CUSTOMER NOTICE GDPR


GDPR CUSTOMER NOTICE General Data Protection Regulation (GDPR) Consent request summary information sheet For the purposes of compliance with the GDPR, which takes over from the Data Protection Act 1998 on 25th May 2018, we need your consent to contact you about your grooming appointment with us. Until you (or your representative) come in and sign your record card, we will assume you are in agreement with us contacting you about your appointment using the details we already hold if you are an existing customer, or the details you gave us when you made your appointment if a new customer. When you come in the first time after 22nd May 2018 you will be required to check the details on the card, sign and date the stamped area, deleting any of the communication means that you don’t want us to contact you contacted by. That is, us initiating contact with you as opposed to replying to an enquiry from you. So, if you delete “SOCIAL MEDIA” for example and you then contact us via FaceBook enquiring about an appointment, we will take that as a temporary consent to reply back using the same medium. Also, if we don’t have an email address for you and you email us, the same applies. In the past we would have automatically added your email address to your booking software record, whereas now we won’t if you deleted “EMAIL” when signing the stamp on your card record, as your consents will be will be noted in the software for future reference. It is an explicit requirement that we have a minimum of your name, address and a phone number (mobile preferred) so that we can sent appointment reminders/changes/dog ready texts (if you wish them by NOT deleting “TEXT”) or if we urgently need to contact you when your dog is with us. Unfortunately, we CANNOT accept a dog for a grooming appointment without valid, up to date contact details. Our data privacy policy is available to view on our website at: http://pamperedpetsonline.net You can of course request to view and amend information we hold on you or request us to delete the data we hold on you by submitting a “Subject Access Request Form” in writing together with a fee of £10 made payable to Pampered Pets Services Ltd. Please be aware if we delete your records, we will not be able to offer you an appointment again without creating a new record and gaining your consent to hold information about you, but we will no longer have access to any previous grooming records for your dog(s) as that information is only on your card record which will have been securely shredded. Please note that we do NOT share your data with 3rd parties for advertising or marketing. gdpr data privacy notice GDPR: DATA PRIVACY NOTICE FOR CLIENTS AND SUPPLIERS Introduction Pampered Pets Services Ltd are committed to protecting and respecting your privacy. .Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. The rules on processing of personal data are set out in the General Data Protection Regulation (the “GDPR”). 1. Definitions Data controller - A controller determines the purposes and means of processing personal data. Data processor - A processor is responsible for processing personal data on behalf of a controller. Data subject – Natural person Categories of data: Personal data and special categories of personal data Personal data - The GDPR applies to ‘personal data’ meaning any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier (as explained in Article 6 of GDPR). For example name, passport number, home address or private email address. Online identifiers include IP addresses and cookies. Special categories personal data - The GDPR refers to sensitive personal data as ‘special categories of personal data’ (as explained in Article 9 of GDPR). The special categories specifically include genetic data, and biometric data where processed to uniquely identify an individual. Other examples include racial and ethnic origin, sexual orientation, health data, trade union membership, political opinions, religious or philosophical beliefs. Processing - means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Third party - means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data. 2. Who are we? Cheryl Claringbold, Proprietor at Pampered Pets Services Ltd is the data controller. This means we decide how your personal data is processed and for what purposes. Our contact details are: Pampered Pets Services Ltd, 55 West Street, Sittingbourne, Kent, ME10 1AN Tel: 01795 227230. For all data matters contact the data controller. 3. The purpose(s) of processing your personal data We use your personal data for the following purposes: To create, notify and control appointments for dog grooming services and to purchase dog grooming supplies for consumption and resale. 4. The categories of personal data concerned With reference to the categories of personal data described in the definitions section, we process the following categories of your data: Personal data. Your record may consist of: first name, surname, assumed whether male/female, assumed marital status, address, telephone number, mobile number, email address, your dog(s) name(s)/breed(s)/age(s) & alive/deceased. Additionally, where alternative contact details have been provided by you or your representative. If you are a supplier, your data may have been supplied from a publicly available source such as a sales or marketing email sent by you or from your company website/social media or contact request from us. 5. What is our legal basis for processing your personal data? a) Personal data (article 6 of GDPR) Our lawful basis for processing your general personal data: Consent of the data subject; By specifically signing the consent stamp on your dogs grooming record card Processing necessary for the performance of a contract with the data subject or to take steps to enter into a contract Product or Service supply contract Processing necessary for compliance with a legal obligation To maintain our own accounting records Processing necessary to protect the vital interests of a data subject or another person If a customer, we must have current contact details to service your grooming requirements to inform you of appointments, changes to appointments or problems/issues with your dog. b) Special categories of personal data (article 9 of GDPR) We do not process special categories of data. Sharing your personal data Your personal data will be treated as strictly confidential, and will not be shared. 6. How long do we keep your personal data? We keep your personal data for no longer than reasonably necessary for a period of up to 15 years from the last date it was used in order to allow for the possibility of deceased dogs being replaced by customers for continuance of grooming record keeping. 7. Providing us with your personal data You are under no statutory or contractual requirement or obligation to provide us with your personal data. But failure to do so will have the following consequences: we will be unable to accept your dog(s) for grooming without your contact details. 8. Your rights and your personal data Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data: The right to request a copy of the personal data which we hold about you; The right to request that we correct any personal data if it is found to be inaccurate or out of date; The right to request your personal data is erased where it is no longer necessary to retain such data; If we relied on consent to process your personal data, you’ll have the right to withdraw your consent to the processing at any time; The right to request that we provide you with your personal data and where possible, to transmit that data directly to another data controller, (known as the right to data portability), (where applicable i.e. where the processing is based on consent or is necessary for the performance of a contract with the data subject and where the data controller processes the data by automated means); The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing; The right to object to the processing of personal data, (where applicable i.e. where processing is based on legitimate interests (or the performance of a task in the public interest/exercise of official authority); direct marketing and processing for the purposes of scientific/historical research and statistics). 9. Transfer of Data Abroad We do not transfer personal data outside the EEA. 10. Automated Decision Making We do not use any form of automated decision making in our business. 11. Further processing If we wish to use your personal data for a new purpose, not covered by this Data Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. 12. Changes to our privacy policy Any changes we may make to our privacy policy in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy policy. 13. How to make a complaint To exercise all relevant rights, queries or complaints please in the first instance contact our Data Controller. If this does not resolve your complaint to your satisfaction, you have the right to lodge a complaint with the Information Commissioners Office on 03031231113 or via email https://ico.org.uk/global/contact-us/email/ or at the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, England. GDPR As a part of Data Protection Act (GDPR) it is necessary for us to inform you of the information we keep about you and your pet, how it is used and stored and to receive permission for specific information to be stored and used. In the salon the following information is stored in online format: details you have given to us about you: your name, your address, your phone number(s) and e-mail address details you have given to us about your dog: name, birthday,, breed, coat type, weight, gender etc. details of what we have done to your dog - blades, combs used, where we have scissored, nails trimmed, date of the visits etc. Any likes or dislikes of your dog e.g sensitive feet, like treats etc. dog`s grooming temperament - good, nervous, hard, biter etc any medical problems (lumps, bumps, warts, heart murmur etc.) Online format is protected by password. Any non-returning customer information will be inactive after 1 year. Our website: You can browse and visit our website without providing your name and contact details. Like many websites, our server logs capture details of your operating system and browser software, IP address, URL, including the date and time of your visit. We use cookies to analyse how our site is used by visitors. If you do not wish cookies to be saved to your system, you may change your browser settings. You might choose to provide your contact details if you do any of these things: Sign up to a mailing list Submit a query Create an account for booking We may use your personal information in the following way: to respond enquiries to keep you informed about our services and innovations, trends, how to maintain your pet`s coat and health and pet related events to send appointment reminders, new appointment confirmation, cancellation, rebook reminder, agreement, pet birthday reminder via email or/and text, to send vouchers and promotions to ask you for reviewing us for market research purpose for record keeping purpose to deal with enquiries and complaints to contact you in connection with your appointment, dog collection or drop off, cancellations or rescheduling We use Pawfinity scheduling software for managing your bookings, our website is built by us and hosted by godaddy, worldly for in-store card payments and Facebook as a social media platform. Pampered Pets DOES NOT share any customer data or information with any third parties for marketing purpose.