The 21st Century brings with it broader use of technology, new definitions of what constitutes personal data, and a vast increase in cross-border processing. The new Regulation aims to standardise data protection laws and processing across the EU; affording individuals stronger, more consistent rights to access and control their personal information.
Who we are?
Phoenix Fireworks Ltd. (‘we’ or ‘us’ or ‘our’) are committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have always had a robust and effective data protection program in place which complies with existing law and abides by the data protection principles. However, we recognise our obligations in updating and expanding this program to meet the demands of the GDPR and the UK’s Data Protection Bill.
What information do we collect?
We will collect information on the firers name, address, contact details and emergency contact information. This will be collected through a contact form sent to all firers.
If the firer is asked to do a job abroad or in a high security setting, we will ask for a passport number or drivers licence number for booking flights or for the security checks that the client requires. This is not collected unless the job requires this information.
How do we use personal information?
We will only use your data to contact you with regards to firing firework displays for us or to contact your emergency contact in an emergency. We will not use this information for any other purposes.
What legal basis do we have for processing your personal data?
We need to process this data for legitimate interests for the business.
When do we share personal data?
All data we collect is confidential and will not be disclosed or shared with any other party. The only exception to this is if we have to provide personal information for a high security job, for booking flights for a job abroad or if the police request this information.
Where do we store, process and secure personal data?
All personal data is stored in the office and on the encrypted file server. No information is passed of the office. The file server has a filewall, passwords and encryptions to prevent any unauthorised access. Any paper copies of the contact forms will be shredded once they have been processed.
How long do we keep your personal data for?
We will only keep your personal data for as long as you are firing displays for Phoenix Fireworks. When you stop firing for Phoenix Fireworks Ltd we will purge all records.
Your rights in relation to personal data
Under the GDPR, you have the right to access and control your personal data. You can request:
- access to personal information
- correction and deletion
- withdrawal of consent (if processing data on condition of consent)
- lodging a complaint with the Information Commissioner’s Office
Should you wish to erase your data with us we will assume that you no longer wish to fire displays for us as we cannot contact you or your emergency contacts if the need arises.
Use of automated decision-making and profiling
We do not use any automated decision-making or profiling.