WovenInWords PRIVACY POLICY
As a small business I am required to use and keep personal data, for processing orders and doing my accounts. I am required to inform you of how I both process and store, personal data for WovenInWords.
DATA COLLECTED AND HOW I USE IT
WovenInWords Etsy Shop
What date is processed?: name, address, email and payments.
Lawful/Legal basis for recording the data, to process orders made by customers.
WovenInWords Social Media Accounts ( facebook, instagram)
What data is processed?: names only.
WovenInWords uses social media accounts to allow people to find my etsy shop. No orders are processd this way. All customers are redirected to my Etsy shop.
Lawful/Legal basis for recording data, to help process orders.
*Payment Processing
All payments that are taken for orders are processed by third party websites, either etsy or paypal.
*Third Party Websites (etsy and paypal)
These sites are governed by their own privacy statements and WovenInWords are not responsible for any of their operations, including, but limited to, their information practices. Users submitting information to or through these third party websites, should review the privacy statements of these sites, before providing them with any personal information.
All information I use as part of WovenInWords is viewed and processed, either using my laptop, which has a password system to be accessed, or my Ipad, which is passsword protected. Passwords are quite often changed.
*Data Sharing: NO data is shared with anyone.
*DISCLOSURE
Any data required or held by me is secure and held only by myself and it will not be distributed to any third parties, unless it is legally required by HMRC, should they request to see my accounts
You may request details of personal information which I hold about you and you may ask for them to be deleted, unless I am required to keep them legally for my accounts.
*RETENTION OF DATA
I do not retain customers information any longer than is required, but I will retain the following information for my accounts/HMRC
+ What data is processed?: documentation required for preparing accounts for HRMC
+ Data refers to: invoices, receipts and payments from customers.
+ Lawful/Legal basis for recording data: The legal basis for processing this data is a 'legal obligation' because it is required by HRMC
+ Data sharing: it will only be shared with HMRC on request.
+ Data storage: The documents are stored securely in paper/online format.
+ Data retention: HMRC state 'I must keep records for at least 5 years after the 31st January submission deadline of the relevant tax year'. HM revenue and customs (HMRC) may check my records to make sure the right amount of tax has been paid.
+ Data destruction: after the required length of time, all documents are shredded or securely deleted.
All other data collected, if not required lawfully, is deleted when no longer required.
DATA BREACHES
I would be obligated to notify the relevant authorities of any data breach within 72 hours of becoming aware of any breach. We understand the high fines in place for failing to follow the correct procedures for a breach of data.