Scope

All data subjects whose personal data is collected, in line with the requirements of the GDPR.

Responsibilities

The Data Protection Officer / GDPR Owner / CIO is responsible for ensuring that this notice is made available to data subjects prior to our company collecting/processing their personal data.

All Employees/Staff of our company who interact with data subjects are responsible for ensuring that this notice is drawn to the data subject’s attention and their consent to the processing of their data is secured.

Privacy notice

Gather ‘N’ Sew

Our Data Protection Officer can be contacted directly here:

[email protected]

01778 420464

The personal data we collect and process from you is:

Contact Name and position within your organisation including responsibilities, titles and contact information
Company bank account details
Services you have subscribed to or may be interested in
Details on related IT infrastructure
The personal data we collect will be used for the following purposes:

Ensure we can trade with your business, receive payments from and make payments to as required
Provide marketing information on related products and services relevant to your position and business
Provide technical support and consultancy as required
Our legal basis for processing for the personal data:

You have given consent to the processing of your personal data for one or more specific purposes;
Processing is necessary for the performance of a contract to which you are party too
Processing is necessary in order to protect the vital interests of the you or your business

Consent

By consenting to this privacy notice you are giving us permission to process your personal data specifically for the purposes identified.

You may withdraw consent at any time by emailing [email protected]

Disclosure

We will not pass on your personal data to third parties without first obtaining your consent.

Retention period

We will store personal data for a period of 3 years following the cease of any trading contact with you unless we are required by law to hold specific information for a longer period.

Your rights as a data subject

The right to be informed: We will always tell individuals what data is being collected, how it’s being used, how long it will be kept and whether it will be shared with any third parties. This information must be communicated concisely and in plain language.
The right to access: Individuals can submit subject access requests, which oblige organisations to provide a copy of any personal data concerning the individual. Organisations have a maximum of one month to produce this information, although there are exceptions for requests that are manifestly unfounded, repetitive or excessive. We cannot charge the individual for this information processing.
The right to rectification: If the individual discovers that the information we hold on them is inaccurate or incomplete, they can request that it be updated. As with the right to access, we have one month to do this, and the same exceptions apply.
The right to erasure (also known as ‘the right to be forgotten’): Individuals can request that we erase their data in certain circumstances, such as when the data is no longer necessary, the data was unlawfully processed, or it no longer meets the lawful ground for which it was collected. This includes instances where the individual withdraws consent.
The right to restrict processing: Individuals can request that we limit the way we use personal data. It’s an alternative to requesting the erasure of data and might be used when the individual contests the accuracy of their personal data or when the individual no longer needs the information but the organisation requires it to establish, exercise or defend a legal claim.
The right to data portability: Individuals are permitted to obtain and reuse their personal data for their own purposes across different services. This right only applies to personal data that an individual has provided to us by way of a contract or consent.
The right to object: Individuals can object to the processing of personal data that is collected on the grounds of legitimate interests or the performance of a task in the interest/exercise of official authority. Organisations must stop processing information unless they can demonstrate compelling legitimate grounds for the processing that overrides the interests, rights and freedoms of the individual or if the processing is for the establishment or exercise of defence of legal claims.
Rights related to automated decision making including profiling: The GDPR includes provisions for decisions made with no human involvement, such as profiling, which uses personal data to make calculated assumptions about individuals. There are strict rules about this kind of processing, and individuals are permitted to challenge and request a review of the processing if they believe the rules aren’t being followed.

Complaints

In the event that you wish to make a complaint about how your personal data is being processed by ourselves or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and our Data Protection Officer by email to [email protected]

© copyright 2018 Gather ‘N’ Sew – all rights reserved.

0
    0
    Your Cart
    Your cart is emptyReturn to Shop