1.0 OUR CORE BELIEFS REGARDING USER PRIVACY AND DATA PROTECTION User privacy and data protection are human rights. I have a duty of care to the people within my data. Data is a liability, it should only be collected and processed when absolutely necessary. I loathe spam as much as you do! I will never sell, rent or otherwise distribute or make public your personal information. I do not currently operate a newsletter but if you would like to stay informed about new products and children’s craft activities, please like my facebook page: www.facebook.com/adorableworksofheart 2.0 RELEVANT LEGISLATION Conscious Crafties complies with the following national and international legislation with regards to data protection and user privacy: UK Data Protection Act 1988 (DPA) EU Data Protection Directive 1995 (DPD) EU General Data Protection Regulation 2018 (GDPR) 3.0 PERSONAL INFORMATION I COLLECT AND WHY I COLLECT IT 3.1 Order Processing When you place an order via my shop on ConsciousCrafties.com or Etsy.com, I receive only the required information in order to process your order -your name, address and email plus details of what you are ordering. I do not receive any card or bank details. You can contact me via my Facebook page to discuss an order. For more information about Facebook’s Privacy Policy click here. If I take your order on Facebook you can pay by PayPal online. For PayPal’s privacy Policy click here. If you pay in person, you can pay using my Paypal Here card machine. Here is further information on the security of the PayPal Here card machine: For Paypal Here security click here. If you pay by PayPal online or using my card machine, I cannot see your bank details. If you choose to pay by Bacs (Bank Transfer) then you can see my details but I cannot see yours. I do not process or hold any bank details for any customers at any point. 4.0 HOW I USE THE INFORMATION The information you provide is used to fulfil your order on a ‘contract’ basis and is only used for the purpose of communicating with you regarding your purchase and for delivery of your items. Your personal information will not be added to my mailing list and you will not be contacted for marketing or advertising purposes unless you request me to do so. You can like my facebook page here to be kept up to date on children’s craft workshops plus new products. I have a separate form which you can request via my Facebook page regarding face to face contact. Here you can consent or decline me contacting you directly about orders and upcoming craft events. This form also covers photography consent for example using photos taken at events and whether or not you’d like to be tagged on Facebook in photographs of your children enjoying themselves at my craft workshops. I never take or share photographs without your signed consent. 5.0 SHARING WITH THIRD PARTIES I will NEVER sell or rent your personal data for marketing purposes. To process your order and to fulfil your contract with us, your information is shared with third parties for the purpose of delivery (Royal Mail and courier services). It may be shared for compliance with legal, regulatory and law enforcement requests as appropriate and necessary. I will endeavour to notify you of any such requests. I am not responsible for how these third parties process your data, please visit their websites to read their privacy policies. Here is Royal Mail’s Privacy Policy. 6.0 HOW I SECURE, STORE AND RETAIN DATA I use Conscious Crafties website and Etsy to trade and complete your purchase. Your data is secured, stored and retained by Conscious Crafties or Etsy to complete your purchase. Conscious Crafties or Etsy websites do not hold hard copies of your data and any data collected is held only as long as is necessary to carry out your order and to maintain adequate and accurate business and financial records (7 years). I also trade on Facebook via my page www.facebook.com/adorableworksofheart. I may keep hard copies of your order, if placed in person or via my Facebook page. This is to enable me to process your order. I do not collect or process any sensitive* data unless this forms part of a design requested by you. Hard copies of information are stored safely and securely in my home. 7.0 HOW YOU CAN ACCESS, UPDATE OR DELETE INFORMATION HELD ABOUT YOU You have the right to access, update or ask us to delete your personal information. Please email our Data Controller found in section 9.0 below. I am obliged by law to provide this service within 30 calendar days of your request free of charge. However, we have the right to refuse or charge for requests that are manifestly unfounded or excessive and repetitive. 8.0 DATA BREACHES I will report any unlawful data breach to any and all relevant persons and authorities within 72 hours of the breach, if it is apparent that personal data stored in an identifiable manner has been stolen. If you feel your data has been compromised you have a right to contact the Information Commissioners Office (ICO). 9.0 DATA CONTROLLER The data controller is Adorable Whose registered and operating office is: 13 Vimy Drive, Dartford, Kent, DA1 5FJ Email: [email protected] 10.0 CHANGES TO OUR PRIVACY POLICY This privacy policy may change from time to time in line with legislation or industry developments. I will not explicitly inform our users of these changes. Instead, I recommend that you check this page occasionally for any policy changes. Specific policy changes and updates will be mentioned in the change log below: Version 1.0 25th May 2018 – New Privacy Policy to be compliant with GDPR * Sensitive Personal Data. Definition under the GDPR: data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation.