Privacy Policy

PRIVACY POLICY – SUNBEAM PHOTOGRAPHIC LIMITED – MAY 2018

 

WHO ARE WE?

The website sunbeamstudios.com (“Site”) is operated by Sunbeam Photographic Limited, a company registered in England and Wales under registration number 07171165 (“Sunbeam Studios”“we”“us” and/or “our”). Our registered address is 69-71 East Street, Epsom, Surrey KT17 1BP. You can contact us as indicated under the “Contact” section below.

The data controller responsible for your personal data is Sunbeam Photographic Limited.

WHAT IS THIS PRIVACY POLICY FOR?

This privacy policy (“Privacy Policy”) applies to personal data that we collect from you as a user of this Site or as a visitor, guest, user or tenant of our premises, as a customer or potential customer, or as a guest or third-party supplier to a customer or potential customer (“you” or “your” being interpreted accordingly). It provides information on what personal data we collect, why we collect the personal data, how it is used and the lawful basis on which your personal data is processed, and what your rights are under the applicable data protection and privacy laws, including the General Data Protection Regulation (“GDPR”) which will become applicable to us and you as of 25 May 2018.

‘Personal data’ as used in this Privacy Policy means any information that relates to you from which you can be identified. We take the security of your data we hold seriously. We have a policy including procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.

We will only share personal data with others when we are legally permitted to do so. When we share data with others, we put contractual arrangements and security mechanisms in place to protect your data.

By using our Site or submitting your personal data you are taken to accept the terms of this Privacy Policy, so please read it carefully.

PERSONAL DATA WE COLLECT

We collect the following personal data about you:

  • Enquiries, Reservations and Contracts: The personal details you provide when submitting an enquiry and / or making a reservation and / or contract. This may include your name, address, e-mail address; business address and phone number; gender and date of birth; country; information about your work and other information that you elect to provide including your crew, sub-contractors, third-party suppliers, talent or guest information, such as first and last name, email address, and other contact details. Personal data collected in relation to reservations will be processed in accordance with a privacy policy provided at the time of requesting a reservation so please ensure that you read our privacy notice on the website that we may provide to you when we collect or process your personal data.
  • Other Information: Personal details you choose to give when corresponding with us by phone or e-mail, participating in user/customer surveys or otherwise visiting and interacting with this Site or any other websites we operate, and personal data that you provide to us when you visit our premises. We can also combine personal data that you provide to us with other information we collect about you when you make a reservation through third-party services or websites, as necessary to process your requests.

AUTOMATICALLY COLLECTED PERSONAL DATA

  • Log Data: When you visit our Site, our servers record information (“log data”), including information that your browser automatically sends whenever you visit the Site. This log data includes your Internet Protocol (“IP”) address (from which we understand the country you are connecting from at the time you visit the Site), browser type and settings, the date and time of your request.
  • Use of Cookies: This site uses cookies to better the users experience while visiting the website. Where applicable this website uses a cookie control system allowing the user on their first visit to the website to allow or disallow the use of cookies on their computer / device. This complies with recent legislation requirements for websites to obtain explicit consent from users before leaving behind or reading files such as cookies on a user’s computer / device.

Cookies are small files saved to the user’s computer’s hard drive that track, save and store information about the user’s interactions and usage of the website. This allows the website, through its server to provide the users with a tailored experience within this website.

Users are advised that if they wish to deny the use and saving of cookies from this website on to their computers hard drive they should take necessary steps within their web browsers security settings to block all cookies from this website and its external serving vendors.

This website uses tracking software to monitor its visitors to better understand how they use it. This software is provided by Google Analytics which uses cookies to track visitor usage. The software will save a cookie to your computer’s hard drive to track and monitor your engagement and usage of the website, but will not store, save or collect personal information. You can read Google’s privacy policy here for further information [ http://www.google.com/privacy.html ].

Other cookies may be stored to your computer’s hard drive by external vendors when this website uses referral programs, sponsored links or adverts including when using embedded media such as vimeo or youtube files and links to sites such as facebook and twitter. Such cookies are used for conversion and referral tracking and typically expire after 30 days, though some may take longer. No personal information is stored, saved or collected. Please see the individual website’s own policies for details and how to opt out.

  • Social Media Platforms: Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are custom to the terms and conditions as well as the privacy policies held with each social media platform respectively.

Users are advised to use social media platforms wisely and communicate / engage upon them with due care and caution regarding their own privacy and personal details. This website nor its owners will ever ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.

This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.

HOW WE USE YOUR PERSONAL DATA

We use your personal data in the following ways:

  • To acknowledge, confirm and deal with your enquiries and requests. Such use of your data is necessary in order to implement your requests.
  • Where you are a customer, provide you with services, administer your contract and contact you regarding your use of the services. Such use is necessary to respond to or implement your request and for the performance of the contract between you and us.
  • To complete and fulfill your reservation or contract, for example, to process your payment, ensure that your contracted services and/or rental spaces are available, and provide you with related customer service, including sending confirmations or pre-arrival messages, assist you with equipment rentals, catering, meetings, events or celebrations and communicate with related third-party suppliers, crew, talent, guests and visitors. Such use is necessary for the performance of the contract between you and us.
  • To contact you in connection with user/customer surveys and use any information you choose to submit in response, provided that you gave us your consent to being contacted in this way at the time you provided us with the personal data.
  • Sunbeam Studios may provide you, or permit selected third-party service providers to provide you, with information about goods or services, events and other promotions we feel may interest you. We (or such third-party providers) will contact you by email only with your consent, which was given at the time you provided us with the personal data.
  • As necessary for certain legitimate business interests, which include the following:
    • where we are asked to deal with any enquiries or complaints you make.
    • to administer our Site, to better understand how visitors interact with our websites and ensure that our Site is presented in the most effective manner for you and for your computer/device.
    • to conduct analytics to inform our marketing strategy and enable us to enhance and personalise the experience we offer to our customers and our communications, including by creating customer profiles to enable personalised direct marketing communications.
    • to provide postal communications which we think will be of interest to you.
    • if you ask us to delete your data or to be removed from our marketing lists and we are required to fulfil your request, to keep basic data to identify you and prevent further unwanted processing.
    • to share personal data among our affiliated businesses for administrative purposes, for providing our services and in relation to our sales and marketing activities.
    • for internal business/technical operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes and as part of our efforts to keep our Site, network and information systems secure.
    • to (a) comply with legal obligations, (b) respond to requests from competent authorities; (c) enforce our Terms and Conditions and Venue Guidelines; (d) protect our operations or those of any of our affiliated businesses; (e) protect our rights, safety or property, and/or that of our affiliated businesses, you or others; and (f) enforcing or defending legal rights, or preventing damage.
  • We may use your personal data for other purposes which you have consented to at the time of providing your data.

As used in this Privacy Policy, “legitimate interests” means the interests of Sunbeam Studios and our affiliated businesses in conducting and managing our organisation. When we process your personal data for our legitimate interests, we make sure to consider and balance any potential impact on you, and your rights under data protection laws. Our legitimate interests do not automatically override your interests. We will not use your personal data for activities where our interests are overridden by the impact on you, unless we have your consent or those activities are otherwise required or permitted to by law. You have the right to object at any time to processing of your personal data that is based on our legitimate interests, on grounds relating to your particular situation (for more information on your rights, please see “Your Data Protection Rights” section below).

DISCLOSURE OF YOUR INFORMATION

We share your personal data with third parties in the following situations:

  • Service Providers: Sunbeam Studios, like many businesses, sometimes hires selected third parties who act on our behalf to support our operations, such as (i) card processing or payment services (see the section below headed “Payment Information”), (ii) credit reference agencies to protect against possible fraud, (iii) IT suppliers and contractors (e.g. data hosting providers or delivery partners) as necessary to provide IT support and enable us to provide services and other goods/services available on this Site or otherwise, (iv) web analytics providers, (v) providers of digital advertising services, (vi) providers of CRM, marketing and sales software solutions and (vii) suppliers for equipment hire and (viii) third-party contractors employed during the course of our contract with you in order to help us deliver the services to you. Pursuant to our instructions, these parties may access, process or store your personal data in the course of performing their duties to us and solely in order to perform the services we have hired them to provide.
  • Administrative and Legal Reasons: if we need to disclose your personal data (i) to comply with a legal obligation and/or judicial or regulatory proceedings, a court order or other legal process. (ii) to enforce our Terms & Conditions, Venue Guidelines or other applicable contract terms that you are subject to or (iii) to protect us, our customers, or contractors against loss or damage. This may include (without limit) exchanging information with the police, courts or law enforcement organisations.

PAYMENT INFORMATION

Any credit/debit card payments and other payments you make through our Site will be processed by our third party payment providers and the payment data you submit will be securely stored and encrypted by our payment service providers using up to date industry standards. Please note that we do not ourselves directly process or store the debit/credit card data that you submit.

We may arrange that card or payment data you submit in support of a contract is stored for the purpose of processing and collecting your fees.

We may store and use this card or payment information for the purpose of processing any future payments that you make as a customer for additional goods and services. We will store this data in accordance with our legal obligations under applicable law and only for so long as legally permitted.

You may choose to opt out of us holding your card or payment data although this means that you will need to re-supply us with card/payment details for the purpose of making any future purchases.

PERSONAL DATA TRANSFERS

Your personal data will be transferred to and stored in countries other than the country in which the information was originally collected, including the United States and other destinations outside the European Economic Area (“EEA”), to our service providers and affiliated businesses for the purposes described above.

Please note that the countries concerned may not provide the same legal standards for protection of your personal data that you have in the United Kingdom or EEA. Where we transfer your personal data to countries outside of the EEA we will take all steps to ensure that your personal data will continue to be protected. We will implement appropriate safeguards for the transfer of personal data to our service providers in accordance with the applicable law, such as relying on our service providers’ Privacy Shield certification or implementing standard contractual clauses for data transfers.

SECURITY

Where we have given you (or where you have chosen) a password or log-in which enables you to access certain restricted parts of our Site, you are responsible for doing everything you reasonably can to keep these details secret. You must not share your password or log-in details with anyone else.

Unfortunately, the transmission of information over the internet or public communications networks can never be completely secure. We will take appropriate technical and organisational security measures to protect the personal data that you submit to us against unauthorised/unlawful access or loss, destruction or damage, although we cannot 100% guarantee the security of personal data that you provide to us online.

PERSONAL DATA RETENTION

We will keep your personal data only for as long as is reasonably necessary for the purposes outlined in this Privacy Policy, or for the duration required by any legal, regulatory, accounting or reporting requirements, whichever is the longer. In particular, we retain customer records for six years after expiration of the contract. When you consent to receive marketing communications, we will keep your data until you unsubscribe.

To determine the appropriate retention period for your personal data, we consider the amount, nature, and sensitivity of the personal data, the purposes for which we process your personal data, applicable legal requirements or operational retention needs, and whether we can achieve those purposes through other means.

Upon expiry of the applicable retention period we will securely destroy your personal data in accordance with applicable laws and regulations. In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case it is no longer personal data.

YOUR PERSONAL DATA PROTECTION RIGHTS

Certain applicable data protection laws give you specific rights in relation to your personal data. In particular, if the processing of your personal data is subject to the GDPR, you have the following rights in relation to your personal data:

  • Right of access: If you ask us, we will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data along with certain other details such as the purpose of the data processing. If you require additional copies, we may need to charge a reasonable fee.
  • Right to rectification: If your personal data is inaccurate or incomplete, you are entitled to ask that we correct or complete it. If we shared your personal data with others, we will tell them about the correction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your personal data so you can contact them directly.
  • Right to erasure: You may ask us to delete or remove your personal data, such as where our legal basis for the processing is your consent and you withdraw consent. If we shared your data with others, we will tell them about the erasure where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your personal data with so you can contact them directly. We may continue processing personal data where this is necessary for a legitimate interest in doing so, as described in this Privacy Policy.
  • Right to restrict processing: You may ask us to restrict or ‘block’ the processing of your personal data in certain circumstances, such as where you contest the accuracy of the personal data or object to us processing it. We will tell you before we lift any restriction on processing. If we shared your personal data with others, we will tell them about the restriction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your personal data so you can contact them directly.
  • Right to data portability: You have the right to obtain your personal data from us that you consented to give us or that was provided to us as necessary in connection with our contract with you. We will provide you with your personal data in a structured, commonly used and machine-readable format. You may reuse it elsewhere.
  • Right to object: You may ask us at any time to stop processing your personal data, and we will do so:
    o If we are relying on a legitimate interest to process your personal data — unless we demonstrate compelling legitimate grounds for the processing or
    o If we are processing your personal data for direct marketing.
  • Right to withdraw consent: If we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing of your data before we received notice that you wished to withdraw your consent.
  • Right to lodge a complaint with the data protection authority: If you have a concern about our privacy practices, including the way we handled your personal data, you can report it to the UK data protection authority (the Information Commissioner’s Office or ICO)

If you wish to exercise any of these rights please contact us as described in the “Contact” section below. We may also need to ask you for further information to verify your identity before we can respond to any request.

CHANGES TO OUR PRIVACY POLICY

Any changes we may make to our Privacy Policy in the future will be posted on this page. Please check back frequently to see any updates or modifications. If required by the applicable law, we will notify you of any material or substantive changes to this Privacy Policy.

CONTACT

Questions, comments or requests regarding this Privacy Policy should be addressed to your reservation contact at Sunbeam Photographic Limited or via the General Manager as listed on the ‘Contact Us’ page on the Site.