Jolly Good Photo Co. is committed to protecting the privacy and personal data of our clients. This Data Protection and GDPR Compliance Policy outlines how we handle, process, and protect personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, you acknowledge and agree to the practices described in this policy.
Data Controller and Contact Information
Jolly Good Photo Co. acts as the data controller for the personal data we collect and process. If you have any questions, concerns, or requests related to your personal data, please contact us using the contact information provided at the end of this policy.
Collection and Use of Personal Data
a. Purpose and Lawful Basis: We collect and process personal data solely for the purpose of providing our photography services. The lawful bases for processing personal data include the necessity of processing for the performance of a contract, compliance with legal obligations, and legitimate interests pursued by Jolly Good Photo Co.
b. Types of Personal Data: The personal data we collect may include, but is not limited to, names, contact information (such as email addresses and phone numbers), event details, and any other information necessary for the provision of our services.
c. Consent: We will obtain explicit consent from individuals before processing their personal data if required by law.
Data Retention and Storage
a. Retention Period: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements.
b. Security Measures: We implement appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction. We regularly review and update our security practices to ensure the ongoing confidentiality, integrity, and availability of personal data.
Sharing of Personal Data
a. Third-Party Service Providers: We may share personal data with third-party service providers who assist us in delivering our services, such as payment processors and photo printing labs. These service providers are contractually obligated to handle personal data securely and only for the purposes specified by Jolly Good Photo Co.
b. Legal Compliance: We may disclose personal data if required by law or in response to valid legal requests, such as subpoenas or court orders.
Rights of Data Subjects
a. Right to Access: Individuals have the right to request access to their personal data held by Jolly Good Photo Co. We will provide the requested information within the timeframe required by applicable law.
b. Right to Rectification and Erasure: Individuals have the right to request the correction or deletion of inaccurate or incomplete personal data.
c. Right to Restriction and Objection: Individuals may request the restriction of processing or object to the processing of their personal data under certain circumstances.
d. Right to Data Portability: Upon request, we will provide individuals with a copy of their personal data in a structured, commonly used, and machine-readable format, where technically feasible.
e. Right to Withdraw Consent: If we rely on consent as the lawful basis for processing personal data, individuals have the right to withdraw consent at any time.
International Data Transfers
If personal data is transferred to a country outside the European Economic Area (EEA), we will ensure that appropriate safeguards are in place to protect the data in accordance with applicable data protection laws.
Data Breach Notification
In the event of a data breach that poses a risk to individuals' rights and freedoms, we will promptly assess and notify the appropriate supervisory authorities and affected individuals, as required by applicable law.
Privacy by Design and Data Protection Impact Assessment (DPIA)
We implement privacy by design principles and conduct DPIAs where necessary to identify and mitigate any potential risks to individuals
Last updated: May 2023
Data Controller and Contact Information
Jolly Good Photo Co. acts as the data controller for the personal data we collect and process. If you have any questions, concerns, or requests related to your personal data, please contact us using the contact information provided at the end of this policy.
Collection and Use of Personal Data
a. Purpose and Lawful Basis: We collect and process personal data solely for the purpose of providing our photography services. The lawful bases for processing personal data include the necessity of processing for the performance of a contract, compliance with legal obligations, and legitimate interests pursued by Jolly Good Photo Co.
b. Types of Personal Data: The personal data we collect may include, but is not limited to, names, contact information (such as email addresses and phone numbers), event details, and any other information necessary for the provision of our services.
c. Consent: We will obtain explicit consent from individuals before processing their personal data if required by law.
Data Retention and Storage
a. Retention Period: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements.
b. Security Measures: We implement appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction. We regularly review and update our security practices to ensure the ongoing confidentiality, integrity, and availability of personal data.
Sharing of Personal Data
a. Third-Party Service Providers: We may share personal data with third-party service providers who assist us in delivering our services, such as payment processors and photo printing labs. These service providers are contractually obligated to handle personal data securely and only for the purposes specified by Jolly Good Photo Co.
b. Legal Compliance: We may disclose personal data if required by law or in response to valid legal requests, such as subpoenas or court orders.
Rights of Data Subjects
a. Right to Access: Individuals have the right to request access to their personal data held by Jolly Good Photo Co. We will provide the requested information within the timeframe required by applicable law.
b. Right to Rectification and Erasure: Individuals have the right to request the correction or deletion of inaccurate or incomplete personal data.
c. Right to Restriction and Objection: Individuals may request the restriction of processing or object to the processing of their personal data under certain circumstances.
d. Right to Data Portability: Upon request, we will provide individuals with a copy of their personal data in a structured, commonly used, and machine-readable format, where technically feasible.
e. Right to Withdraw Consent: If we rely on consent as the lawful basis for processing personal data, individuals have the right to withdraw consent at any time.
International Data Transfers
If personal data is transferred to a country outside the European Economic Area (EEA), we will ensure that appropriate safeguards are in place to protect the data in accordance with applicable data protection laws.
Data Breach Notification
In the event of a data breach that poses a risk to individuals' rights and freedoms, we will promptly assess and notify the appropriate supervisory authorities and affected individuals, as required by applicable law.
Privacy by Design and Data Protection Impact Assessment (DPIA)
We implement privacy by design principles and conduct DPIAs where necessary to identify and mitigate any potential risks to individuals
Last updated: May 2023