Privacy & GDPR
Privacy & GDPR Policy
1. Introduction
Stratum Marquetry is committed to protecting and respecting your privacy. This GDPR policy outlines how we collect, use, store, and protect personal data in compliance with the General Data Protection Regulation (GDPR).
2. Data Collection
Personal Data Collected: We collect the following personal data: names, addresses, emails, and phone numbers.
Method of Collection: Data is collected through our website via a newsletter sign-up form and a contact form for bespoke project inquiries.
Sensitive Data: We do not collect any sensitive personal data such as health information, racial or ethnic origin, or political opinions.
3. Data Usage
Primary Purpose: The primary purpose of collecting personal data is to contact clients after they have made an inquiry or to send products they have purchased.
Secondary Purpose: We do not use personal data for any secondary purposes, such as analytics or customer profiling.
4. Data Sharing
We do not share personal data with any third parties. All data collected is used solely within Stratum Marquetry for the purposes outlined above.
5. Data Storage
Storage Method: Personal data is stored in client folders on our Google Drive, which is password protected. Access is restricted to the two directors of Stratum Marquetry.
Data Retention: Client folders are archived once a job is completed and retained for reference. Data is not deleted unless requested by the client.
6. Data Security
Security Measures: We use Google Drive to store personal data. This platform is password protected, and access is limited to authorized Google accounts. We rely on Google's security protocols, which include encryption and access controls.
Website Security: Our website, hosted on Squarespace, follows their data privacy and security measures.
7. Data Subject Rights
Access, Correction, and Deletion: Individuals have the right to access their personal data, request corrections, or ask for their data to be deleted. Requests can be made via our contact page or by emailing hello@stratummarquetry.co.uk.
Contact for Queries: For any data protection queries, please contact Stratum Marquetry Ltd co-founder, Dan Burke Thomson, via our website contact form or at hello@stratummarquetry.co.uk.
8. International Data Transfers
We do not transfer personal data outside of the European Economic Area (EEA).
9. Website and Cookies
Cookies and Tracking: Our website uses cookies and tracking technologies to improve user experience. Visitors to our website are presented with a cookie consent banner that allows them to accept or deny cookies.
Cookie Consent: Information about the types of cookies used and how to manage consent is available on our website.
10. Data Breach Response
Detection and Reporting: We use platforms like Squarespace and Google Drive, both of which have their own data privacy and security policies. In the event of a data breach, we will follow the procedures outlined by these platforms, including notification to affected individuals if necessary.
11. Data Protection Officer (DPO)
Responsible Person: Dan Burke Thomson, one of the directors of Stratum Marquetry, is responsible for GDPR compliance and data protection matters.
12. Policy Review
This GDPR policy will be reviewed annually or as necessary to reflect any changes in legislation or our business practices.
Approval: This policy has been approved and adopted by the directors of Stratum Marquetry.
