The new Data Processing Regulation (GDPR) regulates storage and processing of personal data. Below is a summary of: what data we hold and why, how we use your data, your rights, who controls our data processes (our Data Controller), and how to contact us.
What Information we hold, and what we do with it
We hold basic contact details for you, together with information relating to past orders, for the sole purpose of allowing us to contact you in relation to the products and services we offer and to allow us to inform you in the future about related information, products and services. We retain your information for a period of 10 years in line with the lawful basis for which we hold and use your information. We will not pass your information to a third party for the purpose of marketing. If ever it may be necessary to pass your information to a third party then we will ensure the people concerned have their own Data Protection Policies in place and that your information is not passed on to any other individuals.
Our Lawful Basis for Processing your Personal Data
Our Lawful basis for holding and processing your information is a legitimate interest: i.e. to
contact you concerning the services / products we are providing to you, and to inform you of any relevant information relating to those services.
In addition, we hold past order information in case you have any queries relating to the order, or wish to reorder using the same information as was provided earlier.
GDPR gives you the following rights:
The right to be informed: To know how your information will be held and used (this notice).
The right of access: To see and verify records of your personal information.
The right to rectification: To ask us to make changes to your personal information if it is incorrect / incomplete.
The right to erasure (also called ‘the right to be forgotten’): to request us to erase any information we hold about you.
The right to restrict processing of personal data: to request limits on how we use your personal information.
The right to data portability: if applicable: the right to ask us to supply you with a copy of your own information, if held electronically, in an easily machine readable form, so that it can be copied into another system.
The right to object: to be able to tell us that you don’t want us to use certain parts of your information, or only to use it for certain purposes.
Rights in relation to automated decision-making and profiling.
The right to lodge a complaint with the Information Commissioner’s Office: To be able to complain to the ICO if you feel your details are not correct, if they are not being used in line with your
permission, or if they are being stored unnecessarily.
For full information about GDPR including full details of your rights, please visit UK Information Commissioner’s Office.