Privacy & Data Protection Policy
We have recently reviewed all of our policies to ensure full GDPR compliance – May 2018.
The nature of hosting a photography session will require us to collect some information in advance of the photoshoot to maximise safety of the photographs, especially those of children. For this reason we will at times ask for contact information to be supplied in advance of a photoshoot by yourself or the Organisation you are associated with.
The collection of this information confirms to the standard known as “legitimate interest” under GDPR and the welfare of children is one of the GDPR’s* foremost concerns, something we as a company take very seriously.
If you would like to know more about the information we collect and how we use it, you can review our privacy policy here and should you wish to change any data we hold on you personally, please complete the data change request form found here.
*as well as the PECR policy, which also plays a part in data collection, use and overriding safe handling considerations
Our Commitment To You
You are at the heart of everything we do. Our goal is to maintain your trust and confidence by handling your personal information with respect and putting you in control.
It’s important that you know what personal information Club Legends (known here as “we” or “Club Legends”) collects about you, and how we use it.
We’ve done our best to make our explanations short and easy to understand. But, if you’d like further information, or have any questions, please contact our Data Protection Officer using the details in the ‘Contact’ section below.
If we ever make any major changes to our privacy practices, we’ll let you know. If necessary, we’ll also ask for your permission.
Our Privacy Promise
Privacy Notice
Our Privacy Notice has been designed with you in mind. How the notice applies to you will depend on the way in which you interact with us. For example, if you:
- purchase a product from us, we will use the information you provide us to fulfil both our obligations to you in delivering that service, and, where permitted, keep you up to date about other events that may be of interest to you; and
- when you browse our sites, we use cookies to tailor your experience and hopefully provide you with a seamless experience.
Your choices and rights under each scenario are explained in more detail below, scroll down to read the full policy.
What Information We Have & Where We Get It
We collect and store different types of information about you when you create an account, buy products, contact us, and use our websites, apps and social media.
How We Use Your Information & Why
We collect and use your information for lots of reasons such as helping you get photos and products you love, sharing news, for marketing and as otherwise required by law.
Who We Share Your Data With & Why
We may share your information with the Event Partner(s) – such as the Photographers, Production Labs, Event Organisers, Event Venue – as well as other third parties associated with the service provided.
Your Choices & Rights
Among other rights, you can choose whether to receive marketing from us. You also have the right to access the information we have about you.
Looking After Your Information
We’re always taking steps to make sure your information is protected and to delete it securely when we no longer need it.
Contact Us
If you have any questions or feedback about this notice, or how we handle your information, get in touch with us.
What Information We Have & Where We Get It
- When you agree to attend, or your child attend a Photo Event, we will collect your contact information to ensure your/your Childs photos are kept safe and made available only to yourself. Under the terms of legitimate interests we may collect this in advance using information the Event Organiser holds on you already.
- When you create an account, buy a product or agree to have you or your child photographed by us, we will collect your information which depending on service we are providing, may include your contact and billing information.
- When you use our websites or apps, we collect information such as the browser and device you’re using, your IP address, your location, the site you came from, what you did and didn’t use our site/app for, or the site you visit when you leave us. For more information on how we collect this information, see our Cookies Policy.
- When you use a social media feature within our website or apps, and you post to social media platforms, the social media site will provide us with some information about you.
- If you have accessibility requirements, we want to make sure you have the best experience when attending events. To do this, we need to collect details of your requirements (which may involve you providing information about your mental or physical health).
- In the few instances where we collect personal information from children, we always seek parental consent and will only ever collect such information for the purposes specified when we collect it.
- Should you or your child be “at risk” or of “protected” status, please inform us in advance and we can advice you of the steps we take to maintain the security of these photos/products.
How We Use Your Information & Why
- For the performance of our contract with you
We use your information when you enter into a contract with us (for example to buy Photographs or a related products) so we can:- process your order
- take payment, and
- provide you with customer support.
- For our legitimate business interests
- To conduct market research and analysis which helps improve and customise our products and services.
- For our marketing purposes, unless your consent is required for such marketing (see section 3 below).
- To send you customer service emails including booking confirmations and event reminders.
- To prevent or detect unlawful behaviour, to protect or enforce our legal rights or as otherwise permitted by law. For example, making sure products get into the hands of the owners/parents/guardians.
- To ensure the security of our and our ‘Event Partners’
- Where you’ve given your consent
- To contact you with information or offers regarding our upcoming events, products or services – this may be via email, via push and web notifications, via SMS, or social media platforms. You can change your marketing preferences at any time, see “Your choices and rights” section below.
- To provide you with location based services, such as sending you notifications about what’s going on around you like special offers from other vendors in relation to the Event
- To deliver tailored advertising and marketing communications on our websites and apps (see our Cookies Policyfor more information).
- To process your health data to meet your accessibility requirements, where specifically required and explicit consent is provided.
Who We Share Your Data With & Why
- Within the Club Legends family of companies who provide services for us such as marketing, profiling, reporting and technical support.
- Our third-party service providers (sometimes known as data processors) such as cloud computing providers who provide the IT infrastructure on which our products and systems are built.
- We may share your information with our Event Partners so that they can run the event and for other reasons described in their privacy policies. We will always name the Event Partners when you purchase our products/register an account on our system and you will be given the option to subscribe to receiving marketing from them.
- Government agencies or other authorised bodies where permitted or required by law.
- Any successor to all or part of our business.
Marketing
We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you. We only use the data you provide to us directly for this purpose along with the Aggregated Data provided to us by our analytics partners and we do not track what other websites you may visit after visiting our site, though in common with most websites, we may register the site which referred you to our site (e.g. a search engine).
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
We generally only send electronic marketing – such as email marketing – to people who have previously bought similar products from us and this is in our legitimate interests. We will always offer a way out of receiving this marketing when you first purchase our products and in every marketing communication afterwards. We may on occasion send out postal marketing for the purpose of growing our sales which is in our legitimate interests and in this scenario we will rely on you to let us know if you do not want to receive this by opting out of marketing (see Opting out below).
Where you have not previously bought from us but have registered your details with us (for example by entering a competition or signing up for a newsletter), we will only send you marketing communications if you opted into receiving marketing at the time and so given us your express consent (which you may withdraw at any time – see Opting out below).
We may also share certain data with third party social media platforms in order to show you targeted ads when you visit them. We do this by:
- The use of cookies which capture your visits to our website. Please refer to our Cookies Policy for more information
- we may also provide these platforms with your email address to create ‘audiences’ of users fitting within a certain demographic/category so that we can target our marketing. Please check the social media platforms’ terms for more details of these services. This is in our legitimate interests of sending you direct marketing. See ‘Opting out’ below for details of how you can adjust your marketing preferences. Our Cookies Policy also explains how you can adjust your cookies preferences.
Opting Out
You can ask us to stop sending you marketing messages at any time by logging into your account and adjusting your marketing preferences, by following the opt-out links on any marketing message sent to you or by contacting us at any time.
If you opt out of receiving email marketing from us, we will no longer share your email address with social media platforms (see ‘External Third Parties’ below). However, you may continue to see our ads through them, due to their general demographic targeting. Please check the social media platforms for more detail of how to opt out from seeing these ads.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase, or related correspondence, and we will continue to process such data in accordance with this Privacy Policy and only ever as permitted by law.
Your Choices & Rights
Your choices
Where you have given us your consent, you can withdraw it by doing the following.
- To stop receiving our marketing you can contact us and we will do it for you.
- To opt out of the use of cookies and tracking tools, please see our Cookies Policy.
- To opt out of location tracking and push notifications, you can change the settings on your device or keep your location off. To stop web push notifications, you will need to use your browser settings.
- To object to personalisation you can change your preferences within your account. If this option is not available you can contact us and we will do it for you
Your rights
You also have rights over how your personal information is used including:
- The right to object to our processing of your data.
- The right to request that your information be erased or restricted from further use.
- The right to request a copy of the information we hold about you.
- The right to correct, amend or update information you have given us (where you have an account with us you can also do this by logging in and updating your information).
- The right to contest any automated decision we make about you. An automated decision is a decision taken without any human intervention which has legal consequences (e.g. credit checking). We don’t typically carry out automated decision making but, if we do, we will make it clear where such decisions are being made.
We have put together this table of data use scenarios and the impact of the use of this data:
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
To register you as a new customer | (a) Identity (b) Contact (c) Profile |
Performance of a contract with you. |
To process and deliver your order, including:
1. managing payments, fees and charges; and 2. managing your queries through our Customer Service team – this may include recording calls to our teams. |
(a) Identity (b) Contact (c) Financial (d) Transaction (e) Marketing and Communications |
Performance of a contract with you. We may also use some of the data related to your queries for our legitimate interests of ensuring our customer service quality standards are met. |
To collect and recover money owed to us in respect of your order | (a) Identity (b) Contact (c) Financial (d) Transaction |
Necessary for our legitimate interests (to recover debts due to us). |
To carry out fraud assessments | (a) Identity (b) Contact (c) Financial (d) Transaction (e) Technical |
Necessary for our legitimate interests of ensuring payments are not fraudulent |
To process your purchase of a gift voucher from us | (a) Identity (b) Contact (c) Financial (d) Transaction |
Performance of a contract with you. |
To notify you in relation to our legal obligations and documents, including changes to our terms or Privacy Policy | (a) Identity (b) Contact (c) Profile |
Necessary for our legitimate interests of ensuring our customers are updated on these changes. |
To help us improve our offering to our customers, including asking you to leave a review or take a survey, or provide customer insights | (a) Identity (b) Contact (c) Profile (d) Marketing and Communications |
Necessary for our legitimate interests (to study how customers use our products/services, to improve our offering to our customers, to develop them and grow our business). |
To enable you to partake in a prize draw or competition | (a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications |
Performance of a contract with you to fulfil the promotion and run the competition/prize draw. We may also subsequently use your entries for the legitimate interests of understanding our customer base more effectively. |
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | (a) Identity (b) Contact (c) Profile (d) Technical |
Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise). |
To deliver relevant website content, advertisements and other marketing material to you and measure or understand the effectiveness of the advertising we serve to you | (a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical |
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business to inform our marketing strategy and to improve our offering to you). Please note that where cookies are used for this purpose, this is covered separately by our Cookies Policy. |
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences | (a) Technical (b) Usage |
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy). Please note that where cookies are used for this purpose, this is covered by our Cookies Policy. |
To make suggestions and recommendations to you about goods or services that may be of interest to you | (a) Identity (b) Contact (c) Technical (d) Usage (e) Profile |
Necessary for our legitimate interests (to develop our products/services and grow our business, and to improve our offering to you). |
To exercise any of the above rights please complete the change request form. Please note that whilst we will carefully assess every request we receive we may not always have to comply. When this happens, we will explain why.
Looking After Your Information
We have security measures in place to protect your information. The security measures we use will depend on the type of information collected.
We only keep your information for as long as required to provide you with the services you request, for the purposes outlined in this policy and for any legal purposes for which we are obliged to keep the information. We will securely delete your information when it is no longer required for these purposes, in line with our company policies.
As a part of a global group of companies, we rely on shared services, some of which are located outside of Europe. At some time, your information may be transferred internationally to our hosted servers.
When transferring information in this way, there are strict rules in place to ensure your data is still protected to a high standard. Where we do this, we will ensure that appropriate safeguards are put in place including, where required, one of the mechanisms listed below.
- Standard Contractual Clauses approved by the European Commission
- EU-US Privacy Shield
- Binding Corporate Rules
- Binding Corporate Processor Rules
For more information, or to get a copy of the relevant documentation please contact us.
Contact Us
If you have any questions about the above, or our approach to privacy, our dedicated Privacy Office email will be handled with the strictest of confidence and can be accessed here privacy@clublegends.co.uk
You can also refer to the Information Commissioner’s Office (ICO) for help and guidance although we encourage you to let us help you first.