Updated August 2019
I Sadie Davies (Bonny Bears) believes it is important to protect your Personal Data (as defined in the GDPR) and I am committed to giving you a personalised service that meets your needs in a way that also protects your privacy. This policy explains how I may collect Personal Data about you. It also explains some of the security measures I take to protect your Personal Data, and tells you certain things I will do and not do.
When I first obtain Personal Data from you, or when you take a new service or product from me, I will give you the opportunity to tell me if you do or do not want to receive information from me about other services or products (as applicable). You may change your mind at any time by emailing or messaging at the address above. Some of the Personal Data I hold about you may be 'sensitive personal data' within the meaning of the GDPR, for example, information about your personal life, dates, and contact details.
Information I Collect
To for fill your order I need certain information, such as your name, email address, postal address, payment information and the details of the product you are ordering. The only information I collect about you is from you. I do not collect information from another source. The information I collect is limited to what I need to complete your order and to keep in touch throughout the order process.
2. How I Use Your Information
Personal Data about my customers is an important part of my business and I shall only use your Personal Data for the following purposes and shall not keep such Personal Data longer than is necessary to fulfill these purposes:
2.1. To help me to identify you when you contact me.
2.2. To help me for fill the contract agreed for services provided by me.
2.3. To settle disputes, or to provide customer support.
2.4. To help me to identify services and/or products which you could have from me.
2.5. If necessary to comply with legal obligation or court order or in connection with a legal claim, such as retaining information about your purchases if required by tax law.
2.6. As necessary for the purpose of my legitimate interests, if these legitimate interests are not overriding by your rights or interests, such as providing and improving my services. I use your information to provide the services you requested and in my legitimate interest to improve my services.
2.7. I may monitor and record communications with you (including phone conversations and emails) for quality assurance and compliance.
3. Information Sharing & Disclosure
Information about my customers is important to my business. I share your personal information for very limited reasons and in limited circumstances as follows:
3.1. Service Providers. I engage certain trusted third parties to perform functions and provide services to my shop, such as delivery companies. I will share your personal information with these third parties, but only at the extent necessary to perform these services.
3.2. Compliance with laws. I may collect, use, retain and share your information if I have good faith belief that it is reasonably necessary to: (a) respond to legal process or government requests; (b) enforce my agreements, terms and policies; (c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues; or (d) protect the rights, property and safety of my customers, or others.
3.3. Sharing photographs of my work. I often share photographs of completed orders with a brief description, on my website and social media pages. By placing your order with me you will automatically give me permission to do so. If you do not want the photographs to be shared, please let me know at email@example.com upon ordering.
4. Data Retention
5. Protecting Information
I have strict security measures to protect Personal Data. Although transmission of any data across the internet is not entirely safe, once I receive that data I do my best to protect it. I maintain physical and electronic safeguards in connection with the collection, storage and disclosure of personally identifiable customer information. All documents received that are hard copy are not kept for longer than necessary, and shredded when no longer needed.
5.1. All Personal Data in physical copy located at the business address above is kept secure under lock and key.
5.2. Data received by email is password protected and only accessed via my business computer, laptop and mobile phone.
5.3. Data received by my website is sent to my email, which is password protected.
5.4. Data received by social media is held within my password protected business account, and only accessed via my computer, laptop and mobile phone.
6. Further Information & rights
6.5. I aim to keep the Personal Data I hold about you accurate and up to date. If you tell me that I am holding any inaccurate Personal Data about you; I will delete it or correct it promptly. Please email me at firstname.lastname@example.org to update your Personal Data.
6.6. You can object to (a) my processing of some of your information based on my legitimate interests and (b) receiving marketing messages from me after providing your express consent to receive them. In such cases I will delete your personal information unless I have compelling or legitimate grounds to continue using that information or if it is needed for legal reasons.
6.7. If you reside in the EU and wish to raise a concern about my use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local data protection authority.
7.1. The Website may include third-party advertising and links to other websites. I do not provide any personally identifiable customer Personal Data to these advertisers or third-party websites.
7.3. I exclude all liability for loss that you may incur when using these third party websites.
9. How To Contact Me
For purposes of EU data protection law, I, Sadie Davies, am the data controller of your personal information. If you have any questions or concerns, you may contact me at email@example.com, or using the contact details above.