January 2025
We have tried to keep this policy as user friendly as possible, but it does need to include a lot of information. There are some key terms at the end of the document which I hope are useful. Any questions, please email: andy.bush@dashsundials.co.uk
DASH Sundials are committed to ensuring that your privacy is protected. Any information you provide by any means when ordering from us, including visiting our website, will only be used in accordance with this privacy policy, which has been updated to comply with the General Data Protection Law (GDPR), effective 25th May 2018.
This policy explains how we collect, store, use and share Personal Data. It also outlines your rights under the GDPR law, including the rights for access to the data we hold.
Contacting Us
The Data Controller for the purposes of the GDPR is:
Andy Bush at DASH Sundials
Phone: 07833592727
Email: andy.bush@dashsundials.co.uk
Website: www.dashsundials.co.uk
You may, at any time, contact Andy Bush with any questions or suggestions regarding data protection or this policy, to exercise any of the rights outlined below, or to make a request to access your data. Andy Bush will provide the details securely, free of charge and within a maximum of one month, unless there is any legal reason why he must not.
Opting Out
If at any time you wish to opt out from receiving any communication from DASH Sundials, then please contact Andy Bush directly using the details above.
Policy Changes
This Privacy Policy may change from time to time to keep up with the law. DASH Sundials will not reduce your rights under this Privacy Policy without your explicit consent. We will post any Privacy Policy changes on this page and, if the changes are significant, we will provide a more prominent notice (including, for certain services, email notification of Privacy Policy changes) on our website. We will also keep prior versions of this Privacy Policy in an archive for you if required.
Security
We have physical, electronic, administrative and managerial procedures in place to safeguard and secure the information we collect from you to protect your Personal Data against accidental, unlawful or unauthorised disclosure.
Lawful Basis for Collecting and Processing Personal Data
DASH Sundials have a lawful basis for collecting and processing your Personal Data as set out in Article 6 of the GDPR. The reason we believe we have the right to gather and use your data is that we have a legitimate interest in doing so for the purpose of managing, operating or promoting our business, and that legitimate interest is not overridden by your interests, fundamental rights, or freedoms.
What that actually means is that we use the data that you share with us so we can carry out our work with you and provide you with the services and goods that you have asked us to supply. Without this data it would not be possible to do this, and so we believe our need for the data is legitimate. You are therefore under no contractual or statutory obligation to provide this data, but without it DASH Sundials would not be able to work with you.
Collection of Personal Data
We may collect Personal Data about you in ways that may include the following:
Categories of Personal Data:
The categories of Personal Data about you that we may collect and process include:
Purposes for which we may Process your Personal Data: To help us deliver the service and products that you have asked for, we may process Personal Data, subject to applicable law, which could include:
Data Retention
The criteria for determining the duration for which we will keep your Personal data are as follows:
Disclosure of Personal Data to Third Parties
We will not share your details with anyone who is not directly connected to or providing a service to DASH Sundials. All third parties providing a service to us (for example the organisation who complete laser etching) will be required to adhere to the requirements of the GDPR.
International Transfer of Personal Data
We will not transfer your Personal Data to other countries outside the UK.
Minors
DASH Sundials does not work with people under the age of 18. We therefore ask that minors do not submit any Personal Data to us, or use any of the services provided on, through or via our website or PayPal.
Data Accuracy
We take every reasonable step to ensure that:
From time to time we may ask you to confirm the accuracy of your Personal Data.
Data Minimisation
We take every reasonable step to ensure that your Personal Data that we Process is limited to that which is reasonably required in connection with the purposes set out in this Policy.
Your legal rights
Subject to applicable law, under GDPR you have rights regarding the Processing of your Personal Data, including:
This does not affect your statutory rights.
You have the right to escalate a complaint to the Data Protection Authority regarding the processing of your Personal Data by us or on our behalf. The Authority for this is the Information Commissioner’s Office, who can be contacted at, casework@ico.org.uk
Key terms
‘Controller’ means the person that decides how and why Personal Data is Processed. In many jurisdictions, the Controller has primary responsibility for complying with applicable data protection laws
‘Data Protection Authority’ means an independent public authority that is legally tasked with overseeing compliance with applicable data protection laws. In the UK this is the Information Commissioner’s Office (ICO)
‘Personal Data’ means information that is about any individual, or from which any individual is identifiable
‘Process’, ‘Processing’ or ‘Processed’ means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing or destroying
‘Processor’ means any person or entity that Processes Personal Data on behalf of the Controller (other than employees of the Controller).