PRIVACY POLICY

 

 

 

THE POLICY

This privacy policy is for this website; https://www.mairigrantphotography.com and governs the privacy of its users who choose to use it. Our company is hosted on the Wix.com platform. Wix.com provides us with the online platform that allows us to sell our products and services to you. Your data may be stored through Wix.com’s data storage, databases and the general Wix.com applications. They store your data on secure servers behind a firewall.  

 

1.1. WHAT DATA DO WE ASK YOU TO PROVIDE US AND WHY?

We collect the following data: Your first and last name, your email address, sign up ip, company name and website (if applicable), phone number, contact and billing address, postcode, latitude and longitude, bank details, optional images, gmtoff, dstoff, country code and timezone.

  • We use this data to deliver our services to you and personalise your experience, as well as to market our services and those of Third Party suppliers, plus for security and authentication purposes

  • We collect this data using the lawful basis of consent and/or for the performance of a contract or to take steps to enter into a contract

 

WHAT DATA DO WE COLLECT WHEN YOU VISIT OUR WEBSITE AND WHY?

We collect cookies. Cookies are small pieces of data that websites send to a user’s computer and are stored on the user’s web browser. They are designed to enable the website to remember information relating to your visit and its use. This is so we can personalise your experience and deliver our service to you as well as for Marketing Purposes.

 

WHAT PERSONAL DATA DO WE SHARE WITH THIRD PARTIES AND WHO ARE THEY?

We share personal data with the following third parties in order to deliver our services or fulfil our obligations to you. The below are either email, newsletter or payment service providers, website or hosting service providers, social media service providers,  other service providers who may assist with our accounts and record keeping.

With the following third parties, the data is not transferred outside of the UK so is protected by the UK General Data Protection Regulation (UK GDPR), tailored by the Data Protection Act 2018 – DAS

 

With the following third parties, the data is not transferred outside of the European Economic Area and is protected by the GDPR – Paypal, GoCardless Ltd, Stripe, Digital Asset Management.

With the following third parties the data is transferred outside of the European Economic Area to the United States under the protection of EU/US Privacy Shield – Wix.com, FastMail, Google Mail, Facebook Ltd.

There are also certain situations in which we may need to share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation.

 

WHY DO WE SHARE DATA OUTSIDE OF THE UK?

We may transfer personal data to a country outside of the UK, for example, if a third party we share data with has servers located outside of the UK. If this is the case we will obtain your consent or otherwise ensure that the transfer is legal and your data is secure by following the EU or EU/US Privacy Shield guidelines.

You can see above where we send data outside of the UK and on what basis we do so.

  1. HOW DO WE KEEP YOUR PERSONAL DATA SECURE?

We keep your data secure:

  • by following internal policies of best practice and training for staff

  • by using Secure Socket Layer (SSL) technology when information is submitted to us online

  • by having Back-Up provision

  • by using a host which is Cyber Essentials Plus Certified

In the unlikely event of a criminal breach of our security, we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we shall also inform you of-

  1. Changes to our privacy policy and control

  2. We may change this privacy policy from time to time. When we do, we will let you know by changing the date on this policy, notifying customers of only significant changes. By continuing to access or use our services after those changes become effective, you agree to be bound by the revised privacy policy.

While we do not hold personal data any longer than we need to, the duration will depend on your relationship with us and we may keep some records for up to 7 years after our working contract with you has finished for Tax reasons, reflecting the Statute of Limitations.

EXTERNAL WEBSITE LINKS & THIRD PARTIES

 

Although we only look to include quality, safe and relevant external links, users are advised to adopt a policy of caution before clicking any external web links mentioned throughout this website.

We cannot guarantee or verify the contents of any externally linked website despite our best efforts. Users should, therefore, note they click on external links at their own risk and we cannot be held liable for any damages or implications caused by visiting any external links mentioned.

ADVERTS AND SPONSORED LINKS

 

This website may contain sponsored links and adverts. These will typically be served through our advertising partners, who may have detailed privacy policies relating directly to the adverts they serve.

Clicking on any such adverts will send you to the advertiser’s website through a referral program which may use cookies and will track the number of referrals sent from this website. This may include the use of cookies which may, in turn, be saved on your computer’s hard drive. Users should, therefore, note they click on sponsored external links at their own risk and we cannot be held liable for any damages or implications caused by visiting any external links mentioned.

SOCIAL MEDIA POLICY & USAGE

 

We adopt a Social Media Policy to ensure our business and our staff conducts themselves accordingly online. While we may have official profiles on social media platforms users are advised to verify authenticity of such profiles before engaging with, or sharing information with such profiles. We will never ask for user passwords or personal details on social media platforms. Users are advised to conduct themselves appropriately when engaging with us on social media.

There may be instances where our website features social sharing buttons, which help share web content directly from web pages to the respective social media platforms. You use social sharing buttons at your own discretion and accept that doing so may publish content to your social media profile feed or page. You can find further information about some social media privacy and usage policies in the resources section below.

RESOURCES

 

We will use your images on social media to promote our business. We will tag you where possible unless you specifically ask us not to. If you do not wish any images to be used on social media you must state this to be the case at the time of booking. Images of children under the age of 13 will only be shared with the express permission of parents or guardians.

https://www.facebook.com/mairigrantphotography/

https://www.instagram.com/mairi_grant_photography/

  1. Your rights

  • the right to be informed about the collection and use of your personal data

  • the right of access to your personal data and any supplementary information

  • the right to have any errors in your personal data rectified

  • the right to have your personal data erased

  • the right to block or suppress the processing of your personal data

  • the right to move, copy or transfer your personal data from one IT environment to another

  • the right to object to the processing of your personal data in certain circumstances, and

  • rights related to automated decision-making (i.e. where no humans are involved) and profiling (i.e. where certain personal data is processed to evaluate an individual).

We also give you the option to manage your data via:

  • online account

  • email

  • telephone

  • by writing to us