Privacy Policy

INTRODUCTION

At Photoface Photography we take Data Security very seriously. We recognise the importance of ensuring that Personal Data is only collected when absolutely necessary and that it is processed only when we have Legal Basis to do so. We continuously monitor our Procedures and Network to ensure that the environments in which any Data is stored are protected adequately to Industry-recognised standards. (Automated, and open certificate authority (CA), which is an initiative of the Internet Security Research Group (ISRG).)

SHA-256 fingerprint
DD 9F 8E 30 47 D6 4A 9A 14 13 A4 C3 88 20 5F 7B BF B3 CA 71 F2 4A 22 29 FD AE B6 D5 06 20 66 87
SHA-1 Fingerprint
9C 65 F1 7C 75 50 2B 19 52 E3 31 9E 0E 17 84 E1 D9 4F A3 46

Under the General Data Protection Regulation (GDPR), we have responsibilities defined for us which we accept and fulfil. In the case of Data provided by you whilst placing an order, we are the Data Controller, which means that we will make decisions as to how we Process your Data in order to fulfil your order. Subsequently we may contact you to give you the opportunity to make purchases of other Photographs we may have captured of you or your child, and you can choose to unsubscribe from such further contact at any time.

Parents and carers who purchase school Photographs will not automatically receive marketing materials from Photoface unless they individually OPT-IN. Their details are used ONLY for the purpose of taking photographs therefore The school is limited by ‘Purpose Limitation’ under UK GDPR. This means that the school can only provide student and parental data to fulfil their purpose as a school and a public authority. Therefore, the school cannot provide parental data for marketing purposes. 

Our Privacy Policy is designed to reassure Website Users, Subscribers and all Customers who make purchases through the Website, that we will only Process your Data when is necessary and where we do so, we do within the most secure physical and electronic environments using secure digitally signed SSL/TLS certificates. In addition to that, the GDPR gives you certain rights, one of which is The Right to be Informed. In line with this Right, this Privacy Notice will inform you of the following:

We review our privacy practices from time to time. To contact us about privacy issues relating to our website, to report a violation of our Privacy Statement, or to raise any other issue, please e-mail us at THE INFORMATION WE GATHER

We gather two types of information about users:

  1. Tracking information:Information that is collected about every user of our website, whether such user registers or not, and is automatically gathered using “Cookies.” A Cookie is a small bit of data that is written to the user’s hard drive by a web server and used to track the pages the user has visited. Cookies do not include personal information about you, rather they are unique to each user, which allows our computers to distinguish between individual users, and personalise your experience if you have previously provided information about yourself. Cookies are only read by the computer that placed them and cannot execute any code or virus.
  2. Personal information:Information that relates to an identifiable individual. When a user registers for our website (as is necessary, for example, for a user to make a purchase through our website), the user may be required to provide personal information such as their name and email address, to select a login name and password, and then will be passed on to a payment processing company to securely provide their credit card information (number, type and expiration date), a telephone number and a billing address. If a user prefers to do so, they can talk offline to a customer service representative, providing the required information over the telephone.

use of the Information:

  1. Tracking Information:We use tracking information in aggregate form to build higher-quality, more useful services by performing statistical analyses of users’ activities, and by measuring demographics and interest regarding specific areas of our website.
  2. Personal Information:At registration, and when a user is purchasing goods through our website, we provide notice to the user that personal information will be collected during the registration and/or purchasing process (as applicable). This Privacy Statement itself is also notice that such information is collected.

Your contact details and other data you supply as part of the registration process are stored and processed by us to enable you to access the Services on our website and to provide you with the goods you have purchased or the information you have requested.

If you have provided an address when purchasing goods, our website may automatically fill in that information on a subsequent order form for your purchase of goods. This is simply a convenience – no information is released to anyone unless you authorise its release, such as by clicking a “Submit” button.

We may pass your contact details only on to our chosen delivery companies, for the sole purpose of delivering your order and informing/updating you on the delivery progress of your order.

We will hold your personal information for as long as is necessary to provide excellent service to you in respect of the product you purchase, normally around 5 years. This is of particular need and importance where similar products are purchased over a number of years and a customer wishes to check the make-up and detail of previous orders.

DISCLOSURE AND TRANSFER OF PERSONAL INFORMATION

We do not pass on any data to third parties except where it is necessary to enable us to fulfil whatever service you are buying from us, for example, a photographic Lab. In these cases, we ensure they have a valid GDPR policy.

We use the appropriate industry standard security methods to protect the data that resides on our servers.

We may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another person.

SOURCES AND LEGAL BASES FOR PROCESSING OF PERSONAL DATA

Under the GDPR (General Data Protection Regulation) we are required to provide you with certain information relating to the Data we Process. These are as follows:

  • The general categories of personal data that we may process;
  • In the case of personal data that we did not obtain directly from you, the source and specific categories of that data;
  • The purposes for which we may process personal data; and
  • The legal basis of the processing.

When you register an online account with us, such as when you place an order through the website, we ask you for your contact details, including your name, address, telephone number and email address. We may process this data to allow essential functions to include communication with you, ensuring data security, and completing your order(s). There are several Legal Bases for these activities, such as fulfilment of our contract with you, and conducting our Legitimate Business Interest of ensuring good customer service.

We may process data about your use of our website and services, and this may include pages you visit, links you follow and ordering data. This usage data may be processed to analyse the use of the website and services, in order to make improvements, and is made available to us through our Web-Analytics reporting system. The legal basis for this processing is our Legitimate Business Interest of making our website as efficient and effective as possible.

We may process information that you provide to us to send you email notifications and/or newsletters, or to send you special offer emails. The legal basis for this processing is Legitimate Business Interest of generating sales through the website and only where OPT-In for marketing has been chosen.

Student data is provided by the School or College with whom we have a contract. This data is limited to Name, Class and Admission Number. Processing is performed in order to provide the services that school have engaged us to perform. The legal basis for this processing is in order to perform a contractual obligation with the School, under our Processing Agreement.

We capture and process Photographs (deemed to be personal data under the GDPR) as our central and core service. The photograph data is processed to provide the service we have been contracted to complete. We use consent as our legal basis for capturing the photographs, and subsequent processing to make the images available for sale to Parents or Pupils is based on our Legitimate Business Interest of generating sales.

In addition to the specific information related to Processing noted above, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another person.

RETENTION AND DELETION OF PERSONAL DATA

The GDPR (General Data Protection Regulation) requires us to maintain a Company Policy in relation to how long we keep various categories of personal data.

Personal data is kept for no longer than it is needed in order to serve the purpose for which it was collected.

We do not store Credit Card information on our systems.

A Summary of the length of time we retain different types of information is as follows:

Photographs: These are the intellectual property of The Company, and Copyright on such work lasts for 75 years. We will, therefore, retain Photographs for 75 years. After this point images are reviewed for longer preservation, to assess their Historical Relevance. If they are likely to become valuable Historically, they are added to the Archive. Photoface will however agree to delete any photographs on the written request of parents/carers and or a school in the interests of safeguarding purpose

Order Data: This is kept for 75 years, in line with the Copyrighted work they relate to, in order to be able to inform you whether or not you have previously ordered a particular photograph(s).

Identification Data (Name Admission Number and Class, provided by the School or College): This is kept electronically alongside Portraits, and is kept in a secure database – only accessible by authorised Users – for 75 years in line with Copyright, and to ensure that these are made available only to the Subject, or to close relatives of the Subject.

In addition to the specific information related to Retention and Deletion noted above, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another person.

YOUR RIGHTS

The GDPR (General Data Protection Regulation) defines certain Rights that you as a Data Subject may exercise in relation to your Personal Data. In Summary, these Rights are as follows:

  • The Right of Access
  • The Right to Rectification
  • The Right to Erasure
  • The Right to Restrict Processing
  • The Right to Data Portability
  • The Right to Object
  • Rights in Relation to Automated Decision Making and Profiling.

Some of the details of Terms listed above are explained as follows. As some of these terms are complex, this should not be seen as a full explanation, and we certainly recommend that you read information presented by the Regulatory Bodies for further details.

The Right of Access

You have the right to request copy of the Personal Data we hold, plus Supplementary information, such as whether we are processing your data, along with the reasons. In most cases, as long as the rights of a third party aren’t compromised, we will comply with your request within a calendar month.

For clarity, we only hold data necessary to record what you have ordered, to make sure the order gets to you at the correct address, and to contact you about your order, and about potential future orders. We don’t collect or store any data which isn’t needed for these purposes.

The Right to Rectification

If any data we hold is incorrect, you have a right to request that this is corrected for you.

The Right to Erasure

If you no longer wish us to store or process your Personal data, you have a right to request that any data we hold is erased, or deleted. If you contact us to request a Right to Erasure, we will comply where possible, but there are exceptions, or exclusions to this right. The general exclusions include where processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise or defence of legal claims. It may also be that the Legitimate Business Interests of the Company would be threatened by the erasure. For these reasons, The Company has the right to reject a request under the Right to Erasure, but we will always explain to you clearly why the decision was taken, and what you can do next. Photoface will forgo any normal rights to copyright when requested to delete photographs by a School, Parent/carer for the purposes of Safeguarding

The Right to Restrict Processing

You may have a reason to request that we do not process your data for a specific period of time. Legal Bases for this could be:

  1. You contest the accuracy of the personal data.
  2. Processing is unlawful but you don’t want the data to be erased.
  3. We no longer need the personal data for the purposes of our processing, but you need the personal data for the establishment, exercise or defence of legal claims.

As an alternative to the Right to Erasure, you may wish to request that we do not process your data for a specific period of time. You can make this request under your Right to Restrict Processing.

There are several legal exemptions to the Right to Restrict Processing: with your consent; for the establishment, exercise or defence of legal claims; for the protection of the rights of another person; or for reasons of important public interest. It may also be that the Legitimate Business Interests of the Company would be threatened by the restriction. For these reasons, The Company has the right to reject a request under the Right to Restrict Processing, but we will always explain to you clearly why the decision was taken, and what you can do next.

The Right to Object

You have the right to object to our Processing of your data in relation to Marketing. If you object, we will cease to contact you for this reason from the date of your request.

You also have a right to object to our processing of your personal data on grounds relating to your particular situation, but the processing may be necessary for: the performance of a task carried out in the public interest or in the exercise of any official authority vested in us; or the purposes of the legitimate interests pursued by us or by a third party. If you exercise your Right to Object, we will cease to process the personal information unless there are legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims. It may also be that the Legitimate Business Interests of the Company would be threatened by the objection. For these reasons, The Company has the right to reject a request under the Right to Restrict Processing, but we will always explain to you clearly why the decision was taken, and what you can do next.

Rights in Relation to Automated Decision Making and Profiling.

To the extent that the legal basis for our processing of your personal data is: (a) consent; or (b) that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, and such processing is carried out by automated means, you have the right to receive your personal data from us in a structured, commonly used and machine-readable format.

If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state where you normally live, your workplace or the place of the alleged infringement.

If the Lawful Basis for processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal of consent cannot be backdated from the actual date of receipt.

HOW TO CONTACT US

If you wish to exercise any of your rights in relation to the data we hold about you, you may do this in writing.

You may also ask us any questions about this Privacy Statement.

You may email us at