There are rules and regulations that govern how companies use and retain your information, as a sole trader I am not exempt from those rules and have to have something written on my website telling you all about them....
Life is too short! So if you are interested in knowing everything about everything feel free to visit the Information Compliance Officer via the link who can explain far better than I can about this whole data retention thing. ICO.
I can tell you this though with some clarity and understanding!
This privacy notice provides you with details of how I collect and process your personal data through your use of my site www.lynnherbertceremonies.co.uk
By visiting my website and providing me with your data you are agreeing that you are over 13 years of age.
I, Lynn Herbert, am a Sole Trader, and as such that makes me the Data Controller. I am responsible for your personal data (referred to as “me”, “I” or “mine” in this privacy notice).
I also have to give you my contact details so here goes:
Full name of legal entity: Lynn Herbert Ceremonies
Email address: email@example.com
Postal address: 4 Widford Road, Hunsdon, Herts SG12 8NW
Please help me to keep up to date with the information I hold on you by emailing me any personal information changes (such as new address) to
2. What information (data) is being collected?
‘Personal data means any information capable of identifying an individual. It does not include anonymised data’
So if you are just passing through and browsing my site, other than the cookie data, not a lot.
However if you are more than passing through, here’s the key info.
Communication Data that includes any communication that you send to me whether that be through the contact form on my website, through email, text, social media messaging, social media posting or any other communication that you send me.
I process this data for the purposes of communicating with you, for record keeping and for the establishment, pursuance or defence of legal claims.
My lawful ground for this processing is my legitimate interests which in this case is to reply to communications sent to me, to keep records and to establish a pursue of a legal contract or defend legal claims.
Customer Data that includes data relating to the contract of my services
for your ceremony, such as your name, title, address, email address, phone number, contact details and ceremony details. I process this data to supply the services you have contracted me for and to keep records of such transactions. My lawful ground for this processing is the performance of a contract between us and and/or taking steps at your request to enter into such a contract.
User Data that includes data about how you use my website and any online services together with any data that you post for publication on my social media or other online services. I process this data to operate my website and ensure relevant content is provided to you, to ensure the security of our website, to maintain back- ups of our website and/or databases and to enable publication and administration of my website, other online services and business. My lawful ground for this processing is my legitimate interests which in this case is to enable me to properly administer my website and my business.
Technical Data that includes data about your use of my website and online services such as your IP address, your login data, details about your browser, length of visit to pages on my website, page views and navigation paths, details about the number of times you use my website, time zone settings and other technology on the devices you use to access our website. The source of this data is from my analytics tracking system. (At present – May 2018 – I do not track and analyse technical data but if I do in the future I will update this notice)
I process this data to analyse your use of our website and other online services, to administer and protect our business and website, to deliver relevant website content. My lawful ground for this processing is my legitimate interests which in this case is to enable me to properly administer my website and my business and to grow my business and to decide my marketing strategy.
I DO NOT send personal marketing messages via email or any other platform.
Given the nature of my role I may well be requesting some sensitive data about you.
The information you provide will allow me to write your ceremony in an inclusive way.
Sensitive data refers to data that includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, and information about your health/ disabilities
However I will not be seeking any sensitive information such as your genetic and biometric data. I do not intend to collect any information about criminal convictions or offences unless they are totally relevant to the ‘script under development”.
Where I am required to collect personal data by law, or under the terms of the contract between us and you do not provide me with that data when requested, I may not be able to perform the contract (for example, to deliver services to you). If you don’t provide me with the requested data, I may have to cancel a service you have contracted me for but if I do, I will notify you at the time.
I will only use your personal data for a purpose it was collected for.
I may process your personal data without your knowledge or consent where this is required or permitted by law.
3. How do I collect your data?
When someone visits my website a third party service is used to collect standard Internet log information and details of visitor behaviour patterns. (Google Analytics based outside of the EU). Currently (May 2018) I have no idea how to use or interpret their findings and it is highly unlikely that I ever will. If this situation should change I will update this privacy notice.
4. What data am I after?
Contact information for you if you have expressed an interest in my product via my webform submission, phone call, text, email, Google, Facebook or Instagram.
5. How is it collected?
Via my website, phone, text or email. I then email or call you back.
If we start to work together I will retain your information my computer. This is password protected and only I have access to it – it is not a ‘shared’ computer. This information is also stored on a hard drive so that I have a back up if required. I create a folder in my email account for ease of communication.
6. Why is it being collected?
I need to retain some of your data and contact information to enable me to work with you and to create your ceremony.
7. How will it be used?
8. Who will it be shared with?
I will not share your data with anyone without your explicit permission. There may be the need during the organisation of your ceremony to liaise with other professionals, this could be your Funeral Director, a venue, photographer or another participating service. I will always ask you first.
However, there might be a few occasions where I do need to share your personal data with the following:
Professional advisers including lawyers, bankers, auditors and insurers, in the event of any complaint or claim either against me by you. Or against you in a claim instigated by me.
Government bodies that require us to report processing activities.
Third parties to whom I transfer or merge parts of my business (in the event I am unable to fulfil my contact due to illness or other unforeseen complication)
I require all third parties to whom I transfer your data to respect the security of your personal data and to treat it in accordance with the law. I only allow such third parties to process your personal data for specified purposes and in accordance with my instructions.
9. What will be the effect of this on the individual concerned?
Having access to your contact details and personal data will ensure a free flow of information and a means of communication to facilitate your ceremony.
10 . Is the intended use likely to cause individuals to object or complain?
If you are concerned, have an objection or a complaint with regard to how I will collect, store and use your personal data – please speak to me in the first instance and hopefully we can find a mutually agreeable solution to enable collaborative working.
My site obviously does use them, and you should have ticked a cookie generation button when you logged into it
You can set your browser to refuse all or some of them, but please be aware the site might not work as well if you refuse or disable them.
12. Social Media
If you send me a private or direct message via any of the social media platforms, I will store the message for three months. It will not be shared with any other organisations. I do not receive personal data via any social media platforms
13. Third Party Links
I do not current have links on my website to any third party suppliers. If I decide to in the future I will update this privacy notice accordingly.
14. Data Security
I have put in place security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed without authorisation. I am a sole- trader and there is no need for me to share your data with any third party other than those persons outlined above.
They will only process your personal data on my instructions and they must keep it confidential.
I have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach if I am legally required to.
15. Data Retention
I will only retain your personal data for as long as necessary to fulfil the purposes I collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
When deciding what the correct time is to keep the data for I look at its amount, nature and sensitivity, potential risk of harm from unauthorised use or disclosure, the processing purposes, if these can be achieved by other means and legal requirements.
For tax purposes the law requires me to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they stop being customers.
In some circumstances I may anonymise your personal data for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
16. How can YOU access your data, to change or delete it?
Your legal rights…
Under data protection laws you have rights in relation to your personal data that include the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent.
You can see more about these rights at:
If you wish to exercise any of the rights set out above, please email me at www. firstname.lastname@example.org
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, I may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive or refuse to comply with your request in these circumstances.
I may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. I may also contact you to ask you for further information in relation to your request to speed up my response.
I try to respond to all legitimate requests within one month. Occasionally it may take me longer than a month if your request is particularly complex or you have made a number of requests. In this case, I will notify you.
If you are not happy with any aspect of how I collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). I would be grateful if you would contact me first if you do have a complaint so that we can try to resolve it for you.
In reality as a sole trader there are not many places I can physically hold your data in reality…my laptop, phone, tablet all tied and held together by the cloud...that’s it.
You DO have the right at any time during our working relationship to ask that I delete the information I hold on you.
Short of standing over my shoulder watching me do so, the only way I CAN reassure you that your records have been deleted is sending you my spread sheet showing date of deletion along with what records have been deleted if you so wish. (I hope that makes sense!)
You'll see affirmations doted throughout my website, these are kind words from couples and families who have used my services. If you too are kind enough to write to me or fill in my feedback sheet I will be seeking YOUR permission to plaster your comments all over my social media and website too, because it's nice to be liked and I like to spread the love!