This website is brought to you by Laura Sorvala t/a Auralab (“I”, “me” or “mine”). I am a sole trader based in the UK and have an office at F36 Meanwhile House Cardiff, Curran Embankment, Cardiff CF10 6DY, Wales.
I may update this Policy from time to time in accordance with the “Changes to this Policy” section below.
References in this Policy to:
- “Data Protection Law” means: the Data Protection Act 1998 (until repealed) (“DPA”), the Data Protection Directive (95/46/EC) (until repealed) and, from 25 May 2018, the General Data Protection Regulation 2016/679 (“GDPR”) or any equivalent provision which may replace the GDPR following the formal political separation of the United Kingdom from the European Union; the Regulation of Investigatory Powers Act 2000; the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 (SI 2000/2699); the Electronic Communications Data Protection Directive (2002/58/EC); the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2426/2003); and all applicable laws and regulations which may be in force from time to time relating to the processing of Personal Data and privacy, including where applicable the guidance and codes of practice issued by the Information Commissioner or any other supervisory authority, and the equivalent of any of the foregoing in any relevant jurisdiction; and
- “Personal Data”, “Data Controller”, “Data Processor” and “processing” shall have the meanings given to them in the DPA or, from 25 May 2018, the GDPR.
For the purposes of applicable Data Protection Law, I (Laura Sorvala t/a Auralab) am the Data Controller and therefore I am responsible for, and control the processing of, your Personal Data in accordance with applicable Data Protection Law. “Personal Data” has a legal definition but, in brief, it refers to information from which a living person can be identified. Such information must be protected in accordance with Data Protection Law.
Information I may collect about you
I will collect information about you when you visit my website or do business with me through my website (including ordering services from me). This information may include your name, your contact details (including postal address, email address and telephone number), your payment details (i.e. relating to any payment you make to me in connection with my services), any other information I request from time to time to enable me to provide my Site and services to you, and any other information you provide to me (together the “Information”). Some of the Information may constitute or include Personal Data.
Occasionally I may receive information about you from other sources, which I will add to the information I already hold about you in order to help me provide goods and services and to improve my service to you.
Additionally I may collect information on your use of my site such as pages visited, links clicked, as well as information more commonly collected such as the referring URL, browser, operating system, cookie information, and Internet Service Provider (“Usage Data”). My purpose in collecting Usage Information is to better understand how users navigate and use this Site.
How long I keep your information
I will keep your Information only for as long as I need to hold it for the purposes set out in this policy. However, if required I will be entitled to hold Information for longer periods in order to comply with my legal or regulatory obligations. I conduct regular checks to ensure no personal data is kept longer than necessary.
Legal basis for processing your information
From 25 May 2018, under applicable Data Protection Law I may only process your Information if I have a “legal basis” (i.e. a legally permitted reason) for doing so. For the purposes of this Policy, my legal basis for processing your Information is:
- your consent (for which see below); or
- subject to your rights set out below (see “Your Rights”), the legitimate interest of providing services to my customers, which requires the processing of your Information to enable me to provide these services.
Your consent to processing
As noted above, you will be required to give consent to the processing of your Information as set out in this Policy. I will seek this consent from you when you first submit Information to or through the Site. If you do not consent to such processing you should not submit any Information to or through the Site.
If you have previously given consent you may freely withdraw such consent at any time. You can do this by notifying me in writing using my contact details below.
If you withdraw your consent, and if I do not have another legal basis for processing your information (see above), then I will stop processing your Information. If I do have another legal basis for processing your information then I may continue to do so subject to your legal rights (for which see “Your Rights” below).
Please note that if I need to process your Information in order to provide our services, and you object or do not consent to me processing your Information, those services may not be available to you.
How I use your Information
I will use your Information for the following purposes:
- administration of user account and any goods or services my users order from me;
- marketing (see ‘Marketing and opting out’ below);
- fraud prevention and detection;
- billing and order fulfilment;
- to notify you of any changes to my services that may affect you; and
- improving my services.
Marketing and opting out
Laura Sorvala t/a Auralab rarely uses direct marketing with customers. In the future, if you have given permission, I may wish to provide you with information by email about services I think may be of interest to you. I will inform you (before collecting your data) and seek your permission if I intend to use your data for such purposes. If you would rather not receive this marketing information, or you no longer wish to receive it, you can always decline and/or opt out (see below).
You have the right at any time to ask me to stop processing your Information for direct marketing purposes. If you wish to exercise this right, you should contact me by sending an email to laura (at) auralab.co.uk, giving me enough information to identify you and deal with your request. Alternatively you can follow the unsubscribe instructions in any direct marketing emails you might receive from me.
Disclosure of your information
I may disclose your Information (including Personal Data) to:
- my agents and service providers who help me to provide my services (and I will ensure they have appropriate measures in place to protect your Information);
- law enforcement agencies and/or HMRC in connection with any investigation to help prevent unlawful activity; and
I may disclose aggregated, anonymous information (i.e. information from which you cannot be personally identified), or insights based on such anonymous information, to selected third parties, including (without limitation) analytics and search engine providers to assist me in the improvement and optimisation of the Site. In such circumstances I do not disclose any information that can identify you personally.
Keeping your Information secure
I will use technical and organisational measures in accordance with good industry practice to safeguard your Information. However, while I will use all reasonable efforts to safeguard your Information, you acknowledge that the use of the internet is not entirely secure and for this reason I cannot guarantee the security or integrity of any Information that is transferred from you or to you via the internet.
I may monitor and record communications with you (such as emails) for the purpose of quality assurance, fraud prevention and compliance. Any information that I receive through such monitoring and communication will be added to the information I already hold about you and may also be used for the purposes listed in above.
Information about other individuals
If you give me information on behalf of a third party, you confirm that the third party has appointed you to act on his/her/their behalf and has agreed that you can:
- give consent on his/her/their behalf to the processing of his/her/their Information;
- receive on his/her/their behalf any data protection notices; and
- give consent to the transfer of his/her/their Information abroad (if applicable).
From time to time I may need to transfer your Information to countries outside the European Economic Area, which comprises the EU member states plus Norway, Iceland and Liechtenstein (‘EEA’). Such countries may not have similar protections in place regarding protection and use of your data as those set out in this Policy. Therefore, if I do transfer your Information to countries outside the EEA I will take reasonable steps in accordance with applicable Data Protection Law to ensure adequate protections are in place to protect the security of your Information.
By submitting your Information to me in accordance with this Policy you consent to these transfers for the purposes specified in this Policy.
If you are an individual, this section sets out your legal rights in respect of any of your Personal Data that I am holding and/or processing. If you wish to exercise any of your legal rights you should put your request in writing to me (using my contact details in clause 22 below) giving me enough information to identify you and respond to your request.
- You have the right (which up until 25 May 2018 may be subject to the payment of a small fee) to request information about Personal Data that I may hold and/or process about you, including: whether or not I am holding and/or processing your Personal Data; the extent of the Personal Data I am holding; and the purposes and extent of the processing.
- You have the right to have any inaccurate information I hold about you be corrected and/or updated. If any of the Information that you have provided changes, or if you become aware of any inaccuracies in such Information, please let me know in writing giving me enough information deal with the change or correction.
- You have the right in certain circumstances to request that I delete all Personal Data I hold about you (the ‘right of erasure’). Please note that this right of erasure is not available in all circumstances, for example where I need to retain the Personal Data for legal compliance purposes. If this is the case I will let you know.
- You have the right in certain circumstances to request that I restrict the processing of your Personal Data, for example where the Personal Data is inaccurate or where you have objected to the processing (see below).
- You have the right to request a copy of the Personal Data I hold about you and to have it provided in a structured format suitable for you to be able to transfer it to a different data controller (the ‘right to data portability’). Please note that the right to data portability is only available in some circumstances, for example where the processing is carried out by automated means. If you request the right to data portability and it is not available to you I will let you know.
- You have the right in certain circumstances to object to processing of your Personal Data. If so, I shall stop processing your Personal Data unless I can demonstrate sufficient and compelling legitimate grounds for continuing the processing which override your own interests.
- You have the right in certain circumstances not to be subject to a decision based solely on automated processing, for example where a computer algorithm (rather than a person) makes decisions which affect your contractual rights. Please note that this right is not available in all circumstances. If you request this right and it is not available to you I will let you know.
- You have the right to object to direct marketing, for which see (‘Marketing and opting out’) above.
If you have any concerns about how I collect or process your Information then you have the right to lodge a complaint with a supervisory authority, which for the UK is the UK Information Commissioner’s Office (‘ICO’). Complaints can be submitted to the ICO through the ICO helpline by calling 0303 123 1113. Further information about reporting concerns to the ICO is available at https://ico.org.uk/concerns/.
- provide you with a good experience when you access my website;
- improve my website; and
- compile statistical reports on website visitors and website activity.
My software will issue cookies to your system when you access and use the Site and you will be asked to consent to this at the time (e.g. when you first visit our website). Cookies do not affect your privacy and security since a cookie cannot read data off your system or read cookie files created by other sites. You can set your system not to accept cookies if you wish (for example by changing your browser settings so cookies are not accepted), however please note that some of our Site features may not function if you remove cookies from your system.
If you access the Site via a mobile application or other software application then you will be required to accept this Policy, including these provisions relating to cookies, as part of the sign-up process.
Changes to this Policy
I keep this Policy under regular review and may change it from time to time. If I change this Policy I will post the changes on this page, and place notices on other pages of the website as applicable, so that you may be aware of the Information I collect and how I use it at all times. You are responsible for ensuring you are aware of the most recent version that will apply each time you access this website. This Policy was last updated on 17/05/2018.
Links to other websites
My website contains links to other websites. This Policy only applies to this website. If you access links to other websites any Information you provide to them will be subject to the privacy policies of those other websites.
This Policy aims to provide you with all relevant details about how I process your Information in a concise, transparent, intelligible and easily accessible form, using clear and plain language. If you have any difficulty in reading or understanding this Policy, or if you would like this Policy in another format (for example audio, large print or braille), please get in touch with me.
My contact details
I welcome your feedback and questions. If you wish to contact me, please send an email to firstname.lastname@example.org or you can write to me at Laura Sorvala, Auralab, F36 Meanwhile House Cardiff, Curran Embankment, Cardiff CF10 5DY, Wales. Or you can contact me on +44 (0) 7793 216257.