In very basic terms Baby Whispers Photography totally respect your personal information and will only ask you for what information we really need from you. It is looked after it in the same way I would want ours looking after, keeping it secure! I will only share it with others where we need their help us deliver our service to you (such as our professional printing laboratory who may need your name and address to post your purchases). Be assured that we will never share your information in any other circumstances – nor will I sell it on elsewhere! Here are more details –
The Data we collect
As a data controller we collect a variety of data in order to deliver our services, and we will manage your personal data transparently, fairly and securely.
We may ask you to provide us the following data – First Name, Last Name, Email, Postal Address, Postcode, Telephone Number and Children’s Names. We will also record a date of birth for all persons we photograph under the age of 13 and require the parent or legal guardian to consent to photography.
You may also communicate to us data that includes any communication that you send to us through email, text, social media messaging, social media posting or any other communication that you send us.
Obviously being a photographic business we also create and manage images as per our contractual agreement(s).
We use the above data collected on our booking form or gallery checkout to deliver our service to you and for marketing purposes.
We collect this data on the following lawful basis: To arrange and fulfill your request and contract.
When you visit our website we also collect Cookies. These are small pieces of data that websites send to a user’s computer and are stored on the user’s web browser. They are designed to enable the website to remember information, such as what a user might have put in a shopping cart for example. This helps us to personalize your experience and deliver our service to you.
Which third parties do we share Personal Data with?
We share personal data with the following third parties:
Paypal – an online payment service provider. Payments are processed via so-called PayPal accounts, which represent virtual private or business accounts. PayPal is also able to process virtual payments through credit cards when a user does not have a PayPal account. A PayPal account is managed via an e-mail address, which is why there are no classic account numbers. PayPal makes it possible to trigger online payments to third parties or to receive payments. PayPal also accepts trustee functions and offers buyer protection services. The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg. If the data subject chooses “PayPal” as the payment option in the online shop during the ordering process, we automatically transmit the data of the data subject to PayPal. By selecting this payment option, the data subject agrees to the transfer of personal data required for payment processing. Paypal invoices are also created by Baby Whispers Photography to collect the clients booking fee in the first instance, also package payments and upgrades. The personal data transmitted to PayPal is usually first name, last name, address, email address, IP address, telephone number, mobile phone number, or other data necessary for payment processing. The processing of the purchase contract also requires such personal data, which are in connection with the respective order. The transmission of the data is aimed at payment processing and fraud prevention. The controller will transfer personal data to PayPal, in particular, if a legitimate interest in the transmission is given. The personal data exchanged between PayPal and the controller for the processing of the data will be transmitted by PayPal to economic credit agencies. This transmission is intended for identity and creditworthiness checks. PayPal will, if necessary, pass on personal data to affiliates and service providers or subcontractors to the extent that this is necessary to fulfil contractual obligations or for data to be processed in the order. The data subject has the possibility to revoke consent for the handling of personal data at any time from PayPal. A revocation shall not have any effect on personal data which must be processed, used or transmitted in accordance with (contractual) payment processing. The applicable data protection provisions of PayPal may be retrieved under https://www.paypal.com/us/webapps/mpp/ua/privacy-full.
Shootproof – is an online gallery provider, your images will be uploaded to a private password protected gallery for your personal viewing. Only those who have access to your link and dedicated passcode will be able to view. Your details such as Name, Address, and Phone number are also stored on Shootproof to allow the contract to be sent to you, the gallery to be linked with you and also for you to checkout your purchase through Shootproof. Shootproof is based outside of the European Economic Area to United States under the protection of the EU/US Privacy Shield.
Mailchimp – Data is saved on a password protected database to allow for mass promotional emails to be sent to my mailing list. Mailchimp is based outside of the European Economic Area to United States under the protection of the EU/US Privacy Shield.
Printing Labs and Album Suppliers – on rare occasions your products may need to be sent to you straight from the labs to your address. This would require your details to be passed to these labs. This is not standard practice as all products are currently first delivered to me to check over. However, there may be occasions when this is not possible, such as if the client has travelled some distance to me for their photoshoot, or if the time frame to delivery is tight. The data will not be transferred outside of the European Union.
There are also certain situations in which we may share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation.
Why do we share your Personal Data with the above?
We share your data in order to deliver our service to you, for marketing and to personalise your experience.
We may transfer personal data to a country outside of the European Economic Area (EEA) if necessary eg if a third party we utilise could have servers located outside of the EEA. If this is the case, we will either obtain your consent or otherwise ensure that the transfer is legal and your data is secure by following the EU’s guidelines. You can see above where we send data outside of the EEA and on what basis we do so.
How do we keep your personal data secure?
We keep your data secure by following internal policies such as all computers are password or fingerprint protected accessible by only one person. When information is submitted online to us Secure Socket Layer (SSL) technology is used.
In the unlikely event of a criminal breach of our security we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we will also inform you.
You have the following rights –
– the right to be informed about the collection and use of your personal data
– the right of access to your personal data and any supplementary information
– the right to have any errors in your personal data rectified
– the right to have your personal data erased
– the right to block or suppressing the processing of your personal data
– the right to move, copy or transfer your personal data from one IT environment to another
– the right to object to processing of your personal data in certain circumstances, and
– rights related to automated decision-making (i.e. where no humans are involved) and profiling (i.e. where certain personal data is processed to evaluate an individual). We also give you the option to manage your data by emailing firstname.lastname@example.org. While we do not hold personal data any longer than we need to. The duration will depend on your relationship with us, and whether it is ongoing. We may keep some of your personal data for 7 years after our working contract with you has finished for Tax Legislation purposes. After this time we will archive your photographs indefinitely along with your relevant details and consent forms. This is due to requests for replacement images being made several years after being taken.