Privacy Policy

Date of publication: 29 May 2019

This privacy policy notice is served by STUDIO GEORGE CHAPMAN, ASC Studios, Art House, Grafton Quarter, London, CR0 3RP under the website www.gnchapman.com. The purpose of this policy is to explain to you how we control, process, handle and protect your personal information through the business and while you browse or use this website. If you do not agree to the following policy you may wish to cease using this website, and or refrain from submitting your personal data to us.

Key definitions

"I", "our", "us", or "we" refer to the business STUDIO GEORGE CHAPMAN.

"you", "the user" refer to the person(s) using this website.

GDPR means General Data Protection Act.

PECR means Privacy & Electronic Communications Regulation.

ICO means Information Commissioner's Office.

Cookies mean small files stored on a users computer or device.

Key principles of GDPR

Our privacy policy embodies the following key principles; (a) Lawfulness, fairness and transparency, (b) Purpose limitation, (c) Data minimisation, (d) Accuracy, (e) Storage limitation, (f) Integrity and confidence, (g) Accountability.

Processing of your personal data

Under the GDPR (General Data Protection Regulation) we control and / or process any personal information about you electronically using the following lawful bases.

We are exempt from registration in the ICO Data Protection Register because we only collect data related to our core business activities.

Lawful basis: Consent

Where our purpose for processing is: Fulfilling sales to customers, and marketing and advertising our products.

Which is necessary because: These are our core activities as a business.

We process your information in the following ways: We forward your payment and billing information to our payment gateway (Stripe Payments Europe, Ltd) to fulfill your order; we also use your contact information (email address) to keep you informed about your order history and marketing information.

Data retention period: We will continue to process your information under this basis until you withdraw consent or it is determined your consent no longer exists.

Sharing your information: We do share your personal information with third parties and they include:

  • Stripe Payments Europe, Ltd (payment gateway)

  • Squarespace (website hosting platform)

If, as determined by us, the lawful basis upon which we process your personal information changes, we will notify you about the change and any new lawful basis to be used if required. We shall stop processing your personal information if the lawful basis used is no longer relevant.

Your individual rights

Under the GDPR your rights are as follows. You can read more about your rights in details here:

  • the right to be informed;

  • the right of access;

  • the right to rectification;

  • the right to erasure;

  • the right to restrict processing;

  • the right to data portability;

  • the right to object; and

  • the right not to be subject to automated decision-making including profiling.

You also have the right to complain to the ICO [www.ico.org.uk] if you feel there is a problem with the way we are handling your data.

We handle subject access requests in accordance with the GDPR.

Internet cookies

When you visit our website, your browser will display a cookie banner to notify you that we use cookies, and display a link to our cookie policy. By using our website, you agree to our use of cookies.

We use cookies on this website to provide you with a better user experience. We do this by placing a small text file on your device to track how you use the website, to record or log whether you have seen particular messages that we display, to keep you logged into the website where necessary, to display relevant adverts or content, referred you to a third party website.

Some cookies are required to use key features of this website.

Below is a list of cookies used by Squarespace [www.squarespace.com] for customer accounts, shopping cart and checkout, and URL redirects:

  • Cookie name: Crumb

    Duration: Session

    Purpose: Prevents cross-site request forgery (CSRF). CSRF is an attack vector that tricks a browser into taking unwanted action in an application when someone’s logged in.

  • Cookie name: RecentRedirect

    Duration: 30 minutes

    Purpose: Prevents redirect loops if a site has custom URL redirects. Redirect loops are bad for SEO.

  • Cookie name: CART

    Duration: 2 weeks

    Purpose: Shows when a visitor adds a product to their cart

  • Cookie name: hasCart

    Duration: 2 weeks

    Purpose: Tells Squarespace that the visitor has a cart

  • Cookie name: Locked

    Duration: Session

    Purpose: Prevents the password-protected screen from displaying if a visitor enters the correct site-wide password.

  • Cookie name: SiteUserInfo

    Duration: 3 years

    Purpose: Identifies a visitor who logs into a customer account

  • Cookie name: SiteUserSecureAuthToken

    Duration: 3 years

    Purpose: Authenticates a visitor who logs into a customer account

  • Cookie name: Commerce-checkout-state

    Duration: Session

    Purpose: Stores state of checkout while the visitor is completing their order in PayPal

  • Cookie name: squarespace-popup-overlay

    Duration: Persistent

    Purpose: Prevents the Promotional Pop-Up from displaying if a visitor dismisses it

  • Cookie name: squarespace-announcement-bar

    Duration: Persistent

    Purpose: Prevents the Announcement Bar from displaying if a visitor dismisses it

  • Cookie name: Test

    Duration: Session

    Purpose: Investigates if the browser supports cookies and prevents errors.

  • Cookie name: ss_cid

    Duration: 2 years

    Purpose: Identifies unique visitors and tracks a visitor’s sessions on a site

Below is a list of cookies used by Squarespace for analytics and performance:

  • Cookie name: ss_cid

    Duration: 2 years

    Purpose: Identifies unique visitors and tracks a visitor’s sessions on a site

  • Cookie name: ss_cvr

    Duration: 2 years

    Purpose: Identifies unique visitors and tracks a visitor’s sessions on a site

  • Cookie name: ss_cvisit

    Duration: 30 minutes

    Purpose: Identifies unique visitors and tracks a visitor’s sessions on a site

  • Cookie name: ss_cvt

    Duration: 30 minutes

    Purpose: Identifies unique visitors and tracks a visitor’s sessions on a site

  • Cookie name: ss_cpvisit

    Duration: 2 years

    Purpose: Identifies unique visitors and tracks a visitor’s sessions on a site

  • Cookie name: ss_cookieAllowed

    Duration: 30 days

    Purpose: Remembers if a visitor agreed to placing Analytics cookies on their browser if a site is restricting the placement of cookies

Data security and protection

We ensure the security of any personal information we hold by using secure data storage technologies and precise procedures in how we store, access and manage that information. Our methods meet the GDPR compliance requirement.

Fair & Transparent Privacy Explained

We have provided some further explanations about user privacy and the way we use this website to help promote a transparent and honest user privacy methodology.

Sponsored links, affiliate tracking & commissions

Our website does not make use of third-party adverts, sponsored and affiliate links.

Email marketing messages & subscription

Under the GDPR we use the consent lawful basis for anyone subscribing to our newsletter or marketing mailing list. We only collect certain data about you, as detailed in the “Processing of your personal data” above. Any email marketing messages we send are done so through an EMS, email marketing service provider. An EMS is a third party service provider of software that allows marketers to send out email marketing campaigns to a list of users.

Email marketing messages that we send may contain tracking beacons / tracked clickable links or similar server technologies in order to track subscriber activity within email marketing messages. Where used, such marketing messages may record a range of data such as; times, dates, I.P addresses, opens, clicks, forwards, geographic and demographic data. Such data, within its limitations will show the activity each subscriber made for that email campaign.

Any email marketing messages we send are in accordance with the GDPR and the PECR. We provide you with an easy method to withdraw your consent (unsubscribe) or manage your preferences / the information we hold about you at any time. See any marketing messages for instructions on how to unsubscribe or manage your preferences, you can also unsubscribe from all MailChimp lists, by following this link, otherwise contact the EMS provider.

Our EMS provider is MailChimp. We hold the following information about you within our EMS system:

  • Email address

  • IP address

  • Subscription time and date

Resources & further information

Overview of the GDPR - General Data Protection Regulation

Data Protection Act 2018

Privacy and Electronic Communications Regulations 2003

The Guide to the PECR 2003

Twitter Privacy Policy

Instagram Privacy Policy

Squarespace Privacy Policy

MailChimp Privacy Policy