Launched in May 2018 the new EU General Data Protection Regulations (GDPR) is a much needed overhaul of Data Protection Laws that had failed to keep pace with the ever-evolving digital world. The GDPR are designed to keep our personal data safe and enhance our individual rights and freedoms by reinforcing the understanding of privacy as a fundamental human right. It is overseen in the UK by the Information Commissioners Office (ICO) and you can find more detail about this legislation and your rights on their website https://ico.org.uk/.
Elsie Grace Photography takes your privacy very seriously. We will only ask you for personal information that is essentially needed and we will guard it as stringently as we guard our own privacy. Elsie Grace Photography will occasionally need to share your information with others in order to help us deliver our services to you (such as a professional printing laboratory who may need your name and address to post your purchased goods). But please be assured that we will never share your information in any other circumstances; nor will we sell it on elsewhere! We also only use third party service providers if we are assured that they too will respect your data.
We will ask you to provide us the following data:-
- Full Name,
- Email Address,
- Telephone Contact Numbers,
- IP address,
- Payment Authorisations.
We may ask you to provide us with additional bespoke but essential personal details that may be relevant to the service you have requested, and should be considered when granting and signing our consent forms.
We will also record the date of birth for all persons we photograph under the age of 13 and will require the parent or a legal guardian to consent to the photography. Obviously, being a photographic business we also create and manage images as per our contractual agreement(s).
We use the above data:
- To deliver the requested and agreed services
- For Elsie Grace Photography marketing purposes
- To personalise your experience
- To provide you with full service access on our website.
We also collect this data on the following lawful basis:
- To comply with the Data Protection Act and GDPR
- To arrange and fulfil our agreed contract
- To meet consent obligations
When you visit our website we also collect Cookies. These are small pieces of data that websites send to a user's computer and are stored on the user's web browser. They are designed to enable the website to remember information, such as what a user might have put in a shopping cart, for example. This helps us personalise your experience, to deliver the most easy to use, convenient service to you, and for Elsie Grace marketing purposes.
Our customers have the right to access, correct and delete personal data relating to them, and to object to the processing of such data, by addressing a written request, at any time. The Company makes every effort to put in place suitable precautions to safeguard the security and privacy of personal data, and to prevent it from being altered, corrupted, destroyed or accessed by unauthorized third parties. However, the Company does not control each and every risk related to the use of the Internet, and therefore warns the Site users of the potential risks involved in the functioning and use of the Internet. The Site may include links to other web sites or other internet sources. As the Company cannot control these web sites and external sources, the Company cannot be held responsible for the provision or display of these web sites and external sources, and may not be held liable for the content, advertising, products, services or any other material available on or from these web sites or external sources.
We share personal data with a number of third parties that assist Elsie Grace Photography in providing you with a fantastic service. We have provided an outline of outsourced services and the current service provider and where they are based. This list will be updated regularly and may be subject to change.
- Website Hosting: Hostgator (Data is transferred outside of the European economic Area to United States under the protection of EU/US Privacy Shield.)
- Email Provider: Google (US - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.)
- Customer Payment Portal Provider: Paypal (US - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.)
- Customer Management Provider i.e. online bookings: Accuity (EU - Data is not transferred outside of the European Economic Area.)
- Image retouching companies: Various (images and image references only (US - Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.)
- Printing Labs: Various depending on requirements and availability (EU - Data is not transferred outside of the European Economic Area.)
There are also certain situations in which we may share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation. We share your data in order to deliver a great, seamless, easy and personalised service to you, to provide you with full service access; and to market Elsie Grace Photography, in order to secure new customers.
We may transfer personal data to a country outside of the European Economic Area (EEA) if necessary eg if a third party we utilise could have servers located outside of the EEA. If this is the case, we will either obtain your consent or otherwise ensure that the transfer is legal and your data is secure by following the EU's guidelines. You can see above where we send data outside of the EEA and on what basis we do so.
We keep your data secure by using Encryption Software, Secure Socket Layer (SSL) technology when information is submitted to us on line through a https website, and using FTPS when exchanging files and images with our cloud back-up service provider.
n the unlikely event of a criminal breach of our security we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we will also inform you. While we do not hold personal data any longer than we need to. The duration will depend on your relationship with us, and whether it is ongoing. We may keep some of your personal data for up to 7 years after our working contract with you has finished, for tax legislation purposes. Images, photographs and video footage will be archived indefinitely along with relevant details and consent forms. This is due to requests for replacement images being made several years after being originally taken and to protect the copyright of the photographer.
You should be aware that you have the following rights:-
- the right to be informed about the collection and use of your personal data
- the right of access to your personal data and any supplementary information
- the right to have any errors in your personal data rectified
- the right to have your personal data erased
- the right to block or suppressing the processing of your personal data
- the right to move, copy or transfer your personal data from one IT environment to another
- the right to object to processing of your personal data in certain circumstances, and
- rights related to automated decision-making (i.e. where no humans are involved) and profiling (i.e. where certain personal data is processed to evaluate an individual).
We also give you the option to manage your data by contacting Elsie Grace Photography by email; email@example.com or by writing to our registered address: Gramarye House, 18 Elm Park Road, Havant, PO9 2AD.
All photographs appearing on this website are the property of Elsie Grace Photography. They are protected by Copyright Laws, and are not to be downloaded or reproduced in any way without the written permission of Elsie Grace Photography. Copyright ©2018-2019 Elsie Grace All Rights Reserved.