Introduction
This Policy sets out the obligations of Collinge & Co Limited, a company registered in England and Wales under registration number 01275240, whose registered address is 127 Telegraph Road, Heswall CH60 0AF, United Kingdom (“the Company”) regarding data protection and the rights of salon clients, apprentices of Collinge & Co Training Limited, website customers, business contacts and employees (“data subjects”) in respect of their personal data under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”).
The UK GDPR defines “personal data” as any information relating to an identified or identifiable natural person (a “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
This Policy sets the Company’s obligations regarding the collection, processing, transfer, storage, and disposal of personal data. The procedures and principles set out herein must be followed at all times by the Company, its employees, agents, contractors, or other parties working on behalf of the Company.
The policy also sets out policies in respect of “company data”, that is any data that pertains to: the company’s performance; any sales data; company trade secrets; or Intellectual Property.
The Company is committed not only to the letter of the law, but also to the spirit of the law and places high importance on the correct, lawful, and fair handling of all personal data, respecting the legal rights, privacy, and trust of all individuals with whom it deals.
The Data Protection Principles
The Rights of Data Subjects
Lawful, Fair, and Transparent Data Processing
Specified, Explicit, and Legitimate Purposes
Adequate, Relevant, and Limited Data Processing
Accuracy of Data and Keeping Data Up-to-Date
Data Retention
Secure Processing
Accountability and Record-Keeping
Data Protection Impact Assessments
Keeping Data Subjects Informed
Data Subject Access
Rectification of Personal Data
Erasure of Personal Data
Restriction of Personal Data Processing
Data Portability
Objections to Personal Data Processing
Automated Decision-Making
Profiling