Divine Art Limited (the Company)
Introduction
The data that customers, press and media contacts, artists and other individuals connected to the business of the Company provide are held and processed electronically and the Company has a duty to comply with all current UK data protection legislation (“the Legislation”) including as from 25 May 2018 the General Data Protection Regulation.
What data does the Company keep?
The Company holds only such data concerning members as are necessary for its activities. This principally consists of all or any of the name, postal address, telephone number(s) and email address(es) of members. This data is not considered to be “sensitive data” as classified in the Legislation. In respect of customers, the Company does not keep bank or credit card information on our servers, as this information is encrypted and passed through our payment processers in order to complete transactions; in the case of those who are entitled to royalty payments, the Company also may keep a record of bank account or Paypal account details. The Company does not keep details of credit or debit cards, age, marital status, ethnicity, religion or any other such personal data which is regarded as Sensitive.
The Company is registered with the Information Commissioner’s Office (registration reference Z7560476) and has been since its incorporation in 1993. The Company has responsibilities of care in respect of the data it holds and this Policy explains how these responsibilities are being addressed.
Accuracy
The data the Company holds is all provided by the individual in question on request or voluntarily and thereafter by way of periodic update. Individuals may ask the Company to confirm the data held. Unless and until individuals come forward with amendments to their data the Company is entitled to assume that such data is accurate. An individual may ask for his or her data to be deleted by email to admin@divineartrecords.com but must accept that if subsequently entering into any transaction with the Company requiring the retention of data then the data will once be stored again at that point.
What is the data used for?
The data is only used for legitimate Company purposes, which include:
- Communication with customers, distributors, dealers, press and media contacts, composers, performing musicians, producers, engineers and other technical staff (including suppliers of photographs, images programme notes and other material inter alia) as necessary for the orderly and efficient management of the Company’s business.
- Contacting customers with details of other products we provide.
- Sharing information from third parties where it is requisite or appropriate to do so in the conduct of the Company’s business.
- The Company will not disclose any such personal data to third parties or use it on behalf of third parties.
Who has access to the data?
Only those who need to have access to the data for the legitimate purposes of the Company have access. The following officers of the Company have access to all the member data: Chief Executive; CEO’s Personal Assistant; Company Secretary/Accounts Director; an agent of the Company managing promotional work.
How is the data protected?
The Company’s site is run through TLS encryption and all data entered into forms is sent securely and stored securely with only the above officers having access. Most of the data the Company keeps is not classified by the Legislation as sensitive, as it comprises only name, address, email address and phone number. It is assumed therefore that the risks that the Company is exposed to are no greater than the risks of an individual providing the same data to a friend for social purposes. Sensitive data such as bank account details are not stored on the Company’s server, but are sent through encryption to our payment processors where necessary for enabling payments to be made. Data held electronically by the Company is held on individual computer drives which are not part of a network and paper records are held in secure storage.
E-mail usage
All group emails to any set of individuals are sent ‘blind-copy’ so that individual addresses are not exposed.
Who is responsible for the implementation of this policy?
A nominated officer of the Company is responsible for ensuring that this policy is adhered to. The current nominee is Stephen Sutton, CEO.
Stephen Sutton
CEO
17 May 2018
The Company:
Divine Art Limited (registered in England and Wales, number 2003292)
Main operations and headquarters office:
Diversions LLC, trading (inter alia) as Divine Art USA
333 Jones Drive, Brandon, Vermont 05733, USA
Incorporating Métier Records, Athene Records, Dunelm Records, and Heritage Media