Jonathan Flint Photography only obtains data from clients relevant to their wedding day and contact details surrounding the build up and delivery of the finished product. This is all acquired via data collation forms on my secure platform which is all regulated by the managing company. All information is voluntarily given by the client and submitted for my use. It never gets shared with any 3rd party company or organisation as the organisation of the day is a one off event and the clients details are stored on file for a period of 730 days - along with images and then they are safely archived into storage should the client recall for them again. Images captured of guests at a wedding is granted to pass the GDPR laws by the Bride and Groom opting in on their behalf and anyone who wishing to be removed under the law should make themselves know on the day.
1. The Data we collect
As a data controller we collect a variety of data in order to deliver our services, and we will manage your personal data transparently, fairly and securely.
We may ask you to provide us the following data –
ACTION: List Needed from Column 1 of your Data Mapping (egs First and Last Name / Address / Postcode, Telephone Number(s) / Email / IP Address etc..)
We will also record a date of birth for all persons we photograph under the age of 13 in a family style manner and require the parent or a legal guardian to consent to photography.
Obviously being a photographic business we also create and manage images as per our contractual agreement(s).
We use the above data to ACTION: List Needed from Column 2 of your Data Mapping which meet the GDPR legal requirements (egs To deliver our service to you / For marketing purposes / Personalise your experience / To provide account access etc..)
We collect this data on the following lawful basis ACTION: List Needed eg Consent / To arrange or fulfil a Contract / To meet a legal obligation other than a Contract)
2. Which third parties do we share Personal Data with?
We share personal data with the following third parties:
NONE. All of your data is personal to your event and will not be shared with anybody.
There are also certain situations in which we may share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule or regulation.
3. How do we keep your personal data secure?
We keep your data secure using a secondary system which ids following the same GDPR rules which we have been obliged to adhere to. They are safe and secure with a password protected entry system.
ACTION: List Needed (egs By following internal policies of best practice and training for staff, Encryption, By using Secure Socket Layer (SSL) technology when information is submitted to us online, The latter is when you have a https website. Also consider adding your image Back-Up service provider(s)
In the unlikely event of a criminal breach of our security we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we will also inform you.
5. You have the following rights -
- - the right to be informed about the collection and use of your personal data
- - the right of access to your personal data and any supplementary information
- - the right to have any errors in your personal data rectified
- - the right to have your personal data erased
- - the right to block or suppressing the processing of your personal data
- - the right to move, copy or transfer your personal data from one IT environment to
- - the right to object to processing of your personal data in certain circumstances, and
- - rights related to automated decision-making (i.e. where no humans are involved) and
profiling (i.e. where certain personal data is processed to evaluate an individual).
We also give you the option to manage your data via:
ACTION: List Needed (eg: Email, Telephone, Writing to us)
While we do not hold personal data any longer than we need to. The duration will depend on your relationship with us, and whether it is ongoing. We may keep some of your personal data for ACTION: Timescale and list needed. See Columns 7 and 8 of your Data Mapping (eg up to 7 years after our working contract with you has finished for Tax legislation purposes You could extend this if you intend to archive images indefinitely by adding After this time we will archive your photographs indefinitely along with your relevant details and consent forms. This is due to requests for replacement images being made several years after being taken.