Clickfoto is a trading style of Colorfoto Limited. We are a company registered in England and Wales (registration number 03135828); the address of our registered office is Image House, East Tyndall Street, Cardiff CF24 5EF. We are registered as a Data Controller with the Information Commissioner's Office (registration number ZA084981).
What personal information do we collect about you?
When you access and move around Clickfoto, register an Account with Clickfoto or purchase a Product from Clickfoto, we may collect some or all of the following personal data about you;
- Name, a username and password;
- Billing and delivery addresses, email address and phone number(s);
- Your Images and other User Content;
- Correspondence with and from Clickfoto;
- Your preferences about receiving communications from Clickfoto;
- Information about your use of Clickfoto and your browsing and online purchasing activities; and details we may ask you to submit to verify your identity.
- We may also collect some of this personal data from third parties who have your consent to pass your details to us.
- In order to take advantage of some of our Services, you may need to supply us with the personal details of a third party (for example, their name and address if you wish to send a Product to them as a gift). We will not use this information for anything other than providing the Services for which the information was supplied.
How do we use your personal information?
We process personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR).
Your personal data will be collected, processed, stored and used by us, and passed to and processed by our subsidiary and/or affiliated companies and other data processors and controllers acting under contract with us:
- To provide Clickfoto products and services to you;
- To tailor aspects of your experience of Clickfoto;
- To contact you to provide examples of Products bearing your Images we think might interest you;
- To create personalised Products selected by you;
- To associate your Account and your Product purchases with you and to verify your identity;
- To provide customer support;
- To contact you by email and mobile communication (such as text (SMS) and “push” notification);
- For customer satisfaction and customer experience improvement purposes;
- In connection with the prevention and detection of fraud and other crime.
The processing of personal data is carried out for the provision of the photographic services and the associated sale of captured images and their electronic transmission or production on photo products and delivery to customers, and in particular also to carry out our contracts or pre-contractual measures with you, as well as the execution of your orders. The purposes of data processing are primarily obligations arising from the sales contract in which you enter with us by placing an order in our shop and can include, among other things, reminders of important events. You can find further details about the purpose of data processing in the respective terms and conditions.
If necessary, we process your data beyond the actual fulfilment of the contract in order to protect our own legitimate interests or those of third parties. For: advertising or market and opinion research, insofar as you have not objected to the use of your data; the enforcement of legal claims and defence in legal disputes; ensuring IT security; prevention and investigation of criminal offences; measures for business management and further development of services and products.
We also process personal data when you contact us through our contact screen. We process any data you include in the screen. This is needed to process and respond to your inquiry or request. As soon as your inquiry or request has been solved, we delete your data.
Should we be engaged in events where our photographic services have been used to take pictures, we process the personal data obtained there on the basis of the justified interest to fulfil the order given to us and to offer it for purchase. If this is the case, we shall refer to the photographs of the persons present during the event, as well as to a right of objection. Please note that an objection only takes effect in the future. All processing carried out until then remains unaffected.
If you have given us consent to the processing of personal data for certain purposes (e.g. publication or use of images), the legality of such processing is based on your consent. You may revoke your consent at any time with effect for the future. Please note that the revocation only takes effect in the future. Processing carried out before the revocation remains unaffected.
We also process personal data on the basis of legal requirements. For example, we store invoice data (name, address) on the basis of existing legislation, such as the retention obligations.
We do not store a Payment Method or payment information. Each order is processed by Stripe, our debit/credit card payment service provider. Your Payment Method will be required to comply with the Payment Card Industry Data Security Standard (PCI DSS). Note that, when using a Payment Method to make payment for your Clickfoto order, certain techniques will be used to assist in maintaining the security of the details of your stored Payment Method. For example, not all of the payment card number will be visible to you (typically, all except the final four digits will be masked), and you will be required to provide certain information (such as, but not limited to, a CV2 card security number) in order to proceed with using that Payment Method.
We may automatically collect anonymous information about your use of Clickfoto. For example, we may automatically log which parts of Clickfoto you access, which web browser you deploy and the website from which you linked to Clickfoto. You cannot be identified from any of this information. It enables us to compile statistics about the use of Clickfoto, and to help target aspects of Clickfoto and advertising to you more accurately.
Disclosing your personal data
We will not disclose any of your personal data, other than to subsidiary and/or affiliated companies and data processors (including payment service providers) under contract with us, without your permission unless:
- We are legally entitled to do so (for example, pursuant to a court order or for the purposes of prevention or detection of crime or fraud)
How Long Will You Keep My Personal Data?
We will not keep your personal data for any longer than is necessary in light of the reason(s) for which it was first collected. Your personal data will therefore be kept for one year after completion of your last contract with us.
How and Where Do You Store or Transfer My Personal Data?
We will only store your personal data in our own secure data centre in Cardiff, UK. This means that it will be fully compliant with the GDPR.
Is there a duty for me to provide data?
In the context of our business relationship, you must provide only the personal data necessary for the establishment, execution and termination of a business relationship or for which we are legally obliged to collect. Without this data, we will usually have to reject the conclusion of the contract or the execution of the order or will no longer be able to execute an existing contract and may have to terminate. Furthermore, it is necessary for us to request additional data for the provision of paid services, including how to process your desired payment method.
Notification of important events
When you register to receive our notifications by email and/or SMS, the data you provide will be used exclusively for this purpose. We log your consent to receive the notification, including your IP address. No further data will be collected. The data will only be used for sending notifications and will be passed on to third parties only for the purpose of delivery. You can revoke your consent to the processing of your personal data and their use for sending notifications at any time. In each notification you will find an applicable link for revocation; in addition you can always send an objection by email to firstname.lastname@example.org. Please note that the revocation will only take effect in the future. Processing carried out before the revocation remains unaffected.
Email and Text preferences
The emails and mobile communication (such as text (SMS) and “push” notification) we send to you fall into two categories:
Emails (we call them newsletters) and mobile communication (such as text (SMS) and “push” notification) (we call them messaging alerts) which provide you with information about offers, new Products and other things that we think may interest you or Clickfoto customers generally. You can notify us of your preferences concerning our newsletters.
The emails that we send concerning activity on your Clickfoto Account (“Service Messages”) include specifically:
- To remind you of Clickfoto coupons, vouchers, deadlines and expiry dates applicable
- To remind you of unordered items in your online basket
- To remind you of Product creations that you have abandoned
- Surveys to capture your feedback on orders you have placed with Clickfoto
- Surveys to capture your feedback on contact with our customer service team
- To inform you of last Product order dates for seasonal events such as Christmas, Valentine’s day, Mother’s Day and Father’s day
- To remind you that you have an Account
- Should you wish to, you can opt out of receiving the above Service Messages by emailing email@example.com.
- Should you wish to, you can opt out of receiving our service emails by emailing firstname.lastname@example.org.
While we do our best to act on your preferences as soon as we reasonably can, please be aware that it may take up to 14 days for changes to your preferences concerning Service Messages to take effect.
Access to Information
Under the GDPR, you have the following rights, which we will always work to uphold:
- The right to be informed about our collection and use of personal data. This Privacy Notice should tell you everything you need to know, but you can always contact us to find out more or to ask any questions.
- The right to access the personal data we hold about you. Any access request may be subject to a fee of £10 to meet our costs in providing you with details of the personal information we hold about you.
- The right to have personal data rectified if any personal data held by us is inaccurate or incomplete
- The right to be forgotten, i.e. the right to ask us to delete or otherwise dispose of any of your personal data that we have.
- The right to restrict (i.e. prevent) the processing of your personal data.
- The right to object to us using your personal data for a particular purpose or purposes.
- The right to data portability. This means that you can ask us for a copy of your personal data held by us to re-use with another service or business in many cases.
- Rights relating to automated decision-making and profiling. We do not use your personal data in this way.
- For more information about our use of your personal data or exercising your rights as outlined above, please contact us using the details provided in Part 11.
- Further information about your rights can also be obtained from the Information Commissioner’s Office or your local Citizens Advice Bureau.
- If you have any cause for complaint about our use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office.
In individual cases we process your personal data in order to perform direct marketing. You have the right at any time to object to the processing of personal data relating to you for the purpose of such marketing. If you object to the processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection must be addressed in writing by email to email@example.com.
A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive.
To make full use of clickfoto.co.uk and to benefit from certain personalised features, your computer, tablet or mobile phone will need to be set up to accept cookies. The clickfoto.co.uk website (like many other shopping websites) will not work when cookies are blocked.
You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our site. If you disable cookies our Site will not operate properly. In particular, note that you may be prevented from making purchases of Products if cookies are disabled.
Social media plugins
Social media plugins (links to social media) are used on our websites by the providers listed below. You can recognise the plugins as they are marked with their respective logos. These plugins may be used to send information, which may include personal information, to the service provider and may also be used by the service provider. We prevent the unconscious and unwanted collection and transmission of data to the service provider using a 2-click solution. To activate a desired social media plugin, you must first click on the corresponding button. The collection of information and its transmission to the service provider will only be triggered through this activation of the plugins.
Note: If you are logged in to Facebook at the same time, Facebook may identify you as a visitor to a particular page. We have integrated the social media buttons of the following companies on our website:
- Facebook Inc. (1601 S. California Ave - Palo Alto - CA 94304 - USA) (for more information, see: https://www.facebook.com/policy.php)
- Twitter Inc. (795 Folsom St. - Suite 600 - San Francisco - CA 94107 - USA) (for more information, see: https://twitter.com/de/privacy)
- Pinterest Europe Ltd. (Palmerston House, 2nd Floor - Fenian Street - Dublin 2, Ireland) (for more information, see: https://policy.pinterest.com/de/privacy-policy)
- WhatsApp Ireland Limited (4 Grand Canal Square - Grand Canal Harbour - Dublin 2) (for more information, see: https://www.whatsapp.com/legal/?l=de#terms-of-service)
- Google Plus/Google Inc. (1600 Amphitheatre Parkway - Mountain View - CA 94043 - USA) (for more information, see: https://policies.google.com/privacy?hl=de)
Links to third party sites
Our Site may, from time to time, contain links to the websites of third parties. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for the content of those websites or their policies.
We take appropriate technical and organisational measures to guard against unauthorised or unlawful processing of your personal data and against accidental loss or destruction of, or damage to, your personal data. While no computer system is completely secure, we believe the measures implemented by our site reduce the likelihood of security problems to a level appropriate to the type of data involved.
We have security measures in place to protect our database of Users and access to this database is restricted internally. However, note that it remains each User's responsibility:
- to ensure no-one else uses Clickfoto through his/her Account;
- to log off or exit from your Clickfoto Account when not using it; and
- to keep his/her password or other access information secret.
We will never ask you to confirm the details of your Account or Payment Method by email or mobile communication. If you receive such contact, please do not respond to it.
Updates to this policy