GDPR Policy for Hand in Hand Festival Community Interest Company (based in Bristol, UK)
Introduction
Hand in Hand Festival Community Interest Company, based in Bristol, UK, is committed to protecting the privacy and personal data of its users and visitors. This GDPR (General Data Protection Regulation) policy outlines how we collect, process, store, and protect personal information in compliance with UK data protection laws.
Data Controller
Hand in Hand Festival Community Interest Company, located in Bristol, UK, acts as the data controller for the personal data collected and processed through its website and related services.
Personal Data Collection
We collect and process personal data for specific purposes, with appropriate legal grounds, and only to the extent necessary. The types of personal data we may collect include:
- Name
- Email address
- Phone number
- Address
- Payment information (if applicable)
- IP address and browsing data
We collect personal data through various channels, including our website, online forms, email communications, and ticketing systems.
Purpose of Data Processing
We process personal data for the following purposes:
- Providing access to our website and services
- Responding to user inquiries and support requests
- Managing user accounts and registrations
- Processing ticket purchases and payments
- Sending updates, newsletters, and marketing communications
- Conducting surveys and gathering feedback
- Consent to Photography: We may capture photographs or videos during Hand in Hand Festival events for promotional purposes. By attending our events, individuals consent to the use of their image for such promotional materials. If anyone does not wish to be photographed or filmed, they can inform the event organizers or staff members.
- Future Marketing: We may keep the contact details of individuals for future marketing purposes related to Hand in Hand Festival and similar events. This may include sending updates, newsletters, and promotional materials regarding upcoming festivals, workshops, or related activities. Users have the right to withdraw their consent for such marketing communications at any time.
Legal Basis for Data Processing
We rely on the following legal bases for processing personal data:
- Contractual Necessity: Processing is necessary for the performance of a contract or to take pre-contractual steps at the user’s request.
- Legitimate Interests: Processing is necessary for our legitimate interests, such as providing and improving our services, ensuring website security, and marketing activities.
- Consent: Processing is based on the user’s freely given consent, which can be withdrawn at any time.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law. We regularly review and update our data retention practices to ensure compliance with applicable regulations.
Data Security
We implement appropriate technical and organizational measures to ensure the security and confidentiality of personal data, protecting it against unauthorized access, loss, or alteration. These measures include encryption, access controls, regular backups, and staff training.
Data Sharing and Transfers
We may share personal data with trusted third parties, including service providers, payment processors, and marketing platforms, solely for the purposes mentioned in this policy. We ensure that any third parties processing personal data on our behalf are compliant with relevant data protection regulations.
User Rights
Under the UK data protection laws, individuals have certain rights regarding their personal data. Hand in Hand Festival Community Interest Company is committed to facilitating the exercise of these rights, including:
- Right to access: Users can request access to their personal data held by us.
- Right to rectification: Users can request the correction or update of their inaccurate or incomplete personal data.
- Right to erasure: Users can request the deletion of their personal data under specific circumstances.
- Right to object: Users can object to the processing of their personal data based on legitimate interests or direct marketing.
- Right to data portability: Users can request the transfer of their personal data to another organization in a structured, commonly used, machine-readable format.
- Right to withdraw consent: Users can withdraw their consent to the processing of personal data that was based on consent.
Data Protection Officer
Hand in Hand Festival Community Interest Company, based in Bristol, UK, has appointed a Data Protection Officer (DPO) to oversee data protection practices and ensure compliance with UK data protection laws. You can contact our DPO by email at dpo@handinhandfestival.org.
Changes to the GDPR Policy
We may update this GDPR policy from time to time to reflect changes in our data processing practices or legal requirements. We encourage users to review this policy periodically for any updates. Significant changes will be communicated through appropriate channels.
Conclusion
Hand in Hand Festival Community Interest Company, based in Bristol, UK, is committed to protecting the privacy and personal data of its users and visitors in accordance with UK data protection laws. If you have any questions or concerns about our data processing practices or this policy, please contact us at privacy@handinhandfestival.org.
Please note that this policy is subject to periodic review and may be revised to ensure compliance with evolving legal requirements and best practices.