Privacy Notice

A middle-aged Londoner (referred to as “I”, “me” or “my” in this Privacy Notice) respects your privacy and is committed to protecting your personal data. I am dedicated to being transparent about what data I collect about you and how I use it.

The purpose of this Privacy Notice

This Privacy Notice aims to provide you with information about how I collect and process your data. This includes what personal data I collect, how I use your data, how I ensure your privacy is maintained and your legal rights relating to your personal data.

It is important that you read this Privacy Notice together with any other documentation on specific occasions when I am collecting or processing personal data about you so that you are fully aware of how and why I am using your data.

What personal data do I collect?

Personal data, or personal information, means any information about an individual from which that person can be identified.

I may collect the following information about you:

-          Identity Data: title, first name, last name, age/date of birth and gender;

-          Contact Data: your contact details, postal address including billing and delivery addresses, telephone numbers and email addresses;

-          Your web browsing activities on my website;

-          Your communication and marketing preferences;

-          Your interests, preferences, feedback and survey responses;

-          Your correspondence and communication with me;

-          Publicly available personal data including information shared on social media platforms such as Twitter, Instagram and Facebook;

-          Your computer’s IP address;

-          Dietary information and/or any accessibility requirements  for events hosted by me.

This list is not exhaustive and in specific instances, I may need to collect additional data for the purposes set out in this Privacy Notice. Some of the above personal data is collected directly, i.e. volunteered by you when registering for information. Other personal data is collected indirectly, i.e. when you are browsing my website.

How do I use your personal data or personal information?

I will primarily use your personal data or personal information to provide a service to you. These may include but are not limited to:

a) Responding to queries;

b) To organise events and activities;

c) To tailor a product or service to you;

d) For marketing and promotional purposes;

e) To improve my products and services;

f) Resolve disputes, troubleshoot problems and enforce my agreements with you, including my website’s Terms of Use, and this Privacy Notice;

g) Informing you of any changes to my website, services or goods and products;

h) Enabling me to manage all interactions with you;

i) Where I have a legal right or duty to disclose your information (for example in relation to an investigation by a public authority or in a legal dispute).

Sensitive Data 

I may need to collect special category data about you. This is personal data that requires more protection because it is sensitive. I may use certain sensitive personal data only where you have given me your explicit consent to better serve and meet your needs. The data I collect may be concerning accessibility and dietary requirements to ensure health and safety at events and activities hosted by me.

The age of consent to data collection in the UK is 13 years of age. My website is not intended for children and I do not knowingly collect data relating to children under this age.

How do I collect your data?

I  may collect your personal data or information through the following ways:

-          Social media platforms such as Instagram, Facebook, Twitter etc.

-          Events and ticket platforms such as Eventbrite.

-          Email.

-          My newsletter.

-          Registration forms for events or activities hosted by me or with my partners.

-          Competitions/contests or sponsored special offers.

Marketing

Promotional communications:

Following your consent, I may use your personal data to provide promotional materials to you, e.g. via my newsletter and to provide updates on products and services which are of interest and relevant to you as an individual.

You have the right to opt out of receiving personal communications at any time by:

  1. Clicking the “unsubscribe” link at the bottom of emails.

  2. Contacting me directly via the contact details within this Privacy Notice.

Usage Data

I may process data about your use of my website and services (“usage data”). The usage data may include your IP address, location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing and pattern of your service use. This is used to allow me to process and analyse the use of my website.

Legal basis for using your data

I am required to set out the legal basis for my processing of your personal data.

I collect and use your personal and sensitive data as necessary and where you have consented.

You have the right to withdraw your consent at any time. Where consent is the only legal basis for processing, I will cease to process data after consent is withdrawn.

My legitimate interests

Your data is processed on the basis of it being necessary for my legitimate interests

 which include:

-          Promoting, marketing and advertising my products and services;

-          Sending promotional communications which are relevant and tailored to my website users; and

-          Improving existing products and services and developing new products and services.

 Sharing data with Third Parties  

My service providers and suppliers

To make certain services available to you, I may need to share your personal data with some of my service partners, including delivery and marketing service providers.

I  only allow my service providers to handle your personal data when I have confirmed that they apply appropriate data protection and security controls. I do not allow my third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with my instructions.

I may share your personal data or personal information with the following third parties:

-          Squarespace; Google Workplace;

-          Social media platforms such as Instagram, Facebook etc.;

-          Ticket platforms such as Eventbrite;

-          Google Analytics.

Other third parties

Aside from my service providers, I will not disclose your personal data to any other third party, except for those set out below:

-          Third-party marketing partners such as Google or Facebook (to deliver advertising);

-          I might store your information on all or some of the following: Mailchimp, Gmail and Google Drive.

I will never sell or rent your data to other organisations for marketing purposes. 

My website may include links to third-party websites, plug-ins and applications. Clicking on these links or enabling these connections may allow third parties to collect or share data about you. I do not control these third-party websites and am not responsible for their Privacy Notices. When you leave my website, I encourage you to read the Privacy Notice of every website you visit.

International transfers

To deliver products and services to you, it may be necessary for me to share your data outside of the United Kingdom (“UK”). This will occur when service providers are located outside the UK. I  shall ensure a similar degree of protection is afforded to your data when using these service providers.

How I protect your data

I am committed to keeping your personal data safe and secure. I have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised, altered or disclosed way.   

The measures I have implemented are:

-          Strong passwords;

-          Two-factor authentication; and

-          Controlled access.

Where I  store your data

When storing data, I may use the following systems:

-          Google Drive attached to Google Workspace;

-          Mailchimp

I  will strive to protect your data by means that are reasonably required. However, no internet website can be 100% secure and so I cannot be held responsible for unauthorised or unintended access that is beyond my control.

I  have appropriate measures in place to deal with any personal data breaches and will notify you and any applicable regulator body of a breach where I am  legally required to do so.

How you can help me protect your data

I  will never ask you to confirm any bank account or credit card details via email. If you receive an email claiming to be from me asking you to do this, please ignore it and do not respond.

How long do I keep your data?

I will only retain your personal and sensitive data for as long as necessary for the purpose I collected it for. The longest I will normally hold any personal and sensitive data is one year. I will hold personal data or information derived from my newsletter subscribers on MailChimp  until the subscriber(s) opts out of my mailing list.

If you no longer wish for me  to hold your information, you can contact me (see rights below). However, please note I have a legal requirement to keep some of your personal data even after you have asked me to delete it. This ensures that I can meet my legal or regulatory requirements, resolve disputes, prevent fraud or enforce my contract with you.

It is important that the personal data I hold about you is accurate and current. Please keep me  informed if your personal data changes during your relationship with me.

Your rights in respect of your data

You have rights relating to your personal information, these are:

-          To ask for a copy of the personal data that I hold about you and check that I am lawfully processing it (right to access);

-          To request that I delete or remove personal data held on you, where I no longer have any legal reason to retain it (right of erasure). Note: I may not always be able to comply with your request for erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request;

-          To ask me to update and correct any incomplete or inaccurate personal data that I hold about you (right of rectification);

-          To opt out of any marketing communications that I may send to you and to object to using/holding your personal data if I have no legitimate reasons to do so (right to object);

-          To ask me to restrict processing of data, this enables you to ask me to suspend the processing of your personal data (only in certain circumstances);

-          To ask me to supply you or a third party with some of the personal data I hold about you in a machine-readable format (right to data portability/transfer);

-          To withdraw consent at any time where I am relying on consent to process your personal data. If you withdraw your consent, I may not be able to provide services to you. I will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the above rights, please contact me using the contact details below.

You will not have to pay a fee to exercise any of the rights above. I may need to request specific information from you to help me confirm your identity. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

I will try to respond to all requests within one month. This may be longer if the request is complex, I will notify you if this is the case.

Cookies

I use cookies on my website. You can set your browser to refuse or block all or some of these cookies. Please note that if you disable or refuse cookies, some parts of my website may become inaccessible or not function properly. For more information on the cookies I use, please see my Cookie Policy.

Exercising your rights

Susan Sandford Smith is the data controller and is responsible for your personal data.

If you have questions about this Privacy Notice or want to exercise your rights, you may contact me using the details set out below.

Contact Details:

Email address: susie@amiddleagedlondoner.com

You have the right to lodge a complaint at any time with the Information Commissioner’s Office (ICO). You can find further information, including contact details at https://ico.org.uk.

Privacy Notice updates

This Privacy Notice was last updated on 16.08.21

I may update this Privacy Notice from time to time so please check this page occasionally to ensure you are happy with any changes to this Privacy Notice.