Privacy Policy

Andy Watts Photography (“we”, “us”, “our”)

Effective date: 14/07/25

1. Introduction

We respect your privacy and are committed to protecting your personal information. This Policy explains how we collect, use, store, share, and delete personal data when you:

- Sign up for our newsletter

- Make a payment

- Contact us via our website

This is in accordance with the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

2. Data Controller

Andy Watts is the data controller.

For any data queries or rights requests, email: hello@andywattsphotography.co.uk

3. What Personal Data We Collect

Identity: name, email address, phone number, address (if provided)

Payment Info: transaction details (amount, date, reference) via third‑party processors

(Stripe/PayPal). We do not store card numbers ourselves .

4. How We Use Your Data

We process your data for the following purposes:

  • To provide photography services and fulfil bookings
  • To process payments securely
  • To send newsletters and marketing communications (with your consent)
  • To respond to enquiries and provide customer support
  • To improve our website and services through analytics

5. Legal Bases for Processing

We rely on the following legal grounds to process your data:

  • Contract: when providing services or processing payments
  • Consent: when sending newsletters or marketing
  • Legal obligation: when required for tax or accounting purposes
  • Legitimate interests: to improve services and manage our business

6. Data Sharing
We may share your data with:

Payment processors (Stripe, PayPal)

Email marketing platforms (e.g. Mailchimp, if used)

Professional advisors (accountants, legal)

Service providers that help us operate our website

We will never sell your personal data.

7. Data Retention

We only keep your personal data for as long as necessary:

  • Payment and booking records: up to 7 years (for tax/legal reasons)
  • Newsletter/marketing data: until you unsubscribe
  • Enquiries: up to 12 months after last contact

8. Data Protection
We use appropriate technical and organisational measures to protect your data, including encryption, secure servers, and restricted access.

9. Your Rights
You have the right to:

- Access your personal data

- Correct inaccurate or incomplete data

- Request deletion of your data (“right to be forgotten”)

- Restrict or object to processing

- Data portability (request a copy in a structured format)

- Withdraw consent at any time (for marketing emails)

- Complain to the Information Commissioner’s Office (ICO) if you believe your rights have been breached: www.ico.org.uk

10. Cookies
Our website may use cookies for functionality and analytics. You can control cookie settings through your browser or decline non-essential cookies when prompted. Read our cookie policy.

11. Changes to This Policy
We may update this Privacy Policy from time to time. Any updates will be posted on this page with a new effective date.