This new regulation requires websites etc to conform to certain standards regarding the collection of customer data. Strawberry Jam Books and our Story Shop site fully support these updated laws. We don’t collect or use or share any customer/user data in our main site. Our Story Shop collects customer names and addresses and emails at point of sale for the purpose of despatching and dealing with orders. We do not use this for anything else or pass this information on to anyone. Our Story Shop webhosts are freewebstore who have their own GDPR compliance statement. You will need to look on their site or contact them for details.
Story Therapy GDPR STATEMENT OF COMPLIANCE
This document that follows explains how I comply. If you have given me your email address (by emailing or buying something from Story Shop then this explains how we look after your data responsibly. The rules are designed for organisations or companies I am an individual with a non-profit project. However:
1 Awareness
This store is hosted by ecommerce and they abide by the GDPR regulations. See their website or contact them for details.
I do not share this information with anyone. Ever. I have a highly trusted freelance web manager. He does not have access to customer email or Shop login. The same applies to all who assist on an occasional and voluntary basis with this family run project.
I have put this document on my Story Therapy site and added a link to it from the News page of my author and Strawberry Jam Books website.
On request, I will delete data. If someone asked to see their data, I would take a screenshot of any entry/entries. Customer data consists of names and addresses, products ordered and amounts paid for those orders.
I aim to respond to all such requests within five working days.
Lawful basis for processing data
I regard this consent as confirmed for the duration of this store, unless a person asks me to remove their data earlier. I have never harvested email addresses, nor would I.
Children
I am a children's author. Young people might sometimes email me but I wouldn't know their age unless they told me – and I would only have their word for that. I would not deliberately keep their email address (but hotmail/outlook would save it in my account.) Since I am not “processing” their data, I would not be required to ask for parental consent. I would reply to the emails and not contact them again.
Data breaches
My computer and accounts are password protected. If any of these were compromised I would take steps to follow security advice immediately.
I have taken steps to abide by the new protection rules and believe that I am using best practice to the best of my knowledge and ability.
contact
admin@storytherapyresources.co.uk for online store issues
International Data protection supervisory authority is the UK’s ICO.
Story Therapy April 2018, checked 2021, 2022, 2024