Privacy Policy

Document and shield representing privacy policy

I am committed to protecting any data collected concerning you


1. Introduction

This Privacy Policy describes how www.davidleonard.london (referred to as “we,” “us,” or “our”) collects, uses, and shares personal data of visitors and customers. We are committed to protecting your privacy and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

2. Data Controller

The data controller responsible for the personal data collected on this website is:

David Leonard
Clapham High Street
London SW4
email@davidleonard.london

3. Personal Data We Collect

We may collect the following types of personal data from you:

If you make a purchase via PayPal, we will collect information necessary to process your payment, which may include your name, billing address, shipping address, email address, and transaction details. Please note that the full payment information (such as credit card details) is handled directly by PayPal and is subject to their privacy policy.

IP Address: our security plugin, Wordfence, processes your IP address to identify and block malicious activity and protect our website.

Cookie Information: we use cookies to enhance your browsing experience and for the functionality of our cookie consent notice.

Website Analytics (WP Statistics): we use the WP Statistics plugin to analyse website traffic. This plugin does not set any cookies, and IP addresses are anonymized by being turned into irreversible hashes before being stored. This helps us understand how visitors use our website without identifying individuals.

Information you provide through our “Contact” page: when you use our “Contact” page, we collect the information you provide in the form, which typically includes your name, email address, and the content of your message.

4. How We Collect Your Personal Data

We collect your personal data in the following ways:

  • Directly from you through PayPal: when you make a payment for our IT services or make a voluntary donation via PayPal, you directly provide them with the necessary information. We receive confirmation of the transaction from PayPal, which includes some of your personal details related to the transaction.
  • Automatically: our Wordfence security plugin automatically processes your IP address when you visit our website. We also use cookies that are stored on your device when you interact with our website and the cookie consent banner.

5. Why We Use Your Personal Data (Purposes of Processing)

We use your personal data for the following purposes:

To process payments: if you pay for our IT services or make a donation via PayPal, we use the information you provide to process the transaction, confirm payment, and, if necessary, provide the services you have paid for or acknowledge your donation.

To ensure website security: we use your IP address, processed by our Wordfence security plugin, to monitor and block potential security threats, prevent malicious activity, and protect our website and its visitors.

To manage cookie consent: we use cookies to remember your preferences regarding cookies and to ensure that the cookie banner is displayed and functions correctly.

To respond to your inquiries: we use the information you provide through our “Contact” page to respond to your questions, comments, or requests.

6. Legal Basis for Processing

Under the General Data Protection Regulation (GDPR), we rely on the following legal bases for processing your personal data:

Contract: for processing payments related to IT services purchased, the legal basis is that it is necessary for the performance of a contract between you and us.
Consent: for the use of non-essential cookies, we rely on your explicit consent obtained through our cookie banner.
Legitimate Interest: for processing your IP address via Wordfence, we rely on our legitimate interests in maintaining the security and integrity of our website and protecting it and its visitors from malicious activity. We also rely on our legitimate interests to respond to your inquiries when you contact us through our “Contact” page. We have balanced our interests against your rights and freedoms and believe this processing is necessary for these purposes.
Voluntary Donation: for processing personal data related to voluntary donations via PayPal, the legal basis is your explicit consent when you choose to make a donation.

7. Sharing Your Personal Data

We may share your personal data with the following third parties:

PayPal: if you make a payment for our IT services or a donation, we share transaction details and necessary personal information (such as your name and contact details) with PayPal to process the payment. PayPal will also process your payment information according to their own privacy policy, which can be found here: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full.

Regarding Wordfence, while it processes IP addresses, the data is primarily used for security purposes within our own website environment and is generally not shared with third parties unless there’s a security incident requiring investigation. We do not routinely share the IP address data collected by Wordfence with external entities.

8. International Transfers of Personal Data

Please be aware that if you use PayPal to make a payment or donation, your personal data may be transferred to and processed in countries outside of the UK and the European Economic Area (EEA) by PayPal. These countries may have data protection laws that are different from the laws in your country. We encourage you to review PayPal’s Privacy Policy (https://www.paypal.com/uk/webapps/mpp/ua/privacy-full) for more information about their data processing practices and international data transfers.

Regarding Wordfence, the IP addresses it collects are primarily for security purposes and are generally processed on our servers. We do not intentionally transfer this data internationally.

9. Data Security

We take reasonable measures to protect the personal data we collect from unauthorized access, use, or disclosure. These measures include implementing security plugins like Wordfence, which helps to protect our website from malicious attacks and unauthorized access.

When you make payments or donations via PayPal, your payment information is processed securely by PayPal. We do not store your full payment details on our website. PayPal uses industry-standard security measures to protect your payment data.

While we strive to use commercially acceptable means to protect your personal data, please remember that no method of transmission over the internet or method of electronic storage is 100% secure

10. Data Retention

We will retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy and to comply with our legal and regulatory obligations.

Transaction data related to PayPal payments and donations will be retained for as long as required for accounting, tax, and legal purposes, typically for a period of several years. PayPal will also have its own data retention policies.

IP addresses collected by our Wordfence security plugin are typically retained for a limited period to analyze security incidents and maintain website security. The specific retention period is managed within the Wordfence plugin.

Data related to your cookie consent is retained for the duration of the cookie’s lifespan as set by the “Simple GDPR Cookie Compliance” plugin (currently set to 30 days).

After the retention period expires, your personal data will be securely deleted or anonymized.

11. Your Rights Under GDPR

Under the General Data Protection Regulation (GDPR), you have several rights regarding your personal data:

The right to access: you have the right to request a copy of the personal data we hold about you.

The right to rectification: you have the right to ask us to correct any personal data you believe is inaccurate or incomplete.

The right to erasure (the “right to be forgotten”): you have the right to ask us to delete your personal data under certain circumstances.

The right to restriction of processing: you have the right to ask us to restrict the processing of your personal data under certain circumstances.

The right to object to processing: you have the right to object to the processing of your personal data under certain circumstances, including for direct marketing purposes.

The right to data portability: you have the right to request that we transfer the data we have collected about you to another organization, or directly to you, under certain circumstances.

The right to withdraw consent: if we are processing your personal data based on your consent (such as for non-essential cookies or voluntary donations), you have the right to withdraw your consent at any time.

The right to lodge a complaint with a supervisory authority: you have the right to lodge a complaint with a data protection authority if you have concerns about how we are processing your personal data. The UK supervisory authority is the Information Commissioner’s Office (ICO).

If you wish to exercise any of these rights, please contact us using the information provided in the “Contact Us” section below. We will respond to your request in accordance with GDPR requirements.

12. Cookies

Our website uses cookies to enhance your browsing experience and to manage your cookie preferences.

We use the following types of cookies:

Necessary Cookies: these cookies are essential for the basic functionality of our website and to remember your cookie consent preferences. The “Simple GDPR Cookie Compliance” plugin sets a cookie to record whether you have accepted our cookie notice. This cookie typically has an expiry period of 30 days.

You can manage your cookie preferences through the cookie banner that appears on our website.

We do not currently use other types of cookies that require explicit consent beyond those necessary for the cookie consent management itself and basic website operation.

13. Third-Party Websites

Our website may contain links to other websites, such as PayPal. Please note that we have no control over the content and privacy practices of these third-party websites. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites, and such sites are not governed by this Privacy Policy. You should exercise caution and look at the privacy statement applicable to the website in question.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time in response to changing legal, technical, or business developments. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We encourage you to periodically review this page for the latest information on our privacy practices.

15. Contact Us

If you have any questions or concerns about this Privacy Policy or our data processing practices, please contact us at:

email@davidleonard.london
+44 7961 387564

 

 

Man guards locked vault containing filing cabinets

 


Icon by VectorPortal