Alexandra Tandy Ltd totally respects your personal information and will only ask you for the information it really needs from you. We will look after it in the same way we would want our own data looking after. We will only share it with others where we need their help us deliver our service to you (such as our professional printing laboratory who may need your name and address to post your purchases).

Be assured that we will never share your information in any other circumstances – nor will we sell it on elsewhere! Here are more details –

Introduction

Alexandra Tandy Ltd takes your privacy very seriously. This privacy policy has been prepared in line with the EU’s General Data Protection Regulation (GDPR), which promotes fairness and transparency for all individuals in respect of their personal data. This privacy policy applies to all data we process, and by using Alexandra Tandy Ltd you consent to our collection and use of such data.

  1. The Data we collect

As a data controller we collect a variety of data in order to deliver my services, and we will manage your personal data transparently, fairly and securely.

We may ask you to provide us the following data –

First Name

Last Name

Address

Postcode

Telephone Number(s)

Email

We will also record a date of birth for all persons we photograph under the age of 13 and require the parent or a legal guardian to consent to photography.

Obviously being a photographic business we also create and manage images as per our contractual agreement(s).

We use the above data to deliver a professional service to you from billing and communication to advising you about future promotions and photo shoot opportunities. It also allows me to store your images securely and retrieve them in years to come should you wish to obtain reprints etc.

We collect this data on the following lawful basis to gain parental or guardian consent, to arrange and fulfil and contract, to meet a legal obligation other than a contract, and to enable me to communicate with you.

When you visit this website it also collects Cookies. These are small pieces of data that websites send to a user’s computer and are stored on the user’s web browser. They are designed to enable the website to remember information. This helps me personalise your experience, deliver a seamless service to you and aid marketing.

 

  1. Which third parties do we share Personal Data with and why?

We do not sell your data. But in order for us to supply a professional service we may need to share your data with the following professional organisations. They will not resell your data either.

  • Bookkeeper to invoice you. Data is not transferred outside of the European Economic Area.
  • Accountant for tax and accountancy reasons. Data is not transferred outside of the European Economic Area.
  • Paypal to enable you to purchase images. Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.
  • Print laboratories in case images need to be mailed to you direct. Data is not transferred outside of the European Economic Area.
  • Delivery and Postage Service Providers to allow me to send you documentation and orders you have placed. Data is not transferred outside of the European Economic Area.
  • Microsoft Outlook so that we can email you. Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.
  • Shootproof so that we can share your final gallery of images with you. Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.
  • Dropbox to archive your images Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.
  • Siteground (website hosting provider) Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.
  • Mailchimp . Data is transferred outside of the European Economic Area to United States under the protection of EU/US Privacy Shield.

There are also certain situations in which we may share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation.

We may transfer personal data to a country outside of the European Economic Area (EEA) if necessary eg if a third party we utilise could have servers located outside of the EEA. If this is the case, we will ensure that the transfer is legal and your data is secure by following the EU’s guidelines. You can see above where we send data outside of the EEA and on what basis we do so.

  1. How do we keep your personal data secure?

We keep your data secure by following internal policies of best practice and training, encryption, by using Secure Socket Layer (SSL) technology when information is submitted to us online.

In the unlikely event of a criminal breach of our security we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we will also inform you.

  1. Changes to our privacy policy and control

We may change this privacy policy from time to time. When we do, we will let you know by changing the date on this policy, notifying customers of only significant changes. By continuing to access or use our services after those changes become effective, you agree to be bound by the revised privacy policy.

  1. You have the following rights 
  • –  the right to be informed about the collection and use of your personal data
  • –  the right of access to your personal data and any supplementary information
  • –  the right to have any errors in your personal data rectified
  • –  the right to have your personal data erased
  • –  the right to block or suppressing the processing of your personal data
  • –  the right to move, copy or transfer your personal data from one IT environment to another
  • –  the right to object to processing of your personal data in certain circumstances, and
  • –  rights related to automated decision-making (i.e. where no humans are involved) and profiling (i.e. where certain personal data is processed to evaluate an individual).

We also give you the option to manage your data by contacting us at alex@alexandra-tandy.com or calling 07740 983602.

While we do not hold personal data any longer than we need to. The duration will depend on your relationship with us, and whether it is on going. We may keep some of your personal data for up to 7 years after our working contract with you has finished for Tax legislation purposes. This is due to requests for replacement images being made several years after being taken.

If you leave a comment on this website, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.

If you email or send messages via social media, these messages are stored within our email system or social media accounts. These messages are stored for as long as practicable to allow us to provide you with better future services.

  1. Company details

This business is owned and operated by Alexandra Tandy, trading as Alexandra Tandy Ltd with a registered office at Wellesley House, 204 London Road, Waterlooville, Hampshire, PO7 7AN

This privacy policy was updated May 2018.

UA-87925748-1