Principles
Miscanthus Bedding will take reasonable steps in order to process data in accordance with the General Data Protection Regulation.
GDPR requires that your personal data shall be:
Processed lawfully and in a fair and transparent manner.
Collected for legitimate purposes and not processed further in a way that is incompatible with that purpose.
Adequate and relevant to the purpose for which it is processed.
Accurate and updated if necessary.
Kept in a form which permits identification of the subject for no longer than is necessary. Personal data may be kept for longer periods for archiving purposes.
Processed securely and protected against unlawful processing, accidental loss, destruction or damage.
Provision
This policy applies to all personal data processed by the company.
The responsible person will take responsibility for ongoing compliance with this policy.
This policy will be subject to review on occasion.
Lawful and transparent processing
Individuals have a right to request details on how their data is processed.
Individuals have the right to access their personal data. This access will be granted in a timely manner.
Lawful purposes
All data will be processed on the following lawful basis: Consent, contract, legal obligation or legitimate interests.
The individual will have the power to revoke consent.
Any communications sent to the subject will have a clearly defined opt-out option available.
Data minimisation
Miscanthus Bedding will ensure that data stored is limited to what is required to carry out the working relationship with the subject.
Data accuracy
We will take reasonable steps to ensure data is accurate.
Where necessary we will ensure that data is kept up to date.
Archiving and removal of data
Data will only be kept for as long as is necessary.
Security
Miscanthus Bedding will ensure data is stored securely and is password protected.
Access to data will be limited to personnel who requires access.
When personal data is deleted this will be done securely.