I respect your right to privacy online and understand that you want to keep control of your personal information. That’s why I am committed to protecting any information you share with us.
I will never sell, distribute or intentionally make your personal information public and have implemented appropriate technical and organisational security measures to protect the data you share with me from loss and preserve its security and confidentiality. All your interactions with my website are protected by strong 256-bit encryption and I aim to collect the minimum of personal information needed to provide an effective service.
My legal bases for processing
I collect and process information about you only where I have legal bases for doing so. This legal bases will depend on the individual services you use and how you use them. Additional information is provided below but in general terms I will only collect and use your information where:
- It is necessary for me to provide you with a service, including for support or to protect the safety and security of the website itself.
- It satisfies a legitimate interest which is not overridden by your data protection interests. Such as for research and development.
- You have given me consent to do so for a specific purpose.
- I need to process your data to comply with a legal obligation.
In cases where you have consented to my use of your personal information for a specific purpose you have the right to change your mind at any time. Where I am using your information because I have a legitimate interest to do so, you have the right to object to that use, but in some cases this may mean your are no longer able to access my service.
Amazon Web Services (file storage):
Google (website analytics):
Google (email services):
HeartInternet (hosting services):
The Pixel Parlour (website development & support):
Before using or sharing your information with third parties in ways not described here or previously authorised by you, I will provide you with notice and an opportunity to control the further use or disclosure of your personal information.
Transfers outside of the European Economic Area
Under certain circumstances I will transfer your information outside of the European Economic Area. I will only do this with your informed consent, when it is necessary to perform a contract I have with you or where the receiving organisation has adequate safeguards in place – for example certification under the EU-US Privacy Shield framework.
My website is hosted in the UK in a data centre managed by Heart Internet. When you visit my website or access one of the files stored on my web server information about this request will be automatically stored in my log files to provide usage statistics, enable security features and aid technical troubleshooting. This is on the legal basis of legitimate commercial interests. In these cases, your IP address at the time acts as a unique identifier and is stored along with information about your operating system, browser version and the pages/files you access. These logs are retained on the server for up to 30 days, after which they are automatically deleted. Heart Internet will also record a similar set of data for the purposes of data management and security. This data is retained by them for up to 3 months.
Like most businesses, I use Google Analytics to help understand how my website is being discovered and interacted with and I use this information to help improve the experience for my visitors and make decisions about future development. Google Analytics presents me with aggregate information about the geographic location, device types and operating systems used by my website visitors, but not in a way that personally identifies you. Additionally, Google will record your computer’s IP address and set a number of temporary cookies in your browser to help distinguish you as an individual visitor as you move around my site. In the interest of limiting the amount of data Google collects via my site I am using Google’s standard Analytics implementation and have not enabled any additional advertising features, such as remarketing tags which would tie your usage of my site in with your broader browsing habits. Any user-level data that is associated with Analytics’ cookies are retained for up to 26 months from your last activity on my site, after which it is automatically deleted from Analytics’ servers.
My website and emails contain a number of links to third party sites. It is important to be aware that these external sites are governed by their own privacy policies and I do not accept any responsibility or liability for these policies. The inclusion of a link to an external source should not be understood to be an endorsement of that website, it’s owners or their products/services. Always check the individual privacy policies of these external sites before you submit any personal data through them.
Cookies are temporary files stored in your web browser by a website to help track usage and enable services that rely on a persistent identity. You can control which cookies you accept and remove them at any time by adjusting your browser settings or using the tools provided by this site, but it is important to be aware that some cookies are essential and my website may not function as expected without them.
These cookies are strictly necessary to provide you with services available through my websites and to use some of its features. But you can still block or delete them by changing your browser preferences.
- PHPSESSID, JSESSIONID (Sarah Murray). Used to give you a unique identifier during your time on the site for security purposes. Expire at the end of your session.
These cookies are used to enhance the performance and functionality of my websites. They are non-essential but without them, certain functionality may become unavailable.
Analytics and customisation cookies
These cookies collect information to help me understand how my website is being used or customise it in order to enhance your experience.
- _ga (Google Analytics) – used to distinguish between users. Expires after 2 years.
- _gat (Google Analytics) – used to distinguish between users. Expires after 24 hours.
- _gid – (Google Analytics) – used to throttle the request rate. Expires after 1 minute.
These cookies are used to make advertising messages more relevant to you and your interests.
Contacting me by email
When you send an email to one of the email addresses displayed in the website I will collect your email address and any other information you provide within your email.
Because your message can include attachments and other information I can’t limit what data you share. I request that you only share information directly relating to your enquiry and that you have the appropriate consent to disclose the information your share with me. It is important to be aware that email is not considered a secure means of communication so please limit the extent of the personal or commercially sensitive information you share with this way. I treat all information provided as confidential and won’t share it with any third parties without your consent.
Google are my email service provider so any emails you send will be stored on their servers. Therefore your email and any associated personal data may be transferred outside of the European Economic Area to servers located in the USA. Google’s certification under the EU-US Privacy Shield Framework commits it to maintaining appropriate safeguards for international data transfers. You can learn more here: https://cloud.google.com/security/gdpr/
The information you provide will only be processed in relation to the purpose of your correspondence with us. I have no fixed retention period for email correspondence, but are committed to only storing your data for as long as is necessary to serve my legitimate interests of record keeping or to perform a contract I have entered into with you.
Children under 16
My website and services are not for use by children under 16 years and I will not knowingly collect or use the personal data of children. If you are under the age of 16 please do not provide any personal data even if prompted to do so.
Personal data breaches
Questions & access requests
The General Data Protection Regulation (2018) gives you the right to know what personal data I hold, to have it updated if it is inaccurate or removed entirely if you no longer consent to my use of it. I will endeavour to respond to any such requests within one month confirming receipt and outlining what follow-up actions will be taken and when. While I will make every effort to act quickly please note it can take up to 3 months before some types of data can be fully removed from both my primary and backup systems.