Privacy and Cookies Policy – Fonz Leather Styles Ltd.
1. Data Protection Policy Introduction
Fonz Leather Styles Ltd. [we] hold personal data about our employees, clients, suppliers, and other individuals for a variety of business purposes.
This policy defines how we protect personal data and ensures that customers and staff understand the rules governing its use.
Staff must consult the Communications Director before initiating any significant new data processing activity, such as setting up a competition or database with identifiable personal details, to ensure compliance with applicable laws.
2. Why Do We Collect Data?
2.1 Business Purposes
We use personal data for purposes such as sales, personnel, administration, finance, payroll, legal compliance, service operations, and business development.
These purposes include:
Order fulfilment and transaction recording
Maintaining confidentiality of commercially sensitive information and CCTV
Legal and regulatory compliance
Supporting investigations by regulatory bodies or in legal matters
Policy enforcement and issue resolution
Monitoring access, conduct, and performance
Staff training and development
Marketing and improving our services
Health and safety compliance
2.2 Personal Data
Personal data includes names, contact details, user IDs, job information, educational background, payroll data, identification numbers, and more.
2.3 Sensitive Personal Data
This includes data on ethnicity, criminal history, or similar. We do not collect sensitive personal data from customers, prospects, or suppliers.
3. Scope
This policy applies to all employees of Fonz Leather Styles Ltd. who handle personal data. It supplements our policies on internet, email, and other forms of data processing.
3.1 Responsibility
The Operations Manager of Fonz Leather Styles Ltd. is responsible for implementing and overseeing this policy.
4. Our Procedures
4.1 Fair and Lawful Processing
We only process personal data when the individual has consented or when we have a legitimate reason.
4.2 Operations Manager Responsibilities
Keeping leadership informed
Reviewing procedures
Coordinating staff training
Responding to data access and privacy requests
4.3 IT Manager Responsibilities
Ensuring systems meet security standards
Monitoring software integrity
Evaluating third-party data processors
4.4 Communications Director Responsibilities
Ensuring employee and customer data practices comply
Approving data protection disclaimers
Reviewing third-party processor contracts
4.5 Finance Director Responsibilities
Supporting data accuracy within payroll and sales
4.6 General Processing Principles
All data must be processed in our business interest while respecting individuals' privacy.
4.7 Processing Sensitive Data
We require explicit consent to process sensitive data unless legally required.
4.8 Accuracy and Relevance
We maintain accurate, up-to-date data and correct inaccuracies upon request.
4.9 Updating Data
Staff should report personal data changes to HR. Suppliers or customers must inform the Operations Manager.
4.10 Data Security
We ensure data is secure and include appropriate clauses in third-party contracts.
4.11 Storing Data
Paper files are stored securely
Unneeded documents are shredded
Digital data is encrypted and password-protected
Servers are secured and backed up
Cloud services must be IT-approved
Mobile devices with sensitive data must use encryption
4.12 Data Retention
We only retain data for as long as necessary for its purpose.
4.13 Transferring Data
All transfers must use secure protocols (e.g., HTTPS, SSH).
4.14 International Transfers
International data transfers require prior approval from the Communications Director.
5. Subject Access Requests
Under data protection laws, individuals may request access to their data. These requests must be referred to the Operations Manager.
5.1 Processing in Line with Rights
We do not send direct marketing unless there's an existing relationship or explicit consent. Individuals may opt out at any time.
5.2 Training
All staff will receive regular data protection training.
6. GDPR Provisions
6.1 Transparency
We provide clear information about data usage upon request.
6.2 Lawful Processing
All personal data use must be based on valid legal grounds.
6.3 Justification
We use Consent, Contract, Legal Obligation, or Legitimate Interest as the basis for processing.
6.4 Consent
Consent is actively obtained and may be revoked.
6.5 Criminal Record Checks
Only conducted when legally justified.
6.6 Data Portability
Data subjects can request structured copies of their data, or its transfer to another system.
6.7 Right to Be Forgotten
Data can be erased on request unless exemptions apply (e.g., ongoing contract obligations).
6.8 Privacy by Design
New IT projects must integrate privacy from the outset.
6.9 International Transfers
Require prior consent and oversight.
6.10 Data Audits
Regular audits are conducted to track and assess data practices.
6.11 Breach Reporting
All staff must report data breaches to the Operations Manager.
6.12 Monitoring
The Operations Manager monitors compliance with this policy.
6.13 Complaints
You may file complaints with the UK’s Information Commissioner’s Office:
Phone: +44 303 123 1113
Email: casework@ico.org.uk
Website: www.ico.org.uk
Address: Water Lane, Wycliffe House, Wilmslow, Cheshire, SK9 5AF
7. Cookies
ashwoodleather.com uses cookies to enhance user experience and maintain functionality such as shopping carts.
We operate an implied consent policy, assuming you accept cookies unless you disable them via your browser.
If you'd like to learn more about managing cookies, visit:
Your Consent
By using ashwoodleather.com, you consent to our use of cookies unless you disable them.