Privacy Notice
1 Who I am
- Gemma Wiltshire is a sole trader operating under the trading name "GEW Creations".
- I am a controller for the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679) and related data protection legislation.
2 How to contact me
- If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact me at c[email protected]
- You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). I would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact me in the first instance.
3 Privacy Information
I am committed to protecting your personal data and your privacy. This privacy notice aims to give you information on how I collect and process your personal data:
It is important that the personal data I hold about you is accurate and current. Please keep me informed if your personal data changes during our working relationship.
I am committed to protecting your personal data and your privacy. This privacy notice aims to give you information on how I collect and process your personal data:
- through your use of my website https://www.gewcreations.weebly.com/ ("Website") including any personal data that you may provide through the Website);
- where I have a contract in place with you (please note that separate terms and conditions may also be applicable here);
- where you are a business contact (or a business contact of one of my clients);
- through our other communications.
It is important that the personal data I hold about you is accurate and current. Please keep me informed if your personal data changes during our working relationship.
4 To whom does this privacy notice apply?
- This privacy notice applies to all individuals who visit the Website, or who contact me by post, telephone, e-mail or other means (including other electronic means), who have a contract in place with me (please note that separate terms and conditions may also be applicable here) or who have some other form of business relationship with me.
5 Information about the Website
- The Website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. I do not control these third-party websites and I am not responsible for their privacy statements. You are encouraged to read the privacy notice of every website you visit.
- Cookies are small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site.
6 Children
- I do not knowingly collect any personal data relating to children.
7 What personal data do I collect and process?
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
I may collect, use, store and transfer different kinds of personal data about you for necessary work related items.
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
I may collect, use, store and transfer different kinds of personal data about you for necessary work related items.
- Identity Data includes first name, last name, social media username (in particular LinkedIn, Twitter, Instagram or email information) or similar identifier, marital status, title, and gender.
- Contact Data includes home or work address, email address and telephone numbers.
- Financial Data includes bank account and payment card details.
- Transaction Data includes details about payments from you and other details of services I provide to you.
- Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access the Website.
- Usage Data includes information about how you use the Website.
- Marketing and Communications Data includes your preferences in receiving marketing from me and your communication preferences.
8 How is your personal data obtained?
I use different methods to collect personal data from and about you including through:
I use different methods to collect personal data from and about you including through:
- Direct Interactions.
- Automated technologies or interactions.
- Third parties or publicly available sources.
9 Failure to provide personal data
- Where I need to collect personal data by law, or under the terms of a contract I have with you and you fail to provide that data when requested, I may not be able to perform the contract I have or are trying to enter into with you (for example, to provide you with services). In this case, I may have to cancel a service you wish me to provide but you will be notified if this is the case at the time.
10 How will I use your personal data?
- I will process your personal data where you consent to the processing or where that processing is necessary for 1) the performance of a contract with you; or 2) compliance with a legal obligation to which I am subject; or 3) the purposes of my legitimate interests (or those of a third party).
- Your personal data will be used for the purposes for which I collected it, unless I reasonably consider that I need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact me at [email protected]
11 Marketing
- If you are a consumer, I will only provide you with direct marketing communications where you have consented to receive such communications. You can subscribe to such marketing communications, and you can adjust your marketing preferences at any time by contacting me at [email protected]
- You can also opt-out or unsubscribe from all or some of these marketing communications at any time by contacting me or by clicking “unsubscribe” at the bottom of any marketing e-mail.
- Where you opt out of receiving these marketing communications, this opt-out will not apply to personal data provided to me for any other purpose.
12 With whom do I share your personal data?
I may have to share your personal data with the parties set out below for the purposes set out in the table above.
I may have to share your personal data with the parties set out below for the purposes set out in the table above.
- Service providers acting as processors who provide IT and system administration services.
- Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
- Any relevant regulatory authority or law enforcement agency, including HM Revenue & Customs, Trading Standards, Advertising Standards Authority, courts or tribunals who require reporting of processing activities in certain circumstances.
13 International transfers
I generally do not transfer your personal data out of the European Economic Area (EEA). However, whenever I am required to transfer your personal data out of the EEA (for example where a third party supplier is located outside of the EEA), I ensure a similar degree of protection is afforded to it by ensuring that appropriate safeguards are implemented, including any of the following:
I generally do not transfer your personal data out of the European Economic Area (EEA). However, whenever I am required to transfer your personal data out of the EEA (for example where a third party supplier is located outside of the EEA), I ensure a similar degree of protection is afforded to it by ensuring that appropriate safeguards are implemented, including any of the following:
- I will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.
- Where I use certain service providers, I may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
- Where I use providers based in the USA, I may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the European Union and the USA. For further details, see European Commission: EU-US Privacy Shield.
- You have provided your explicit consent to the transfer of your personal data outside of the EEA. The transfer is necessary for the purposes of performing a contract between you (the data subject) and I.
14 Automated decision making and profiling
- I do not use automated decision-making (including profiling) to make any decisions which would produce a legal effect or similarly significantly affect a data subject.
15 How long do I retain your personal data?
- I will only retain your personal data for as long as necessary to fulfil the purposes I collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- To determine the appropriate retention period for personal data, I consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which I process your personal data and whether I can achieve those purposes through other means, and the applicable legal requirements.
- For tax purposes, I retain basic information about my clients (including Contact, Identity, Financial and Transaction Data) for six years after they cease being clients.
16 Data security
- I have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, I limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on my instructions and they are subject to a duty of confidentiality.
- I have put in place procedures to deal with any suspected personal data breach and will notify you and the Information Commissioner's Office of a breach where I am legally required to do so.
17 Your rights
17.1 - Your personal data is protected by legal rights, which include your rights to:
17.3 - I may need to request specific information from you to help me confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. I may also contact you to ask you for further information in relation to your request to speed up my response.
17.4 - You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, I may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, I may refuse to comply with your request in these circumstances.
17.5 - I try to respond to all legitimate requests within one month. Occasionally it may take longer than a month if your request is particularly complex or you have made a number of requests. In this case, I will notify you and keep you updated.
17.6 - 17.6 You also have the right to complain to the Information Commissioner's Office, which regulates the processing of personal data, about how I am processing your personal data.
17.1 - Your personal data is protected by legal rights, which include your rights to:
- Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data I hold about you and to check that I am lawfully processing it.
- Request correction of the personal data that I hold about you. This enables you to have any incomplete or inaccurate data I hold about you corrected, though I may need to verify the accuracy of the new data you provide to me.
- Request erasure of your personal data. This enables you to ask me to delete or remove personal data where there is no good reason for me continuing to process it. Note, however, that I may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, following your request.
- Object to processing of your personal data where I am relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where I am processing your personal data for direct marketing purposes.
- Request restriction of processing of your personal data. This enables you to ask me to suspend the processing of your personal data in the following scenarios: if you want me to establish the data's accuracy; where my use of the data is unlawful but you do not want me to erase it; where you need me to hold the data even if I no longer require it as you need it to establish, exercise or defend legal claims; or you have objected to my use of your data but I need to verify whether I have overriding legitimate grounds to use it.
- Request the transfer of your personal data to you or to a third party (data portability). I will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for me to use or where I have used the information to perform a contract with you.
- Withdraw consent at any time where I am relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, I may not be able to provide certain products or services to you. I will advise you if this is the case at the time you withdraw your consent.
17.3 - I may need to request specific information from you to help me confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. I may also contact you to ask you for further information in relation to your request to speed up my response.
17.4 - You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, I may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, I may refuse to comply with your request in these circumstances.
17.5 - I try to respond to all legitimate requests within one month. Occasionally it may take longer than a month if your request is particularly complex or you have made a number of requests. In this case, I will notify you and keep you updated.
17.6 - 17.6 You also have the right to complain to the Information Commissioner's Office, which regulates the processing of personal data, about how I am processing your personal data.