Privacy Policy
We think the world of you. You buy from us, you work alongside us and you sell things to us. We take our responsibility seriously; to ensure your privacy, when it comes to what you tell us and that we get to now about you. This Privacy Policy tells you about how we process your information and what your rights are.
The Herring Girl Collection
Our Contact Details
Name: The Herring Girl Collection
Address: 243 Bruernish, Northbay, Isle of Barra HS9 5UY
Phone Number: 07479 499 813
E-mail: bruernish@hotmail.co.uk
​
The type of personal information we collect
We currently collect and process the following information:
-
Personal identifiers, contacts and characteristics (for example, name and contact details)
-
If you contact us directly, written correspondence and summaries of telephone conversations and other verbal communication may be collected.
-
Information relating to payments for services or products purchased including the amount of the payment the payment dates, the service or product purchased, the date of despatch of the product and whether payment was accepted or rejected by the third-party payment gateway.
-
Information provided to The Herring Girl Collection or gathered by The Herring Girl Collection during the performance of the contracted consultancy and other services.
-
Financial information required to make payments to suppliers and to receive payments from customers.
How we get the personal information and why we have it
​
Most of the personal information we process is provided to us directly by you for one of the following reasons:
-
To ensure successful delivery of services and/or products ordered from us.
-
To ensure effective communication with our customers. For example, to discuss specific requests and commissions for work to be undertaken.
-
To ensure that we are able to respond effectively to enquiries from customers and former customers.
-
To ensure effective inventory management.
​
We also receive personal information indirectly, from the following sources in the following scenarios:
-
When you visit, download, and/or use any of the services on our website or social media presence, we may collect aggregated usage Personal Information, such as Visitors’ and Users’ browsing and ‘click-stream’ activity on these platforms, session heatmaps and scrolls, non-identifying Personal Information regarding the Visitor’s or User’s device, operating system, internet browser, screen resolution, language and keyboard settings, internet service provider, referring/exit pages, date/time stamps, etc
-
We may receive Personal Information about you from third-party sources, such as security providers and fraud detection / prevention providers for example to help us screen out fraudulent purchases.
-
We may use Google products including: Google Analytics and Google Search Console. We use these products to understand how the website is being used in order to improve the user experience. User data is all anonymous. The types of data collected includes: IP address, browser-generated information e.g. browser type, operating system, date and time of access, how long a person looks at a website, what they look at etc. Click here for an overview of Google’s privacy policies.
We use of several communications systems which gathers Personal Information which is processed in accordance with the following policies
-
Microsoft Teams – https://docs.microsoft.com/en-us/microsoftteams/teams-privacy.
-
Zoom – https://zoom.us/docs/en-us/privacy-and-security.html.
We use the information that you have given us in order to understand your needs and provide you with a better service, and in particular for the following reasons:
-
To deliver the products and services you have ordered.
-
To improve our products and services.
-
From time to time, we may also use your information to contact you. We may contact you by email, phone or mail.
We may share this information with parcel delivery organisations or payment processing organisations, for the purpose of fulfilling our contractual obligations.
We use a number of third-party professional services providers, necessary to run our business, such as IT, and Internet Service Providers, web developers, financial and legal professional services suppliers. Your information will be shared with these service providers where necessary to provide you with the service you have requested, whether that is accessing our website or ordering goods and services from us.
​
We do not display the identities of our service providers publicly by name for security and competitive reasons. If you would like further information about the identities of our service providers, however, please contact us directly by email and we will provide you with such information where you have a legitimate reason for requesting it and where we have shared your information with such service providers.
Lawful basis for processing
Under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018, the lawful bases we rely on for processing this information are:
1. Your consent.
Where your personal data is processed by us on the lawful basis of consent, you are able to remove your consent at any time. You can do this by contacting:
The Herring Girl Collection
243 Bruernish
Northbay
Isle of Barra
HS9 5UY
Or
2. We have a contractual obligation.
3. We have a legal obligation.
4. We have a legitimate interest.
How we store your personal information
Your information is securely stored in the information systems of The Herring Girl Collection in the United Kingdom and elsewhere as described in this section of this Privacy Policy.
Information gathered via the website as described in the “How we get the personal information” section of this policy above may be processed in the United States of America, Ireland, Japan and Israel. This information will be stored securely in accordance with the Wix.com Ltd. privacy and security policy – https://www.wix.com/about/privacy
Information provided by you and to you while you are outwith the EU will be transferred outwith the EU.
Retention and disposal
We keep:
-
Financial Records for a period of 8 Years (7 Years from the end of the financial year in which any financial record relates)
-
Information relating to services delivered or items purchased for a period of 3 years following the period when any potential warranty, liability or claim has expired in relation to the provision of such a product or service.
-
General correspondence to and from a data subject for a period of 3 Years after the last date when correspondence has been received from that data subject.
We will then dispose of your information by running an audit no less than annually of our live information systems and delete personal data which has gone beyond the retention periods described above. Personal Data contained in Backup data storage shall only be deleted or destroyed and rendered inaccessible when those back-ups are scheduled for deletion. In the event of data being required to be restored from back-up devices, an audit of the restored data shall be carried out as soon as reasonably possible to ensure that any restored data that has passed the stated retention period can then be deleted.
Your data protection rights
Under data protection law, you have rights including:
-
Your right of access – You have the right to ask us for copies of your personal information.
-
Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
-
Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.
-
Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances.
-
Your right to object to processing – You have the right to object to the processing of your personal information in certain circumstances.
-
Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
-
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us at the Registered Address above or Bruernish@hotmail.co.uk if you wish to make a request.
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us at the Registered Address above or Bruernish@hotmail.co.uk
You can also complain to the ICO if you are unhappy with how we have used your data.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk