1. Purpose and scope
This document explains the approach Mindvision Media Ltd takes to personal data when you interact with our websites, request quotes, open an account, place orders, or otherwise use our services. It is intended for account managers, accountants, business owners, directors and purchasers who need a clear, usable summary of how we handle personal data.
This Policy is draft content and contains operational and legal details that must be checked before publication. All items marked with [REVIEW REQUIRED] need confirmation by an authorised person or legal adviser.
What this section helps you decide:
- Whether this Policy covers your activities with us (web, account, order).
- Who should review and approve the document internally before it goes live.
Next step: Confirm the scope and the list of covered services and mark any exclusions with [REVIEW REQUIRED].
2. Definitions and responsibilities
This section gives concise definitions for terms used in the policy and identifies the internal contact points for data protection queries.
Key terms (brief):
- Account — an access arrangement for site features.
- Cookies — small text files placed on a device by the website.
- Processor / Controller — roles that describe whether we decide purposes of processing or act on another party's instructions. Confirm our published legal roles with legal counsel [REVIEW REQUIRED].
Primary operational contacts (confirm details):
- General enquiries: info@mindvision.co.uk [REVIEW REQUIRED]
- Support (technical or site issues): support@mindvision.co.uk [REVIEW REQUIRED]
- Telephone: 01666 826 226 [REVIEW REQUIRED]
Company identifiers to confirm before publication:
- Company name: Mindvision Media Ltd (as used in this draft) [REVIEW REQUIRED]
- Registered company number: 6205932 [REVIEW REQUIRED]
- Registered / trading address: 41 High Street, Malmesbury, Wiltshire, SN16 9ZZ [REVIEW REQUIRED]
- VAT number: 923 6616 21 [REVIEW REQUIRED]
- Memberships (e.g. BPMA): membership mentions must be verified before publication [REVIEW REQUIRED]
Next step: Confirm and approve the contact list and organisational details marked with [REVIEW REQUIRED].
3. What we collect and why
This section explains categories of personal data we may collect when you use our services and the types of purpose that typically justify processing. Exact legal bases, required fields and any sensitive categories must be validated by a responsible person or legal adviser [REVIEW REQUIRED].
Examples of data we may collect (confirm before publishing):
- Identity and contact details: name, business name, job title, postal and billing address, telephone and email [REVIEW REQUIRED]
- Transactional details: order history, invoicing and payment information needed to fulfil contracts (payment processor details are held by third-party processors) [REVIEW REQUIRED]
- Technical and behavioural data: IP address, browser and device information, pages visited and referrers to help operate and improve the site [REVIEW REQUIRED]
- Communications: notes of calls, emails and support interactions for customer service and dispute handling [REVIEW REQUIRED]
Typical lawful purposes (high level):
- To perform contracts (e.g. process and fulfil orders).
- To manage accounts and provide customer support.
- To operate and improve the website and services (including analytics and testing).
- To communicate service messages, transactional notices and marketing where consent or another lawful basis applies — details to be confirmed [REVIEW REQUIRED].
Next step: Review the list of data categories and stated purposes; confirm which are mandatory and the lawful basis for each processing activity with legal counsel [REVIEW REQUIRED].
4. Storage, transfers, sharing and security
This section summarises storage locations, categories of recipients and the approach to protecting data. Specific technical measures, vendor names and transfer mechanisms must be verified and approved by the operational lead and legal adviser [REVIEW REQUIRED].
Storage and transfers (draft):
- We expect to store and process data using our systems and authorised third-party providers. Any statement that personal data is stored or transferred within the EEA or elsewhere must be confirmed and, if necessary, documented with appropriate safeguards [REVIEW REQUIRED].
- If personal data is transferred outside the UK/EEA, the legal basis and safeguards must be specifically recorded and approved [REVIEW REQUIRED].
Categories of third-party recipients (examples to be confirmed):
- Payment processors, delivery and logistics providers, marketing or analytics platforms, IT hosting and support providers, and chat or customer-help platform vendors. Each supplier relationship and data access level should be confirmed and documented [REVIEW REQUIRED].
Security approach (summary only):
- Access control, contractual protections with processors, and reasonable technical and organisational measures are expected; exact controls and evidence must be supplied by the IT/data leads for publication [REVIEW REQUIRED].
Next step: Obtain and attach confirmed supplier list, transfer records and security measures; verify all items marked [REVIEW REQUIRED] before publishing.
5. Data subject rights and requests
This section gives a practical summary of the rights people can expect to exercise in relation to their personal data and the internal process for responding. The final wording, timescales and escalation must be confirmed by legal and data-protection leads [REVIEW REQUIRED].
Typical rights (summary for guidance):
- Access: to request a copy of personal data we hold.
- Rectification: to ask us to correct inaccurate or incomplete data.
- Erasure: to request deletion where a lawful ground exists.
- Restriction and objection: to ask that processing be limited or objected to for specific purposes.
- Portability: to request a machine-readable copy of data provided directly when applicable.
- Automated decision-making: rights relating to profiling and automated decisions where these occur. Confirm whether any such processing is performed by our systems [REVIEW REQUIRED].
Operational handling (draft steps):
- All requests should be sent in writing to the contact addresses in section 7.
- The requester’s identity should be verified before any personal data is provided; verification procedures must be specified and approved internally [REVIEW REQUIRED].
- Response times and any fees must be set and approved; draft timings in legacy documents should be reviewed (examples in older drafts include a 5-day acknowledgement and up to one month for a substantive reply — verify for publication) [REVIEW REQUIRED].
Next step: Confirm request-handling workflow, identity verification steps and final response times with the DPO or legal adviser and mark them in the published policy [REVIEW REQUIRED].
6. Cookies and tracking technologies
This section summarises the categories of cookies and third‑party tracking used on our site in draft form. The specific cookie list, providers, and consent text must be verified and finalised before publication [REVIEW REQUIRED].
Draft categories used on the site (to be confirmed):
- Strictly necessary cookies: essential for core site functions.
- Functional cookies: remember choices and help improve experience.
- Analytics cookies: used to gather anonymous usage data to improve the site; if Google Analytics or another analytics provider is used, this must be confirmed and the relevant provider named in the published table [REVIEW REQUIRED].
- Third-party cookies: for chat, payment widgets or embeds; each third party’s cookies and privacy practices must be listed and linked to their policies [REVIEW REQUIRED].
User controls (general guidance):
- Users should be told how to give and withdraw cookie consent and how to manage cookies via their browser; provide clear, tested consent UI and instructions before going live [REVIEW REQUIRED].
Next step: Produce the definitive cookie table (names, providers, purposes, expiry) and consent text, then confirm with the web team and legal adviser for publication [REVIEW REQUIRED].
7. Contact, escalation and review/change control
This section tells users how to contact Mindvision Media Ltd about personal data, how to escalate unresolved matters, and how the policy will be updated. All contact details and review intervals must be finalised before publishing [REVIEW REQUIRED].
Contact points (confirm actual addresses before publication):
- General enquiries: info@mindvision.co.uk [REVIEW REQUIRED]
- Support (site or technical): support@mindvision.co.uk [REVIEW REQUIRED]
- Telephone: 01666 826 226 [REVIEW REQUIRED]
- Postal: Mindvision Media Ltd, 41 High Street, Malmesbury, SN16 9ZZ [REVIEW REQUIRED]
Escalation and complaints (summary):
- Users should raise data concerns with the contacts above in the first instance.
- Internal escalation paths for unresolved complaints must be documented and authorised internally (include named roles and timescales) [REVIEW REQUIRED].
Review and change control (draft):
- The policy should carry a clear version number and publication date once finalised.
- Set a routine review frequency and an approval process for changes; the frequency and approvers must be decided and recorded [REVIEW REQUIRED].
Next step: Confirm the final contact details, escalation contacts and review cadence; replace each [REVIEW REQUIRED] item with the approved information before publishing.