Our Privacy policy.
GENERAL DATA PROTECTION REGULATION COMMITMENT
After four years of preparation and debate The EU General Data Protection Regulation (EU) 2016/679 (‘GDPR’) has been approved by the EU Parliament, and came into force on the 25th May 2018, which marks a significant change in the EU data protection regime. The GDPR will repeal and replace the Data Protection Directive of 1995 , which will strengthen the rights that EU individuals have over their data, and thus creating a uniform data protection law across Europe.
As a Data Controller, Wooden Roots comply with applicable GDPR regulations which became effective from the 25th May 2018, where we we will keep the Regulation at the forefront of our activities and ensure we continually respect the law whenever we use your data.
1.0 Introduction
We are Wooden Roots Ltd. (registered in England and Wales) and are the data controllers who are responsible for your personal data (collectively referred to as “Wooden Roots”, “Company”, “we”, “us” or “our” in this privacy policy).
Wooden Roots is a purveyor of the finest West African Drums & percussion. We can build bespoke and custom Djembes as well as Dunun. We supply drum building supplies, drumming accessories, branded merchandise and can even provide studio space. We pride ourselves in building strong drumming communities through drum classes and workshops provided at our studio to all levels of drummers.
We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Notice describes our policies and practices regarding its collection and use of your personal data, and sets forth your privacy rights. We recognise that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies.
Under the EU’s General Data Protection Regulation (GDPR) personal data is defined as:
“any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
2.0 Data Protection Officer
Wooden Roots has its headquarters in Rendlesham, Woodbridge, UK, and has appointed a data protection officer (DPO) for you to contact if you have any questions, queries or concerns about our personal data policies or practices. Wooden Roots data protection officer’s name and contact information are as follows:
Name: Gemma Brown
Address: Building 136, Bentwaters Parks, Rendlesham, Woodbridge, IP12 2TW Email: info@woodenroots.com
Tel No: + +44 (0)7848 905 888
3.0 Use of the website
As is true of most other websites, Wooden Roots website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information about the use of the the website, including a history of the pages you view. We use this information to help us design our site to better suit our users’ needs.
We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences. The website also uses cookies and web beacons. It does not track users when they cross to third party websites, does not provide targeted advertising to them, and therefore does not respond to Do Not Track (DNT) signals.
Cookies and web beacons
● Cookies are pieces of data that a Website transfers to a user's hard drive for record-keeping purposes. Web beacons are transparent pixel images that are used in collecting information about website usage, e-mail response and tracking.
● The Site uses cookies and Web beacons to provide enhanced functionality on the site (e.g., user ID and password prompts, and registration) and aggregate traffic data (e.g., what pages are the most popular). These cookies may be delivered in a first-party or third-party context. Wooden Roots may also use cookies and web beacons in association with e-mails delivered by us. Our Site also captures limited information (user-agent, HTTP referrer, last URL requested by the user, client-side and server-side clickstream) about visits to our Site; we may use this information to analyze general traffic patterns and to perform routine system maintenance. You have many choices with regards to the management of cookies on your computer. All major browsers allow you to block or delete cookies from your system. To learn more about your ability to manage cookies and web beacons, please consult the privacy features in your browser.
● This website uses Google Analytics, a web analytics service provided by Google, Inc. ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website
(including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purposes of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you possibly may not be able to use the full functionality of this website. By using Wooden Roots website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.
● For additional information, please refer to our Cookie Policy.
Do not track (DNT)
● Wooden Roots does not track its users when they cross to third party websites, does not provide targeted advertising to them, and therefore does not respond to ‘Do Not Track (DNT)’ signals.
4.0 How we collect and use (process) your personal information
In order for us to provide you with a service we need to collect personal data for correspondence purposes and/or detailed service provision. In any event, we are committed to ensuring that the information we collect and use is appropriate for this purpose, and does not constitute an invasion of your privacy. In terms of being contacted for marketing purposes Wooden Roots would contact you for additional consent.
We will only process personal data where we have a lawful basis on which to do so. The lawful basis on which data is processed will depend on the nature of the information collected and the purposes for which it is used by us but will be one or more of following:
● Consent:you have provided your consent for us to process their personal data for a specific purpose.
● Contract:the processing is necessary for a contract you have with us or because you have asked us to take specific steps before entering into a contract.
● Legal obligation:the processing is necessary for us to comply with our legal obligations.
● Vital interests:the processing is necessary to protect someone’s life.
● Public task:if we process personal data in the exercise of official authority; or to perform a specific task in the public interest that is set out in law.
● Legitimate interests:the processing is necessary for our legitimate interests or the legitimate interests of a third party.
We use a variety of personal information depending on the circumstances under which personal information is made available to us.
If you have subscribed to our Contact or Marketing Lists, we will use your personal data to email you with updates, details of new services and articles we believe will be of interest – you will have the option to unsubscribe whenever you feel the content of our emails is no longer of interest to you as we are relying on your consent (please note that we will not share your email address with others for any purposes here);
Where you have contacted us with a query, we will use your personal information to respond to your query as it is necessary to protect our legitimate interests – this is to provide you with good customer service, perhaps giving you additional information on how we can support you and we hope this will lead to us working together in the near future; and when you contact us with the intention to enter into a contract with us, we will then respond to your query on the basis of contractual necessity.
When we process on the lawful basis of legitimate interest, we apply the following test to determine whether it is appropriate:
● The purpose test – is there a legitimate interest behind the processing?
● Necessity test – is the processing necessary for that purpose?
● Balancing test – is the legitimate interest overridden, or not, by the individual’s interests, rights or freedoms?
If you are applying for a role within the organisation, we will process the personal information you provide to us as part of your application and any interview selection process. This will ordinarily include your name, personal contact details, professional history, education and qualifications and references.
We use Constant Contact and Mail Chimp to send email newsletters. You will always find a link to unsubscribe from receiving future emails from Wooden Roots at the footer of every email sent from this platform.
5.0 Personal information you give to us:
Wooden Roots will process (collect, store and use) the information you provide in a manner compatible with the EU’s General Data Protection Regulation (GDPR). We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary. How long certain kinds of personal data should be kept may also be governed by specific business-sector requirements and agreed practices. Personal data may be held in addition to these periods depending on individual business needs.
We collect and process the following Personal Data:
Individual details ► name, address, email and telephone details
Financial information (to fulfil payments via payment card) ► payment card number, bank account number and account details.
Marketing data ► whether or not the individual has consented to receive marketing from us and/or from third parties. We will get your express opt-in consent before we share your personal data with any other company for marketing purpose
We collect, use, disclose and otherwise process Personal Data that is necessary for the purposes identified in this Privacy Notice or as permitted by law. If we require Personal Data for a purpose inconsistent with the purposes we identified in this Privacy Notice, we will notify clients of the new purpose and, where required, seek individuals’ consent (or ask other parties to do so on our behalf) to process Personal Data for the new purposes.
We collect personal data from our customers where necessary to provide our services or where an individual has otherwise consented to its collection. We may use the personal data collected for the purposes of:
● Providing our products and services to you or the organisation you represent.
● Operating back office, internal record keeping and administration services connected with the provision of our products and services.
● For billing, invoicing and payment purposes.
6.0 Why we use personal information
We will use personal information for the following purposes:
● Business Contacts:We process the personal information of our business contacts as necessary for the legitimate interests of managing the day-to-day operation of our business, including correspondence, engaging suppliers, and promoting our services to business contacts;
● Clients:We process the personal information of individuals that may work for our clients in the course of providing any of our services as detailed in Clause 1.0.
● Job Applicants:We process the personal information of job applicants for the legitimate interests of determining whether or not to employ a particular individual for a role in our organisation. Where we decide to employ a job applicant, we process their personal information for the purposes of entering into and performing our employment contract with the applicant.
7.0 Personal information shared with third Parties
We may pass your personal data on to third-party service providers contracted to Wooden Roots in the course of dealing with you. Any third parties that we may share your data with are obliged to keep your details securely, and to use them only to fulfil the service they provide you on our behalf. When they no longer need your data to fulfil this service, they will dispose of the details in line with Wooden Roots procedures. If we wish to pass any form of sensitive personal data onto a third party we will only do so once we have obtained your consent, unless we are legally required to do otherwise.
Typically these third parties will consist of:
● Suppliers: We use a number of different suppliers with whom we share personal information so that these suppliers can process services on our behalf. In these circumstances, we take steps required by data protection laws to ensure that these suppliers protect the personal information we share with them;
● Government bodies:We may be required by law to share personal information with government bodies and regulators.
We will not disclose your personal information to any other party other than in accordance with this Privacy Policy and in the circumstances detailed below:
i. In the event that we sell any or all of our business to the buyer.
ii. Where we are legally required by law to disclose your personal information. iii. To further fraud protection and reduce the risk of fraud.
We do not collect or compile personal data for release or sale to outside parties for consumer marketing purposes or host mailings on behalf of third parties.
8.0 Contacting you
Our aim is not to be intrusive, and we undertake not to ask irrelevant or unnecessary questions. Moreover, the information you provide will be subject to rigorous measures and procedures to minimise the risk of unauthorised access or disclosure.
9.0 What happens if you don’t give us your data
You can enjoy many of Wooden Roots services without giving us your personal data. Some personal information is necessary so that the we can supply you with the services you may have purchased or requested, and to authenticate you so that we know it is you and not someone else.
You may manage your subscriptions and you may opt-out of receiving marketing communication at any time. If we are not provided with access to personal information for the purposes outlined in this privacy notice we may not be able to offer or provide certain services, or we may not be able to complete job applications processing.
10.0 When and how we share information with others
The personal information Wooden Roots collects from you is stored in one or more databases hosted by a third party. This third party does not use or have access to your personal information for any purpose other than cloud storage and retrieval.
Wooden Roots website may use social media interfaces such as Facebook, LinkedIn and Twitter. If you choose to "like" or share information from the the website through these services, you should review the privacy policy of that service. If you are a member of a social media site, the interfaces may allow the social media site to connect your site visit to your personal data.
not otherwise reveal your personal data to third-parties for their independent use unless:
you request or authourise it;
the information is provided to comply with the law;
to address emergencies or acts of God; or
to address disputes, claims, or to persons demonstrating legal authority to act on your behalf.
to the extent necessary for fulfilling the purposes outlined in paragraph 5 and 6, including where necessary for the provision of services;
where we are under a legal or contractual obligation to do so; or
where is it fair and reasonable for us to do so in the circumstances.
11.0 Data Subject Rights
The European Union’s General Data Protection Regulation and other countries’ privacy laws provide certain rights for data subjects. A good explanation of them (in English) is available on the website of the United Kingdom’s Information Commissioner’s Office.
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr
At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
● Right of access – you have the right to request a copy of the information that we hold about you.
● Right of rectification– you have a right to correct data that we hold about you that is inaccurate or incomplete.
● Right to be forgotten– in certain circumstances you can ask for the data we hold about you to be erased from our records.
● Right to restriction of processing– where certain conditions apply to have a right to restrict the processing.
● Right of portability– you have the right to have the data we hold about you transferred to another organisation.
● Right to object– you have the right to object to certain types of processing such as direct marketing.
● Right to object to automated processing, including profiling– you also have the right to be subject to the legal effects of automated processing or profiling.
● Right to judicial review: in the event that we refuse your request under rights of access, we will provide you with a reason as to why.
Wooden Roots accepts the following forms of ID when information on your personal data is requested:
● Driving license
● Birth certificate
● Utility bill (within the last 3 months of request being made) If you wish to confirm that Wooden Roots is processing your personal data, or to have access to the personal data we may have about you, please contact us at dpo@Woodenroots.com
12.0 Security of Your Information
To help protect the privacy of data and personally identifiable information you transmit through use of this Site, we maintain physical, technical and administrative safeguards. We update and test our security technology on an ongoing basis. We restrict access to your personal data to those employees who need to know that information to provide benefits or services to you. In addition, we train our employees about the importance of confidentiality and maintaining the privacy and security of your information. We commit to taking appropriate disciplinary measures to enforce our employees' privacy responsibilities.
We take, when appropriate, all reasonable measures based on Privacy by design and Privacy by default principles to implement the necessary safeguards and protect the Processing of Personal data. We also carry out, depending on the level of risk raised by the processing, a Privacy impact assessment (“PIA”) to adopt appropriate safeguards and ensure the protection of the Personal data. We also provide additional security safeguards for data considered to be Sensitive Personal data.
When technically feasible, we will - at your request - provide your personal data to you or if technically feasible, transmit it directly to another controller.
13.0 Special Category of Information & Children 13.1 Special Category
Wooden Roots do not require or process any forms of sensitive personal data, if these circumstances change, we will always tell you why and how the information will be used.
Special categories of personal data are classified as
● Racial or ethnic origin
● Political opinions
● Religious or philosophical beliefs
● Trade-union membership
● Health or sex life
● Unique identity of a person by processing biometric or genetic data
13.2 Children
Children merit specific protection with regard to their Personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the Processing of Personal data. Such specific protection should, in particular, apply to the use of Personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child.
Our services are not targeted to children, therefore we do not collect and process Children’s Personal data. If in the future this in fact does change, then we shall not do so without the consent of the holder of parental responsibility where required. If you believe that we have mistakenly collected a Children's Personal data, please notify us using the contact details provided: dpo@woodenroots.com
14.0 Data Subject Access Request (SAR’s)
Wooden Roots at your request, can confirm what information we hold about you and how it is processed. If Wooden Roots does hold personal data about you, you can request the following information:
● Identity and the contact details of the person or organisation that has determined how and why to process your data.
● Contact details of the data protection officer, where applicable.
● The purpose of the processing as well as the legal basis for processing.
● If the processing is based on the legitimate interests of Wooden Roots or a third party, information about those interests.
● The categories of personal data collected, stored and processed.
● Recipient(s) or categories of recipients that the data is/will be disclosed to.
● If we intend to transfer the personal data to a third country or international organisation, information about how we ensure this is done securely. The EU has approved sending personal data to some countries because they meet a minimum standard of data protection. In other cases, we will ensure there are specific measures in place to secure your information.
● How long the data will be stored.
● Details of your rights to correct, erase, restrict or object to such processing.
● Information about your right to withdraw consent at any time.
● How to lodge a complaint with the supervisory authority.
● Whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether you are obliged to provide the personal data and the possible consequences of failing to provide such data.
● The source of personal data if it wasn’t collected directly from you.
● Any details and information of automated decision making, such as profiling, and any meaningful information about the logic involved, as well as the significance and expected consequences of such processing.
All data access request forms will be submitted to us (The Data Controller) at no additional cost. You will receive an email confirming acknowledgement of our receipt. The Data Protection Officer will respond to all data requests within 30 days. If for some reason access is denied, we shall provide an explanation as to why access has been denied. Should there be a delay due to unforeseen circumstances, you will be notified. If you remain unhappy by the way in which your request or data has been handled, you may email Wooden Roots at info@woodenroots.com or contact the Office of the Information Commissioner.
15.0 Data storage and retention
Your personal data is stored by Wooden Roots on a third-party cloud-based database management servers located in the United Kingdom. We retain data for the duration of the business relationship with both parties. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact Wooden Roots data protection officer.
16.0 Transferring Personal Data to Third Countries
Wooden Roots has its headquarters in the United Kingdom and information we collect from you will be processed within the United Kingdom. We do not share or retain any information outside of the E.U.
If however our business operations in the future constitute the need to transfer Personal Data to other countries outside the EEA, we will establish legal grounds justifying such transfer in order to safeguard Personal Data as set out in this Privacy Notice, which will consist of either:
● Binding Corporate Rules;
● Model Contractual Clauses;
● Individuals’ Consent;
● or other legal grounds permitted by applicable legal requirements.
17.0 Changes and updates to the Privacy Notice
By using this Site, you agree to the terms and conditions contained in this Privacy Notice and Conditions of Use and/or any other agreement that we might have with you. If you do not agree to any of these terms and conditions, you should not use this Site. You agree that any dispute over privacy or the terms contained in this Privacy Notice and Conditions of Use, or any other agreement we have with you, will be governed by the laws of the United Kingdom. You also agree to arbitrate such disputes within the United Kingdom, and to abide by any limitation on damages contained in any agreement that are stipulated by the Supervisory Authority.
We reserve the right to amend the Privacy Notice and Conditions of Use at any time, for any reason, without notice to you, other than the posting of the amended Privacy Notice and Conditions of Use at this Site. We may email periodic reminders of our notices and terms and conditions, but you should check our Site frequently to see the current Privacy Notice and Conditions of Use that is in effect and any changes that may have been made to it. Historic versions can be obtained by contacting us.
18.0 Lead Regulator
Wooden Roots is governed by the Office of the Information Commissioner (ICO) in the United Kingdom. Should we be unable to resolve your complaint, you may contact the ICO directly as detailed in Clause 19.0 of this Privacy Notice
19.0 Questions, Concerns or Complaints
In the event that you wish to make a complaint about how your personal data is being processed by us or any of our third parties, or how your complaint has been handled, you have the right to lodge a complaint directly with the Supervisory Authority or our Data Protection Officer as detailed below:
Please contact Wooden Roots Data Protection Officer:
Wooden Roots
Contact Name: Gemma Brown
Address: Building 136, Bentwaters Parks, Rendlesham, Woodbridge, IP12 2TW Tel No: + +44 (0)7846 761 145
Email: info@Woodenroots.com
Please contact Information Commissioner's Office:
Head Office Scotland Wales
Email: scotland@ico.org.uk Email: wales@ico.org.uk
N.Ireland
Email: ni@ico.org.uk
Wycliffe House Water Lane Wilmslow Cheshire
SK9 5AF
45 Melville Street Edinburgh
EH3 7HL
2nd floor Churchill House Churchill way Cardiff
CF10 2HH
3rd Floor
14 Cromac Place Belfast
BT7 2JB
Telephone No: 0303 123 1113 or
01625 545 745
Telephone No: 0303 123 1115
Telephone No: 029 2067 8400
Telephone No: 028 9027 8757 or
0303 123 1114