St Albans Musical Theatre Company

Size: px
Start display at page:

Download "St Albans Musical Theatre Company"

Transcription

1 St Albans Musical Theatre Cmpany ST ALBANS MUSICAL THEATRE COMPANY PRIVACY POLICY This ntice describes hw St Albans Musical Theatre Cmpany (als referred t as "SAMTC", "we", "us" r ur ), prcess yur persnal data, as independent cntrllers. Our address is 37 St. Lenards Curt, Huse Lane, Sandridge, St Albans, AL4 9UZ. If yu require further infrmatin, yu can cntact ur Data Prtectin Officer via MembershipSAMTC@gmail.cm r inf@samtc.rg.uk At St Albans Musical Theatre Cmpany, we are 100% cmmitted t prtecting the privacy and security f ur members, prductin teams and audiences. We will nly use yur data t enhance yur experience with SAMTC and we will prtect yur data like it s ur wn. Here is why we need it and hw we ll use it. Summary f the purpses fr prcessing yur persnal data and the legal basis fr ding s SAMTC will prcess yur persnal data t Maintain ur membership agreements and prfessinal relatinships mnitr, test and cntrl the systems and prcesses we need t enter int and deliver ur services. We take apprpriate steps t ensure the security f yur persnal data in these envirnments. If yu d nt prvide the infrmatin we request, we may nt be able t enter int r cmply with a cntract r ur legal bligatins. We will make clear during the membership and recruitment prcess what ther persnal data is required and the cnsequences f failing t prvide it. In sme cases, where yu (r a persn acting n yur behalf) prvide us with accessibility, dietary r ther health r sensitive persnal data, fr example in a free text field, we will seek yur r yur agent s explicit cnsent t prcess that persnal data. On ur website we use essential ckies t allw us t mnitr the perfrmance f ur website thrugh Ggle Analytics, and with yur cnsent ckies t enhance yur experience f the website, as explained in ur Ckie Ntice: Mre abut ckies. We prcess yur persnal data fr the purpses f dealing with enquiries, gathering membership feedback, undertaking market research and direct marketing (including analysis t create prfiles), in ur legitimate interests t prmte ur charity and imprve ur service. When yu pst n scial media abut ur charity, we may use yur cntact details t respnd t any cmplaints r cmments n the legal basis f ur legitimate interest. In rder t fulfil the abve purpses (n the basis f the specified legal grunds): where it is necessary t transfer yur persnal data utside the EEA, we will ntify yu and ensure that there are adequate safeguards in place. Yu can btain details f the safeguards by cntacting us, using the details shwn abve. Further infrmatin is als belw under Internatinal Transfers 1

2 we retain yur persnal data fr perids f up t 25 mnths frm yur last interactin with us (we may chse, r yu may ask us, t delete it earlier). Befre we prcess yur persnal data fr any purpse nt listed abve, we will cntact yu t explain the legal basis n which we will be relying and, where apprpriate, give yu a right t bject. Summary f yur rights Any cnsent(s) yu give us may be withdrawn at any time, withut affecting pre-withdrawal prcessing. Yu have the qualified right t: request access, rectify, and erase yur persnal data; bject t prcessing fr any abve purpse where we rely n ur legitimate interests as the legal basis, r we are sending yu direct marketing; restrict prcessing; and supply r transfer yur persnal data in a prtable frmat. Where yu exercise any f yur rights, we will prcess yur persnal data t cmply with yur request in accrdance with ur legal bligatins. Where we use autmated decisin-making, we will infrm yu, and yu have the right t human interventin, t add a statement, and t have the decisin reviewed. Shuld yu wish t exercise any f yur rights, r update yur persnal data, please cntact us via inf@samtc.rg.uk, r directly cntact ur membership secretary via MembershipSAMTC@gmail.cm Yu have the right t ldge a cmplaint with a data prtectin supervisry authrity (in the UK, this is the Infrmatin Cmmissiner s Office) and details f ther EU supervisry authrities can be fund at 2

3 Hw d we use yur infrmatin, and what is the legal basis fr this use? Here is a list f the purpses fr which we prcess persnal data and the legal basis we rely n: In the instance t fulfil ur membership agreement. This includes: Cmmunicating cmpany updates including cmpany meetings, upcming shws, events and scials Prviding the cmpany newsletter Prviding membership services including payment reminders Prcessing Payments Prcessing Gift Aid We will use yur infrmatin t prvide prducts and services yu have requested Verifying yur identity Prvide infrmatin abut relevant 3 rd party perfrming arts activities and pprtunities In the instance t fulfil ur prfessinal relatinship. This includes: Cmmunicating n upcming shws and ptential prfessinal relatinship pprtunities We may cllect varius types f infrmatin abut yu, and we may btain this infrmatin in a variety f ways. Fr example, data might be cllected thrugh applicatin frms, CVs r resumes, btained by identity dcuments r cllected thrugh the recruitment prcess. We may als cllect persnal data abut yu frm third parties, such as frmer emplyers, external rganisatins wh carry ut the Disclsure and Barring Service (where applicable and/r required fr specific rles), and the Hme Office. We may als cllect infrmatin n yu in line with ur child Safeguarding plicy and prcedure. Verifying yur identity In ur legitimate interests regarding the cnduct f ur business, in particular: Ensuring membership satisfactin and maintaining gdwill we use infrmatin yu prvide t investigate any cmplaints received frm yu r frm thers abut ur website r ur services, and t maintain apprpriate recrds fr internal administrative purpses; Develping and Marketing Prducts and Services fr raising brand awareness; fr marketing, cmpetitins and prmtins by s, where permitted t d s by law; and 3

4 we use persnal data f sme individuals t invite them t take part in market research. Legal and Regulatry purpses we will use persnal data in cnnectin with legal claims, cmpliance, regulatry and investigative purpses as necessary (including disclsure f such infrmatin in cnnectin with legal prcess r litigatin); fr health and safety reasns such as lgging accidents at ur rehearsal and perfrmance premises; Where yu give us cnsent: we will send yu s in relatin t ur relevant prducts and services, r ther prducts and services prvided by ur named affiliates and carefully selected partners; we place ckies and use similar technlgies n yur cmputer, mbile r ther device (see ur Ckie Banners and Ntices); n ther ccasins where we ask yu fr cnsent, we will use the persnal data fr the purpse which we explain at that time; and t participate in cmpetitins we run and, if yu win, t use yur infrmatin fr prmtinal purpses. Fr purpses which are required by law: In respnse t requests by gvernment r law enfrcement authrities cnducting an investigatin; If required t cmply with health and safety legislatin t which we are subject; Respnding t a rights request under data prtectin legislatin. When we cllect persnal infrmatin frm anther surce When we receive persnal data abut yu frm anther surce, we will advise wh the surce f the persnal infrmatin is and what categries f persnal data we cllect and prcess, including: Cntact Details - title, name, pstal and addresses, pstcde, cntact telephne numbers Third parties that we receive persnal data frm may include: Scial netwrks Public infrmatin surces such as Cmpanies Huse Lcal business frums Member, prductin persns and cmmittee recmmendatins 4

5 Wh will we share this persnal data with We will nt share yur persnal data with ther cmpanies r persns. If apprached by a third party r cmpany we will cntact yu t establish yur wishes and prceed as yu advise. Internatinal transfers Where infrmatin is transferred utside the Eurpean Ecnmic Area (EEA), and where this is t a vendr in a cuntry that is nt subject t an adequacy decisin by the EU Cmmissin, persnal data is adequately prtected by EU Cmmissin apprved standard cntractual clauses, an apprpriate Privacy Shield certificatin r a vendr's Prcessr Binding Crprate Rules, Cdes f Cnduct r Eurpean Data Prtectin Seal. A cpy f the relevant mechanism can be prvided n request t [see cntact details abve]. Fr example, we use 3 rd party ckie prviders, Ggle, as well as Mailchimp fr cmmunicatins, which are in the USA and certified under Privacy Shield. Minrs and children under 16 years ld The safety f children is very imprtant t us. If yu are under 16 years ld, please ensure that yu btain yur parent f guardian s cnsent befre yu prvide us with yur persnal infrmatin. We cannt accept yur persnal infrmatin withut this cnsent. What rights d I have? Withdrawing cnsent r therwise bjecting t direct marketing Wherever we rely n yur cnsent, yu will always be able t withdraw that cnsent, althugh we may have ther legal grunds fr prcessing yur persnal data fr ther purpses, such as thse set ut abve. In sme cases, we are able t send yu direct marketing withut yur cnsent, where we rely n ur legitimate interests. Yu have a right t pt-ut f direct marketing, r prfiling we carry ut fr direct marketing, at any time. Yu can d this by fllwing the instructins in ur s r using ur cntact details abve. Where yu have a relatinship with anther rganisatin, we may ask them t send marketing t yu, if yu have cnsented t them ding s. Please cntact the rganisatin directly, if yu want t withdraw yur cnsent. Yu have the right t knw whether r nt we prcess infrmatin abut yu and t access that infrmatin yu can cntact us via the inf@samtc.rg.uk, r directly cntact ur membership secretary via MembershipSAMTC@gmail.cm Yu have the right t update, crrect and cmplete any infrmatin we hld abut yu which is inaccurate r incmplete; 5

6 Yu have the right t btain the persnal data yu prvide t us fr a cntract r with yur cnsent in a cmmnly used, structured, and machine-readable frmat, and t ask us t share (prt) this persnal data t anther cntrller. Yu have the right t ask that we erase r restrict (stp active) prcessing f yur persnal data; In additin, yu can bject t the prcessing f yur persnal data in sme circumstances, in particular, where we d nt have t prcess the persnal data t meet a cntractual r ther legal requirement, r where we are using the persnal data fr direct marketing (r related prfiling). These rights may be limited, fr example if fulfilling yur request wuld reveal persnal data abut anther persn, where yu bject t us prcessing persnal infrmatin but we have a cmpelling justificatin fr prcessing it, r yu ask us t erase infrmatin which we are required by law t keep. T exercise any f these rights, yu can get in tuch with us using the details set ut belw. If yu have unreslved cncerns, yu have the right t cmplain t the data prtectin authrity where yu live, wrk r where yu believe a breach may have ccurred. In the UK, this is the Infrmatin Cmmissiner s Office and details f ther EU supervisry authrities can be fund at Hw d I get in tuch with yu? We hpe that we can satisfy queries yu may have abut the way we prcess yur persnal data. If yu have any cncerns abut hw we prcess yur persnal data, r wuld like t pt ut f direct marketing, yu can get in tuch at MembershipSAMTC@gmail.cm r by writing t 4 Ardentinny, Grsvenr Rad, St. Albans, AL1 3BZ Hw lng will yu retain my persnal data? Where we prcess persnal data in cnnectin with entering int r perfrming a cntract, we keep yur persnal data until a perid f 3 years has elapse since yur last interactin with us. Where we prcess persnal data fr marketing purpses r with yur cnsent, we prcess the data until yu ask us t stp and fr a shrt perid after this (t allw us t implement yur requests). We als keep a recrd f the fact that yu have asked us nt t send yu direct marketing r t prcess yur persnal data fr up t 7 years s that we can respect yur request in future. If persnal data is required fr the purpses f an internal r external investigatin, r litigatin, we may retain it until the matter is reslved. 6

7 The data we cllect abut yu, and what we d with that data, may include the fllwing: The infrmatin we cllect Why we cllect the infrmatin Hw we use the infrmatin Yur title, name, address and cntact details including address and telephne number as well as persnal details such as date f birth, perfrmance ability and experience and length f time with the cmpany T enter int/perfrm the membership cntract Legitimate interests Maintain accurate recrds abut ur members, enable cmmunicatin with ur members 7