Website Privacy Notice
The full name of our company is PhotograFX (“we”, “us” or “our”).We operate the website that you are currently using. Our address is 19 Headley Dr, Epsom, KT18 5RP UK. You can contact us by writing to our Data Protection Officer by email at [email protected]
his Website Privacy Notice (
This Policy may change occasionally and we will update this document and the last reviewed date. You should check this page from time to time or when notified to ensure that you understand and are happy with any changes. By using or continuing to use the Website, you agree to this Policy as in force at the time of that use.
-
1 Purpose of this privacy notice
This Privacy Notice explains our approach to any personal data that we might collect from you and the purposes for which we process your personal data. This Privacy Notice also sets out your rights in respect of our processing of your personal data.
When we talk about “personal data”, we mean any information which relates to an identified or identifiable living individual. An individual is ‘identified’ or ‘identifiable’ if they can be distinguished from other individuals.
So your Purchase Data or Enquiry Data (which we fully define below in What Personal Data We Collect) that you may enter in to the Website may include your name and contact details and would fall within the definition of personal data.
This Privacy Notice is intended to assist you in making informed decisions when using our Website. Please take a moment to read and understand it.
This Privacy Notice only applies to the use of your personal data obtained by us directly. It does not apply to personal data collected by third parties during your communications with those third parties or your use of their products or services.
-
2 How to contact us
If you have any questions about this Privacy Notice or want to exercise your rights as a data subject set out in this Privacy Notice, you can contact us using the following methods:
On Site Contact us using our enquiry form on our website. Email Sending an email to:
[email protected]Post Writing to us at:
19 Headley Drive, Epsom, KT18 5RP, UK -
3 What personal data we collect
In providing our Services, we may collect and process different types of personal data about you for different processing purposes. The types of personal data we collect depends on who you are and how you use the Services and includes the following:
Purchase Data (when you buy a product or service from our Website)
This may include: Name; telephone number; purchase/order details (what you are buying); home address; contact preferences; email address; shipment address; billing address.
Enquiry Data (including any enquiry form data and chat data)
Name; and email address.
Behavioral Data
How long you spend on the Website; what pages you open; how long you spend on each page; where you leave the Website; your journey through the Website; how you have come to the Website; what pages you look at; what you do when you are on a particular web page (such as links you may click on); whether you are accessing the Website on your mobile device or laptop; your web browser type; demographic (i.e. age band and gender).
-
4 How we collect and receive personal data
We collect and receive personal data using different methods:
Payment Data
None of your payment data is retained by us.
Personal data you provide to us
We will collect the information directly from you, e.g. when you enter information into the Website, we also collect information when you are browsing the Website (please see our Cookies policy for more information).
Personal data received from third parties
We may receive personal data about you from third parties. Such third parties may include photographic companies and third parties that provide technical services to us so that we can provide our Website.
-
5 Who we collect personal data about
We collect and process personal data from the following people:
Customers and Users
If you buy from or use the Website, we may collect and process your personal data in connection with the supply of goods or services to you.
-
6 How we use your personal data
We use your personal data for the purposes set out in this section. If we wish to make any changes to these purposes, or if we wish to use your personal data for any purpose that is not listed in this section, we will notify you using the contact details we hold for you:
To provide you with our goods and services when you make a purchase
Personal data used: Purchase Data; Payment Data. Explanation: In order to make a purchase via the Website, we will need to obtain personal data from so that we can take payment and send the goods to you and / or provide you with the services that you have requested.
Retaining and evaluating information on your recent visits to our website and how you move around different sections of our website for analytics purposes to understand how people use our website so that we can make it more intuitive or to check our website is working as intended
Personal data used: Behavioural data; Explanation: Your consent as gathered with reference to our ‘Cookies policy’ available on our website.
Marketing our services to customers who have enquired about our products or services as well as existing and former customers
Personal data used: Enquiry Data; Purchase Data. Explanation: For our legitimate interests, i.e. to promote our business to newly enquiring, existing and former customers, to promote product trials and new products.
Develop our products
Personal data used: Purchase Data; Location data (regional only). Explanation: We use this information to help us to monitor and improve our Services, to assist with the selection of future service lines and to train our personnel.
Answer your enquiries
Personal data used: Enquiry Data; Purchase Data. Explanation: When you make an enquiry, we will collect this information, as well as any other personal data you volunteer, to enable us to respond to your enquiry.
To manage our relationship with you including notifying you of changes to the Website
Personal data used: Enquiry Data; Purchase Data; Explanation: We may use your personal data to inform you of any changes to our Website.
Comply with our legal obligations and assist with the administration of our business
Personal data used: Enquiry Data; Purchase Data; Explanation: We may use your personal data: (i) to comply with our legal obligations; (ii) to enforce our legal rights; (iii) to protect the rights of third parties; and (iv) in connection with a business transition such as a merger, reorganisation, acquisition by another company, or sale of any of our assets.
We also collect and use ‘Aggregated Data’ which is statistical data about several individuals that has been combined to show general trends or values without identifying individuals within the data. We use this sort of data for various business purposes. Aggregated Data could be derived from your personal data but is not considered personal data as this data will not directly or indirectly reveal your identity or location. For example, we may aggregate your data to calculate the percentage of users accessing a specific application feature. We also anonymise your data which means that we cannot identify an individual. After anonymising your data, we may use elements of the data to operate and improve the quality of the Products and the Services. We may share such anonymised data with carefully selected partners.
-
7 Our legal basis for processing your data
We will use your personal data where it is necessary for us to do so to perform our obligations in accordance with a relevant contract to which you are a party. This may be a contract that we have entered into with you (for example when you agree to purchase something from us via our web store).
We will use your personal data where it is in our legitimate interest to do so. For example, to ensure that we provide access to the Website in a secure and effective way and so that we can make improvements to our services to best meet your needs. Or, for example, in connection with business transitions, to enforce our legal rights or to protect the rights of third parties.
We will use your personal data where it is necessary for us to do so to comply with any legal obligations imposed upon us, such as a court order or specific regulatory rules.
We will use your personal data to send you updates (by email, text message, telephone or post) about our products and/or services, including exclusive offers, promotions or new products.
We have a legitimate interest in using your personal data for marketing purposes. This means we do not need your consent to send you marketing information. If we change our marketing approach in the future so that consent is needed, we will ask for this separately and clearly.
You have the right to opt out of receiving marketing communications at any time by using the ‘unsubscribe’ link in emails.
-
8 Sharing personal data
We only share personal data with others when we are legally permitted to do so. When we share personal data with others, we put contractual arrangements and security mechanisms in place to protect the personal data shared and to comply with our data protection, confidentiality and security standards and obligations.
We share personal data with third parties who support us in providing our services and help provide, run and manage our internal IT systems. Such third parties may also include, for example, providers of information technology, cloud-based software-as-a-service providers, identity management, hosting and management, data analysis, data back-up, security and storage services.
When processing your personal data, we may need to share it with third parties as set out in the table below. This list is non-exhaustive and there may be circumstances where we need to share personal data with other third parties.
Third-party suppliers who provide applications/ functionality, data processing or IT services We share personal data with third parties who support us in providing our services and help provide, run and manage our internal IT systems. Such third parties may also include, for example, providers of information technology, cloud-based software-as-a-service providers, identity management, hosting and management, data analysis, data back-up, security and storage services. The servers powering and facilitating that cloud infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them. We also share your personal data with third-party service providers to assist us with insight analytics. Payment service providers, warehouses and delivery companies We may share your personal data with payment providers who help deliver our products and/or services to you, e.g. payment service providers, warehouses and delivery companies, our banks Auditors, lawyers, accountants and other professional advisers We share personal data with professional services firms who advise and assist us in relation to the lawful and effective management of our organisation and in relation to any disputes we may become involved in. Law enforcement or other government and regulatory agencies and bodies We share personal data with law enforcement or other government and regulatory agencies or other third parties as required by, and in accordance with, applicable law or regulation. Another corporate entity in connection with a business transition If we are involved in a business transition such as a merger, reorganisation, acquisition by another company, or sale of any of our assets, we may share or transfer personal data to a third party. Any new owner of our business may continue to use your personal data in the same way(s) that we have used it, as specified in this Privacy Notice. Other third parties Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, or to establish, exercise or defend legal rights. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation. -
9 Transfers outside the UK and the European Economic Area (“EEA”)
We may transfer, store and process your personal data outside the UK. Where we do so, we will ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data.
Where we use certain service providers, we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK.
-
10 How long we keep your personal data
In respect of personal data that we process in connection with the supply of our services, we may retain your personal data for as long as you are a customer with us and in compliance with our data protection obligations. We may then destroy such files without further notice or liability.
Where we process personal data in connection with the registration and use of an account that may be accessed via the Website, we may retain your personal data for up to 2 years from the date that the relevant account is terminated (and in compliance with our data protection obligations). We may then destroy such files without further notice or liability.
-
11 Confidentiality and security of your personal data
We are committed to keeping the personal data you provide to us secure and we have implemented information security policies, rules and technical measures to protect the personal data under our control from unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss. In addition, all our employees and data processors (i.e. those who process your personal data on our behalf) are obliged to respect the confidentiality of the personal data of all users of our Services.
-
12 Personal data of minors
Our Website is not intended for use by, or targeted at, minors (individuals under the age of 18) and we do not knowingly collect personal data of minors. However, this does not prevent minors from providing personal data to us. If we do collect personal data of minors, we will comply with all applicable laws and regulations relating to the processing of personal data of minors.
If you are under the age of 18, you must not use our Website to purchase goods from us and you must not provide us with any personal information. If we discover that we are holding the personal data of a minor, we will delete that information as soon as possible. Please contact us if you have reason to believe that a minor may have submitted personal data to us (see the “How to contact us” section above).
-
13 Your rights as a data subject
You have certain rights in relation to the personal data we hold about you. These rights include the right: (i) to obtain copies of your personal data; (ii) to have your personal data corrected or deleted; (iii) to limit the way in which your personal data is used; (iv) to object to our use of your personal data; (v) to transfer your personal data; (vi) not to be subject to decisions based on automated processing (including profiling); and (vii) to complain to a supervisory authority. If you would like to exercise any of these rights, please contact us using the details set out in the “How to Contact Us” section above.
Your right of access If you ask us, we will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data (along with certain other details). If you require additional copies, we may charge a reasonable fee for producing those additional copies. Your right to rectification If the personal data we hold about you is inaccurate or incomplete, you are entitled to have it rectified. If we have shared your personal data with others, we’ll let them know about the rectification where possible. If you ask us, where possible and lawful to do so, we will also tell you who we’ve shared your personal data with so that you can contact them. Your right to erasure You can ask us to delete or remove your personal data in some circumstances, such as where we no longer need it or where you withdraw your consent (where applicable). If we have shared your personal data with others, we will let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we will also tell you who we have shared your personal data with so that you can contact them directly. Your right to restrict processing You can ask us to “block” or suppress the processing of your personal data in certain circumstances such as where you contest the accuracy of that personal data or you object to us processing it for a particular purpose. This may not mean that we will stop storing your personal data but, where we do keep it, we will tell you if we remove any restriction that we have placed on your personal data to stop us processing it further. If we’ve shared your personal data with others, we’ll let them know about the restriction where it is possible for us to do so. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we’ve shared your personal data with so that you can contact them directly. Your right to data portability You have the right, in certain circumstances, to obtain personal data you have provided to us (in a structured, commonly used and machine-readable format) and to reuse it elsewhere or to ask us to transfer it to your chosen third party. Your right to object You can ask us to stop processing your personal data, and we will do so, if we are: (i) relying on our own or someone else’s legitimate interest to process your personal data, except if we can demonstrate compelling legal grounds for the processing; or (ii) processing your personal data for direct marketing purposes. Your rights in relation to automated decision-making and profiling You have the right not to be subject to a decision when it is based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for the entering into, or the performance of, a contract between you and us. Your right to withdraw consent If we rely on your consent (or explicit consent) as our legal basis for processing your personal data, you have the right to withdraw that consent at any time. You can exercise your right of withdrawal by contacting us using our contact details in the “How to Contact Us” section above or by using any other opt-out mechanism we may provide, such as an unsubscribe link in an email. Your right to lodge a complaint with the supervisory authority If you have a concern about any aspect of our privacy practices, including the way we have handled your personal data, please contact us using the contact details provided in the “How to Contact Us” section above. You can also report any issues or complaints to the Information Commissioner’s Office (“ICO”). Contact details for the ICO can be found on its website at https://ico.org.uk.
Copyright © 2023
Updated December 2023