Santosa (also referred to as “we”, “us”, or “our”) is an independent ‘sole trader’ business trading from 21 Albert Street, Edinburgh EH7 5HL.
THE PURPOSE OF THIS NOTICE
This Notice is designed to help you understand what kind of information we collect in connection with our services and how we will process and use this information. In the course of providing you with services we will collect and process information that is commonly known as personal data.
This Notice describes how we collect, use, share, retain and safeguard personal data.
This Notice sets out your individual rights; we explain these later in the Notice but in summary these rights include your right to know what data is held about you, how this data is processed and how you can place restrictions on the use of your data.
WHAT IS PERSONAL DATA?
Personal data is information relating to an identified or identifiable natural person. Examples include an individual’s name, age, address, date of birth, gender and contact details.
Personal data may contain information which is known as special categories of personal data. This may be information relating to and not limited to, an individual’s health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, or data relating to sexual orientation.
Personal data may also contain data relating to criminal convictions and offences.
For the purposes of safeguarding and processing criminal conviction and offence data responsibly, this data is treated in the same manner as special categories of personal data, where we are legally required to comply with specific data processing requirements.
PERSONAL DATA WE COLLECT
We collect the following types of personal data:
- Personal data: your name, address, and contact details – if you have opted in to receive our marketing emails, purchased from our online store or have registered and/or booked online for a class or workshop at our studio.
We do not share your personal data with any other third party.
For the purposes of meeting the Data Protection Act 2018 territorial scope requirements, the United Kingdom is identified as the named territory where the processing of your personal data by us takes place.
If you require more information about how we collect personal data and with whom we share data with, please contact our Data Privacy Representative by e-mailing email@example.com.
We retain your contact details for a period of seven years. Please contact our Data Privacy Representative at firstname.lastname@example.org if you object to the use of, or you have any questions relating to the use of, your data or the retention of your personal data.
You can opt out of receiving marketing services by e-mailing email@example.com
Individuals are provided with legal rights governing the use of their personal data. These grant individuals the right to understand what personal data relating to them is held, for what purpose, how it is collected and used, with whom it is shared, where it is located, to object to its processing, to have the data corrected if inaccurate, to take copies of the data and to place restrictions on its processing. Individuals can also request the deletion of their personal data.
These rights are known as Individual Rights under the Data Protection Act 2018. The following list details these rights:
– The right to be informed about the personal data being processed;
– The right of access to your personal data;
– The right to object to the processing of your personal data;
– The right to restrict the processing of your personal data;
– The right to rectification of your personal data;
– The right to erasure of your personal data;
– The right to data portability (to receive an electronic copy of your personal data);
– Rights relating to automated decision making including profiling.
Individuals can exercise their Individual Rights at any time. As mandated by law we will not charge a fee to process these requests, however if your request is considered to be repetitive, wholly unfounded and/or excessive, we are entitled to charge a reasonable administration fee.
In exercising your Individual Rights, you should understand that in some situations we may be unable to fully meet your request, for example if you make a request for us to delete all your personal data, we may be required to retain some data for taxation, prevention of crime and for regulatory and other statutory purposes.
If you require further information on your Individual Rights or you wish to exercise your Individual Rights, please contact our Data Privacy Representative by e-mailing firstname.lastname@example.org or by writing to The Data Protection Representative at Santosa, 21 Albert Street, Edinburgh EH7 5HL.
PROTECTING YOUR DATA
We will take all appropriate technical and organisational steps to protect the confidentiality, integrity, availability and authenticity of your data, including when sharing your data within our organisation and authorised third parties.
DATA PROTECTION OFFICER
To ensure data privacy and protection has appropriate focus within our organisation we have a Data Protection Officer, Janis Binnie, who may be contacted at: email@example.com.
If you are dissatisfied with any aspect of the way in which we process your personal data please contact our Data Protection Officer. You also have the right to complain to the UK’s data protection supervisory authority, the Information Commissioner’s Office (ICO). The ICO may be contacted via its website which is https://ico.org.uk/concerns/, by live chat or by calling their helpline on 0303 123 1113.
HOW TO CONTACT US
If you have any questions regarding this Notice, the use of your data and your Individual Rights please contact our Data Protection Officer at the Santosa, 21 Albert Street, Edinburgh EH7 5HL or by e-mailing XX.
The Santosa is registered with the UK ICO registration number TBC.