What is GDPR? General Data Protection Regulation (GDPR) is a new european law to update the Data Protection Act 1998 to incorporate the digital world. Your customers need to be able to trust you to look after and use their personal data properly and safely. Knowing they can trust you is good for your business. The new law comes into affect on May 25th 2018 and if you live in UK/Europe or sell to customers within these countries you are legally bound to adhere to the regulations. More information can be found on the Information Commissioners Office (ICO) website. Cute Creations by Ceri Privacy Policy 25th May 2018 1.0 OUR CORE BELIEFS REGARDING USER PRIVACY AND DATA PROTECTION User privacy and data protection are human rights. We have a duty of care to the people within our data. Data is a liability, it should only be collected and processed when absolutely necessary. We loathe spam as much as you do! We will never sell, rent or otherwise distribute or make public your personal information. 2.0 RELEVANT LEGISLATION We comply with the following national and international legislation with regards to data protection and user privacy: UK Data Protection Act 1988 (DPA) EU Data Protection Directive 1995 (DPD) EU General Data Protection Regulation 2018 (GDPR) 3.0 PERSONAL INFORMATION I COLLECT AND WHY I COLLECT IT 3.1 Order Processing When you place an order via my shop on ConsciousCrafties.com, I receive only the required information in order to process your order (your name, address and email). I do not receive any card or bank details. 4.0 HOW I USE THE INFORMATION The information you provide is used to fulfil your order on a ‘contract’ basis and is only used for the purpose of communicating with you regarding your purchase and for delivery of your items. Your personal information will not be added to my mailing list and you will not be contacted for marketing or advertising purposes unless you request me to do so. 5.0 SHARING WITH THIRD PARTIES We will NEVER sell or rent your personal data. To process your order and to fulfil your contract with us, your information is shared with third parties for the purpose of delivery (Royal Mail and courier services). It may be shared for compliance with legal, regulatory and law enforcement requests as appropriate and necessary. I will endeavour to notify you of any such requests. I am not responsible for how these third parties process your data, please visit their websites to read their privacy policies. 6.0 HOW I SECURE, STORE AND RETAIN DATA We use Conscious Crafties website to trade and complete your purchase. Your data is secured, stored and retained by Conscious Crafties to complete your purchase. We do not hold hard copies of your data and any data collected is held only as long as is necessary to carry out your order and to maintain adequate and accurate business and financial records (7 years). 7.0 HOW YOU CAN ACCESS, UPDATE OR DELETE INFORMATION HELD ABOUT YOU You have the right to access, update or ask us to delete your personal information. Please email our Data Controller found in section 9.0 below. We are obliged by law to provide this service within 30 calendar days of your request free of charge. However, we have the right to refuse or charge for requests that are manifestly unfounded or excessive and repetitive. 8.0 DATA BREACHES We will report any unlawful data breach to any and all relevant persons and authorities within 72 hours of the breach, if it is apparent that personal data stored in an identifiable manner has been stolen. If you feel your data has been compromised you have a right to contact the Information Commissioners Office (ICO). 9.0 DATA CONTROLLER Our data controller is Cute Creations by Ceri Whose registered and operating office is: 18 Leasowes Close. Watling Street North. Church Stretton. Shropshire. SY6 7BB Email: [email protected] 10.0 CHANGES TO OUR PRIVACY POLICY This privacy policy may change from time to time inline with legislation or industry developments. We will not explicitly inform our users of these changes. Instead, we recommend that you check this page occasionally for any policy changes. Specific policy changes and updates will be mentioned in the change log below: Version 1.0 25th May 2018 – New Privacy Policy to be compliant with GDPR. Account Registration If you create an account on our website, we may need to collect personal information such as name, address, phone number and email. You may review, change, or remove this information through your account settings. You need to provide this information to enable us to provide you with the Services, for example if you purchase though our website we would need a physical postal address in order for us to deliver your parcel. Other website visitors may see ratings and reviews for items you purchased or sold and be able to view your profile name. Site Visitation Tracking Like most websites, this site uses Google Analytics (GA)to track user interaction. We use this data to determine the number of people using our site, to better understand how they find and use our web pages and to see their journey through the website. Although Google Analytics records data such as your geographical location, device, internet browser and operating system, none of this information personally identifies you to us. Google Analytics also records your computer’s IP address which could be used to personally identify you but Google do not grant us access to this. We consider Google to be a third party data processor (see section 5.0). Google Analytics makes use of cookies, details of which can be found on Google Analytics developer guides. Disabling cookies on your internet browser will stop Google Analytics from tracking any part of your visit to pages within this website Cookies We use cookies to track use and allow customers to purchase from our website. Please note that these cookies do not contain or pass any personal, confidential or financial information or any other information that could be used to identify individual visitors or customers purchasing from our website. Please note that you are free to refuse cookies by disabling them in your browser settings. However, for purely technical reasons this may prevent you from purchasing from our website. This is because anonymous cookies are commonly used to keep track of the contents of customers shopping baskets during the checkout process. This facility ensures that the items added to (or removed from) your basket are accurately stated when you go to pay. Contact forms and email links Should you choose to contact us using the contact form on our Contact Us page or an email, none of the data that you supply will be passed to / be processed by any of the third party data processors defined in section 5.0. We would suggest you always consider email as an insecure medium and not include personal, confidential or otherwise sensitive information within an email. Your data will only be held for as long as necessary in order to communicate with you and respond to your request. Ceri Smith Owner of Cute Creations by Ceri