Privacy policy
I store and process people’s personal data, so I have obligations under
data protection legislation. This document outlines how I meet these
obligations.
If you have a question or request relating to my handling of
your personal data, you can contact me on 07837
751985 or martin@martinedwards.co.uk.
Summary
The Data Protection Act and UK GDPR are about how people’s personal data is
collected, processed and stored. They require that the data be collected
and processed only for well-defined purposes, handled securely, kept up to
date, and retained no longer than necessary.
I collect and process personal data for a variety of purposes, and store it
in multiple places.
In this document, I use the word ‘customer’ to mean any person who has
contacted me in relation to the services I offer.
Address book
For each customer, I store basic contact details like name, address, email
address and phone number.
- I obtain some of these details implicitly. For example, if a new
customer phones me, their number will likely show up on my phone.
- I obtain some details explicitly. For example, I might ask a customer
for their address in order to visit them.
- I obtain some details from public sources, usually to fill gaps or
verify other information. For example, if a customer gives me just the
first line of their address, I might use an online service to find the
postcode.
I call the sum of this information my ‘address book’, and its main purpose
is the legitimate interest of serving customers in a more personal way. For
example, when a customer phones me I can greet them by name, or when they
require home visits I can look up their address rather than ask for it each
time. It also enables me to provide
proper invoices.
I store my address book in Google Workspace. The account is protected by
two-factor authentication. I sync the address book to my computer, and back
it up to an external drive, both of which are encrypted. It is also synced
to my phone, which is encrypted, can be erased remotely if lost, and is
set to erase automatically after repeated incorrect passcode entry.
Customers can contact me to request that I update or delete their data in
my address book, or to request a copy of this data.
Once a year I compare my address book to my financial records for the year
just ended and the two before it, and delete from the address book any
customers who don’t appear in those financial records. In other words, I
delete the personal data of customers I haven’t served for three years. An
exception is made for customers on my mailing list, whose contact details I
retain for as long as they remain opted in to the list.
Updates or deletions may take months or even years to propagate to backups,
although these copies are kept only in a single, offline location. Any
customer with a particular need can request that I expedite the complete
deletion of their data, and I will do my best to accommodate this.
Email messages
I retain email messages on a legitimate interest basis for two main
reasons. First, I can maintain context for subsequent messages – in other
words, ‘threads’ or ‘conversations’ – as is expected in email. Second, I can
refer back to information that may help me serve customers better in
future.
I store email messages in Google Workspace, sync them to my phone, archive
them to my computer, and back them up to an external drive — which are
protected as detailed in the address book section above.
Customers can contact me to request a copy of my email exchanges with them,
or to have them deleted.
At least once a year I delete all email messages older than three
years.
Offline backup copies will remain longer, as detailed in the address book
section above.
Other electronic messages: SMS, WhatsApp and similar
I retain messages sent and received via SMS, RCS, iMessage, WhatsApp and
similar platforms on a legitimate interest basis for the same reasons as
email messages, detailed above.
These messages are varyingly synced between my computer and phone, which
are protected as detailed in the address book section above.
Customers can contact me to request a copy of my electronic conversations
with them, or to have them deleted.
I delete these messages periodically, on an automatic basis where possible.
Typically, none are retained for more than a few months. They are not
backed up anywhere. These factors, along with the end-to-end encryption in
iMessage and WhatsApp, make these channels preferable to email for the
exchange of more sensitive information.
Mailing list
I operate a mailing list to communicate occasional tips and significant IT
news. Customers join this list by giving their explicit
consent. I may occasionally ‘refresh’ this consent by reminding
customers of their membership and asking them to remain opted in.
I record a customer’s membership of the list by adding a label to their
entries in my address book, detailed above.
A customer can contact me to update their email address. A customer can
withdraw their consent – that is, be removed from the mailing list – by
contacting me or by following the ‘unsubscribe’ link in any of the
mailings.
Financial records
I have a
legal obligation to keep financial records for
Self
Assessment. These records include customers’ names, products or services
purchased from me and amounts paid.
I store my financial records in Google Workspace, and back them up to my
computer and external drive, which are protected as detailed in the address
book section above.
HMRC requires that I
keep financial records for at least five years. After this time, I
anonymise them by removing customers’ names. This anonymisation may take
considerable time to propagate to backup copies, as detailed in the address
book section above.
Invoicing systems
Customers can choose to pay me by debit card, credit card or PayPal. I use
SumUp to send invoices and accept payments by card, and PayPal to send
invoices and accept payments both by card and directly via PayPal. With both
companies I store necessary information about customers and their purchases,
much the same as in my address book and financial records detailed above.
This, along with any personal and financial information entered by customers
when settling SumUp and PayPal invoices, will be processed and stored by
those companies.
‘Coffee’ contributions
The explanatory articles and how-to guides on my website include links to
my page on Buy Me a Coffee, via which anyone can buy me one or more
‘coffees’ as a show of appreciation (it’s not really coffee, just a small
financial contribution). Personal and financial information entered during
this process will be processed and stored by both Buy Me a Coffee and
Stripe.
Feedback
I welcome feedback to help me improve this privacy policy and the clarity
with which it is explained. I can be contacted on
07837 751985 or
martin@martinedwards.co.uk.