This policy explains how we handle your personal data and what you can do if you have any concerns.
At CORGI Fenestration we are committed to protecting and respecting your privacy.
This policy sets out the basis on which any personal data we collect from you, that you provide to us or that we may receive from others about you will be processed by us. It includes data that we hold electronically and in paper files.
We are required to provide you with this information under the General Data Protection Regulation (GDPR).
We will process data to deliver the services CORGI Fenestration has contracted to provide you with. These include administration of registration, provision of technical updates, promotion and administration of events, and the promotion and administration of CORGI Fenestration.
Legal Basis for processing Data
The GDPR come into force on 25 May 2018. The legal bases for the processing of this data will be under the following paragraphs of the GDPR: Article 6 1.(b), the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering
into a contract, and Article 6 1.(f), it is in the legitimate interests of the data controller.
Our legitimate interest is the need to properly administer your registration and to provide you with all the services and information necessary. Safeguards have been put in place to ensure we achieve the correct balance between our interests and yours.
Who has access and Why
Data will be held and processed for the purposes of administrating your registration. Only those staff who have a legitimate need to access data will be authorised to do so.
Retention of Data
Data will be stored for certification and registration purposes and will be held for the duration of your registration period plus for a period of 10 years from your leaving the scheme for whatever reason.
From time to time we will invite you to check that everything is correct and up to date. You can contact us at email@example.com at any time to verify your details.
Right of Access
You have the right to know what information we hold about you. Unless the issue is complex, we will respond within one month.
Right to Rectification
You have the right to have any information we hold about you corrected if it is inaccurate or incomplete. Unless the issue is complex, we will respond within one month.
Right to Erasure
You have the right to request the deletion or removal of personal data where there is no compelling reason for us to continue to hold it.
Right to Restrict Processing
You have the right to restrict our processing of your data in certain circumstances, such as when there is a question over the way in which we are using it.
Right to Data portability
You have the right to obtain and reuse your personal data for your own purposes.
Right to object
You have the right to object to our processing of your personal data on the basis of legitimate interest, for direct marketing and for the purposes of research. We will stop processing your data on the basis of legitimate interest unless there are compelling legitimate grounds for us to continue. We will stop any processing of your data for direct marketing as soon as we receive an objection.
We will not make any decision regarding you or your registration by purely automated means.