Legal
A practical statement of the principles Atlas Leather Limited should apply when handling personal data.
This policy applies to personal data handled by ATLAS LEATHER LIMITED in connection with website enquiries and ordinary business administration. The business should take proportionate steps to ensure personal data under its control is handled in accordance with applicable UK data-protection requirements.
Personal data should be processed lawfully, fairly and transparently; collected for specified and legitimate purposes; limited to what is necessary; kept accurate where appropriate; retained no longer than necessary; and protected using proportionate security measures. Accountability should be supported through appropriate records and procedures.
An appropriate lawful basis should apply before personal data is processed. Depending on the situation this may include consent, steps requested before a contract, performance of a contract, legal obligation or legitimate interests. Special-category data should not be requested or processed unless there is a clear need and an appropriate legal condition.
Requests for access, rectification, erasure, restriction, objection or portability should be handled without unnecessary delay and in accordance with the conditions that apply. Where a request is unclear or identity cannot be confirmed, reasonable clarification or verification may be requested.
A person may ask whether their personal data is being processed and request a copy of relevant information. Requests can be made through hello@atlasleather.co.uk. Searches should be proportionate to the request, while information relating to other individuals or legally protected material may need to be withheld where the law requires.
Only information reasonably relevant to the business purpose should be collected. Records should be reviewed and removed or anonymised when there is no continuing business or legal reason to retain them.
Where third-party providers process personal data on behalf of the business, the relationship should be assessed and appropriate data-processing terms used where required. Access should be limited to what is necessary for the service being provided.
Reasonable safeguards should reduce the risk of unauthorised access, loss, alteration or disclosure. Suspected personal-data breaches should be assessed promptly. Where statutory reporting thresholds are met, notifications should be made within the applicable legal requirements.
The theme does not implement automated decision-making or profiling that produces legal or similarly significant effects. If such processing is introduced later, it should be assessed and documented before use.
This policy should be reviewed when business systems, processing activities or legal requirements materially change.