GDPR Compliance Statement
The EU General Data Protection Regulation (“GDPR”) comes into force across the European Union on 25th May 2018 and brings with it the most significant changes to data protection law in two decades. Based on privacy by design and taking a risk-based approach, the GDPR has been designed to meet the requirements of the digital age.
The 21st Century brings with it broader use of technology, new definitions of what constitutes personal data, and a vast increase in cross-border processing. The new Regulation aims to standardise data protection laws and processing across the EU; affording individuals stronger, more consistent right.
Types of information collected:
We retain two types of information:
This is data that identifies you or can be used to identify or contact you and may include your name, address, email address, user IP addresses in circumstances where they have not been deleted, clipped or anonymised, telephone number, birth date and billing and credit card information. Such information is only collected from you if you voluntarily submit it to us.
Like most websites, we gather statistical and other analytical information collected on an aggregate basis of all visitors to our website. This Non-Personal Data comprises information that cannot be used to identify or contact you, such as demographic information regarding, for example, user IP addresses where they have been clipped or anonymised, browser types and other anonymous statistical data involving the use of our website.
Purposes for which we hold your Information
We will process any Personal Data you provide to us for the following purposes:
(a) to provide you with the goods or services you have ordered;
(b) to contact you if required in connection with your order or to respond to any communications you might send to us.
We use the Non-Personal Data gathered from visitors to our website in an aggregate form to get a better understanding of where our visitors come from and to help us better design and organise our website.
Disclosure of Information to Third Parties
We may provide Non-Personal Data to third parties, where such information is combined with similar information of other users of our website. For example, we might inform third parties regarding the number of unique users who visit our website, the demographic breakdown of our community users of our website, or the activities that visitors to our website engage in while on our website. We will not disclose your Personal Data to third parties unless you have consented to this disclosure. We will disclose your Personal Data if we believe in good faith that we are required to disclose it in order to comply with any applicable law, a summons, a search warrant, a court or regulatory order, or other statutory requirement.
Sale of Business
Your Personal Data is held on secure servers hosted by Blacknight Solutions (our Internet Service Provider). The nature of the Internet is such that we cannot guarantee or warrant the security of any information you transmit to us via the Internet. No data transmission over the Internet can be guaranteed to be 100% secure. However, we will take all reasonable steps (including appropriate technical and organisational measures) to protect your Personal Data.
Updating, Verifying and Deleting Personal Data
We have already stated what personal data we hold, why and how we use it. However, if you wish to have your details removed, please contact firstname.lastname@example.org.
We at Blueberry Design are committed to ensuring the ongoing security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have always had a robust and effective data protection program in place which complies with existing law and abides by the data protection principles. However, we recognise our obligations in updating and expanding this program to meet the demands of the GDPR and the Data Protection Act 1988 in conjunction with the Data Protection Amendment Act 2003.
Blueberry Design takes the privacy and security of individuals and their personal information very seriously and take every reasonable measure and precaution to protect and secure the personal data that we process. We have robust information security policies and procedures in place to protect personal information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures, including: very restricted access to database with password protection and SSL. Please find summarised in the statement below our measures and procedures, including the development and implementation of new data protection roles, policies, procedures, controls and measures to ensure maximum and ongoing compliance.
Blueberry Design are committed to training Staff in compliant data collection, correlation and disposal.
Policies & Procedures – implementing new data protection policies and procedures to meet the requirements and standards of the GDPR and any relevant data protection laws, including:
Data Subject Rights
In addition to the policies and procedures mentioned above that ensure individuals can enforce their data protection rights, we provide easy to access information via our website, in the office, during induction of an individual’s right to access any personal information that Blueberry Design processes about them and to request information about:
GDPR Roles and Employees
Blueberry Design have designated Alan Martin as its Data Protection Officer to develop and implement our road map for complying with the new data protection regulation. He shall be responsible for promoting awareness of the GDPR across the organisation, assessing our GDPR compliance, identifying any gap areas and implementing the new policies, procedures and measures.
Blueberry Design understands that continuous employee awareness and understanding is vital to the continued compliance of the GDPR and have involved our employees in our preparation plans. We have implemented an employee training program which will be provided to all employees prior to May 25th 2018, and forms part of our induction and annual training program.
If you have any questions, please contact: