This Privacy Notice sets out how Tiffany Kay Brett (the Data Controller) collects and uses your personal data. When we refer to “we”, “us” “our” or “controller” in this Privacy Notice we mean Tiffany Kay Brett.
Our Privacy Notice is structured in a way for you to easily find the specific details of what we do with your personal data, depending on which processing activity you want to find out more about.
Part 1 of our Privacy Notice is information we must tell everyone regardless of your relationship with us. The remaining parts give specific information on how we use your personal data for each of the different processing activities we undertake.
PART 1 – GENERAL INFORMATION
Our contact details
Tiffany Kay Brett is the data controller for the personal data we process about you.
You can contact us regarding the use of your personal data using the contact form on this website.
Although we do not have a legal obligation under GDPR to appoint a Data Protection Officer a member of our team does oversee our data protection compliance with the General Data Protection Regulation, the Data Protection Act 2018 and other relevant privacy laws (e.g. the Privacy & Electronic Communication Regulations 2003). The various ways you can contact us to discuss any data protection issues or concerns are shown in the “Our contact details” section.
How we get your personal data
We obtain your personal data either directly from you or indirectly from third parties.
Directly
We obtain personal data directly from you, i.e. you have given your details to us, when you:
Indirectly
We do not collect any personal data about you from third parties.
The legal basis to process your personal data
When gathering and using your personal data we must have a legal basis to do so – this is a requirement of data protection law.
The legal basis we rely on to process your personal data varies depending on the processing activity undertaken. The full details of the processing activities we undertake along with the legal basis we rely on to process your personal data are given in the specific Parts of this privacy notice.
Where we process your personal data for us to comply with a legal/regulatory requirement we will rely on the legal basis of “legal obligation” as the processing is necessary for us to fulfil our legal obligation to which we are subject to.
Your rights
Depending on the purpose and legal basis we rely on for processing your personal data, there are various rights available to you. You can:
We do not undertake any solely automated decision making, including profiling, about you.
To find out more about how to exercise your rights please refer to the guidance on the Information Commissioner’s Office website.
You do not pay a fee to us to exercise any of your rights. However, if your request is manifestly unfounded or excessive, we may either charge a reasonable fee or refuse the request.
We shall respond to a valid request within one month of receiving it.
If you wish to exercise one of your rights, please contact us via one of the methods shown in the “Our contact details” section.
How to make a complaint about us to the Information Commissioner’s Office
If you are not happy with how we are processing your personal data or you believe we have not dealt with one of your rights correctly you are entitled to make a complaint to the Information Commissioners Office (ICO). The ICO has several ways in which you can get in touch with them, including post, email, and online forms. For full details how to make a complaint please refer to their website.
Sharing your information
We do not share, sell or rent your personal data to third parties for them to use for their own marketing purposes.
We may share information in the following ways:
When we do use third party businesses to process personal data on our behalf (they are known as data processors) to enable us to provide our services/delivery of goods to you we ensure we have appropriate GDPR compliant contracts in place with each one. The data processor is not allowed to do anything with your personal data other than what we have instructed them to do with it. They will not share your personal data with any organisation apart from us, unless they are required to do so by law. They will hold it securely and retain it for the period we instruct.
Our data processors include:
Transferring personal data outside of the UK and EU
Sometimes it is not possible for us to store or process your personal data either wholly in the UK or EU. When your personal data does need to be transferred or stored outside of the UK or EU we make sure we comply with the specific requirements set out in GDPR for us to undertake this. We will only transfer personal data outside of the UK or EU when one of the following provisions are in place to safeguard your personal data:
If we are unable to rely on any of the above provisions we will seek your explicit consent to make the transfer of personal data, unless another exception under GDPR applies to allow us to process your personal data.
Children’s information
We do not collect and process personal data relating to children.
Cookies
You can find full details of our Cookie Policy here.
Links to other websites
Our website may provide links to websites of other organisations. Our Privacy Notice does not cover how those organisations process your personal data when you visit their website. We advise you to read their Privacy Notices.
Changes to our Privacy Notice
We keep our Privacy Notice under review to ensure it remains accurate and up to date and we reserve the right to modify this policy at any time. Changes to this policy will be posted on our website and you should endeavour to review the policy frequently.
If you have any questions about our Privacy Notice, please contact us via one of the ways shown in the “Our contact details” section.
This Privacy Notice was last updated on 23 August 2023.
IF YOU ENQUIRE ABOUT OR USE ONE OF OUR SERVICES
What personal data do we need?
When you use one of our services we need to collect the following type of personal data from you:
How do we get your personal data?
We gather your personal data directly from you when you either enquire about our services or enter into a contract with us to purchase one of our services.
Why do we need your personal data and which legal basis do we rely on for the processing?
We use your personal data to:
The legal basis we rely on for these purposes are:
Contractual obligation (GDPR Article 6(1)(b))
The services we provide to you are done so under contract or with a view to entering into a contract with you. We require certain information from you to enable us to fulfil our contractual obligation. If you are not able to provide all the information we need we may not be able to provide the service to you and the arrangement may be terminated.
Legitimate interests (GDPR Article 6(1)(f)
GDPR allows us to use legitimate interests for direct marketing purposes in certain circumstances. We have undertaken a legitimate interest assessment, which balances our business purposes for the processing against your right to privacy. The outcome of the balancing test justifies our use of legitimate interests for this purpose as it would not be an unreasonable expectation for anyone who either enquired about our services with a view to purchasing them, or is an existing customer using our services to receive information from us about our services.
This also complies with e-Privacy laws, currently the Privacy & Electronic Communication Regulations 2003, which governs how a business can undertake electronic direct marketing. We can rely on soft opt-in for “individual subscribers” for email marketing to prospective and existing customers. We do not need consent or soft opt-in for “corporate subscribers”.
We always give you the opportunity to object to receiving marketing communications from us, when we first collect your personal data and with every marketing communication thereafter.
Who do we share your personal data with?
Your personal data is used by internal employees, contract staff and business associated for the purposes as set out in “why we need your personal data”.
How long do we keep your personal data?
When we have concluded the provision of our service to you, we will keep your data for a stated period of before it is securely disposed as follows:
Marketing contact details are held for as long as you want to remain on our marketing contact list.
Do we use any data processors?
Yes, we use the following data processors to deliver our service to you:
IF YOU JUST WANT TO RECEIVE OUR BLOG, NEWSLETTERS & MARKETING
What personal data do we need?
To receive marketing communications from us we need the following personal data:
How do we get your personal data?
We gather your personal data directly from you when you sign up to receive marketing information from us.
Why we need your personal data and the legal basis we rely on for the processing
We need your personal data to be able to send you relevant news about us and our services and products, etc that you have subscribed to receive.
The legal basis we rely on is:
Consent (GDPR Article 6(1)(a)
By submitting your contact details to receive marketing from us you have given your consent for us to use your personal data for this purpose.
You always have the right to withdraw your consent to receive marketing, you can do this by clicking the “unsubscribe” link in the marketing email you receive.
Who do we share your personal data with?
Your personal data is used by internal employees and contract staff for the purposes as set out in “why we need your personal data”.
How long do we keep your personal data?
Marketing contact details are held for as long as you want to remain on our marketing contact list.
Do we use any data processors?
Yes, we use the following data processors:
IF YOU ARE A SUPPLIER OR CONTRACTOR
What personal data do we need?
For us to pay you for the service or goods you have provided to us we need to collect and use a small amount of information about you and your business, this is also likely to include some information about the individuals who work at your business. The personal data we are likely to need is:
How do we get your personal data?
We obtain your data directly when we start to use your services or have purchased goods from you. We gather the relevant information from you to enable us to process payment to you for those services and goods.
We also obtain some data, such as your business name and contact details, indirectly from publicly available sources or recommendations from 3rd parties to enable us to contact you to enquire about the services and goods you provide prior to us making a purchase.
Why we need your personal data and the legal basis we rely on for the processing
We need your personal data to either enquire about the services or goods you provide that we may be interested in purchasing or to make a purchase. We then use your personal data to pay for those goods and services when you invoice us or to raise any queries about the payment.
The legal basis we rely on are:
Contractual obligation (GDPR Article 6(1)(b))
The services or goods you have provided to us are done so under contract or with a view to entering into a contract (i.e. we have asked you for a quote for the goods or to undertake the service for us).
We require certain information from you to enable us to fulfil our part of the pre-contractual and contractual obligations, e.g. we need to have certain information to make the purchase and to process payment. If you are not able to provide all the necessary information for us to do this, we will not be able to purchase the goods or services you provide or be able to make payment once purchased.
Legal obligation (GDPR Article 6(1)(c))
We have a legal obligation to pay for any services or goods we have purchased.
Who do we share your personal data with?
Your personal data is used by internal employees and contract staff for the purposes as set out in “why we need your personal data”.
Our Accountant will see personal data relating to suppliers and any payments we make.
How long do we keep your personal data?
We keep all financial data (which includes supplier information) for 6 years from end of the financial year it relates to.
Do we use any data processors?
Yes, we use the following data processors: