Privacy Policy

Privacy Policy

Last updated: February 26, 2021

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy. 

Portraits In The Park, 1 Shaftesbury Avenue, Leeds, LS8 1DR, is a company incorporated in England and Wales with a registered number 9487741.

Portraits In The Park is committed to upholding and protecting the privacy of its customers, staff, co-workers, and suppliers.

As required by the UK Data Protection Act of 1998, we follow strict guidelines to protect data and prevent unauthorized access to data. Our company policy is outlines below.

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access our Service or parts of our Service.

  • Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Agreement) refers to Portraits In The Park, 1 Shaftesbury Avenue.

  • Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.

  • Country refers to: United Kingdom

  • Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.

  • Personal Data is any information that relates to an identified or identifiable individual.

  • Service refers to the Website.

  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.

  • Third-party Social Media Service refers to any website or any social network website through which a User can log in or create an account to use the Service.

  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

  • Website refers to Portraits In The Park, accessible from www.portraitsinthepark.co.uk

  • You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address

  • First name and last name

  • Phone number

  • Address, State, Province, ZIP/Postal code, City

  • Usage Data

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.

Information from Third-Party Social Media Services

The Company allows You to create an account and log in to use the Service through the following Third-party Social Media Services:

  • Google
  • Facebook
  • Twitter

If You decide to register through or otherwise grant us access to a Third-Party Social Media Service, We may collect Personal data that is already associated with Your Third-Party Social Media Service’s account, such as Your name, Your email address, Your activities or Your contact list associated with that account.

You may also have the option of sharing additional information with the Company through Your Third-Party Social Media Service’s account. If You choose to provide such information and Personal Data, during registration or otherwise, You are giving the Company permission to use, share, and store it in a manner consistent with this Privacy Policy.

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:

  • Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service. Unless you have adjusted Your browser setting so that it will refuse Cookies, our Service may use Cookies.
  • Flash Cookies. Certain features of our Service may use local stored objects (or Flash Cookies) to collect and store information about Your preferences or Your activity on our Service. Flash Cookies are not managed by the same browser settings as those used for Browser Cookies. For more information on how You can delete Flash Cookies, please read “Where can I change the settings for disabling, or deleting local shared objects?” available at https://helpx.adobe.com/flash-player/kb/disable-local-shared-objects-flash.html#main_Where_can_I_change_the_settings_for_disabling__or_deleting_local_shared_objects_
  • Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).

Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser. Learn more about cookies: Cookies: What Do They Do?.

We use both Session and Persistent Cookies for the purposes set out below:

  • Necessary / Essential Cookies

    Type: Session Cookies

    Administered by: Us

    Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.

  • Cookies Policy / Notice Acceptance Cookies

    Type: Persistent Cookies

    Administered by: Us

    Purpose: These Cookies identify if users have accepted the use of cookies on the Website.

  • Functionality Cookies

    Type: Persistent Cookies

    Administered by: Us

    Purpose: These Cookies allow us to remember choices You make when You use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter your preferences every time You use the Website.

For more information about the cookies we use and your choices regarding cookies, please visit our Cookies Policy or the Cookies section of our Privacy Policy.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain our Service, including to monitor the usage of our Service.

  • To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.

  • For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.

  • To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application’s push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.

  • To provide You with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information.

  • To manage Your requests: To attend and manage Your requests to Us.

  • For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.

  • For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and your experience.

We may share Your personal information in the following situations:

  • With Service Providers: We may share Your personal information with Service Providers to monitor and analyze the use of our Service, to contact You.
  • For business transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
  • With Affiliates: We may share Your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.
  • With business partners: We may share Your information with Our business partners to offer You certain products, services or promotions.
  • With other users: when You share personal information or otherwise interact in the public areas with other users, such information may be viewed by all users and may be publicly distributed outside. If You interact with other users or register through a Third-Party Social Media Service, Your contacts on the Third-Party Social Media Service may see Your name, profile, pictures and description of Your activity. Similarly, other users will be able to view descriptions of Your activity, communicate with You and view Your profile.
  • With Your consent: We may disclose Your personal information for any other purpose with Your consent.

Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Company’s operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.

Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.

The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.

Business Transactions

If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other legal requirements

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of Users of the Service or the public
  • Protect against legal liability

Security of Your Personal Data

The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.

Children’s Privacy

We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.

If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent’s consent before We collect and use that information.

Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.

We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the “Last updated” date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, You can contact us:

General Data Protection Regulation

 
Introduction

GDPR – General Data Protection regulations which came into force on 25 May 2018 in the EU and applies to all businesses doing business in or with a person in the EU. 

The GDPR includes the following rights for individuals and you will find information on how the software platform is compliant with these rights below:   

  • the right to be informed;  
  • the right of access;  
  • the right to rectification;  
  • the right to erasure;  
  • the right to restrict processing;  
  • the right to data portability;  
  • the right to object; 
  • and the right not to be subject to automated decision-making including profiling:


The right to be informed
 
Individuals have the right to be informed about the collection and use of their personal data. This is a key transparency requirement under the GDPR.
 
In our privacy policy we inform about the purposes for processing personal data, the retention periods for that personal data, and who it will be shared with. 

Our privacy policy is always visual in the web-shop both as short link in the footer and also as a pop-up together with the cookie warning.
 

The Right of Access
 
Individuals have the right to access their personal data and supplementary information.
The right of access allows individuals to be aware of and verify the lawfulness of the processing.
 
In the users “my account” section in the web-shop, the user can easily download a .zip file containing a full copy of all data we hold on them.


The Right to Rectification 
 
Under Article 16 of the GDPR individuals have the right to have inaccurate personal data rectified. An individual may also be able to have incomplete personal data completed.

The Right to Erasure/Be Forgotten
 
Under Article 17 of the GDPR individuals have the right to have personal data erased. This is also known as the ‘right to be forgotten’. 
 
The user will at any time get access to the “delete me” feature in the “my account” section in the web-shop. If they press this button, their user account will be “frozen” and inactivated. If they regret, they can reactivate their account within 30 days. After 30 days the user account and all data stored on their account will be erased. 


The Right to Restrict Processing  
 
Article 18 of the GDPR gives individuals the right to restrict the processing of their personal data in certain circumstances. This means that an individual can limit the way that an organization uses their data. This is an alternative to requesting the erasure of their data.
 
In the users “my account” they can select to stop all reminders on both desktop and mobile.


The Right to Data Portability  
 
The right to data portability gives individuals the right to receive personal data they have provided to a controller in a structured, commonly used and machine-readable format. It also gives them the right to request that a controller transmits this data directly to another controller.
 
The content in the .zip file downloaded with data stored can be sent to the third party. But since we have the copyright to the pictures, we are not committed to transfer these to a new controller.


The Right to Object 
 
Individuals have the right to object to processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling); direct marketing (including profiling); and processing for purposes of scientific/historical research and statistics. 

The user needs to actively opt-in to receive communication related to pure marketing of services when they create an account. In the users “my account” they can select to stop all reminders and prevent us from contacting them with sales related communication. Communication related to gallery access, including reminders is not considered as marketing.
 

Cookie Warning
 
We will display a warning in the webpage footer regarding the use of cookies, where the user needs to accept before continuing to register an account. Users can at any time read more about how the cookies are used on a dedicated system webpage with a direct link in the web-shop footer. 


GDPR

Portraits In The Park needs to collect certain information about individuals. This can include employees, customers, business contacts, school staff and student data, in fact, anyone dealing with Portraits In The Park for the day to day running of our business in providing a product or service to you.

This policy describes how we collect, store, and protect personal data. By adhering to and complying with the general Data Protection Regulation, Portraits In The Park protects the data held and follows good working practice. 

We protect the rights of staff, customers, parents and students, we are open and transparent about how we collect, store, and protect your data. We also protect ourselves against data breach.

 
General Data Protection Regulation

The General Data Protection Regulation takes effect on May 25th 2018 and organisations like ours must be compliant. Your data is safe with us. We safeguard it and we do not misuse it. These rules apply no matter how and what data is stored irrespective of how long it is stored. To comply with the law, information must be collected, stored, and used fairly and safely and must not be disclosed unlawfully.

Data should be collected for a specified legitimate purpose and limited to a use which is compatible with the purpose for which it is collected. Data must be accurate and where possible kept up to date. Where data is not accurate or up to date or is no longer needed for the purpose it was collected, it must be rectified or deleted securely.

Data must be protected from unauthorised access, loss, or unlawful processing.

 
Risks and Responsibilities

This policy applies to the staff, contractors, suppliers, and any person working with or on behalf of Portraits In The Park. This policy applies to all the data collected or held for Portraits In The Park for the purpose of running the business and supplying products and services.

This can include names, addresses, telephone numbers, barcodes, images, and encrypted data supplied to and by Portraits In The Park (this list is not exhaustive). This policy helps to protect Portraits In The Park from data security risks, such as hackers, malicious software, individual data access from non-authorised personnel (this list is not exhaustive).

It is the responsibility of all staff, suppliers, contractors and working partners to inform Portraits In The Park of any breach of the contents of this policy. It is the responsibility of the Director to review this policy in line with an agreed schedule and arrange any data protection training. It is the responsibility of the office manager to inform the Director of any questions from customers relating to this policy.

 
General Guidelines for Data Users and Staff

Only authorized access to those who need to use data in the course of doing their work.

Data should not be shared informally other than for the purpose which it is collected and saved.

Portraits In The Park will supply any required training for data use, protection and storage and a record of the training will be held.

Employees and contractors should keep data secure and take all reasonable precautions to protect data. This includes the use of passwords on all computers, servers, and network devices. Passwords should only be shared with staff if it is a requirement of carrying out their contracted duties.

Data should be regularly reviewed and updated and if it is found to be out of date or not accurate, it should be deleted when it has no further use for the purpose it was gathered.

Staff should request guidance from the Director if they are unsure or unclear about any of this Data Policy.


Storage of Data

Portraits In The Park may collect and use data for the day to day running of the business. This may be collected on paper or electronically. Electronic data may have to be printed out.

All paper date must be stored safely and locked away when not in use or out of business hours. Once papers copies are no longer required these should be returned to the customer or securely destroyed. This is done by crosscut secure shredding or incineration.

When data is stored electronically this should be encrypted, anonymised or password protected. Passwords should not be shared amongst unauthorised personnel and should only be shared if it is a requirement of the production process.

If data is stored on removable media, it should be kept in a locked cabinet when not in use. Data should only be stored on designated devices supplied by Portraits In The Park.

Data is backed up regularly and these are also securely deleted once they are no longer required.

All servers and computers are protected by security and firewall.

All pupil information supplied by schools for linking images to the school database should be provided by the school as a password protected file. This is encrypted once received by Portraits In The Park. This information can only be accessed by staff authorised to do so in order to carry out their contracted duties.

 
Supplier Agreement and Access to Data

The suppliers of Portraits In The Park’s digital workflow software solution may from time to time have to carry out system integration, upgrades, and maintenance. This may be done remotely via a point to point secure connection.  This supplier has entered into a non-data sharing agreement with Portraits In The Park and only nominated employees have access privileges. Portraits In The Park has also entered into a no-share agreement with the supplier for additional security. This agreement is updated and reviewed annually.
 
 
Office Administration Staff

Portraits In The Park office administration staff, including production staff have limited authorised access to data and will only be able to access data in order to carry out their contracted duties. Authorised staff have access to passwords for their workstation on a local basis and are not privy to other passwords used on our internal network.

A firewall is in place to protect the internal network from external unauthorised access. Data held on our internal server is password protected and only the Director and Senior Production Manager have additional clearance to passwords. No single staff member will have access to all the passwords.


Our Photographers

Portraits In The Park photographers are enhanced DBS checked and carry photo I.D. with them when working alongside children and young adults in schools, nurseries, and clubs.

Portraits In The Park photographers also wear clothing branded with the company logo whilst working.

Portraits In The Park have a code of conduct which our photographers must adhere to at all times.

Portraits In The Park photographers will also adhere to your setting phone policy whilst working with you.