Privacy Policy

GDPR Privacy Policy of Great and Small Limited
Last updated: September 2021

Definitions
The Company
Great and Small Limited t/s Station House Vets, Teal House, Welburn, York YO60 7EP

GDPR General Data Protection Regulation Act.
Data Controller Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are, or are to be, processed.

Data Processor
Data Processor means any natural or legal person who processes the data on behalf of the Data Controller. This could be a third party – for example external laboratory, external reminder services etc

Data Subject
Data Subject is any living individual who is using our Service and is the subject of Personal Data.

1. Principles for processing personal data

Our principles for processing personal data are:

Fairness and lawfulness.
When we process personal data, the individual rights of the Data Subjects must be protected. All personal data must be collected and processed in a legal and fair manner.

Restricted to a specific purpose.
The personal data of Data Subject must be processed only for specific purposes.

Transparency.
The Data Subject must be informed of how his/her data is being collected, processed and used.

2. What personal data we collect and process

The Data controller collects several different types of personal data for various purposes. Personal Data may include, but is not limited to:
Email address
First name and last name
Phone numbers
Address, Postal code,

3. How we use the personal data
Station House Vets Ltd uses the collected personal data for various purposes:
To provide you with services. This could include a third party – for example external laboratory, external reminder services etc
To gather analysis or valuable information so that we can improve our services
To detect, prevent and address technical issues

4. Legal basis for collecting and processing personal data
The data controller legal basis for collecting and using the personal data described in this Data Protection Policy depends on the personal data we collect and the specific context in which we collect the information:
The Data controller needs to perform a contract with you
You have given the Data Controller permission to do so
Processing your personal data is in the Data Controllers legitimate interests
The Data Controller needs to comply with the law

5. Retention of personal data
The Data Controller will retain your personal information only for as long as is necessary, we consider this to be five years.

The Data Controller will retain and use your information to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our policies.

6. Data protection rights
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. If you wish to be informed what personal data we hold about you and if you want it to be removed from our systems, please contact us.
In certain circumstances, you have the following data protection rights:
The right to access, update or to delete the information we have on you
The right of rectification
The right to object
The right of restriction
The right to data portability
The right to withdraw consent