Teaching lovely people to learn to sew!

Privacy Policy

   

Last updated: 5 October 2018

www.salledecouture.co.uk ('Website') is provided by S. Boakes, trading as Salle de Couture  ('I'/'me'/'my'). In doing so, I may be in a position to receive and process personal information relating to you.


As the controller of this information, I'm providing this Privacy Notice ('Notice') to explain my approach to

personal information.


I intend only to process personal information fairly and transparently as required by data protection law

including the General Data Protection Regulation (GDPR). I'll only process the information if you consent to that processing. The GDPR also defines certain 'special categories' of personal information that's considered

more sensitive. These categories require a higher level of protection, as explained below.


Of course, you may browse parts of this Website without providing any information about yourself and

without accepting cookies. In that case, it's unlikely I'll possess and process any information relating to you.


I'll start this Notice by setting out the conditions I must satisfy before processing your data. However, you

may wish to start with this table at clause 4, which summarises what I intend to collect, or clause

8.0, which summarises my use of cookies. The Notice also explains some of the security measures I take to

protect your personal information, and tells you certain things I will or won't do.

Sometimes, when you take a new service or product from me, or discuss taking a new service or product but

decide against it, I might wish to provide you with further information about similar services or products by

email or other written electronic communication. In that situation, I'll always give you the opportunity to refuse to receive that further information and you can change your mind at any point (opt-out) by contacting my Data Protection Officer (DPO) as set in clause 1.3. I'll endeavour to remind you of your right to opt-out on each occasion that I provide such information.


1 Identity and contact details

1.1 Place of business: Bassingbourn, Royston, SG8 5LF

1.2 info@salledecouture.co.uk

1.3 I will act as Data Protection Officer (DPO), (S Boakes) and would welcome communication from you

regarding any matter relating to data protection, and can be contacted by email at

info@salledecouture.co.uk.

2 When I'm allowed to collect information from you

I will only collect personal information relating to you if one of the following conditions have been satisfied:

2.1 You have clearly told me that you are content for me to collect that information for the certain

purpose or purposes that I will have specified.

2.2 The processing is necessary for the performance a contract that I have with you.

2.3 The processing is necessary so that I can comply with the law.

2.4 The processing is necessary to protect someone's life.

2.5 The processing is necessary for performance of a task that's in the public interest.

2.6 The processing is necessary for my or another's legitimate interest - but in this case, I'll balance

those interests against your interests.

3 How to consent

3.1 At the point of collecting the information, I'll endeavour to explain how I intend to use the

Information and which of these purposes apply. If I rely on consent, I'll provide you with the

opportunity to tell me that you're happy to provide the information.

3.2 If at any point in time you change your mind and decide that you don't consent, please let me

know and I'll endeavour to stop processing your information in the specified manner, or I'll delete

your data if there is no continuing reason for possessing it.

3.3 If you don't consent to a particular bit of processing, I'll endeavour to ensure that the Website and

my service continue to operate without the need for that information.

4 Information I expect to collect from you

4.1 I envisage asking for the following types of information from you:

 Information type

Contact

information (first

name, last

name, email

address, phone

number)

Purpose and related details

I ask for this to be able to contact   you, following

registration for a course, in order to   supply you

with full course and directions to the   course

location.

This data may be transferred to the US, and the

receiving entity is registered with the   EU-US Privacy Shield

Justification

It's necessary for the

performance of a contract with

you

4.2 I may collect personal information about you from a number of sources, including the following:

4.2.1 From you when you agree to take a service or product from me, in which case this may

include your contact details, date of birth, how you will pay for the product or service

and your bank details.

4.2.2 From you when you contact me with an enquiry or in response to a communication from

me, in which case, this may tell me something about how you use my services.

4.2.3 From documents that are available to the public, such as the electoral register.

4.2.4 From third parties to whom you have provided information with your consent to pass it

on to other organisations or persons - when I receive such information I will let you

know as soon as is reasonably practicable.

4.3 If you refuse to provide information requested, then if that information is necessary for a service I

provide to you I may need to stop providing that service.

4.4 At the time of collecting information, by whichever method is used, I'll endeavour to alert you and

inform you about my purposes and legal basis for processing that information, as well as whether I

intend to share the information with anyone else or send it outside of the European Economic

Area. If at any point you think I've invited you to provide information without explaining why, feel

free to object and ask for my reasons.

5 Using your personal information

5.1 Data protection, privacy and security are important to me, and I shall only use your personal

information for specified purposes and shall not keep such personal information longer than is

necessary to fulfil these purposes. The following are examples of such purposes. I have also

indicated below which GDPR justification applies, however it will depend on the circumstances of

each case. At the time of collecting I will provide further information, and you may always ask for

further information from me.

5.1.1 To help me to identify you when you contact me. This will normally be necessary for the

performance my contract.

5.1.2 To help me to identify accounts, services and/or products which you could have from me

or selected partners from time to time. I may do this by automatic means using a

scoring system, which uses the personal information you've provided and/or any

information I hold about you and personal information from third party agencies

(including credit reference agencies). I will only use your information for this purpose if

you agree to it.

5.1.3 To help me to administer and to contact you about improved administration of any

accounts, services and products I have provided before, do provide now or will or may

provide in the future. This will often be necessary, but sometimes the improvements will

not be necessary in which case I will ask whether you agree.

5.1.4 To allow me to carry out marketing analysis and customer profiling (including with

transactional information), conduct research, including creating statistical and testing

information. This will sometimes require that you consent, but will sometimes be exempt

as market research.

5.1.5 To help to prevent and detect fraud or loss. This will only be done in certain

circumstances when I consider it necessary or the law requires it.

5.1.6 To allow me to contact you by written electronic means (such as email, text or

multimedia messages) about products and services offered by me where:

5.1.6.1 these products are similar to those you have already purchased from me,

5.1.6.2 you were given the opportunity to opt out of being contacted by me at the

time your personal information was originally collected by me and at the

time of my subsequent communications with you, and

5.1.6.3 you have not opted out of me contacting you.

5.1.7 To allow me to contact you in any way (including mail, email, telephone, visit, text or

multimedia messages) about products and services offered by me and selected

partners where you have expressly consented to me doing so.

5.1.8 I may monitor and record communications with you (including phone conversations and

emails) for quality assurance and compliance.

5.1.8.1 Before doing that, I will always tell you of my intentions and of the specific

purpose in making the recording. Sometimes such recordings will be

necessary to comply with the law. Alternatively, sometimes the recording

will be necessary for my legitimate interest, but in that case I'll only record

the call if my interest outweighs yours. This will depend on all the

circumstances, in particular the importance of the information and whether I

can obtain the information another way that's less intrusive.

5.1.8.2 If I think the recording would be useful for me but that it's not necessary I'll

ask whether you consent to the recording, and will provide an option for

you to tell me that you consent. In those situations, if you don't consent, the

call will either automatically end or will not be recorded.

5.1.9 When it's required by law, I'll check your details with fraud prevention agencies. If you

provide false or inaccurate information and I suspect fraud, I intend to record this.

5.2 I will not disclose your personal information to any third party except in accordance with this

Notice, and in particular in these circumstances:

5.2.1 They will be processing the data on my behalf as a data processor (where I'll be the

data controller). In that situation, I'll always have a contract with the data processor as

set out in the GDPR. This contract provides significant restrictions as to how the data

processor operates so that you can be confident your data is protected to the same

degree as provided in this Notice.

5.2.2 Sometimes it might be necessary to share data with another data controller. Before

doing that I'll always tell you. Note that if I receive information about you from a third

party, then as soon as reasonably practicable afterwards I'll let you know; that's required

by the GDPR.

5.2.3 Alternatively, sometimes I might consider it to be in your interest to send your

information to a third party. If that's the case, I'll always ask whether you agree before

sending.

5.3 Where you give me personal information on behalf of someone else, you confirm that you have

provided them with the information set out in this Notice and that they have not objected to such

use of their personal information.

5.4 In connection with any transaction which I enter into with you:

5.4.1 If you provide false or inaccurate information to me and I suspect fraud, I will record this

and may share it with other people and organisations. I, and other credit and insurance

organisations, may also use technology to detect and prevent fraud.

5.4.2 I may need to transmit the payment and delivery information provided by you during the

order process for the purpose of obtaining authorisation from your bank.

5.5 I may allow other people and organisations to use personal information I hold about you in the

following circumstances:

5.5.1 If I, or substantially all of my assets, are acquired or are in the process of being acquired

by a third party, in which case personal information held by me, about my customers,

will be one of the transferred assets.

5.5.2 If I have been legitimately asked to provide information for legal or regulatory purposes

or as part of legal proceedings or prospective legal proceedings.

5.5.3 I may employ companies and individuals to perform functions on my behalf and I may

disclose your personal information to these parties for the purposes set out above, for

example, for fulfilling orders, delivering packages, sending postal mail and email,

removing repetitive information from customer lists, analysing data, providing marketing

assistance, providing search results and links (including paid listings and links) and

providing customer service. Those parties will be bound by strict contractual provisions

with me and will only have access to personal information needed to perform their

functions, and they may not use it for any other purpose. Further, they must process the

personal information in accordance with this Notice and as permitted by the GDPR.

From time to time, these other people and organisations to whom I may pass your

personal information may be outside the European Economic Area. I will take all steps

reasonably necessary to ensure that your personal information is treated securely and

in accordance with this Notice and the GDPR.

6 Protecting information

6.1 I have strict security measures to protect personal information.

6.2 I work to protect the security of your information during transmission by using Secure Sockets

Layer (SSL) software to encrypt information you input.

6.3 I reveal only the last five digits of your credit card numbers when confirming an order. Of course, I

transmit the entire credit card number to the appropriate credit card company during order

processing.

6.4 I maintain physical, electronic and procedural safeguards in connection with the collection, storage

and disclosure of personally identifiable customer information. My security procedures mean that I

may occasionally request proof of identity before I disclose personal information to you.

6.5 It is important for you to protect against unauthorised access to your password and to your

computer. Be sure to sign off when you finish using a shared computer.

7 The internet

7.1 If you communicate with me using the internet, I may occasionally email you about my services

and products. When you first give me personal information through the Website, I will normally

give you the opportunity to say whether you would prefer that I don't contact you by email. You

can also always send me an email (at the address set out below) at any time if you change your

mind.

7.2 Please remember that communications over the internet, such as emails and webmails

(messages sent through a website), are not secure unless they have been encrypted. Your

communications may go through a number of countries before they are delivered - this is the

nature of the internet. I cannot accept responsibility for any unauthorised access or loss of

personal information that is beyond my control.

8 Cookies and other internet tracking technology

8.1 When I provide services, I want to make them easy, useful and reliable. This sometimes involves

placing small amounts of information on your computer, which is sent back to me at a later time.

These are called 'cookies'. Some websites

don't use cookies but use related technology for gaining information about website users such as

JavaScript, web beacons (also known as action tags or single-pixel gifs), and other technologies

to measure the effectiveness of their ads and to personalise advertising content. Multiple cookies

may be found in a single file depending on which browser you use.

8.2 Where applicable, this section of the Notice also relates to that technology but the term 'cookie' is

used throughout.

8.3 Some of these cookies are essential to services you've requested from me, whereas others are

used to improve services for you, for example through:

8.3.1 Letting you navigate between pages efficiently

8.3.2 Enabling a service to recognise your computer so you don't have to give the same

information during one task

8.3.3 Recognising that you have already given a username and password so you don't need

to enter it for every web page requested

8.3.4 Measuring how many people are using services, so they can be made easier to use and

that there is enough capacity to ensure they are fast

8.4 To learn more about cookies, you may wish to visit: www.allaboutcookies.org ,

www.youronlinechoices.eu  or www.google.com/policies/technologies/cookies/

8.7 As with any other information I may collect from you, I'll work to protect the security of your

information during transmission by using by using Secure Sockets Layer (SSL) software to encrypt

information you input.

9 Further information

9.1 If you would like any more information or you have any comments about this Notice, please write

to my Data Protection Officer as detailed in clause 1.3.

9.2 Please note that I may have to amend this Notice on occasion. If I do that, I will publish the amended version on the Website. In that situation I will

endeavour to alert you to the change, but it's also your responsibility to check regularly to

determine whether this Notice has changed.

9.3 You can ask me for a copy of this Notice by writing to the above address or by emailing me at

info@salledecouture.co.uk. This Notice applies to personal information I hold about individuals. It

does not apply to information I hold about companies and other organisations.

9.4 If you would like access to the personal information that I hold about you, you can do this by

emailing me at info@salledecouture.co.uk or writing to me at the address noted above. There is

not normally a fee for such a request, however if the request is unfounded, repetitive or excessive

I may request a fee or refuse to comply with your request. You can also ask me to send the

personal information I hold about you to another controller.

9.5 I aim to keep the personal information I hold about you accurate and up to date. If you tell me that

I'm holding any inaccurate or incomplete personal information about you, I will promptly amend,

complete or delete it accordingly. Please email me at info@salledecouture.co.uk or write to me at

the address above to update your personal information. You have the right to complain to the

Information Commissioner's Office if I don't do this.

9.6 You can ask me to delete the personal information that I hold about you if I relied on your consent

in holding that information or if it's no longer necessary. You can also restrict or object to my

processing of your personal information in certain circumstances. You can do this by emailing me

at info@salledecouture.co.uk or writing to me at the address noted above.

9.7 I will tell you if there is a breach, or a likely breach, of your data protection rights.