Your Privacy is Paramount
Why do we collect your data?
We collect your personal data as soon as you place an order with us. We collect data for account and marketing purposes only.
How do we collect your data?
We collect your data in a number of ways, from the information you provide. Our priority is to protect and treat your data with the upmost care.
When do we share your data?
We will never share your data.
If you wish to opt out
The General Data Protection Regulation (“GDPR”) governs the controlling and processing, such as the use or holding, of personal data, which is essentially any information about identifiable living individuals, and also gives those individuals certain rights and remedies in respect of that information.
The purpose of this notice is to supply you with the required information at the time of providing us with your personal data. This will lay out the essentials such as the what; where; when; and how in relation to the personal information collected. This should help you feel more confident about the privacy and the security of your personal information.
Please read this Privacy Notice carefully. By visiting our website or using any of our services, you indicate your agreement to our use of your personal information as set out in this Privacy Notice.
Rosemary Goodenough (“RG”) is the Data Controller and is committed to protecting the rights of individuals in line with the GDPR.
Any questions relating to data security should be directed to Rosemary Goodenough at firstname.lastname@example.org
We will collect information from you when you register with us, apply to use any of our services, become our client, or contact us in person, by telephone, by email or by post. We also collect information from you when you provide feedback or complete a contact form on our website.
§ Your contact details, such as your name, address, telephone number and email address;
§ Your date of birth, nationality, country of birth, country of residence;
§ Details of the services you request from us;
In some cases, you are not obliged to provide any personal data to us, but if you have requested information or a service from us, we will not be able to provide it without certain information, such as your contact details.
We also collect information from you when you voluntarily complete customer surveys, provide feedback or complete a contact form on our website.
RG does not currently make use of automated processing or decision making.
We use information held by you in the following ways:
§ To process your orders;
§ To comply with our obligations arising from any contracts entered into between you and us and to provide you with the information, products and services that you request from us;
§ To help protect your information and prevent unauthorised access to it;
§ To deal with any queries, complaints or problems reported by you;
§ To generate statistics relating to use of our website, such as the popularity of certain features or services. We do not use personally identifiable information for these purposes;
§ if required to do so by law and to the extent necessary for the proper operation of our systems, to protect us/our customers, or for the enforcement of any agreement between you and us;
§ to notify you of changes to our services; and
§ to help improve the services we provide to you.
We take appropriate security measures (including physical, electronic and procedural measures) to help protect the confidentiality, integrity and availability of your personal information from unauthorised access and disclosure.
We may disclose your information to:
§ Businesses that are legally either part of the same group of businesses or companies within RG, or that become part of that group;
§ Our IT providers, services providers and agents in order to provide and maintain the provision of the services;
§ Our appointed auditors, accountants, lawyers and other professional advisers to the extent that they require access to the information in order to advise us;
§ Meet applicable law, the order of a Court or market rules and codes of practice applicable to the circumstances at the time;
§ Investigate or prevent fraud or activities believed to be illegal or otherwise in breach of applicable law;
§ Relevant tax, payments and customs authority, who may pass this on to tax authorities in other jurisdictions.
§ Prospective seller or buyer of such business or assets in the event that we sell or buy any business or assets, in which case we will disclose your personal information. If all of RG’s assets are acquired by a third party, in which case personal information held by it about its clients may be one of the transferred assets.
We will not lend or sell your information to third parties.
We are committed to only keeping your personal data for as long as we need to in order to fulfil the relevant purpose(s) it was collected for, as set out above in this notice, and for as long as we are required or permitted to keep it by law.
We retain copies of our customer contracts in order to enable us to deal with any legal issues. We retain details of complaints for 5 years from the date of receipt.
Transferring information overseas
We may share your personal information with our service providers or between businesses that are or become legally part of the RG group of businesses or companiesfor the purposes of providing our services to you. This may involve transferring it to countries outside the European Economic Area (EEA) whose data protection laws may not be as extensive as those which apply to us. Where we do so, we will ensure that we do this in accordance with the Acts and take appropriate measures to ensure that the level of protection which applies to your personal information processed in these countries is similar to that which applies within the EEA. Such measures may include only transferring your data to jurisdictions in respect of which there is a European Commission adequacy decision or, where this is not the case, by using model clauses which have been approved by the European Commission.
When we receive such a request we will endeavour to provide you with these details without delay and at the latest within one month of receipt. We may extend the period of compliance by a further two months where requests are complex or numerous. In such instances RG will inform you within one month of the receipt of the request and explain why the extension is necessary.
When RG receives a subject access request we will provide a copy of the information held free of charge. We may charge a reasonable fee to comply with requests for further copies of the same information. This does not mean that we will charge for all subsequent access requests rather that the RG reserves the right to charge a fee based on the administrative cost of providing the information.
If the after reviewing a request the Data Protection Officer believes a request is manifestly unfounded or excessive, particularly if it is repetitive, then RG may charge a ‘reasonable fee’ which will be decided on a case by case basis. In certain circumstances RG may even refuse to respond to such requests.
You also have the following rights (unless exemptions apply), which can be exercised by contacting us using the details provided below.
§ To ask us not to process your personal data for marketing purposes;
§ To prevent any processing of personal data that is causing or is likely to cause unwarranted and substantial damage or distress to you or another individual;
§ To request the rectification or completion of personal data which are inaccurate or incomplete;
§ To restrict or object to the processing of your personal data (from 25th May 2018 onwards);
§ To request its erasure under certain circumstances;
§ In certain circumstances, to receive your personal data, which you have provided to us, in a structured, commonly-used and machine-readable format and the right to transmit that data to another data controller without hindrance, or to have that personal data transmitted to another data controller, where technically feasible (from 25th May 2018 onwards);
§ To be informed about any use of your personal data to make automated decisions about you, and to obtain meaningful information about the logic involved, as well as the significance and the envisaged consequences of this processing; and
§ To lodge a complaint about the way in which your personal data is being used to your Data Protection Authority: The Information Commissioner's Office (United Kingdom).
When you contact us to exercise any of the rights above, we may ask you to provide some additional information in order to verify your identity, such as your name, your address and proof of identity.
If you would like to lodge a complaint or exercise any of your rights set out above, you can contact us at:
Alternatively, if you would like to contact your Data Protection Authority, please use the contact details below.
United Kingdom: Information Commissioner’s Office
Where we rely on your consent to use your personal data, you have the right to withdraw that consent at any time.