Privacy Policy

Introduction

The privacy and security of your information is extremely important to us. This policy is intended to give you a clear view of what data we collect, how we use it, how long we keep it for and how we get rid of it, so you can be confident in submitting data when dealing with us.

We’ll keep this page updated to show you what we do with your personal data. This policy applies to you if you visit our website, use any of our services, email us, contact us or visit our premises.

We will never sell your personal data and we will only share it with other organisations we work with to deliver the services we provide where they have shown they’ll respect your privacy and security.

Who are We?

Throughout this document when you see the words ‘us’, ‘we’ and ‘our’ this is referring to Memorabilia Pack Company Ltd.

We are a limited company, registered in Scotland, our registration number is SC151622 and our registered office is 16 Forth Street, Edinburgh, Scotland, EH1 3LH. Our place of business is 16 Forth Street, Edinburgh, Scotland, EH1 3LH

We are a publishing company who carries out the design and development of memorabilia products. We collect personal data to allow us to maintain our own records and accounts and to also support our staff.

If you have any questions regarding this privacy policy you should contact The Memorabilia Pack Company Ltd, 16 Forth Street, Edinburgh, Scotland, EH1 3LH

What Personal Data do we collect?

Personal data is any data which may identify you, or be identified as relating to you. For example, your name, address, phone number and email address. We will sometimes need to collect this information. We will only collect the personal data we need.

We collect data in connection with sales for any products you may order with us or enquiries you may make with us via email.

You can give us personal data in various ways. You can submit personal data through forms on our website, you can phone us, you can email us or you can visit our premises.

This personal data may include name, title, address, date of birth, age, gender, employment status, email address, phone numbers, personal description, photographs, usernames, passwords, databases.

Personal Data that is provided by you

This data includes information you give us when interacting with us, for example, you filling out a contact form, registering as a client with us, placing an order or communicating with us. For example :

  • Personal details – name, address, phone number, email address and so on
  • Financial details – bank name, bank address, bank account number and SORT code
  • Technical information used in projects – usernames, passwords, databases, concepts, logos, drawings, designs, documents, spreadsheets and so on
  • Information about your visit – full URL and query string, pages you viewed on our website, length of visit to pages on our website and any search terms you used to find our website.

Personal Data created by your involvement with us

Your activities and involvement with us will generate personal data being created. This could include project details, documentation and so on.

How we use your Personal Data

We will only use your personal data on relevant lawful grounds, as permitted by the EU General Data Protection Regulation (from 25th May 2018)/UK Data Protection Act and Privacy of Electronic Communication Regulation.

Personal data provided to us will be used for the purposes of carrying out our business as web designers, in a transparent manner, in accordance with any preferences you express. Below we have listed the main uses of the data we collect from you :

Projects

We deliver services associated with the supply of memorabilia based products. If you have contacted us to provide these services, we will need to collect personal data from you to carry out these services. This may include name, address and phone number, but also more technical data like databases, usernames, passwords and previous versions of systems.

Accounting

We are required by law to keep accurate and up to date accounts of our business transactions. When you interact with us you may be added to our accounting system.

Marketing

We occasionally run marketing campaigns. We will always ask for your consent before sending you any marketing material.

Disclosure of Personal Data to other bodies

In order to carry out the running of our business day to day and fulfil the requirements of the projects we work on, we sometimes need to disclose your data to other bodies or third party suppliers.

These other bodies may be sub contractors, systems we use, online applications allowing us to meet project requirements and so on. You can find a list of third-party suppliers here, including links to their privacy policies.

How can I change my preferences

You can contact us at any time to change or discuss your privacy preferences. Contact us using the details below:

Call us: 0131 550 3799 (hours are 8.00am to 2.30pm Monday to Friday)

Write to us:
Memorabilia Pack Company Ltd.
16 Forth Street
Edinburgh
EH1 3LH

Email us : neil@mempackcompany.com

Your Rights under GDPR

Under the GDPR, where we are using your data under consent, you have the right to withdraw that consent at any time. You also have the right to ask us to stop using your personal data for marketing purposes. Please contact us using the details above if you would like to do this.

Subject Access Requests

If you would like to make a Subject Access Request, you can do so using this form. Please note, there is no charge for making this request, although you will be asked to verify your identity. We will respond within 30 days of receiving your request and verifying your identity.

What to do if you’re not happy

Please contact us in the first instance if you feel unhappy regarding any issues around the use of your personal data. We would welcome the opportunity to resolve any problem or query you have. You also have the right to contact the Information Commissioners Office (ICO). You can contact them via their website here : https://ico.org.uk

Keeping your information

If you have submitted any information through our website forms, we will keep this data for 30 days, then automatically delete it from our website and website database. We keep email data and project files for 7 years, keeping us in line with any potential audit by HMRC where we may need to produce evidence of work carried out. You can read more about how we store and delete your personal data by asking for a copy of our data retention policy and data deletion policy.

How we secure your data

Information systems and data security is imperative to us to ensure that we are keeping your data safe. We operate and implement robust procedures for managing your data, the hardware it is present on. We only host your personal data with suppliers who have confirmed that they take your personal data security as a priority and we regularly assess these suppliers as the threat landscape changes.

Staff are given mandatory annual, information security training.

Internally we utilise password managers so your passwords can be shared securely, we use and enforce strong passwords and where we store your data we encrypt it if possible and make sure that the suppliers we use have robust attitudes to privacy and data security.

Disclosure of Information

Sometimes, when working on projects, we have to share your data with sub-contractors or other people working on the project. When we are sharing the data, we will always do so in such a way that access can be revoked again.

Who will see your data?

When you submit your data to us, we might disclose it to parties as part of our normal project workflow. These parties may include :

  • Our employees
  • Contractors we work with
  • Service providers providing services to us
  • Advisors
  • Agents

We may also disclose your information to third parties if we are compelled to by law or to comply with any legal obligation.

Storage of Information

Memorabilia Pack Company Ltd. is based in the UK and as such, the majority of our hosting services are also based in the UK. Some of the other data storage services we use are located in the European Union region. We do not collect or store payment information and we do not transmit your data outside the European Union.

Payments

To process payments, we use Paypal, which is connected to our accounting software Xero. We do not store your card details.

Changes to this policy

We will amend this privacy policy from time to time, ensuring that it stays up to date. Please visit our website to keep up with any changes we make. The most up to date version will always be posted on our website.

This privacy policy was last updated on 31st October 2019.