Privacy Policy / GDPR


Sam Rundle Photography Privacy Policy

Introduction

Sam Rundle Photography takes your privacy very seriously. This privacy policy has been prepared in line with the EU’s General Data Protection Regulation (GDPR), which promotes fairness and transparency for all individuals in respect of their personal data. This privacy policy applies to all data we process and by using Sam Rundle Photography, you consent to our collection and use of such data. If you would like to get in touch about anything in this policy or about your personal data, then please contact Sam Rundle at info@samrundlephotography.com 

The Data We Collect

As a data controller, we collect a variety of data in order to deliver our services and we will manage your personal data transparently, fairly, and securely.

We may ask you to provide us the following data:

  • First and last names, contact numbers, email, and postal addresses

Obviously, being a photographic business, we also create and manage images as per our contractual agreement(s).

We use the above data to deliver our service to you.

We collect this data on the following lawful basis: to arrange or fulfil a Contract.

Which Third Parties Do We Share Personal Data With?

We share personal data with the following third parties:

PIXIESET – https://pixieset.com/ 


We will use images to process orders for prints and products using external printing labs and album manufacturers; none of these have access to personal information.

Data is transferred outside of the European Economic Area to the United States under the protection of the EU/US Privacy Shield.

There are also certain situations in which we may share access to your personal data without your explicit consent; for example, if required by law, to protect the life of an individual, or to comply with any valid legal process, government request, rule, or regulation.

Why Do We Share Your Personal Data With the Above?

We share your data in order to deliver our service to you and for marketing purposes.

We may transfer personal data to a country outside of the European Economic Area (EEA) if necessary, e.g., if a third party we utilize has servers located outside of the EEA. If this is the case, we will either obtain your consent or otherwise ensure that the transfer is legal and your data is secure by following the EU’s guidelines. You can see above where we send data outside of the EEA and on what basis we do so.

How Do We Keep Your Personal Data Secure?

We keep your data secure and only accessible by trained members of our team.

In the unlikely event of a criminal breach of our security, we will inform the relevant regulatory body within 72 hours and, if your personal data were involved in the breach, we will also inform you.

Changes to Our Privacy Policy and Control

We may change this privacy policy from time to time. When we do, we will let you know by changing the date on this policy and notifying customers of significant changes. By continuing to access or use our services after those changes become effective, you agree to be bound by the revised privacy policy.

You Have the Following Rights:

  • The right to be informed about the collection and use of your personal data
  • The right of access to your personal data and any supplementary information
  • The right to have any errors in your personal data rectified
  • The right to have your personal data erased
  • The right to block or suppress the processing of your personal data
  • The right to move, copy, or transfer your personal data from one IT environment to another
  • The right to object to the processing of your personal data in certain circumstances
  • Rights related to automated decision-making (i.e., where no humans are involved) and profiling (i.e., where certain personal data is processed to evaluate an individual)

We also give you the option to manage your data via email or post.

While we do not hold personal data any longer than we need to, the duration will depend on your relationship with us and whether it is ongoing. We may keep some of your personal data for up to 7 years and images for one year from the wedding date.