updated 21 May 2018
In very basic terms we totally respect your personal information and will only ask you for what information we really need from you. Will look after it in the same way we would want ours looking after, keeping it secure. We will only share it with others where we need their help us deliver our service to you (such as our professional printing laboratory who may need your name and address to post your purchases). Be assured that we will never share your information in any other circumstances, nor will we sell it on elsewhere.Â
stephencotterell.com is a specialised website for the display and sale of electronic and printed photographs, created by Stephen Cotterell Photography Associates, which have people as their main subjects.
Introduction
Stephen Cotterell Photography Associates takes your privacy very seriously. This privacy policy has been prepared in line with the UK’s General Data Protection Regulation (GDPR), which promotes fairness and transparency for all individuals in respect of their personal data. This privacy policy applies to all data we process, and by using Stephen Cotterell Photography Associates you consent to our collection and use of such data. We are registered with the Information Commissioners Office, registration number ZA318815
If you would like to get in touch about anything in this policy or about your personal data then please contact Stephen Cotterell our Data Protection Officer at photography@stephencotterell.com
1) The Data we collect
As a data controller we collect a variety of data in order to deliver our services, and we will manage your personal data transparently, fairly and securely.
We may ask you to provide us the following data
First and Last Name,
Address and Postcode
Telephone Number(s)
Email(s)
IP address
We will also record a date of birth for all persons we photograph under the age of 13 and require the parent or a legal guardian to consent to photography. For persons 13 years and over we collect their confirmation that they are either 13 or over or 18 or over.
Obviously being a photographic business we also create and manage images as per our contractual agreement(s).
We use the above data to:
Deliver our service to you
Personalise your experience
To provide access to photographs
To create and send you invoices to enable you to pay for our services
To send follow-up messages to confirm delivery of services and provide aftercare as you require.
We collect this data on the following lawful basis:
To record your consent
To arrange or fulfil a Contract
To meet our legal obligations to create and maintain accounting records
When you visit our website we also collect Cookies. These are small pieces of data that websites send to a user's computer and are stored on the user's web browser. They are designed to enable the website to remember information, such as what a user might have put in a shopping cart for example. This helps us to:
Personalise your experience
Deliver our service to you
2) Which third parties do we share Personal Data with?
We share personal data with third parties:
With providers of offsite backup, also known as cloud services
With file transfer services to enable you to access your photographs
With third-party printing companies when we are unable to print photographs in-house
With electronic payment services
Data is transferred outside of the European Economic Area to United States under the
protection of EU/US Privacy Shield.
There are also certain situations in which we may share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation.
3) Why do we share your Personal Data with the above?
We share your data in order to:
Ensure that your data is safe and secure
Deliver our service to youÂ
Personalise your experience
Provide you with access to your electronic copies of photographs
We may transfer personal data to a country outside of the European Economic Area (EEA) if necessary eg if a third party we utilise could have servers located outside of the EEA. If this is the case, we will either obtain your consent or otherwise ensure that the transfer is legal and your data is secure by following the EU's guidelines. You can see above where we send data outside of the EEA and on what basis we do so.
4) How do we keep your personal data secure?
We keep your data secure by
Following internal policies of best practice and training for staff
Using secure Passwords
Using Secure Socket Layer (SSL) technology when information is submitted to us online
In the unlikely event of a criminal breach of our security we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we will also inform you.
5) Changes to our privacy policy and control
We may change this privacy policy from time to time. When we do, we will let you know by changing the date on this policy, notifying customers of only significant changes. By continuing to access or use our services after those changes become effective, you agree to be bound by the revised privacy policy.
6) You have the following rights
- the right to be informed about the collection and use of your personal data
- the right of access to your personal data and any supplementary information
- the right to have any errors in your personal data rectified
- the right to have your personal data erased
- the right to block or suppressing the processing of your personal data
- the right to move, copy or transfer your personal data from one IT environment to
another
- the right to object to processing of your personal data in certain circumstances, and
- rights related to automated decision-making (i.e. where no humans are involved) and
profiling (i.e. where certain personal data is processed to evaluate an individual).
We also give you the option to manage your data via:
Social media messaging
SMS/Text messaging
Telephone
Postal or courier services
While we do not hold personal data any longer than we need to. The duration will depend on your relationship with us, and whether it is ongoing. We may keep some of your personal data for up to 7 years after our working contract with you has finished for Tax legislation purposes. In the case of photographs we intend to archive images indefinitely along with your relevant details and consent forms. This is due to requests for replacement images being made several years after being taken.
MAILING LISTS
We do not use mailing lists, send newsletters or other marketing material to individuals. We do create information which can be accessed online for existing and and potential clients to read.
Stephen Cotterell Photography Associates
10 Cleavedon Road
Kingston upon Thames
KT1 3AD
photography@stephencotterell.com
07990525814