PRIVACY AND COOKIES POLICY
This policy was last updated: May 14th 2018
Use of this website constitutes your legal agreement to the terms contained within this Policy. If you do not accept these terms, you are advised not to use the website.
Incandescence provides a professional DJ service for weddings and special occasions. Usually in the Oxford area. We can be contacted by phone on 01865 989588 or 07774 205608, by email to firstname.lastname@example.org or by post at 46 Hendred Street, Cowley, Oxford OX4 2ED.
Where we manage personal data, we identify as a Data Controller and recognise and act on our obligations under applicable data protection laws. For any issues relating to data protection please contact Dave Buckett.
This policy explains how Incandescence will handle the privacy of your information. We are committed to maintaining robust privacy protections for all our users. We will take the necessary steps to ensure that users personal information is safeguarded and kept in accordance with the law and any applicable regulations.
What data do we collect?
Information that you provide to us is retained and processed in accordance with UK legislation.
Information you provide to us
Contact: We have a Contact Form on this website and this is used to collect your name, email and phone number as well as your message, so that we can contact you and provide details of our services to you, make bookings, confirm bookings and deal with general company enquiries. Data is held on the grounds of being legitimate to our business interests.
Phone calls: Phone calls to the local (01865) number are handled by a third-party company and subject to their own privacy & data policies. They are instructed to take a name and telephone number along with any message. These calls may be recorded and any data relating to the call may be retained by us. The data will be held on the basis of it being for our legitimate business needs or in order to fulfil our contractual obligations if you are a client of ours.
Social media: We use social media to engage with users and the Incandescence website links to our Facebook, Twitter and LinkedIn pages. We do not keep any specific data that identifies you as an individual user, but hold details of our followers on these platforms. You should refer to the Privacy Policies of these channels to understand how they treat your data in relation to linking to our site.
Testimonials: We may ask you for a testimonial in relation to our services, and you will be contacted by email after an event for suitable comments that may be used on our website or social media. We provide links to 3rd party social media pages and any comments made will be copied in full and added to the Incandescence testimonial page on www.incawed.co.uk. Your full name may be used, where this is supplied to the 3rd party. The websites used are:
Guides for Brides (a web directory of wedding suppliers) – https://www.guidesforbrides.co.uk/find/wedding-discos/oxfordshire/incandescence/48326
Facebook (Directly to business page) – https://www.facebook.com/incawed/
Google+ (Directly to business page) – https://plus.google.com/b/116919660996378743126/
You have the right to request that this information is not used by us or that it is rectified or amended in accordance with your rights as a data subject. You should also refer to the privacy policies on these sites.
Incandescence accepts payment by bank transfer, cheque or cash. On request, we can also provide an invoice for payment through PayPal. Incandescence do not receive personal bank details or hold identifying information on an individual’s banking transactions. Bank details may only be requested from clients in order to process any refunds.
Payment information is stored on QuickBooks Pro and uses cloud-based storage. The details held include the customer contact information, invoice details (or estimate) and payment records. By law, this Information has to be kept for a minimum of 6 years for tax accountancy purposes.
We do not market this website at those under 18 years old. Consistent with the GDPR we will never knowingly request personally identifiable information from anyone under the age of 16 years old.
Information we get from other sources
From time to time, we may need to obtain information from third parties about you. This will only apply where it is necessary to provide our services and as permitted by law.
How we use your personal information
Your information will be used by us to enable us to provide our services to you. We act as a Data Controller (see below) of your information and undertake to protect your personal and sensitive data in a manner that is consistent with the requirements of the General Data Protection Regulation (GDPR). We will take reasonable measures to ensure the secure storage of your data.
- administer the website;
- improve your browsing experience by personalising the website;
- follow up with email enquires;
- send you general (non-marketing) communications;
- send you email notifications which you have specifically requested;
- send to you marketing communications, where expressly agreed;
- provide third parties with statistical information about our users – but this information will not be used to identify any individual user;
- ask for feedback and reviews;
- photographs representative of our services for promotional purposes [Note: Photographs of crowds are not classified as personal data, providing no Individual person is the focus of the photograph];
- deal with enquiries and complaints made by or about you relating to the website.
Users of this website do so at their own discretion and provide any such personal details at their own risk.
We may disclose your personal information if we are required to do so by law, in connection with any legal proceedings, and in order to establish, exercise or defend our legal rights, or if otherwise legally permitted.
We may use Data Processors who act on our instruction in relation to the management of your data and they must adhere to all data protection laws and regulations. We will ensure that any Data Processors used only operate on our written instructions and comply with their obligations under the GDPR.
You will be informed of any other Data Controllers who have access to your data and who may determine processing activities separately to us, or as a Joint Data Controller.
We will only send you emails about our services, i.e. direct marketing, with your express consent. You have the option not to give consent and to withdraw consent at any time. You may withdraw your consent for us to contact you by contacting us at email@example.com.
Non-personally identifiable visitor information may be provided to third parties for marketing, advertising or other uses.
Incandescence cannot guarantee or verify the contents of any externally linked website and users click on external links at their own risk. Incandescence and its owners cannot be held liable for any damages or implications caused by visiting any external links mentioned.
Social media platforms
Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are subject to our terms and conditions as well as the privacy policies held with each social media platform respectively.
Users are advised to use social media platforms wisely and communicate and/or engage with them with due care and caution in regard to their own privacy and personal details. This website nor its owners will not ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.
Incandescence uses social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised that before using such social sharing buttons, that they do so at their own discretion, and should consider that the social media platform may track and save requests to share a web page, through the users’ social media platform account.
Retaining your data
We keep your personal information in accordance with our Data Retention Policy which reflects our needs to provide services to you as contracted and also as required to meet legal, statutory and regulatory obligations. The need to hold information is regularly reviewed and information/data will be disposed of when no longer required.
Our website is hosted by hosting.co.uk. Any information that you supply to us may be stored and processed by our servers located in the US. Your data maybe transferred in accordance with the relevant data protection laws.
Data Subject Rights
Subject Access Requests
The General Data Protection Regulation (GDPR) gives individuals, known as ‘data subjects’, the right to access personal data that is held by organisations by a subject access request (SAR). We will endeavour to respond quickly to any such requests, which legally require us to respond within one month of receiving the request and necessary information. To make a SAR request email us at firstname.lastname@example.org
Right to Rectification
Data subjects have the right to request that we amend or change personal information that we hold about you, that is inaccurate or incorrect.
Right to erasure
Data subjects have the right to ask us to delete personal information from our systems without giving any reason and at any time. We will act on any request without delay.
Right to restrict processing
Data subjects have the right to rectification or erasure of personal data in the following circumstances:
- Personal data is not accurate;
- The processing of data is unlawful – data subjects may request that processing is restricted;
- Data is required to exercise legal rights or defend legal claims;
- Data is unlawful but there may be lawful grounds for processing, which override this right.
Right to data portability
Data subjects have the right to obtain and transfer their data to different service providers.
Right to object
Data subjects have the right to object to the processing of data at any time based on their particular situation. This includes objecting to profiling unless it is in the ‘public interest’ or exercised lawfully by an official authority. We will only process data under lawful grounds.
Right not to be subject to decisions based on automated processing
We do not use any automated processing that results in any automated decision based on a data subject’s personal information.
Using your rights
If you wish to invoke any of these rights, you can email us at email@example.com
We will report any unlawful breach of data as required by the GDPR within 72 hours of the breach occurring, if it is considered that there is an actual, or possibility, that data within our control including the control of our data processors, has been compromised. If the breach is classified as ‘high risk’ we will notify all data subjects concerned using an appropriate means of communication. We will report any relevant breaches to the ICO, see below.
Cookies are small files saved to the user’s computer hard drive that track, save and store information about the user’s interactions and usage of the website. This allows the website, through its server, to provide the user with a tailored experience when navigating the website. Session cookies may be used to validate your access to different parts of the website.
Cookies we use
The Cookies we use are shown in this table below.
|_cfduid||cloudflare.com||HTTP||Identify trusted web traffic||1 year|
|_cfduid||incawed.co.uk||HTTP||Identify trusted web traffic||1 year|
|ASPSESSIONID#||incatools.co.uk||HTTP||Preserves users states across page requests||Session|
|_ga||incawed.co.uk||HTTP||Statistical data on how user uses the website||2 years|
|_gat||incawed.co.uk||HTTP||Google Analytics use to throttle request rate||Session|
|_gid||incawed.co.uk||HTTP||Registers unique ID for statistics on website use||Session|
|mf_#||incawed.co.uk||HTTP||Data on navigation & interaction for personalising purchasing info||3 months|
|ads/ga-audience||Google.com||Pixel||Google Ad words to re-engage visitors likely to convert to customers based on online behaviour||Session|
|collect||Google-analytics.com||Pixel||Information about users device & behaviour. Tracks across devices & marketing channels||Session|
Incandescence uses tracking software provided by Google Analytics to monitor its visitors, and to better understand how they use the site. See above table. The software will save a cookie to the user’s hard drive in order to track and monitor engagement and usage of the website. The cookie will not store, save or collect personal information.
Guidelines for the processing and handling of data is available from the Information Commissioner’s Office, the UK supervisory authority on data protection, see ico.org.uk.
Information is also available at www.ec.europa.eu/ipg/basics/legal/cookies/index_en.html.
Questions and queries
If you have any concerns about how we handle your data, you can contact the Data Controller by email to firstname.lastname@example.org or write to Incandescence, 46 Hendred Street, Cowley, Oxford OX4 2ED.
Changes to this policy
If you want to raise a concern about the use of your data, you can contact us by email to email@example.com. Alternatively, you can formally raise a concern or complaint to the Information Commissioner’s Office (ICO) directly on 0303 123 1113, or see the options for reporting issues on https://ico.org.uk/concerns/
Third Party Rights
Jurisdiction and Governing Law
© 2018 Incandescence | Privacy and Cookies Policy v1