I am committed to respecting and protecting any personal data I collect.
When do I collect personal data about you?
There are several reasons why I may have personal data about you:
- If you have signed up to my mailing list via my website.
- If you have signed up to my mailing list by writing your email address in my book when attending a workshop or other event.
- If you have emailed or phoned me to ask to be added to my mailing list.
- If you have made a purchase from my website or set up an account on my website.
- If you have made a purchase from me via Etsy or Folksy.
- If you have commissioned work from me via a retailer (for example Bespoke Global or Architectural Plants).
- If you have commissioned work directly from me via email or phone calls.
- If you have purchased products from me at an event and paid by credit or debit card.
- If you visit my website the host (Shopify) will collect information on my behalf about which pages you visit and how long you spend on the site using cookies.
What personal data do I hold about you?
- If you have signed up to my mailing list you will have provided first name, last name and email address. My mailing list is managed by Mailchimp who collect data about your responses to my emails.
- If you have commissioned work from me directly you will usually have given me your first name, last name, email address, phone number and postal address.
- If you have commissioned work from me via a retailer and the retailer has asked me to deliver the item to you, they may have passed on to me your first name, last name, email address, phone number and postal address.
- If you have made a purchase from me via Etsy or Folksy, they will have passed on to me your first name, last name, email address, phone number and postal address.
- If you have visited my website I will have collected information including your IP address, browser type and version, operating system and platform, and information about how you use my website.
- If you have made a purchase via my website or set up an account via my website you will have given me your first name, last name, email address, phone number, postal address, log in data and payment card details. I will also have recorded what products you have purchased, when you purchased them and what you paid.
- If you have purchased products from me at an event and paid by credit or debit card, then PayPal will have collected payment card data and transaction information on my behalf. If, at the time of the transaction, you opted to receive an email or text receipt, then you will have given me your email address and/or phone number.
Why do I collect personal data about you?
I collect your personal data in order to:
- Send you newsletters by email approximately monthly to give you information about upcoming classes or events or to tell you about my products. I will only send you newsletters if you have subscribed to my mailing list. You can unsubscribe at any time by choosing ‘unsubscribe’ at the bottom of any email from me.
- Deliver products that you have bought from me.
- Market my products and services and monitor the efficacy of my website.
- Comply with legal obligations.
What is the basis for collecting & processing personal data?
To process your personal data, I rely on the following legal bases:
- To fulfil the obligations of a contract I have with you (providing you with a product or service for which you have paid me).
- To comply with a legal obligation to which I am subject (such as tax obligations).
- To further my legitimate business interests, provided that such processing does not outweigh your rights and freedoms.
If I use your personal data for a purpose to which the above legal bases would not apply (for example sending you marketing communications), I will first seek your consent to do so.
Sharing your personal data
I will never sell any of your personal data.
I will not share your personal data with any other organisation or individual except as may be required by law and with the following third parties who process data on my behalf:
- My mailing list is maintained by Mailchimp (US – Privacy Shield compliant)
- My website host is Shopify. Shopify processes all purchases via my website including financial transactions.
- I have an online shop maintained by Etsy.
- I have an online shop maintained by Folksy.
- I use PayPal to process payments through my Etsy and Folksy shops, when accepting card payments at events and occasionally to invoice customers for commissions.
- If I am using a courier to deliver a product that you have purchased from me, I will need to pass on to them your name, phone number and postal address.
How long do I keep your personal data?
I keep your personal data for no longer than is reasonably necessary to comply with my obligations to you and what the law requires, and to satisfy any accounting or reporting requirements. This means I will generally need to retain your details for a maximum of 6 years after your last transaction or other recorded interaction with us.
In determining the retention period of all personal data, I take into account the amount, sensitivity and potential risk to you of any unauthorised disclosure and aim to minimise both the amount of personal data I hold and the duration we retain it.
If you have given your consent for me to send you marketing communications (i.e. subscribed to my mailing list), I will continue to hold the minimum amount of personal data to allow me to do so either until you withdraw your consent or I cease to send out marketing emails whichever comes first.
What if I do not want to provide my personal data?
I need to collect a certain amount of information about you in order to provide the products and services I offer. If you decline to provide the personal data I require I will not be able to enter any contract with you to provide products or services.
You have the following rights with respect to your personal data:
- The right to request a copy of the personal data which I hold about you;
- The right to request that I correct any of your personal data if it is found to be inaccurate or out of date;
- The right to request your personal data is erased where it is no longer necessary to retain it;
- The right to withdraw your consent (where relied on) for me to process any of your personal data;
- The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
- The right to object to the processing of personal data; and
- The right to lodge a complaint with the Information Commissioners Office (ICO).
You can contact the ICO on 0303 123 1113 or online or write to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire. SK9 5AF.
Exercising your rights
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, I may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, I may refuse to comply with your request in these circumstances.
To make sure personal data is not disclosed to anyone without the right to access it I may need to request specific information from you to help me confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). I may also contact you to ask you for further information in relation to your request to speed up my response.
I try to respond to all legitimate requests within one month. Occasionally it may take me longer than a month if your request is particularly complex or you have made a number of requests. In this case, I will notify you and keep you updated.
If I am processing your personal data based solely on your consent, you can withdraw your consent at any time by contacting us.
Cookies are text files placed on your computer to collect standard internet log information and visitor behaviour information. This information is used to track visitor use of the website and to compile statistical reports on website activity.
You can set your browser not to accept cookies and the above websites tell you how to remove cookies from your browser. However, in a few cases some of my website features may not function as a result.
My website contains links to other websites. When you link to other websites you should read their own privacy policies.
If you would like to contact me in respect of this policy or any personal data which I control, please do so via the following:
by email: firstname.lastname@example.org
by telephone: 01252 659134 or 0774 985 2229
Changes to this policy