DATA PRIVACY NOTICE
This privacy notice aims to give you information on how All Good Co CIC (“we”, “us” or “our”) has collected and will process the following categories of personal information about you:
This privacy notice only relates to how we will process the personal information specified above.
It is important that you read this privacy notice together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about you, for example, if you are using our website, so that you are fully aware of how and why we are using your information. This privacy notice is in addition to those other notices and does not replace those notices.
How and why will we use your personal information?
We are the controller of and are responsible for your personal information.
We will only use your personal information when the law allows us to. We will use your personal information where we have your consent to do so, and otherwise, where we have a legitimate interest to do so and your interests and fundamental rights do not override those interests. Such uses may include:
Change of purpose
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Disclosure of your personal information and international transfers
We may need to share your personal information with others from time to time, including:
Your personal information may be shared, stored and processed outside of the European Economic Area (EEA), in countries that may have different data protection rules to our own. However, we will only transfer your personal information outside of the EEA where appropriate safeguards have been put in place. There are several appropriate safeguards available under UK data privacy law which are: (i) the use of standard EU model clauses; (ii) transfers to companies in the US who have a privacy shield certification; and (iii) transfers to countries that have a "white list status".
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
We only retain your personal information for as long as is necessary for us to use your information as described above, where it is in our legitimate interest, or to comply with our legal obligations. However, please be advised that we may retain some of your information, for instance if this is necessary to meet our legal obligations, such as retaining the information for tax and accounting purposes.
When determining the relevant retention periods, we will take into account factors including:
Otherwise, we will securely erase your information once this is no longer needed.
Your rights in relation to your personal information
You have certain additional rights, beyond receiving this notice, in relation to your personal information as summarised here. For more information on your rights, please see the contact details at the bottom of this notice:
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
If you have any questions about anything in this privacy notice, please contact firstname.lastname@example.org.