Data Protection and Privacy Policy
Introduction
This Data Protection and Privacy Policy governs the collection, storage and use of the personal information that you provide to Catherine Alexandra (this practice).
This policy describes this practice’s obligations to its clients, suppliers, and the users of its website. It also details the way that this practice and its website processes, stores and protects the personal information that it holds. The policy also describes options this practice provides for you to access, update or otherwise control your personal data that it processes.
To contact this practice with respect to this Data Protection and Privacy Policy use the Contact Form or write to: Privacy, Catherine Alexandra, 36 Colwell Road, Wellingborough NN8 1NT.
Please note that this Data Protection and Privacy Policy may be revised at any time in order to improve how personal information is processed and protected. In that case those changes will be publicised.
Controller of personal information
For the purpose of the General Data Protection Regulation (GDPR) and Data Protection (Charges and Information) Regulations 2018, the data controller is the design, development and research practice known as Catherine Alexandra of 78 York Street, London W1H 1DP and 36 Colwell Road, Wellingborough NN8 1NT.
This practice is exempt from registration in the ICO Data Protection Register as it only keeps personal information for its own contract administration, accounting and marketing purposes.
Personal Information
Catherine Alexandra does not collect any information about you except where it is specifically and knowingly provided by you to this practice or to a third party which shares information with this practice in keeping with its own privacy policy. In order to provide its services to you as its client, this practice will require you to provide certain personal information – such as name, address, email address, and telephone number – for communications and accounting purposes. Similarly, in sourcing or procuring goods or services this practice may need to collect that same personal information from you if you might supply those goods or services. If you collaborate on projects with this practice then that same personal information will need to be collected from you.
If you use this website then you can browse the website without directly identifying yourself or providing any information about yourself. Information about your computer, including where available your IP address, operating system and browser type, though, will be collected and logged; this information is used only to prevent abuse or to detect attempted fraudulent use of the website.
Personal information is collected and used only as it might be needed for this practice to deliver to you the services that you have instructed it to provide or to comply with the law.
All such personal information will be held securely in accordance with the General Data Protection Regulation (EU) 2016/679, as adopted into law of the United Kingdom in the Data Protection (Charges and Information) Regulations 2018.
Catherine Alexandra will not sell or rent your personally identifiable information to anyone.
You have the right at any time to request a copy of the personal information held on you, or to be removed from Catherine Alexandra’s records.
Your personal information that is collected and stored
The personal information that Catherine Alexandra collects includes information such as:
- Name
- Address
- Telephone number
- Email address
- Various other information that could indirectly identify you, such as your Internet Protocol (IP) address, the date and time of accessing the website, or information about your computer or computing device.
Personal information is collected directly from you when you instruct this practice or make enquiries by post, telephone, email or the website’s Contact Form. Notes explaining what you asked for will be kept.
Sometimes Catherine Alexandra obtains your personal information from other sources such as publicly available databases or from other firms with which this practice works.
If you provide personal information about other people, or if other people provide personal information about you, then that information will only used for the specific reason for which it was provided.
If you choose not to provide certain personal information then it might not be possible to respond to you enquiry or to perform the services that you instruct this practice to carry out for you.
Account information
When you instruct Catherine Alexandra, information is created and kept for contract management and accounting purposes.
That information will include will include information that can be used to identify you, as well as accounting information such as sums billed and paid and account balances.
This information will be stored securely and only divulged as required to execute the terms of a contract, to perform normal accounting, or as required by legal authorities.
Cookies and similar technologies
This website does not use cookies.
Certain information, however, is logged automatically by the webserver.
Web server logs
Catherine Alexandra’s website is hosted on a third party webserver located in the EU. That webserver automatically logs information about each visit to the website. The information logged includes the IP address of the computer used to access the website, the pages browsed, the date and time of the visit, the browser used, and the type of device and its operating system. The webserver does not collect mobile device location data.
How personal information is collected
Catherine Alexandra collects your personal information in several ways, both directly from you or indirectly from third party sources or through certain automated processes.
Information that you provide
This is information about you that you provide by communicating with this practice by telephone, e-mail or by filling in the Contact Form on the Catherine Alexandra website.
The personal information you provide may include your name, address, e-mail address and telephone number.
Information automatically collected
This is information that is collected by the webserver when you visit Catherine Alexandra’s website.
When you access the website the webserver logs the Internet protocol (IP) address used to connect your computer to the Internet, the type of computing device and its operating system, the type of browser used, the pages visited, and the time and date of access.
The information is collected automatically and always.
E-mail communications (including the contact form)
Information is collected when you send an email to CatherineAlexandra.com, either directly by using an email client or indirectly by using the Contact Form on its website. When you send an email your email address and any other personal information that you provide in that email is collected. When you use the Contact Form on the website you are asked to provide your name, an email address or a telephone number, and a brief message of introduction and this information is collected.
Information from other sources
This includes personal information obtained from more traditional communications such as by post or over the telephone.
Sometimes personal information is obtained from third party sources.
Telephone
When you telephone Catherine Alexandra written notes are made of your conversation.
These notes will record your telephone number and the instructions or other information that you gave during the conversation.
This practice does not record telephone calls.
Post
When you write to Catherine Alexandra your letter will be held on file.
Your contact details will be noted and the instructions or other information that you gave in the letter will be added to the notes kept.
Third party sources
Sometimes use is made of third party sources of information.
These sources can include information provided by other clients or businesses.
Third party sources might also be your own website, or publicly available databases, such as white page and yellow page telephone directories, Government sources such as Companies House, or professional bodies’ membership lists; these will be used to verify or complete the information that this practice holds about you.
How personal information is utilized
The main use of personal information held by this practice is to maintain client or supplier relations and to fulfill any contracts entered into.
Further uses of that information are to improve, update or otherwise enhance the services provided, to communicate with you, to share with trusted third parties as required to fulfill your instructions,
or to comply with legal, regulatory and law enforcement requests.
If you provide personal information about others, or if others provide your information, then that information will only be used for the specific reason for which it was provided.
Delivering, improving, updating and enhancing services provided
When you instruct this practice, your information will be used to provide the service contracted and to alert you to relevant matters related to your instructions.
Your personal information will be used in the administration of contracts including issuing invoices and other notices.
The information that Catherine Alexandra holds about you will also be used to understand how you use this practice’s services and which services are most relevant to you.
That analysis is intended to improve the performance of those services and also to improve the range of services provided.
Information collected by visits to the website will be used to identify problems with the website as will as any errors, security issues such as detecting fraud and other abuses of the website, or other general improvements that the website needs such as usability or information content.
Your personal information will also be used in resolving any complaints you might raise.
Sharing with trusted third parties
Sometimes it is necessary to share your personal information with other professionals in order to fulfill your instructions.
In those cases you will be advised of that need and your consent will be sought before any information is shared.
Communicating with you
The personal information that you provide, such as address, email address, or telephone number, will be used in order to communicate with you.
The purposes of those communications include fulfilling your instructions or providing information that you request,
notifying you about changes to the services this practice offers, or of new services it has begun to offer where you have consented to receiving such marketing emails.
Transfer of personal information abroad
Catherine Alexandra uses a third party email server located in the United States of America.
That means that when you email Catherine Alexandra or use the Contact Form on its website your personal information in those communications will be transfered and temporarily stored outside the European Economic Area (EEA).
This email service provider complies with the EU-U.S. Privacy Shield which is an approved certification scheme under Article 42 of the General Data Protection Regulation, and is permitted under Article 46(2)(f) of the General Data Protection Regulation.
Disclosure of your personal information to others
Catherine Alexandra will not disclose your information to anyone outside this practice without your consent, unless required to in order to comply with legal, regulatory and law enforcement requests.
Disclosure for legal reasons
Requests for your personal information by government or other legal authorities will be balanced against your legal right to privacy.
If, however, disclosure is required by the police, the courts or other legal authorities, Catherine Alexandra will disclose some or all of your personal information without your consent.
Reporting possible criminal acts or threats to individual or public safety or security
If this practice considers it to be in the public good to disclose your personal information to a legal authority such as the police in order to prevent criminal acts or threats to the safety of individuals or the public, then it will do so without obtaining your consent.
This will include where threats or malicious communications are sent to anyone in this practice, as well as cyber attacks against, or attempts to defraud, this practice.
Enforcing Catherine Alexandra’s legal rights
If needed, Catherine Alexandra will disclose your personal information in order to enforce this practice’s legal rights, for example to be paid moneys owed.
Those rights might be due to a contract entered into with you or more generally under the law of England and Wales.
Resolving legal disputes or in legal proceedings
If needed, Catherine Alexandra will disclose your personal information if this practice is in a legal dispute with you or another party in order to resolve the dispute or during legal proceedings against you or that other party.
Complying with regulations, laws, and other legal obligations
When necessary in order to act lawfully, Catherine Alexandra will disclose your personal information to the government, local authorities, regulatory bodies, the police or the courts without first seeking your consent.
Disclosure to third parties
This practice will sometimes have a legitimate need to disclose your personal information to third parties in the course of normal professional activities, but they may not use your personal information for purposes other than that for which it was provided.
Providing information to Planning Authorities
Your personal information, for example name and address, might be on documents submitted to local planning departments in order to support planning applications.
That information will then by subject to that Local Authority’s Privacy Policy which policy also must satisfy the General Data Protection Regulation (EU) 2016/679 and the Data Protection (Charges and Information) Regulations 2018.
Providing your information to other professionals
Sometimes this practice will instruct or otherwise work with other professionals such as accountants, solicitors, and project partners.
Your personal information will be shared only as needed in order for them to provide the services for which they were instructed, or in order for a project you have requested to be completed according to your instruction.
Those other professionals will also be subject to the General Data Protection Regulation (EU) 2016/679 and the Data Protection (Charges and Information) Regulations 2018 and will act according to their own Privacy Policies.
With your consent
Catherine Alexandra will notify you if your personal information is to be provided to one of these third parties.
You have the right to choose not to share your information with these third parties when disclosure is not for legal reasons, but doing so might mean that the services that you have requested cannot be provided.
Use of webserver logs
The webserver’s logs are only used for IT security.
This use includes ensuring that the website is not compromised by malicious code or other attack vectors and in general for identifying and investigating malicious or suspicious activity on the website.
No other use is made of those logs.
How your personal information is kept secure
Catherine Alexandra protects your personal information that it collects in both transmission and storage of that data by using encryption and restricted access where appropriate.
Information that you enter into Catherine Alexandra’s Contact Form or that you email to this practice is secured during transmission by using the Secure Sockets Layer (SSL) protocol.
That personal information is then stored on a secure computer with restricted access.
When personal information is shared, appropriate confidentiality restrictions are applied.
When a request is made to disclose your personal information this practice will verify the identity of the person making the request to ensure that it is you.
Your personal information will be retained as long as it is needed in order to fulfill your instructions and the contract entered into with you, and further only for legal or legitimate business reasons.
Transmission of personal information by email
When you email personal information to Catherine Alexandra or you enter personal information into it’s Contact Form that information is secured during transmission by using the Secure Sockets Layer (SSL) protocol.
Catherine Alexandra uses a third party email provider located in the United States of America.
This email service provider complies with the EU-U.S. Privacy Shield which is an approved certification scheme under Article 42 of the General Data Protection Regulation, and is permitted under Article 46(2)(f) of the General Data Protection Regulation.
How long your personal information is retained
When you provide personal information to Catherine Alexandra that information is retained by, and will only be used by, this practice in order to support its professional relationship with you.
Your personal information will be retained for as long as is needed in order to fulfill your instruction.
It will be kept after that for legal or legitimate business reasons for periods that can be: required by law, contract or similar obligations such as to maintain accurate financial records for tax purposes; necessary for resolving disputes or enforcing rights confered by contract such as the right to be paid for work done; required by standard professional practice to maintain adequate and accurate records of the practice’s activities; allowed by your consent or for legitimate business purposes.
Your right to manage your personal information held
You have the right to access your personal information held by this practice, and the right to have that information revised and updated, or deleted.
You also have the right to control how your personal information is used .
How you can access your personal information
You have the right to access the personal information that Catherine Alexandra holds about you, and to know how that information is used and processed.
To access your personal data you must make a Subject Access Request (SAR).
You must put that request in writing to Catherine Alexandra, 36 Colwell Road, Wellingborough NN8 1NT.
If this practice holds information about you then you will be provided with a description of that information, an explanation of why your personal information is being held, and an account of those to whom it might be disclosed.
Provided that your indentity can be confirmed, you will be given with this information within 30 days of your request and without charge.
How you can update your personal information
You have the right to have your personal information held by this practice corrected if it is inaccurate.
When you update information, a copy of the previous version is usually kept for reasons of data integrity.
You also have the right to have your personal information deleted if there is no legitimate reason for this practice to hold it.
Again, you must make any request in writing.
Choices you have about personal information collected and held
You can choose not to provide personal information.
You have the right to request that the use of your personal information is restricted, for example that it is not used for marketing purposes.
You can withdraw your consent to the use or processing of your personal information.
Note that if you choose to do any of these it may mean that your instruction cannot be fulfilled and you might effectively terminate any contract you have with this practice;
in that case the clauses of the contract dealing with termination will come into force.
Data portability
You have the right to be provided with your personal information in a standard portable format such as clear text,
or in a commonly used structured machine-readable format as appropriate according to your request, provided this practice is able to produce data in that format.
Account closure and deletion of personal information
You have the right to end your professional relationship with this practice and to request that your personal information be deleted.
It might nonetheless be necessary to retain your personal information for a period in order to comply with legal or regulatory requirements before that information can be deleted.
Verifying your identity to protect your personal information
In order to reduce the risk of fraud, identity theft or any other unauthorised access to your personal information, certain measures will be taken in order to verify your identity before you are given access to, or permitted to correct, your personal information.
Where there is appropriate information about you in its records, Catherine Alexandra will attempt to verify your identity using that information.
If that is not possible, you will be required to produce further documentation as needed in order that your identity can be verified.
The website
This website exists to provide you with information about the design, research and development practice Catherine Alexandra.
You cannot purchase anything using this website.
You can, though, communicate with this practice using the Contact Form.
This section explains some aspects of the website and its behaviour as it affects the protection of your personal information.
Use of cookies and similar technologies
This website does not use cookies.
Certain information, however, is logged automatically by the webserver.
The information collected is described above in the section Information Collection, Storage and Use.
“Do Not Track” notifications
It is possible to configure some browsers so that they notify websites you visit not to track you by sending a “Do Not Track” message to the website.
At present, there is no agreed meaning on the internet for such messages.
For that reason this website does not behave any differently whether it receives a “Do Not Track” message or not.
Third party websites
On some pages, Catherine Alexandra’s website has links to other websites.
Those websites will be governed by the privacy and data protection policies of the owners of those websites, and Catherine Alexandra has no control over and accepts no responsibility or liability for the collection and storage of personal information by those websites.
If you follow a link to any of those websites, you should read the privacy notices on those other websites before you submit any personal data to those websites.
Conditions of use, notices and revisions
This Privacy Notice applies to all your personal information that you provide to Catherine Alexandra.
This practice reserves the right to change the policy at any time.
Any changes to this policy will be posted on this page and where appropriate notified to you by e-mail.
Catherine Alexandra’s privacy policy and data protection practices will never materially change other than in order to better protect your personal information.
Changes in our Privacy Policy
This privacy notice is reviewed from time to time.
You should periodically visit this page, so that you are aware of any such revisions.
Your personal information will not, however, be used in a manner not previously stated unless you give consent to any new use.
This privacy notice was last updated on 1st June 2018.
Data protection authority
Residents of the European Economic Area (EEA) who believe that this practice maintains their personal information subject to the General Data Protection Regulation (GDPR), may direct questions or complaints to the United Kingdom’s lead supervisory authority, the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Contact Catherine Alexandra
If you have questions, concerns, or complaints about this Privacy Policy, this website, or the execution of its services, then you may contact this practice by using the Contact Form or by writing to Privacy, Catherine Alexandra, 36 Colwell Road, Wellingborough NN8 1NT