GDPR & Privacy Statement
GDPR & Privacy Statement
Northern Print Studio Ltd
Newcastle upon Tyne,
Information Commissioner’s Office
Registration No: Z8160950
Northern Print is a studio, gallery and education space all dedicated to printmaking. Learning and participation are at the heart of what we do. We support artists in their professional practice as well as working with school groups and running a programme of classes and events for everyone.
Northern Print Studio Ltd is committed to transparency about how we process and keep your data safe. Our GDPR process policy provides you with clear information about how we process and protect your data, including how to exercise your rights relating to your data.
Lawfulness, fairness and transparency
Northern Print Studio Ltd is committed to protecting and respecting your privacy while remaining compliant with UK General Data Protection Regulation (UK GDPR), tailored by the Data Protection Act 2018 (DPA). This policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us.
We have an Information Governance Framework embedded within the organisation, which is compliant with the General Data Protection Regulation.
Identity & Contact Details for the Data Protection Officer
Northern Print Studio Ltd is the Data Controller and the Trustees of Northern Print Studio Ltd are ultimately responsible for the implementation of the Data Protection and GDPR regulations. However, they have appointed a Data Protection Officer, Anna Wilkinson, who will deal with day to day matters and may be contacted at by email at email@example.com
You can also contact Northern Print Studio Ltd by post at: Stepney Bank, Newcastle Upon Tyne, Tyne & Wear, NE1 2NP.
Use of Information
We will use your information to provide and personalise our service. Where we collect personal data, we may store this securely in both hard copy and electronic copy. This data may be used to compile reports that comply with contractual requirements and for general administration purposes. We ensure that the provisions and obligations imposed by the Data Protection Act 2108 and Data Protection Principles together with any subsequent re-enactment or amendment thereof in storing and processing personal data, are complied with at all times. We may use your information to send you news about products or services which we think may be of interest to you. We will never pass your personal data to anyone else, except for any suppliers that process data on our behalf.
Lawful basis for processing personal data
Northern Print Studio Ltd collects and processes personal data for several different purpose:
Provision of services
The legal basis for processing personal data for the purpose of providing services to our customers is either to fulfil our contractual obligations to customers or in the pursuit of related legitimate interests including maintaining accurate records relating to accounting and finance, monitoring the quality or improving our service offer.
Business development including fundraising
The legal basis for processing personal data for the purpose of business development is the pursuit of our legitimate interest in developing our business and undertaking sales and marketing activities, including fundraising. We acquire personal data from a number of sources including directly from data subjects, from referrals, from social media platforms, and from our own research activities such as reviewing websites. We will retain personal and services may be of interest to prospects, customers and former customers.
Procurement of services
The legal basis for processing personal data for the purpose of procurement is the pursuit of our legitimate interest in maintaining efficient and effective procurement processes. Personal data we collect from suppliers and prospective suppliers is usually supplied directly by the data subject or their employer. We will retain personal information we collect through our procurement processes for as long as we need to comply with accounting and taxation rules, policies and conventions.
There are circumstances whereby we are legally required to collect personal data. When you enter the Northern Print premises, we collect personal data for health and safety and building evacuation purposes. When you become a studio member or sign up for a workshop we may request and/or receive “sensitive personal information” about you. For example, if it is relevant, we may need access to information about your health or access needs in order to provide you with appropriate support and services.
Northern Print Studio Ltd asks for consent when a subject joins the general mailing list through Mailchimp and /or through Shopify and when a subject fills out a form to become a member of the Northern Print studio.
Consent to keep visual personal data, such as a photographic record will be requested at the time, for a specific purpose, and recorded in our photographic consent log.
Recording and managing ongoing consent
If a member of the Northern Print mailing list does not interact with (open or click) an email within a 12 month period; the subject will receive an email asking for ongoing consent to remain in contact. If that email is not actioned the subject will be removed from the Northern Print mailing list.
Information we may collect from you
The personal information that we collect will depend on your relationship with us and how you approach us – please see the Information Classification Flowchart attached for more information. We will collect different personal information depending on whether you are a customer, a beneficiary or another third party. In most cases the information we collect will be classified as ‘Personal/Confidential’.
When a studio member renews their membership (12-month period), they have the option to renew or withdraw consent and in all cases a subject may exercise their right to withdraw consent by emailing firstname.lastname@example.org or telephoning 0191 261 7000.
Legitimate Interests of Northern Print Studio Ltd
We may use your information for other specific legitimate purposes such as:
- To ensure that content we provide is presented in the most effective manner for you.
- To provide you with information, products or services that your request from us or which we feel may interest you, where you have either explicitly consented to or we believe we have a legitimate interest in.
- To carry out our obligations arising from any contracts entered between you and us.
- To notify you about changes to our business or service.
We do not sell rent or lease customer lists to third parties.
Processors & Subprocessors
Northern Print Studio Ltd uses a number of processors and sub processors in order to deliver its services. We regularly review all the processors to ensure that they align with our own data security and privacy processes and ethics.
Storage of information
All information provided to us is either stored electronically on Microsoft SharePoint servers or stored securely in a locked cupboard as a paper based hard copy. We do our best to protect your personal data, however, we cannot guarantee the security of your data while being transmitted to us - any transmission is at your own risk. Once we have received your information, we use strict procedures and security features to prevent unauthorised access.
Access to personal data is limited to personnel who need access and when personal data is deleted this is done safely such that the data is irrecoverable.
When browsing northernprint.org.uk data is collected by cookies. A cookie is a small piece of data that is sent from Shopify’s web server to your browser and stored on your hard drive. A cookie cannot read data off your hard disk other than the cookie itself, files created by other websites, and will not damage your system.
- Track users as they navigate the website
- Improve the website’s usability
- Analyse the use of the website
- Administer the website
- Prevent fraud
- Improve the security of the website
We use Google Analytics Universal to analyse the use of our website. Our analytics service provider generates statistical and other information about website use by means of cookies.
We regularly review data retention periods in accordance with The General Data Protection Regulation guidelines and keep personal data for enough time to complete the function for which it was collected, unless:
a) you ask for us to remove it
b) we believe that you are no longer interested in our business
c) we no longer need it for the purposes it was collected
Your Individual Rights
As a Data Subject (individual) which Northern Print Studio Ltd, process information on behalf of, you have the right to:
- Rectification and data quality
- Erasure including retention and disposal
- Restrict processing
- Data portability
- Automated decision-making including profiling
You have the right to make a Data Subject Access Request to Northern Print Studio Ltd if you wish to determine what information we hold on you. We welcome these requests and once your identity has been confirmed we aim to respond within 72 hours of receipt.
If a data breach occurs, Northern Print Studio Ltd will:
- Investigate the cause of the breach
- Take action to contain the breach
- Assess the likelihood and severity of risk to any of a data subject’s rights
Where personal data has been sent to someone who is not authorised to have access to it,
Northern Print Studio Ltd will:
- Inform the recipient not to distribute it in any way or discuss it with anyone else
- Inform the recipient to destroy or delete the data, and require them to confirm in writing that they have done so
- Where relevant, inform the data subject(s) so they can take any necessary action
If there is a risk to the individual(s) rights, Northern Print Studio Ltd will notify the ICO within 72 hours of becoming aware of the breach. If a risk is unlikely, there is no requirement for Northern Print Studio Ltd to report the data breach to the ICO.
You also have the right to lodge a complaint with the Supervisory Authority (Information Commissioners Office (ICO)) in the UK - www.ico.org.uk, should you feel that we have not handled your information in line with legislative and regulatory requirements.
Changes to our GDPR Policy
We may change this policy from time to time. If we make significant changes in the way we treat your personal information, or the policy, we will make it clear on our websites or by email, so that you are able to review the changes.
Updated March, 2023