Over 100 Years of Heritage
At Miltons Diamonds, we are committed to protecting the privacy and security of our customers' personal data.
This GDPR Compliance Policy outlines our approach to ensuring compliance with the General Data Protection Regulation (GDPR), which governs the collection, use, and management of personal data within the European Union.
Our aim is to handle personal data responsibly and transparently, respecting the rights of individuals.
Data Collection and Use
We collect personal data only for specific, legitimate purposes related to our business activities. This may include information necessary for processing orders, providing customer service, and marketing communications, with consent where required.
Personal data collected includes, but is not limited to, names, contact details, payment information, and any other details necessary for the fulfilment of our services. We ensure that data is accurate, relevant, and limited to what is necessary for the intended purposes.
Data Processing and Security
Personal data is processed in a manner that ensures its security and confidentiality. We implement appropriate technical and organisational measures to protect against unauthorised access, alteration, disclosure, or destruction of personal data.
These measures include encryption, access controls, and regular security assessments. Data processing activities are documented and regularly reviewed to ensure compliance with GDPR requirements.
Data Subject Rights
Individuals have the right to access, rectify, erase, restrict, and object to the processing of their personal data. They also have the right to data portability and to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Requests to exercise these rights will be responded to promptly and within the timeframe stipulated by GDPR.
We provide clear and accessible information on how individuals can exercise their rights and lodge complaints with supervisory authorities if they believe their data protection rights have been violated.
Data Retention
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.
We have established data retention periods and regularly review the necessity of retaining data. Data no longer required is securely deleted or anonymised to ensure privacy and compliance with GDPR.
Third-Party Disclosure
We do not share personal data with third parties except as necessary for business operations, legal obligations, or with the explicit consent of the individual. When third-party service providers are engaged, we ensure they comply with GDPR requirements through appropriate data processing agreements.
We remain responsible for the protection of personal data when shared with third parties and take steps to ensure it is processed securely and lawfully.
Data Breaches
In the event of a data breach, we have a protocol in place to respond promptly and mitigate any potential harm.
This includes notifying affected individuals and the relevant supervisory authority when required by GDPR. We maintain records of all data breaches, regardless of severity, to identify patterns and improve our data protection practices.
Continuous Improvement
We are committed to continuous improvement in our data protection practices. This includes regular training for employees, ongoing assessment of our data protection measures, and staying informed about changes in data protection laws and regulations.
Our GDPR Compliance Policy is reviewed and updated regularly to reflect any changes in our operations or the regulatory environment.