Privacy Policy

  

Privacy Policy Notice

The policy: This privacy policy notice is served by Carole Bowley Millinery, of 2 Cottage, Middle Battenhall Farm, Red Hill Lane, Worcester, under the website www.carolebowleymillnery.co.uk The purpose of this policy is to explain to you how we control, process, handle and protect your personal information through the business and while you browse or use this website. If you do not agree to the following policy you may wish to cease viewing / using this website, and or refrain from submitting your personal data to us.

Policy key definitions:

  • "I", "our", "us", or "we" refer to the business, Carole Bowley Millinery.
  • "you", "the user" refer to the person(s) using this website.
  • GDPR means General Data  Protection Act.
  • PECR means Privacy & Electronic Communications Regulation.
  • ICO means Information  Commissioner's Office.
  • Cookies mean small files  stored on a users computer or device.

Key principles of GDPR:

Our privacy policy embodies the following key principles; (a) Lawfulness, fairness and transparency, (b) Purpose limitation, (c) Data minimisation, (d) Accuracy, (e) Storage limitation, (f) Integrity and confidence, (g) Accountability.

Processing of your personal data

Under the GDPR (General Data Protection Regulation) we control and / or process any personal information about you electronically using the following lawful bases.


  • Lawful basis: Contract
    Where our purpose for processing is: to fulfil order requirements  and to comply with legal and regulatory requirements. Personal data will  only be used for the purposes for which it is collected.
    Which is necessary because: to enable contact and complete payment  and shipping.
    We process your information in the following ways: To register you  as a customer; to process and deliver your order; to process payment. 
  • Data  retention period: Personal data is retained for as long as is  necessary to fulfil the contract and to satisfy any legal accounting/ reporting that is legally required. We will continue to process your  information under this basis until you withdraw consent or it is determined your consent no longer exists.
    Sharing your information: We do not share your information with  third parties other than the normal course of payment transactions.

  

If, as determined by us, the lawful basis upon which we process your personal information changes, we will notify you about the change and any new lawful basis to be used if required. We shall stop processing your personal information if the lawful basis used is no longer relevant.

Your individual rights

Under the GDPR your rights are as follows. You can read more about your rights at ICO.org.uk;

  • the right to be informed;
  • the right of access;
  • the right to  rectification;
  • the right to erasure;
  • the right to restrict  processing;
  • the right to data  portability;
  • the right to object; and
  • the right not to be  subject to automated decision-making including profiling.

You also have the right to complain to the ICO [www.ico.org.uk] if you feel there is a problem with the way we are handling your data.

We handle subject access requests in accordance with the GDPR.