of the European Economic Area.

  • PayPal and Stripe payments system - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.

  • Apple Calendar (My calendar management software) - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.

  • Wix (My website provider) - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.

  • My Chosen Print Lab 1- Data may be transferred outside of the European Economic Area to Australia with the consent of the client.

  • My Chosen Print Lab 2- Data is not transferred outside of the European Economic Area.

There are also certain situations in which I may share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation.

 

3. Why do I share your Personal Data with the above?

 

I share your data in order to -

  • Deliver my service to you.

  • For marketing purposes.

  • To personalise your experience.

I may transfer personal data to a country outside of the European Economic Area (EEA) if necessary eg if a third party I utilise could have servers located outside of the EEA. If this is the case, I will either obtain your consent or otherwise ensure that the transfer is legal and your data is secure by following the EU's guidelines. You can see above where I send data outside of the EEA and on what basis we do so.

 

4. How do I keep your personal data secure?

 

I keep your data secure -

  • By following internal policies of best practice.

  • By using Secure Socket Layer (SSL) technology when information is submitted to me online.

In the unlikely event of a criminal breach of our security I will inform the relevant regulatory body within 72 hours and, if your personal data was involved in the breach, I will also inform you.

 

5. Changes to my privacy policy and control

 

I may change this privacy policy from time to time. When I do, I will let you know by changing the date on this policy, notifying customers of only significant changes. By continuing to access or use my services after those changes become effective, you agree to be bound by the revised privacy policy.

 

6. You have the following rights -

  1. The right to be informed about the collection and use of your personal data.

  2. The right of access to your personal data and any supplementary information.

  3. The right to have any errors in your personal data rectified.

  4. The right to have your personal data erased.

  5. The right to block or suppressing the processing of your personal data.

  6. The right to move, copy or transfer your personal data from one IT environment to another.

  7. The right to object to processing of your personal data in certain circumstances, and

  8. Rights related to automated decision - making (i.e. where no humans are involved) and profiling (i.e. where certain personal data is processed to evaluate an individual).

 

I also give you the option to manage your data via -

  • Email

  • Writing to me

 

While I do not hold personal data any longer than I need to, the duration will depend on your relationship with me and whether it is on-going. I may keep some of your personal data for up to 7 years after my working contract with you has finished for Tax legislation purposes. After this time I will archive your photographs indefinitely along with your relevant details and consent forms. This is due to requests for replacement images being made several years after being taken.

If you do have any queries regarding the above information, please feel free to contact me...