Legal
Privacy & Cookies, Terms & Conditions, and Copyright Notice
Privacy and cookies policy
- Introduction
1.1 We are committed to safeguarding the privacy of our website visitors and customers; in this policy we explain how we will handle your personal data.
1.2 This policy applies where we are acting as a data controller with respect to your personal data; in other words, where we determine the purposes and means of the processing of that personal data.
1.3 We use cookies on our website. Insofar as those cookies are not strictly necessary for the provision of our website and services, we will ask you to consent to our use of cookies when you first visit our website.
1.5 In this policy, "we", "us" and "our" refer to KC Multimedia Ltd. For more information about us, see Section 19.
- The personal data that we collect
2.1 In this Section 2 we have set out the general categories of personal data that we process.
2.2 We may process data enabling us to get in touch with you ("contact data").[ The contact data may include your name, email address, telephone number, postal address and/or social media account identifiers. The source of the contact data is you and/or your employer. If you log into our website using a social media account, we will obtain elements of the contact data from the relevant social media account provider.
2.3 We may process your website user account data ("account data"). The account data may include your account identifier, name, email address, business name, account creation and modification dates, website settings and marketing preferences. The primary source of the account data is you and/or your employer, although some elements of the account data may be generated by our website. If you log into our website using a social media account, we will obtain elements of the account data from the relevant social media account provider.
2.4 We may process information relating to our customer relationships ("customer relationship data"). The customer relationship data may include your name, the name of your business or employer, your job title or role, your contact details, your classification / categorisation within our customer relationship management system and information contained in or relating to communications between us and you, or between us and your employer. The source of the customer relationship data is you and/or your employer.
2.5 We may process information relating to transactions, including purchases of goods and/or services, that you enter into with us and/or through our website ("transaction data"). The transaction data may include your name, your contact details, your payment card details (or other payment details) and the transaction details. The source of the transaction data is you and/or our payment services provider.
2.6 We may process information contained in or relating to any communication that you send to us or that we send to you ("communication data"). The communication data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms.
2.7 We may process data about your use of our website and services ("usage data"). The usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is our analytics tracking system.
- Purposes of processing and legal bases
3.1 In this Section 3, we have set out the purposes for which we may process personal data and the legal bases of the processing.
3.2 Operations - We may process your personal data for the purposes of operating our website, the processing and fulfilment of orders, providing our services, supplying our goods, generating invoices, bills and other payment-related documentation, and credit control. The legal basis for this processing is our legitimate interests, namely the proper administration of our website, services and business OR the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
3.3 Publications - We may process account data for the purposes of publishing such data on our website and elsewhere through our services in accordance with your express instructions. The legal basis for this processing is consent OR our legitimate interests, namely the publication of content in the ordinary course of our operations OR the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
3.4 Relationships and communications - We may process contact data, account data, customer relationship data, transaction data and/or communication data for the purposes of managing our relationships, communicating with you (excluding communicating for the purposes of direct marketing) by email, SMS, post, fax and/or telephone, providing support services and complaint handling. The legal basis for this processing is our legitimate interests, namely communications with our website visitors, service users, individual customers and customer personnel, the maintenance of our relationships, enabling the use of our services, and the proper administration of our website, services and business.
3.5 Personalisation - We may process account data and/or usage data for the purposes of personalising the content and advertisements that you see on our website and through our services to ensure that you only see material that is relevant to you. The legal basis for this processing is consent OR our legitimate interests, namely offering the best possible experience for our website visitors and service users OR the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
3.6 Direct marketing - We may process contact data, account data, customer relationship data and/or transaction data for the purposes of creating, targeting and sending direct marketing communications by email, SMS, post and/or fax and making contact by telephone for marketing-related purposes. The legal basis for this processing is consent OR our legitimate interests, namely promoting our business and communicating marketing messages and offers to our website visitors and service users.
3.7 Research and analysis - We may process usage data and/or transaction data for the purposes of researching and analysing the use of our website and services, as well as researching and analysing other interactions with our business. The legal basis for this processing is consent OR our legitimate interests, namely monitoring, supporting, improving and securing our website, services and business generally.
3.8 Record keeping - We may process your personal data for the purposes of creating and maintaining our databases, back-up copies of our databases and our business records generally. The legal basis for this processing is our legitimate interests, namely ensuring that we have access to all the information we need to properly and efficiently run our business in accordance with this policy.
3.9 Security - We may process your personal data for the purposes of security and the prevention of fraud and other criminal activity. The legal basis of this processing is our legitimate interests, namely the protection of our website, services and business, and the protection of others.
3.10 Insurance and risk management - We may process your personal data where necessary for the purposes of obtaining or maintaining insurance coverage, managing risks and/or obtaining professional advice. The legal basis for this processing is our legitimate interests, namely the proper protection of our business against risks.
3.11 Legal claims - We may process your personal data where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure. The legal basis for this processing is our legitimate interests, namely the protection and assertion of our legal rights, your legal rights and the legal rights of others.
3.12 Legal compliance and vital interests - We may also process your personal data where such processing is necessary for compliance with a legal obligation to which we are subject or in order to protect your vital interests or the vital interests of another natural person.
- Automated decision-making
4.1 We do not use automated decision-making.
- Providing your personal data to others
5.1 We may disclose your personal data to our insurers and/or professional advisers insofar as reasonably necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, obtaining professional advice.
5.2 Your personal data held in our website database will be stored on the servers of our hosting services providers identified at https://kcmhosting.online.
5.3 Financial transactions relating to our website and services are OR may be handled by our payment services providers, [identify PSPs]. We will share transaction data with our payment services providers only to the extent necessary for the purposes of processing your payments, refunding such payments and dealing with complaints and queries relating to such payments and refunds. You can find information about the payment services providers' privacy policies and practices at [URLs].
5.4 In addition to the specific disclosures of personal data set out in this Section 5, we may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. We may also disclose your personal data where such disclosure is necessary for the establishment, exercise, or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
- International transfers of your personal data
6.1 In this Section 6, we provide information about the circumstances in which your personal data may be transferred to a third country under UK and/or EU data protection law.
6.2 You acknowledge that personal data that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.
- Retaining and deleting personal data
7.1 This Section 7 sets out our data retention policies and procedures, which are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal data.
7.2 Personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
7.3 We will retain your personal data as follows:
(a) contact data will be retained for a minimum period of 2 years after the account is closed following the date of the most recent contact between you and us, and for a maximum period of 7 years following that date;
(b) account data will be retained for a minimum period of 2 years following the date of closure of the relevant account, and for a maximum period of 7 years following that date;
(c) customer relationship data will be retained for a minimum period of 2 years following the date of termination of the relevant customer relationship and for a maximum period of 7 years following that date;
(d) transaction data will be retained for a minimum period of 2 years following the date of the transaction, and for a maximum period of 7 years following that date;
(e) communication data will be retained for a minimum period of 18 months following the date of the communication in question, and for a maximum period of 7 years following that date;
(f) usage data will be retained for 7 years following the date of collection.
7.4 Notwithstanding the other provisions of this Section 7, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
- Security of personal data
8.1 We will take appropriate technical and organisational precautions to secure your personal data and to prevent the loss, misuse or alteration of your personal data.
8.2 We will store your personal data on secure servers, personal computers and mobile devices, and in secure manual record-keeping systems.
8.3 The following personal data will be stored by us in encrypted form: your name, contact information, password(s) and cardholder data.
8.4 Data relating to your enquiries and financial transactions that is sent from your web browser to our web server, or from our web server to your web browser, will be protected using encryption technology.
8.5 You acknowledge that the transmission of unencrypted (or inadequately encrypted) data over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.
8.6 You should ensure that your password is not susceptible to being guessed, whether by a person or a computer program. You are responsible for keeping the password you use for accessing our website confidential and we will not ask you for your password (except when you log in to our website).
- Your rights
9.1 In this Section 9, we have summarised the rights that you have under data protection law. Some of the rights are complex, and not all of the details have been included in our summaries. Accordingly, you should read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights.
These rights are subject to certain limitations and exceptions. You can learn more about the rights of data subjects by visiting https://edpb.europa.eu/our-work-tools/general-guidance/gdpr-guidelines-recommendations-best-practices_en and https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/.
9.2 Your principal rights under data protection law are:
(a) the right to access - you can ask for copies of your personal data;
(b) the right to rectification - you can ask us to rectify inaccurate personal data and to complete incomplete personal data;
(c) the right to erasure - you can ask us to erase your personal data;
(d) the right to restrict processing - you can ask us to restrict the processing of your personal data;
(e) the right to object to processing - you can object to the processing of your personal data;
(f) the right to data portability - you can ask that we transfer your personal data to another organisation or to you;
(g) the right to complain to a supervisory authority - you can complain about our processing of your personal data; and
(h) the right to withdraw consent - to the extent that the legal basis of our processing of your personal data is consent, you can withdraw that consent.
9.3 You have the right to confirmation as to whether or not we process your personal data and, where we do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, we will supply to you a copy of your personal data. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee.[ You can access your personal data by visiting https://cp.kcmhosting.online when logged into our website.
9.4 You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.
9.5 In some circumstances you have the right to the erasure of your personal data without undue delay. Those circumstances include: the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the processing is for direct marketing purposes; and the personal data have been unlawfully processed. However, there are exclusions of the right to erasure. The general exclusions include where processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise or defence of legal claims.
9.6 In some circumstances you have the right to restrict the processing of your personal data. Those circumstances are: you contest the accuracy of the personal data; processing is unlawful but you oppose erasure; we no longer need the personal data for the purposes of our processing, but you require personal data for the establishment, exercise or defence of legal claims; and you have objected to processing, pending the verification of that objection. Where processing has been restricted on this basis, we may continue to store your personal data. However, we will only otherwise process it: with your consent; for the establishment, exercise or defence of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public interest.
9.7 You have the right to object to our processing of your personal data on grounds relating to your particular situation, but only to the extent that the legal basis for the processing is that the processing is necessary for: the performance of a task carried out in the public interest or in the exercise of any official authority vested in us; or the purposes of the legitimate interests pursued by us or by a third party. If you make such an objection, we will cease to process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.
9.8 You have the right to object to our processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, we will cease to process your personal data for this purpose.
9.9 You have the right to object to our processing of your personal data for scientific or historical research purposes or statistical purposes on grounds relating to your particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
9.10 To the extent that the legal basis for our processing of your personal data is:
(a) consent; or
(b) that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract,
and such processing is carried out by automated means, you have the right to receive your personal data from us in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.
9.11 If you consider that our processing of your personal data infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. In relation to complaints under EU data protection law, you may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement; in relation to complaints under UK data protection law, you should do so in the UK.
9.12 To the extent that the legal basis for our processing of your personal data is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.
9.13 You may exercise any of your rights in relation to your personal data by written notice to us, in addition to the other methods specified in this Section 9.
- Third party websites
10.1 Our website includes hyperlinks to, and details of, third party websites.
10.2 In general we have no control over, and are not responsible for, the privacy policies and practices of third parties.
- Personal data of children
11.1 Our website and services are targeted at persons over the age of 18.
11.2 If we have reason to believe that we hold personal data of a person under that age in our databases, we will delete that personal data.
- Updating information
12.1 Please let us know if the personal information that we hold about you needs to be corrected or updated.
- About cookies
13.1 A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.
13.2 Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.
13.3 Cookies may not contain any information that personally identifies a user, but personal data that we store about you may be linked to the information stored in and obtained from cookies.
- Cookies that we use
14.1 We use cookies for the following purposes:
(a) authentication and status - we use cookies to identify you when you visit our website and as you navigate our website, and to help us determine if you are logged into our website (cookies used for this purpose are: ure-3PSIDCC; SIDCC; __Secure-1PSID; SID; __Secure-1PAPISID; SAPISID; SSID; APISID; __Secure-3PAPISID; __Secure-1PSIDCC; __Secure-3PSID; HSID; NID; AEC; wordpress_test_cookie; OTZ; SEARCH_SAMESITE; 1P_JAR; OGPC; OGP; _gid; _ga; wp-settings-time-1; wp-settings-1; _ga_0LHPVH6Q00; wordpress_test_cookie; wordpress_logged_in_8919aae2fc381b26b579e5764dbfe759;
wordpress_sec_8919aae2fc381b26b579e5764dbfe759);
(b) personalisation - we use cookies to store information about your preferences and to personalise our website for you (cookies used for this purpose are: _gid; _ga; _ga_0LHPVH6Q00; _ga; _ga_5046XKWKPL; _gat_gtag_UA_225397677_1; _gid);
(c) security - we use cookies as an element of the security measures used to protect user accounts, including preventing fraudulent use of login credentials, and to protect our website and services generally (cookies used for this purpose are: ure-3PSIDCC; SIDCC; __Secure-1PSID; SID; __Secure-1PAPISID; SAPISID; SSID; APISID; __Secure-3PAPISID; __Secure-1PSIDCC; __Secure-3PSID; HSID; NID; AEC; wordpress_test_cookie; OTZ; SEARCH_SAMESITE; 1P_JAR; OGPC; OGP; _gid; _ga; wp-settings-time-1; wp-settings-1; _ga_0LHPVH6Q00; wordpress_test_cookie; wordpress_logged_in_8919aae2fc381b26b579e5764dbfe759;
wordpress_sec_8919aae2fc381b26b579e5764dbfe759);
(d) analysis - we use cookies to help us to analyse the use and performance of our website and services (cookies used for this purpose are: _gid; _ga; _ga_0LHPVH6Q00; _ga; _ga_5046XKWKPL; _gat_gtag_UA_225397677_1; _gid); and
(e) cookie consent - we use cookies to store your preferences in relation to the use of cookies more generally (cookies used for this purpose are: seopress-user-consent-accept).
- Cookies used by our service providers
15.1 Our service providers use cookies and those cookies may be stored on your computer when you visit our website.
15.2 We use Google Analytics. Google Analytics gathers information about the use of our website by means of cookies. The information gathered is used to create reports about the use of our website. You can find out more about Google's use of information by visiting https://www.google.com/policies/privacy/partners/ and you can review Google's privacy policy at https://policies.google.com/privacy. The relevant cookies are: _gid; _ga; _ga_0LHPVH6Q00; _ga; _ga_5046XKWKPL; _gat_gtag_UA_225397677_1; _gid.
- Managing cookies
16.1 Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
(a) https://support.google.com/chrome/answer/95647 (Chrome);
(b) https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop (Firefox);
(c) https://help.opera.com/en/latest/security-and-privacy/ (Opera);
(d) https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);
(e) https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac (Safari); and
(f) https://support.microsoft.com/en-gb/help/4468242/microsoft-edge-browsing-data-and-privacy (Edge).
16.2 Blocking all cookies will have a negative impact upon the usability of many websites.
16.3 If you block cookies, you will not be able to use all the features on our website.
- Amendments
18.1 We may update this policy from time to time by publishing a new version on our website.
18.2 You should check this page occasionally to ensure you are happy with any changes to this policy.
18.3 We may notify you of changes to this policy by email.
- Our details
19.1 This website is owned and operated by KC Multimedia Ltd.
19.2 We are registered in England and Wales under registration number 13742477, and our registered office is at 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UK.
19.3 Our principal place of business is at 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UK.
19.4 You can contact us:
(a) by post, to the postal address given above;
(b) using our website contact form;
(c) by telephone, on the contact number published on our website; or
(d) by email, using the contact form on our website.
- Data protection registration
20.1 We are registered as a data controller with the UK Information Commissioner's Office.
20.2 Our data protection registration number is ZB310077.
- Data protection officer
21.1 Our data protection officer's contact details are: dataprocessor@kcmultimedia.ltd.
Terms and conditions of use
- Introduction
1.1 These terms and conditions shall govern your use of our website.
1.2 By using our website, you accept these terms and conditions in full; accordingly, if you disagree with these terms and conditions or any part of these terms and conditions, you must not use our website.
1.3 If you [register with our website or make a purchase on our website], we will ask you to expressly agree to these terms and conditions.
1.4 You must be at least 18 years of age to use our website; by using our website or agreeing to these terms and conditions, you warrant and represent to us that you are at least 18]years of age.
- Copyright notice
2.1 Copyright (c) 2022 KC Multimedia Ltd.
2.2 Subject to the express provisions of these terms and conditions:
(a) we, together with our licensors, own and control all the copyright and other intellectual property rights in our website and the material on our website; and
(b) all the copyright and other intellectual property rights in our website and the material on our website are reserved.
- Permission to use website
3.1 You may:
(a) view pages from our website in a web browser;
(b) download pages from our website for caching in a web browser;
(c) print pages from our website for your own personal and non-commercial use, providing that such printing is not systematic or excessive;
(d) stream audio and video files from our website using the media player on our website; and
(e) use our website services by means of a web browser,
subject to the other provisions of these terms and conditions.
3.2 Except as expressly permitted by Section 3.1 or the other provisions of these terms and conditions, you must not download any material from our website or save any such material to your computer.
3.3 You may only use our website for your own personal and business purposes; you must not use our website for any other purposes.
3.4 Except as expressly permitted by these terms and conditions, you must not edit or otherwise modify any material on our website.
3.5 Unless you own or control the relevant rights in the material, you must not:
(a) republish material from our website (including republication on another website);
(b) sell, rent or sub-license material from our website;
(c) show any material from our website in public;
(d) exploit material from our website for a commercial purpose; or
(e) redistribute material from our website.
3.6 We reserve the right to suspend or restrict access to our website, to areas of our website and/or to functionality upon our website. We may, for example, suspend access to the website during server maintenance or when we update the website. You must not circumvent or bypass, or attempt to circumvent or bypass, any access restriction measures on the website.
- Misuse of website
4.1 You must not:
(a) use our website in any way or take any action that causes, or may cause, damage to the website or impairment of the performance, availability, accessibility, integrity or security of the website;
(b) use our website in any way that is unlawful, illegal, fraudulent or harmful, or in connection with any unlawful, illegal, fraudulent or harmful purpose or activity;
(c) hack or otherwise tamper with our website;
(d) probe, scan or test the vulnerability of our website without our permission;
(e) circumvent any authentication or security systems or processes on or relating to our website;
(f) use our website to copy, store, host, transmit, send, use, publish or distribute any material which consists of (or is linked to) any spyware, computer virus, Trojan horse, worm, keystroke logger, rootkit or other malicious computer software;
(g) impose an unreasonably large load on our website resources (including bandwidth, storage capacity and processing capacity);
(h) decrypt or decipher any communications sent by or to our website without our permission;
(i) conduct any systematic or automated data collection activities (including without limitation scraping, data mining, data extraction and data harvesting) on or in relation to our website without our express written consent;
(j) access or otherwise interact with our website using any robot, spider or other automated means, except for the purpose of search engine indexing;
(k) use our website except by means of our public interfaces;
(l) violate the directives set out in the robots.txt file for our website;
(m) use data collected from our website for any direct marketing activity (including without limitation email marketing, SMS marketing, telemarketing and direct mailing); or
(n) do anything that interferes with the normal use of our website.
4.2 You must not use data collected from our website to contact individuals, companies or other persons or entities.
4.3 You must ensure that all the information you supply to us through our website, or in relation to our website, is true, accurate, current, complete and non-misleading.
- Products
5.1 The advertising of products on our website constitutes an "invitation to treat" rather than a contractual offer.
5.2 We may periodically change the products available on our website, and we do not undertake to continue to supply any particular product or type of product.
5.3 Prices stated on our website may be stated incorrectly.
5.4 The sale and purchase of products through our website will be subject to terms and conditions of sale, and we will ask you to agree to the terms of that document each time you make a purchase on our website.
5.5 Any product reviews that you submit for publication on our website shall be subject to the terms of Section 9 and Section 10.
- Registration and accounts
6.1 You may register for an account with our website by completing and submitting the account registration form on our website, and clicking on the verification link in the email that the website will send to you.
6.2 You must not allow any other person to use your account to access the website.
6.3 You must notify us in writing immediately if you become aware of any unauthorised use of your account.
6.4 You must not use any other person's account to access the website, unless you have that person's express permission to do so.
- User login details
7.1 If you register for an account with our website, we will provide you with OR you will be asked to choose a user ID and password.
7.2 Your user ID must not be liable to mislead and must comply with the content rules set out in Section 10; you must not use your account or user ID for or in connection with the impersonation of any person.
7.3 You must keep your password confidential.
7.4 You must notify us in writing immediately if you become aware of any disclosure of your password.
7.5 You are responsible for any activity on our website arising out of any failure to keep your password confidential, and may be held liable for any losses arising out of such a failure.
- Cancellation and suspension of account
8.1 We may:
(a) suspend your account;
(b) cancel your account; and/or
(c) edit your account details,
at any time in our sole discretion with or without notice to you.
8.2 We will usually cancel an account if it remains unused for a continuous period of 18 months.
8.3 You may cancel your account on our website using your account control panel on the website.
- Our rights to use your content
9.1 In these terms and conditions, "your content" means all works and materials (including without limitation text, graphics, images, audio material, video material, audio-visual material, scripts, software and files) that you submit to us or our website for storage or publication on, processing by, or transmission via, our website.
9.2 You grant to us a worldwide, irrevocable, non-exclusive, royalty-free licence to use, reproduce, store, adapt, publish, translate and distribute your content in any existing or future media OR reproduce, store and publish your content on and in relation to this website and any successor website OR reproduce, store and, with your specific consent, publish your content on and in relation to this website.
9.3 You grant to us the right to sub-license the rights licensed under Section 9.2.
9.4 You grant to us the right to bring an action for infringement of the rights licensed under Section 9.2.
9.5 You hereby waive all your moral rights in your content to the maximum extent permitted by applicable law; and you warrant and represent that all other moral rights in your content have been waived to the maximum extent permitted by applicable law.
9.6 You may edit your content to the extent permitted using the editing functionality made available on our website.
9.7 Without prejudice to our other rights under these terms and conditions, if you breach any provision of these terms and conditions in any way, or if we reasonably suspect that you have breached these terms and conditions in any way, we may delete, unpublish or edit any or all of your content.
- Rules about your content
10.1 You warrant and represent that your content will comply with these terms and conditions.
10.2 Your content must not be illegal or unlawful, must not infringe any person's legal rights, and must not be capable of giving rise to legal action against any person (in each case in any jurisdiction and under any applicable law).
10.3 Your content, and the use of your content by us in accordance with these terms and conditions, must not:
(a) be libellous or maliciously false;
(b) be obscene or indecent;
(c) infringe any copyright, moral right, database right, trade mark right, design right, right in passing off or other intellectual property right;
(d) infringe any right of confidence, right of privacy or right under data protection legislation;
(e) constitute negligent advice or contain any negligent statement;
(f) constitute an incitement to commit a crime, instructions for the commission of a crime or the promotion of criminal activity;
(g) be in contempt of any court or in breach of any court order;
(h) be in breach of racial or religious hatred or discrimination legislation;
(i) be blasphemous;
(j) be in breach of official secrets legislation;
(k) be in breach of any contractual obligation owed to any person;
(l) depict violence in an explicit, graphic or gratuitous manner;
(m) be pornographic, lewd, suggestive or sexually explicit;
(n) be untrue, false, inaccurate or misleading;
(o) consist of or contain any instructions, advice or other information which may be acted upon and could, if acted upon, cause illness, injury or death, or any other loss or damage;
(p) constitute spam;
(q) be offensive, deceptive, fraudulent, threatening, abusive, harassing, anti-social, menacing, hateful, discriminatory or inflammatory; or
(r) cause annoyance, inconvenience or needless anxiety to any person.
- Report abuse
11.1 If you learn of any unlawful material or activity on our website, or any material or activity that breaches these terms and conditions, please let us know.
11.2 You can let us know about any such material or activity by email or using our contact form.
- Limited warranties
12.1 We do not warrant or represent:
(a) the completeness or accuracy of the information published on our website;
(b) that the material on the website is up to date;
(c) that the website will operate without fault; or
(d) that the website or any service on the website will remain available.
12.2 We reserve the right to discontinue or alter any or all of our website services, and to stop publishing our website, at any time in our sole discretion without notice or explanation; and save to the extent expressly provided otherwise in these terms and conditions, you will not be entitled to any compensation or other payment upon the discontinuance or alteration of any website services, or if we stop publishing the website.
12.3 To the maximum extent permitted by applicable law and subject to Section 13.1, we exclude all representations and warranties relating to the subject matter of these terms and conditions, our website and the use of our website.
- Limitations and exclusions of liability
13.1 Nothing in these terms and conditions will:
(a) limit or exclude any liability for death or personal injury resulting from negligence;
(b) limit or exclude any liability for fraud or fraudulent misrepresentation;
(c) limit any liabilities in any way that is not permitted under applicable law; or
(d) exclude any liabilities that may not be excluded under applicable law.
13.2 The limitations and exclusions of liability set out in this Section 13 and elsewhere in these terms and conditions:
(a) are subject to Section 13.1; and
(b) govern all liabilities arising under these terms and conditions or relating to the subject matter of these terms and conditions, including liabilities arising in contract, in tort (including negligence) and for breach of statutory duty, except to the extent expressly provided otherwise in these terms and conditions.
13.3 To the extent that our website and the information and services on our website are provided free of charge, we will not be liable for any loss or damage of any nature.
13.4 We will not be liable to you in respect of any losses arising out of any event or events beyond our reasonable control.
13.5 We will not be liable to you in respect of any business losses, including (without limitation) loss of or damage to profits, income, revenue, use, production, anticipated savings, business, contracts, commercial opportunities or goodwill.
13.6 We will not be liable to you in respect of any loss or corruption of any data, database or software.
13.7 We will not be liable to you in respect of any special, indirect or consequential loss or damage.
13.8 You accept that we have an interest in limiting the personal liability of our officers and employees and, having regard to that interest, you acknowledge that we are a limited liability entity; you agree that you will not bring any claim personally against our officers or employees in respect of any losses you suffer in connection with the website or these terms and conditions (this will not, of course, limit or exclude the liability of the limited liability entity itself for the acts and omissions of our officers and employees).
- Breaches of these terms and conditions
14.1 Without prejudice to our other rights under these terms and conditions, if you breach these terms and conditions in any way, or if we reasonably suspect that you have breached these terms and conditions in any way, we may:
(a) send you one or more formal warnings;
(b) temporarily suspend your access to our website;
(c) permanently prohibit you from accessing our website;
(d) block computers using your IP address from accessing our website;
(e) contact any or all of your internet service providers and request that they block your access to our website;
(f) commence legal action against you, whether for breach of contract or otherwise; and/or
(g) suspend or delete your account on our website.
14.2 Where we suspend or prohibit or block your access to our website or a part of our website, you must not take any action to circumvent such suspension or prohibition or blocking (including without limitation creating and/or using a different account).
- Third party websites
15.1 Our website includes hyperlinks to other websites owned and operated by third parties; such hyperlinks are not recommendations.
15.2 We have no control over third party websites and their contents, and subject to Section 13.1 we accept no responsibility for them or for any loss or damage that may arise from your use of them.
- Trade marks
16.1 The green, white and blue circular logo, our logos and our other registered and unregistered trade marks are trade marks belonging to us; we give no permission for the use of these trade marks, and such use may constitute an infringement of our rights.
16.2 The third party registered and unregistered trade marks or service marks on our website are the property of their respective owners and, unless stated otherwise in these terms and conditions, we do not endorse and are not affiliated with any of the holders of any such rights and as such we cannot grant any licence to exercise such rights.
- Variation
17.1 We may revise these terms and conditions from time to time.
17.2 The revised terms and conditions shall apply to the use of our website from the date of publication of the revised terms and conditions on the website, and you hereby waive any right you may otherwise have to be notified of, or to consent to, revisions of these terms and conditions. OR We will give you written notice of any revision of these terms and conditions, and the revised terms and conditions will apply to the use of our website from the date that we give you such notice; if you do not agree to the revised terms and conditions, you must stop using our website.
17.3 If you have given your express agreement to these terms and conditions, we will ask for your express agreement to any revision of these terms and conditions; and if you do not give your express agreement to the revised terms and conditions within such period as we may specify, we will disable or delete your account on the website, and you must stop using the website.
- Assignment
18.1 You hereby agree that we may assign, transfer, sub-contract or otherwise deal with our rights and/or obligations under these terms and conditions.
18.2 You may not without our prior written consent assign, transfer, sub-contract or otherwise deal with any of your rights and/or obligations under these terms and conditions.
- Severability
19.1 If a provision of these terms and conditions is determined by any court or other competent authority to be unlawful and/or unenforceable, the other provisions will continue in effect.
19.2 If any unlawful and/or unenforceable provision of these terms and conditions would be lawful or enforceable if part of it were deleted, that part will be deemed to be deleted, and the rest of the provision will continue in effect.
- Third party rights
20.1 A contract under these terms and conditions is for our benefit and your benefit, and is not intended to benefit or be enforceable by any third party.
20.2 The exercise of the parties' rights under a contract under these terms and conditions is not subject to the consent of any third party.
- Entire agreement
21.1 Subject to Section 13.1, these terms and conditions, together with our privacy and cookies policy, shall constitute the entire agreement between you and us in relation to your use of our website and shall supersede all previous agreements between you and us in relation to your use of our website.
- Law and jurisdiction
22.1 These terms and conditions shall be governed by and construed in accordance with English law.
22.2 Any disputes relating to these terms and conditions shall be subject to the exclusive jurisdiction of the courts of England.
- Statutory and regulatory disclosures
23.1 Our VAT number is 398 1608 56.
- Our details
24.1 This website is owned and operated by KC Multimedia Ltd.
24.2 We are registered in England and Wales under registration number 13742477, and our registered office is at 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UK.
24.3 Our principal place of business is at 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UK.
24.4 You can contact us:
(a) by post, to the postal address given above;
(b) using our website contact form;
(c) by telephone, on the contact number published on our website; or
(d) by email, using the email address published on our website.
Copyright notice
- Copyright notice
1.1 Copyright (c) 2017,2018,2019,2020,2021,2022 KC Multimedia Ltd.
1.2 Subject to the express provisions of this notice:
(a) we, together with our licensors, own and control all the copyright and other intellectual property rights in our website and the material on our website; and
(b) all the copyright and other intellectual property rights in our website and the material on our website are reserved.
- Copyright licence
2.1 You may:
(a) view pages from our website in a web browser;
(b) download pages from our website for caching in a web browser;
(c) print pages from our website;
(d) stream audio and video files from our website; and
(e) use our website services by means of a web browser,
subject to the other provisions of this notice.
2.2 Except as expressly permitted by the other provisions of this notice, you must not download any material from our website or save any such material to your computer.
2.3 You may only use our website for your own personal and business purposes; you must not use our website for any other purposes.
2.4 Except as expressly permitted by this notice, you must not edit or otherwise modify any material on our website.
2.5 Unless you own or control the relevant rights in the material, you must not:
(a) republish material from our website (including republication on another website);
(b) sell, rent or sub-license material from our website;
(c) show any material from our website in public;
(d) exploit material from our website for a commercial purpose; or
(e) redistribute material from our website, save to the extent expressly permitted by this notice.
- Acceptable use
3.1 You must not:
(a) use our website in any way or take any action that causes, or may cause, damage to the website or impairment of the performance, availability or accessibility of the website;
(b) use our website in any way that is unlawful, illegal, fraudulent or harmful, or in connection with any unlawful, illegal, fraudulent or harmful purpose or activity;
(c) use our website to copy, store, host, transmit, send, use, publish or distribute any material which consists of (or is linked to) any spyware, computer virus, Trojan horse, worm, keystroke logger, rootkit or other malicious computer software; or
(d) conduct any systematic or automated data collection activities (including without limitation scraping, data mining, data extraction and data harvesting) on or in relation to our website without our express written consent.
- Report abuse
4.1 If you learn of any unlawful material or activity on our website, or any material or activity that breaches this notice, please let us know.
4.2 You can let us know about any such material or activity by email.
- Enforcement of copyright
5.1 We take the protection of our copyright very seriously.
5.2 If we discover that you have used our copyright materials in contravention of the licence set out in this notice, we may bring legal proceedings against you, seeking monetary damages and/or an injunction to stop you using those materials. You could also be ordered to pay legal costs.
- Permissions
6.1 You may request permission to use the copyright materials on our website by writing to us by email or post, using the contact details published on the website.
GDPR Statement
Introduction
The General Data Protection Regulation (GDPR) is a new legal framework set up by the European Union in April 2016 to build upon existing data protection legislation. GDPR came into effect on 25th May 2018, and has introduced a range of fresh guidelines spelling out the rights of consumers and dictating how companies can store and share information.
As a hugely significant change to the global business landscape, it is critical that KC Multimedia Ltd embraces all aspects of GDPR to maintain full compliance.
Our obligations for GDPR compliance
Here at KC Multimedia Ltd, we fully appreciate and support the European Union’s focus on expanding upon digital rights. As a company, we strongly believe in the need for greater business transparency and accountability concerning the collection and handling of personal data.
That is why KC Multimedia Ltd is a firm advocate of GDPR and its many implications. These include among many other aspects:
- The Right to Object to Processing
- The Right to Be Forgotten
- The Right to Data Portability
- The Right to Withdraw Consent
As part of our commitment to GDPR and the rights of our customers and clients, KC Multimedia Ltd vows to ensure our organisation considers and actions all necessary changes surrounding data processing, data storage and the disposal of personal data.
This includes a commitment to fully fulfil Breach Disclosure Requirements by notifying authorities and concerned individuals of any compromise within 72 hours. Moreover, as part of our GDPR strategy, KC Multimedia Ltd will complete impact assessments wherever possible, to identify and deliver the best service possible, as well as to extend our customers a guarantee that data is being kept secure.
Furthermore, we pledge to uphold the following key values and responsibilities:
- We vow to demonstrate full responsibility and dutiful respect as a keeper of customer, client and employee data.
- We totally support GDPR and its requirements, and will do everything within our power to appropriately resource and fund any changes we must enforce to ensure KC Multimedia Ltd can meet its obligations.
- We promise to maintain ownership and transparency concerning data protection and privacy across all elements of our company.
- We pledge to create and maintain a purposeful data processing inventory documenting all data operations, including collection, processing and storage.
- We guarantee to extend every possible show of support to individuals intent on exercising their rights as outlined under GDPR legislation.
- We will conduct a regular review to assess the legality and purpose for the collection, processing and storage of personal data.
- We vow to act upon identified gaps and develop robust processes to maintain full GDPR compliance.
- We promise to clearly communicate the business purpose and legal grounds for any transfer of data – including transfer outside of the European Union.
- We will contact all partner organisations, contractors or other third parties to identify their own GDPR commitments, establish relevant contract terms and solidify GDPR compliance controls.
Introduction
Here at KC Multimedia Ltd, we collect, process and store personal data for a range of business purposes. Data subjects include customers, suppliers, partners, employees, clients and other stakeholders and individuals.
Bearing in mind KC Multimedia Ltd’s commitment to uphold the rights of the individual as enshrined in law, our data security policy is designed to protect all past, current and future employees, customers, or partners, from illegal or damaging activity conducted by others using their personal data.
Our data security policy outlines how KC Multimedia Ltd will endeavour to guard and protect all personal data. It also sets out to raise the awareness of staff members in relation to the ways in which GDPR impacts their use of individual’s personal data.
This policy applies to all data processing activities involving KC Multimedia Ltd, and includes activities or systems related to both internal business operations, as well as external relations and any third-party agreements.
Please note that KC Multimedia Ltd’s data security policy applies to all employees, and this policy may be subject to review and amendment on a regular basis. For more information about this policy and its overall implementation, consult our Data Protection Officer.
This document is subject to regular review to ensure ongoing regulatory compliance.
Data security policy definitions
Personal data
Personal data encompasses any type of information that relates to an identifiable individual. Various types of personal data KC Multimedia Ltd may collect, store and process could include:
- Contact details
- Financial information
- Educational background
- Certifications
- Skills
- Nationality
- Marital status
- Job title
The above list is by no means exhaustive, and should be used merely as a point of reference from which a working definition of personal data can be established and further developed.
Sensitive personal data
Under GDPR, sensitive personal data is defined as encompassing any of the following:
- Racial or ethnic origin
- Political opinion
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data
- Health-related information
- Sexual orientation
It is paramount that all sensitive personal data is kept under stringent control as part of the implementation of our data security policy.
Purposes of personal data
KC Multimedia Ltd uses personal data for a range of various purposes. These purposes may include:
- Financial
- Administrative
- Human resources
- Regulatory compliance
- Payroll
- Business development
Please note the above list is by no means exhaustive, and should merely be used as a reference point from which a working definition of purpose can be established.
Business purposes
KC Multimedia Ltd must carry out a range of functions and processes as part of our operational activity. Data kept in relation to these activities falls under the category of data for business purposes, which includes information of the following nature:
- Operational
- Compliance
- Policy adherence
- Human resources and personnel
- Marketing
The above list is by no means exhaustive, and should be used merely as a point of reference from which a working definition of business purposes can be established and further developed.
Fair processing
At KC Multimedia Ltd, there will be occasions when employees will need to process personal data; however, processing activities must always be carried out in a fair and lawful manner that is compatible with the rights of each corresponding individual. Consequently, we should avoid processing the personal data of any individual who has not provided us with explicit consent.
Our company must strive to obtain explicit consent at all costs, and we must clearly identify to the individual what data is being processed, why we need to use it and who will have access to their data. These factors must be identified and clearly reiterated to the individual at the point of request for consent.
It’s worth noting there may be exceptional circumstances in which we are asked to process sensitive personal data without consent. An example of an exceptional circumstance could include legal obligations we may need to carry out to comply with health and safety regulations.
KC Multimedia Ltd endeavours to take all actions necessary to ensure that all personal data we obtain, process and store is accurate, relevant and adequate in relation to the reason in which we asked for that information. We should not hold excessive or irrelevant data on any individuals, and we will not process any personal data for a purpose unrelated to the purpose in which the relevant individual has consented to the processing of their data.
Our roles and responsibilities
Data security is a critical component of our business. It falls on everyone at KC Multimedia Ltd to take responsibility for data security, and all employees must familiarise themselves with our data security policy and do everything within their power to uphold that policy on a day-to-day basis.
Please note that KC Multimedia Ltd takes data protection incredibly seriously, and we expect all staff members to adhere to this data security policy. Any failure and refusal to comply with this policy could ultimately place our company at risk.
Bearing that in mind, personal non-compliance with this data security policy could lead to disciplinary action as they relate to ordinary personnel procedures. Please contact your line manager with any further questions concerning data protection at KC Multimedia Ltd.
As a staff member at KC Multimedia Ltd, you can expect to receive data protection training in line with our data security policy. All incoming employees will be provided training as an aspect of the wider staff induction process, and all staff members can anticipate the requirement to undergo additional training as a result of subsequent regulatory updates to GDPR or other relevant legislation as it relates to data security.
Data security will inevitably encompass a range of additional responsibilities for various roles within the company. These roles and their responsibilities include (but are not limited to):
Data Protection Officer
GDPR stipulates our company must appoint a Data Protection Officer. It is our Data Protection Officer’s responsibility to:
- Organise data security training for all employees not specifically referenced within this data security policy.
- Review and analyse all existing data security protocols and processes on a regular basis.
- Be a point of contact for all employees, clients and stakeholders to answer questions about data protection and data security.
- Respond to internal or external queries from individuals wanting to know what data relating to them may have been obtained, processed or stored by our company.
- Conduct due diligence and submit approval in relation to any contractual agreement with a third party involving the processing or storage of data.
- Maintain constant contact with company directors, board members and stakeholders in relation to data security, company responsibilities and data risk management.
IT Manager
Information technology plays a crucial role in the way our company operates. Any processes relating to IT and the processing and storage of data must be carefully monitored, assessed and guided by an IT Manager.
It is the responsibility of KC Multimedia Ltd’s IT Manager to:
- Conduct due diligence and appropriate levels of research into any third-party service that our company may call upon to store or process any data.
- Make sure that all company software, IT systems, equipment and services meet changing levels of data security standards.
- Carry out regular checks, audits and scans to ensure security hardware and security software are fully functional and optimised to manage and mitigate data security risks.
Marketing Manager
A significant proportion of our marketing activities involve the collection, storage and processing of data. Consequently, our Marketing Manager must oversee the following responsibilities:
- Accept all queries relating to data security and data protection from leads, media outlets, clients or other individuals and oversee and deliver an adequate response.
- Work alongside KC Multimedia Ltd’s Data Protection Officer to make sure that all of our marketing processes, campaigns and activities are compliant with all relevant data security and data protection laws – as well as our own company data security policy.
- Review, draft and approve any relevant data security statements that must accompany emails, other messages or applicable marketing collateral.
Our data security policies
KC Multimedia Ltd takes data security extremely seriously, and we place the rights of the individual and regulatory adherence at the heart of everything we do as a company.
In light of our commitments, it is mandatory all staff members must observe and adhere to the following data security policies:
Data storage policy
- All information or data that is collected and processed is subject to all of the applicable requirements as outlined and documented within this policy. This includes information collected electronically, by paper, telephone or data collected through any other means.
- All data must be collected, stored and protected in a secure location appointed by KC Multimedia Ltd, for a retention period as predefined by corresponding legislature or company policy.
- Staff members are strictly forbidden to retain confidential information or personal data not relating to themselves on their personal devices. Exceptions to this policy include information that is needed for a purpose that is work-related, temporary and specified and approved by a relevant manager.
- Staff members should avoid downloading sensitive files or confidential information to local devices wherever possible. Information being necessarily processed for work purposes may be exempt from this policy.
- Employees must install and use software and systems that have been licensed and approved by the company on devices while carrying out the duties of their role. Downloading or using any software, app or system that is not preapproved by the company will require prior approval from the company’s IT Manager.
- All mobile and portable devices used by staff members should be approved by the company’s IT Manager and secured to prevent unauthorised access or breach. Personal devices could include a laptop, smartphone, tablet or any other handheld computing devices. This policy also applies to any shared cloud storage spaces.
- All internet access and online operations carried out by employees could be subject to monitoring and filtering in accordance with relevant legislation and company policy. This monitoring should be carried out only by the IT Manager or an authorised member of staff.
- Employees must adhere to all applicable elements of this policy when using personal devices to access company resources. Similarly, employees must observe and adhere to all applicable elements of this data security policy when using equipment provided by KC Multimedia Ltd to access information externally.
- Employees are forbidden from using public access devices. This practice is allowed in some circumstances; however, prior and explicit approval from a line manager for regular public access must be obtained and recorded.
- Employees must use access tools provided to them by a client or partner of KC Multimedia Ltd if access is granted to any third-party storage system or data storage facility.
- It is forbidden to send, forward or submit any of the information or data referred to within this data security policy to a third-party unless deemed essential to complete approved processes.
- If an employee needs to carry out an approved submission of data to any relevant third-party, that data must be made secure in accordance with company policy and any relevant third-party data protection protocols.
Please note that KC Multimedia Ltd will carry out regular system audits to monitor and ensure ongoing compliance with this data security policy and all regulatory requirements as outlined under GDPR.
Data retention policy
While KC Multimedia Ltd must routinely collect and store data, we are committed to the rights of individuals. That’s why we retain all information and personal data for no longer than we need to.
The necessary length of retention will often be decided on a case-for-case basis, bearing in mind the rationale and original purpose surrounding data collection and retention. Decisions of this nature must be made in a way that is compatible with our existing data retention guidelines under GDPR.
For additional guidance, consult the following corresponding documents:
- Data retention and erasure policy document
International data transfer policy
Employees must observe a series of restrictions that apply towards the international transfer of data or personal information. Employees are not permitted to transfer personal information or data outside of the United Kingdom without having obtained explicit permission in the first instance from the company’s Data Protection Officer.
Data encryption and anonymisation policy
KC Multimedia Ltd deploys encryption to secure and protect data that is stored on devices from unlawful processing or unauthorised access. Encryption is also used to protect information that is in transit.
We also use the anonymisation of personal data wherever deemed prudent to ensure the rights of the individual are fully protected and observed.
In line with these principles, we are committed to the use both encryption and anonymisation as a risk management tool alongside existing systems, to protect the company from accidental loss, as well as from the damage or destruction of data or personal information.
Activities that are prohibited
Unless otherwise noted or informed, employees are strictly forbidden from using company equipment, tools or systems for any purpose unrelated to their role responsibilities, excluding any previously mentioned exceptions. This policy also relates to any relevant systems, tools or equipment belonging to a company client or partner.
Bearing that in mind, the following activities should be deemed forbidden with no exceptions:
- Any unauthorised replication of copyrighted materials.
- The violation of individual rights by way of the unnecessary collection, storage and processing of personal data or information.
- The violation of rights of an individual or organisation protected under intellectual property law in any jurisdiction.
- The use of any programme, command or interface designed to interfere with a user or corresponding user session.
- The accessing of any data, user account or server for any purpose unrelated to the business function of an individual’s company role.
- Issuing fraudulent product or service offers from a company account.
- The allowed sharing or use of employee login credentials or company systems by anyone apart from the named individual.
- The export of proprietary or confidential information as it relates to the company.
- The export of any software or data that is in breach of regulation or the company’s data security policy.
- Knowingly causing a network disruption or security breach.
- An employee is not allowed to access data that is not intended for them by logging into a system or gaining access to a confidential or limited-access account. The only exception to this rule is if the employee is granted access as part of a specific company project.
Please note that any violation of this policy can lead to disciplinary action, alongside legal action where deemed prudent or necessary.
Reporting security issues
If you encounter any incidents or issues relating to the security or protection of information or data, you must report this immediately to company management. Management will subsequently take and record any action deemed necessary to prevent damage or loss in relation to a security threat.
If necessary, it is the responsibility of company management to report relevant incidents relating to a data breach or information security threat to regulators or the authorities. Under GDPR, it also falls upon management to contact the individuals involved in any breach or security threat.
KC Multimedia’s Data Protection Notice
KC Multimedia Ltd collects, processes and stores the information and personal data you submit to our website in relation to carrying out our day to day business activities. All processing activities shall be carried out in accordance with your individual rights as defined by the European Union’s General Data Protection Regulation.
Please note that by submitting information about yourself through our website, you are agreeing for KC Multimedia Ltd to process and store that data. This data shall be stored only for the duration of the previously outlined purpose for collection. We never store or process your data longer than we need to, and we do not use your data for any purpose other than those you have agreed to.
The data you submit to our website will never be shared with or transferred to a third-party organisation. The following partners are exempt from this policy as they assist KC Multimedia Ltd in processing your personal data and delivering its services; PayPal, GoCardless, Stripe and WorldPay.
You reserve the right to request KC Multimedia Ltd update your personal data at any time. You can also request information about your personal data, withdraw your consent for us to process your information or request a transfer or deletion of your data.
For more information about KC Multimedia Ltd and how we protect and secure your data, consult our Privacy Notice and Consent below.
Please tick this box to indicate you have read and consent to our Privacy Notice:
1. Policy introduction
Here at KC Multimedia Ltd, we are committed to data security, the privacy of the individual and upholding all our compliance obligations under GDPR. We take our responsibilities seriously, and we recognise that the use of information assets and data form a crucial aspect of our business activity. That is why we’ve devised the following Data Classification Policy to outline the way in which we classify and use data.
Our Data Classification Policy is designed to ensure that:
- KC Multimedia Ltd adheres to all necessary legal obligations
- We implement controls to maximise return on investment
- KC Multimedia Ltd maintains availability, confidentiality and integrity where necessary for all data
- Our company has the ability to chart data protection levels that protect both KC Multimedia Ltd as well as the individuals whose personal data we must collect, process or store
- We are able to avoid threats of disclosure and/or unauthorised access to data
2. Policy values
Data classification is a vital process our company must carry out to ensure the individuals who claim a legitimate right to access information we hold are able to do so. Our data classification process must also ensure our data and any other piece of information we hold is protected from any and all individuals or organisations that should not have access to that information.
KC Multimedia Ltd’s Data Classification Policy identifies and elaborates upon the correct handling and classification processes our company must use, as per the regulatory requirements that we:
- Make data available to all those individuals who have a legitimate reason to access it
- Manage all data in line with its corresponding classification
- Maintain the integrity of all data
- Ensure all data our company holds is accurate, complete and consistent
3. Policy objectives
KC Multimedia Ltd’s Data Classification Policy has been developed to meet the following objectives:
- To outline the duties and responsibilities of KC Multimedia Ltd employees that ensure data is kept safe and secure
- To establish a robust data classification process that is consistent and compliant with UK regulatory requirements
- To ensure data is sufficiently protected and encrypted so that unwarranted actions will not be taken against KC Multimedia Ltd in the event data is lost, damaged or accessed illegally
- To avoid and minimise reputational or operational damage to KC Multimedia Ltd, our stakeholders, clients, customers or partners associated with compromised data
4. Policy implementation
To make sure our Data Classification Policy is effective, KC Multimedia Ltd will implement the following procedures:
- All users of data will be identified and provided access to data in which they have a legitimate need to access
- All data will be classified, managed and controlled in relation to its correct categorisation, as per the processes and requirements outlined within this policy
- KC Multimedia Ltd must ensure control mechanisms are created and implemented to protect data we collect, process or store
- All control mechanisms and classification protocols must be reviewed and amended as required by law on a regular basis
- Data users and data controllers must implement and maintain adequate levels of physical security as required, in relation to computer facilities or access terminals from which data can be viewed or accessed
- KC Multimedia Ltd must ensure that all data and relevant equipment is safely disposed of, as and when required
5. Obligations under GDPR (2018) and Data Protection Act 2018 (DPA)
KC Multimedia Ltd is committed to meet its regulatory obligations under GDPR and DPA. That is why we are committed to ensure that adequate and appropriate measures are taken to prevent the unauthorised access or illegal processing or storage of data. We are required to do everything we can, within reason, to protect the data we use and hold against destruction, accidental loss or damage.
6. Data classifications
Data that is sensitive in nature must be adequately protected at all times. To properly assign safeguards, all data that our company collects, processes or stores must be assigned one of the following classification categories:
- Public
- Open
- Confidential
- Strictly Confidential
- Secret
A vast amount of the data KC Multimedia Ltd uses will most likely be classed as being either ‘Public’ or ‘Open’ data. Any information relating to an individual or organisation that could identify them or is personal or private in nature must be assigned a category of either ‘Confidential’ or ‘Strictly Confidential’.
This is to ensure KC Multimedia Ltd upholds its regulatory commitment to uphold the rights of individuals, as outlined under GDPR.
On rare occasions, KC Multimedia Ltd may wish to class data as ‘Secret’. If an employee is unsure as to whether they should categorise a piece of data as being secret – or if they need assistance in classifying any other piece of data, they should consult a line manager. If no manager is available for consultation, data should default to a ‘Confidential’ classification.
7. Data classification types and handling procedures
To minimise discrepancies and ensure KC Multimedia Ltd does everything it can to uphold its regulatory commitments, the following working definitions should be associated with the aforementioned classification categories.
Public data
Public data is information or data that can be accessed by any external individual or organisation.
Types of public data might include:
- Official contact data of relevant company employees
- News updates or press releases
- Company publications
- External-facing company policies or procedures
How to handle public data:
Public data should be formatted to allow for the most basic security measures. Examples might include converting a Word document into a PDF to avoid others editing it, as this could subsequently cause some form of reputational damage.
Open
Anyone is able to access this information.
Types of open data might include:
- Official contact data e.g. full name, primary email address and telephone number
- Authorised communications, such as blogs, news articles and industry updates
- Approved company policies, guidance and processes
How to handle open data:
Open data should be formatted to allow for the most basic security measures. Examples might include converting a Word document into a PDF to avoid others editing it, as this could subsequently cause some form of reputational damage.
Confidential data
Access to confidential data must be limited only to individuals who have been granted appropriate authorisation to view or process that information.
Alternatively, there may be occasions in which unauthorised individuals or stakeholders may need to be granted access to confidential data; however, this access must only be provided on a need-to-know basis.
Types of confidential data might include:
- Someone’s personal details or any information that could be used to identify them. Examples of identifiable or personal details include:
- Name
- Date of birth
- Address
- Telephone number
- Email address
- National Insurance number
- Race
- Religion
- Health details
- Political affiliations
- Trade union membership
- Criminal offences
- Employee contracts
- Non-Disclosure Agreements
- Unfinished or unapproved company documents
- Employee wage slips
- Death certificates
- PDR documentation
How to handle confidential data:
As and where required to handle confidential data, employees should exercise the following handling processes:
Paper documents must be:
- In secure locked storage
- Transported in sealed envelopes only
- Transported by an approved third-party courier service
- Securely disposed of
Electronic data must be:
- Encrypted
- Password-protected wherever possible
- Transportation must follow secure file transfer protocol
- Storage must be limited to secure file stores
- Securely disposed of
Strictly confidential data
A minimal number of authorised individuals, authorities or other stakeholders may be permitted access to data that has been classified as being ‘Strictly confidential’.
Types of strictly confidential data might include:
- Bank details
- Credit card information
- Financial information
- Server information
- Usernames or passwords
- Test data
- Medical records
- Disciplinary proceedings
- Patent information
- Network information
How to handle strictly confidential data:
As and where required to handle strictly confidential data, employees should exercise the following handling processes:
Paper documents must be:
- In secure locked storage
- Transported in sealed envelopes only
- Transported by an approved third-party courier service
Electronic data must be:
- Encrypted
- Password-protected wherever possible
- Tagged
- Transportation must follow secure file transfer protocol
- Storage must be limited to secure file stores
Secret data
Access to data that has been classed as ‘Secret’ or a request to access secret data is subject to the Official Secrets Act.
Various types of secret data may require different controls and circumstances. Bearing that in mind, individual protocols should be reviewed on a case-for-case basis in line with UK Government requirements. Government advice concerning the handling of secret data should be sought.
8. Data classification markings
Data classification markings need to be clearly visible at all times and must match the classification category in which that data has been assigned. Appropriate data classification identification markings should be included either at the top, bottom or centre of each document page.
9. Reclassifying data
There may be occasions in which data must be reclassified from one data category to another data category. The need for reclassification could depend upon a content change, or an alteration in terms of the data’s intent, where it is stored or how it is being used. Before reclassifying data, a firm and justifiable rationale must be established. If in doubt, contact the Data Protection Officer or your line manager for guidance.
10. Sensitive data
It is the responsibility of the data owner or the data originator to define the category of data classification for a piece of data. Responsibility also rests with the data owner or originator to ensure that adequate protection has been afforded to that data in line with its relevant classification.
Any data that could or should be defined as being personal in nature must be afforded a higher level of protection and be treated as data that is sensitive. Personal data can be classed as information relating to an individual that could identify them. Aforementioned examples of sensitive personal data might include (among other pieces of data) a person’s name, contact information, race, religion, political affiliations, sexual preference and so on.
Sensitive data must be identified and assessed on a case-for-case basis. In most cases, sensitive data will inherently be classed as confidential; thus, access and/or availability must be limited.
Sensitive data which is made available in the public domain can lead to reputational damage for private individuals or company employees. As a company we must ensure that sensitive data is given sufficient protection to protect individuals, company employees and the company itself.
11. Data storage and backup
Because data is such an integral aspect of our business, it is everyone’s responsibility at KC Multimedia Ltd to do everything within their power to ensure that sensitive data is being collected, processed, backed up, stored and secured in line with company policy.
12. Data anonymisation
Prior to the sharing, transfer or disclosure of data, KC Multimedia Ltd and its employees must take all necessary steps to ensure that the anonymity of corresponding data subjects is protected and maintained in line with our regulatory commitments.
Necessary steps may include omitting or redacting (deleting) said personal identifiers within a piece of data. Audio visual data or verbally exchanged data recordings should be likewise edited.
13. Secure data disposal
Sensitive data that is no longer needed or has reached an ‘end of life’ classification as decided upon by the relevant authorised individuals must be disposed of in a secure fashion. Examples of disposing data as stored on paper would include shredding.
14. Data security response
If data is damaged or lost, it must be immediately reported to an appropriate line manager and company Data Protection Officer, and logged as an incident requiring urgent response.
Data retention and erasure policy introduction
Our approach towards data retention
This policy is designed to ensure KC Multimedia Ltd does everything within its power to adequately protect, maintain and store data. This policy has also been developed to ensure that any data, documents or records that have no further use or value to KC Multimedia Ltd are disposed of in line with our regulatory obligations and relevant company policy.
Employees should consult our data retention and erasure policy, to develop an understanding of our company’s obligations relating to the ways in which we retain data or electronic documents. These documents may include, but are not limited to:
- Emails
- Word Documents
- Spreadsheets
- PDF documents
- Web files
- Sound files
- Videos
Personal data must never be kept for longer than it is needed. Consequently, employees should utilise our company’s data retention schedule as a guide to understanding KC Multimedia Ltd’s general retention period time for various data categories that have been assigned based upon the purpose of the data. In line with our regulatory obligations, all data that is no longer necessary should be deleted and all copies must be destroyed in line with our data erasure schedule.
Data retention schedule administration
This data retention schedule documents the maintenance, retention and disposal guidelines relating to any and all records our company holds. It must be reviewed and accordingly amended on a regular basis to ensure data storage and erasure processes are adhering to KC Multimedia Ltd’s wider data retention policy approach.
There will be times when data may need to be retained longer than the pre-defined amount of time permitted. Circumstances in which our policy will need to be suspended may include, but are not limited to:
- Legal proceedings
- Regulatory investigations
- If criminal activity is suspected or alleged
- If relevant data concerns a company or organisation in receivership or liquidation
- If the relevant data is of historical importance to the owner or controller
In the event of legal proceedings, criminal activity or investigations, KC Multimedia Ltd and its employees must retain data that relates to the situation and could serve to aid the company’s case or position, liability or amount involved. If such a situation may occur during the lifetime of this policy, KC Multimedia Ltd will inform all staff of the policy’s suspension as it relates to said situation.
Data retention schedule
KC Multimedia Ltd has developed its data retention policy in line with the following data retention schedule:
|
Department |
Function |
|
1 |
Accounting and finance data |
|
2 |
Contract data |
|
3 |
Corporate records |
|
4 |
Correspondence and internal memoranda |
|
5 |
Personal data |
|
6 |
Electronic data |
|
7 |
Insurance data |
|
8 |
Legal data |
|
9 |
Miscellaneous data |
|
10 |
Personnel records and data |
|
11 |
Tax records and data |
1. Accounting and finance data
|
Record |
Retention period |
|
Company financial statements and annual audit reports |
Permanent |
|
Annual audit records (including relevant documents) |
7 years after audit completion |
|
Company bank statements |
7 years |
|
Cancelled cheques |
7 years |
|
Employee expense reports |
7 years |
|
Interim company financial statements |
7 years |
|
Credit card records |
2 years |
|
Annual plans and company budgets |
2 years |
Any and all items that display customer bank details or credit card information must be kept under secure conditions when not in immediate use. This includes keeping printed records in a locked desk drawer or filing cabinet.
If KC Multimedia Ltd determines it is necessary to keep a document that displays customer financial details beyond a retention period of 2 years, all identifying details or financial information as it relates to any customer must be redacted or removed from the document in question.
2. Contract data
|
Record |
Retention period |
|
All company contracts |
7 years after expiration or termination |
|
All correspondence relating to contracts |
7 years after expiration or termination |
3. Corporate records
|
Record |
Retention period |
|
Corporate records |
Permanent |
|
Licenses and permits |
Permanent |
For the purpose of this schedule and corresponding policy, ‘corporate records’ should be defined to include anything relating to:
- Meeting minutes
- Signed minutes of the board
- Signed minutes of any committees
- Record of incorporation
- Articles of incorporation
- Annual corporate reports
4. Correspondence and internal memoranda
The vast majority of correspondence and internal memoranda must be retained to match the period of time as the document or data to which they relate. Examples may include an email relating to a contract – in which case the email in question would be expected to be retained for a period of 7 years after the expiration of the corresponding contract.
Bearing this in mind, KC Multimedia Ltd recommends that all correspondence and internal memoranda as it relates to a company project be kept with said project as part of a project-wide file.
Company correspondence or internal memoranda unrelated to documents that have a defined retention period, should be securely destroyed at an earlier time depending upon which of the following two categories it corresponds:
Category 1
Category 1 correspondence or internal memoranda includes any and all data as it relates to routine processes. Category 1 correspondence and internal memoranda generally do not carry any significant consequences and should be disposed of with 2 years.
Examples of category 1 correspondence and internal memoranda may include (but are not limited to):
- Notes of appreciation or thanks
- Plans for meetings
- Forms or letters that do not require a follow up
- General enquiries that have been settled
- Chronological correspondence data
- Complaints requesting a specific action that have already been addressed and carry no further value
- Correspondence relating to inconsequential subject matter
All copies of internal office correspondence should be read and destroyed as per this policy unless that correspondence includes data or content that must be retained as part of a wider project.
Category 2
Category 2 correspondence or internal memoranda includes non-routine information or correspondence that is likely to have a consequential impact upon the company or its employees. Category 2 correspondence and internal memoranda should be retained on a permanent basis.
5. Personal data
There will be times when KC Multimedia Ltd and its employees must retain and/or delete personal data in line with its legal obligations.
For the purposes of this data retention and erasure policy, ‘personal data’ can be defined as any identifying information as it relates to an individual. We never keep personal data for longer than is necessary for the purpose in which that data was collected. All personal data as defined within the following categories should be deleted based upon this retention and erasure schedule:
|
Record |
Retention period |
|
Data relating to customer devices |
2 years after the account is closed |
|
Data relating to use of our company website |
2 years after the account is closed |
|
Any data collected when registering with our website |
2 years after the account is closed |
|
Data collected and submitted as part of any profile creation processes |
2 years after the account is closed |
|
Data submitted for the purpose of subscribing to email marketing activities |
Indefinitely (or until customer unsubscribes) |
|
Data submitted as part of online service delivery |
Indefinitely |
|
Data relating to any subscriptions |
2 years after the account is closed |
|
Data posted in a public area on our company website |
2 years after the post |
|
Data contained in communications sent through the website |
2 years after contact |
|
Any other personal data |
2 years after contact |
KC Multimedia Ltd reserves the right to retain any and all documents (both electronic and print) containing personal data to the extent our company is required by law to do. We will also retain documents containing personal data if we have reason to believe said documents could be relevant to legal proceedings, or to establish and/or exercise our own legal rights.
Our company will organise backups of our database and all of the electronic data held within our company server(s). Backup activities should include all data that relates to current users or customers, alongside any document or dataset relating to one of the aforementioned reasons as outlined within this data retention and erasure policy. KC Multimedia Ltd does this to ensure that lost information can be retrieved within one year, as and where needed.
6. Electronic data
Emails
Most emails do not need to be kept. Emails that are inconsequential or unrelated to contracts or projects should subsequently be treated in line with the following policies:
- All emails should be deleted after 12 months. This includes both internal and external emails
- KC Multimedia Ltd will archive emails for six months after employees have deleted them. After this six-month period, archived emails will be destroyed
- Employees should never send emails containing confidential or proprietary data to external sources unless it has been approved by a relevant manager
Electronic documents
Electronic documents include, among other formats, both PDF document and files originating from Microsoft Office Suite or similar software.
Retention and erasure will depend upon the purpose of the electronic document, yet as a general rule of thumb employees can apply the following rules:
For PDF documents, the maximum period of retention should be 6 years. PDF documents that employees deem vital to their performance or role should be printed and/or stored in the relevant employee’s workspace.
For text documents or other formatted files, the maximum period of retention should be 5 years. Text documents or other formatted files that employees deem vital to their performance or role should be printed and/or stored in the relevant employee’s workspace.
KC Multimedia Ltd does not and will not automatically delete electronic documents or corresponding data beyond the time periods defined within this policy. It is the responsibility of our employees to ensure they are adhering to our policy guidelines.
7. Insurance data
|
Record |
Retention period |
|
Certificates |
Permanent |
|
Claims files |
Permanent |
|
Current insurance policies |
Permanent |
|
Expired insurance policies |
Permanent |
8. Legal data
|
Record |
Retention period |
|
Legal memoranda and legal opinions |
7 years after resolution |
|
Litigation data |
1 year after expiration of appeals or time for filing appeals |
|
Court orders |
Permanent |
|
Requests for a departure from KC Multimedia Ltd retention and erasure schedule |
10 years |
|
Register of members |
Permanent |
|
Director’s meetings minutes |
10 years |
9. Miscellaneous data
|
Record |
Retention period |
|
Reports from consultants |
2 years |
|
Documents containing content of historical value |
Permanent |
|
Original policy and procedures manuals |
Current version with revision history |
|
Copies of policy and procedures manuals |
Retain current version only |
|
Annual company reports |
Permanent |
|
Records of personal identification |
5 years |
|
Any work-related reportable accident, injury or death |
3 years from incident |
|
Immigration checks |
2 years from termination of job |
10. Personnel data
|
Record Type |
Retention Period |
|
Job applications and/or related interview data concerning unsuccessful candidates |
6 months |
|
Employee personnel records |
6 years after end of contract |
|
Employment contracts |
7 years after end of contract |
|
Employment records correspondence with employment agencies |
3 years from date of hiring |
|
Job descriptions |
3 years after superseded |
|
Working time opt-out documentation |
2 years |
|
Financial details of employees |
As long as necessary |
11. Tax data
KC Multimedia Ltd keeps accounts and/or records to demonstrate and establish amounts of gross income, deductions, credits and other information. These records are crucial to maintaining our company’s compliance of tax laws.
Associated records and documentation will include (but are not limited to) the following records and associated schedules:
|
Record |
Retention period |
|
Tax-exemption documentation |
Permanent |
|
Tax bills |
7 years |
|
Tax returns |
Permanent |
|
Tax receipts |
Permanent |
|
Tax statements |
Permanent |
|
Sales and/or use of tax records |
7 years |
|
Annual returns |
Permanent |
|
Payroll/wage records for unincorporated businesses |
5 years after 31 Jan following the year of assessment |
|
PAYE records |
3 years from the end of the tax year to which they relate |
|
Maternity records |
3 years after the end of the tax year in which the maternity pay period ends |
Frequently asked questions
|
Who is using my data? |
KC Multimedia Ltd |
|
What is my data being used for? |
KC Multimedia Ltd stores and processes data to help us maintain your account, process and store transaction details, offer customer support, send system updates and send offer details. |
|
What will happen to my data? |
KC Multimedia Ltd may use your data to send you information, updates and offers we think you’ll be interested in. |
|
What data will be kept and stored? |
KC Multimedia Ltd stores registration details, transaction details, usage information and any information about your web preferences on our website. |
|
What data will be shared with others? |
We only share your data with regulators or government bodies if requested. |
|
How long will my data be kept for? |
KC Multimedia Ltd will store your data for a period of 18 months after your last attempted login. After this period, your account will be deleted. You can request your account to be delete at any time. |
|
Who will be able to access my data? |
KC Multimedia Ltd will never sell or share your data to any third-party, unless you grant us your explicit permission to do so. |
|
How will my data be kept and made secure? |
KC Multimedia Ltd stores your data on secure servers that are based in the UK. Data is processed in the UK, and we use standard industry security protocols. |
Privacy Notice
Date: 06 April 2022
KC Multimedia Ltd takes your privacy seriously. That is why we will only use your personal information to provide you with the products and services you have requested, as well as to administer your account. We will not sell or share your information with third-parties you grant us explicit permission to do so, and we will never use your personal data for any reason other than the reasons described within this policy.
About our privacy policy
Our privacy policy outlines your relationship with our company and explains in detail how we use the information that you provide us with.
About KC Multimedia Ltd
KC Multimedia Ltd is the trading name of KC Multimedia Ltd, which is registered in England and Wales and registered with the UK’s Information Commissioner’s Office under the Data Protection Act 2018. Our data controller is Ken Cope, and we encourage you to get in touch with any questions you may have about KC Multimedia Ltd.
You can reach us by:
- Post: 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UK
- Telephone: 07952 599578
- Email: info@kcmultimedia.ltd
- Website: https://kcmultimedia.ltd
Changing your preferences
If you’d like to change your web, contact or marketing preferences, you can do so at any time. Simply contact us at support@kcmultimedia.ltd to request the necessary amendments.
How we do business
KC Multimedia Ltd is committed to upholding and maintaining your personal rights. We operate our business in-line with the European Union’s General Data Protection Regulation and observe your rights to change or withdraw your opt-in options at any time. As part of our ongoing commitment to uphold your rights, KC Multimedia Ltd will also extend advice on how you can issue formal complaints to relevant authorities, such as the Information Commissioner’s Office.
Sensitive data
KC Multimedia Ltd does not collect any sensitive data about you. Sensitive data refers to (but is not limited to) information about your race or ethnic background, religious or political affiliations, trade union affiliations, sexual orientation, criminal background or health background.
Who our privacy policy applies to
This privacy policy has been developed to inform users of KC Multimedia Ltd how we use their data. KC Multimedia Ltd is a multimedia company offering website design, graphic design, webhosting and Domain Names, and we need to process the data of individuals to offer our products and/or services. Bearing that in mind, our privacy policy applies to any and all individuals registered with us as a user, customer, administrator or in any other capacity.
What information this policy applies to
There is a lawful basis for processing your data, and this section of our privacy policy outlines how this applies to the personal information you provide us with or allow us to collect.
The information this policy applies to includes information that you:
- Provide as part of any registration process
- Provide as part of any campaign creation activity
- Provide in the form of numerical data, metadata or communications
- Give us as part of our ongoing relationship
This policy also applies to information that we:
- Collect relating to how you interact with our website
- Must process to complete purchases and other transactions
Consent
Please note that when you submit personal data on our website, you are giving KC Multimedia Ltd your explicit consent that we can use that data in line with our privacy policy.
Opting-out
After giving KC Multimedia Ltd your consent, you are free to amend your consent or withdraw your consent at any time. You have the right to object to the processing of your data. To opt-out, change your preferences or revoke your consent, simply contact us by emailing dataprocessor@kcmultimedia.ltd.
Data processing and storage
KC Multimedia Ltd collects and stores data in the UK. We will store your data for a period of 18 months after your last recorded login attempt unless otherwise noted and explicitly stated.
KC Multimedia Ltd stores data relating to transactions, payments and orders for a period of up to seven years. This period may be extended under certain circumstances as part of our ongoing commitment to comply with UK and international law.
We use carefully selected and recognised third-parties to help us take payments, provide commerce services and manage company accounts. Some of these third-parties may operate outside the European Union.
KC Multimedia Ltd may process your data based on more than one legal ground.
Circumstances under which we may be required to process your data under more than one legal ground may include:
|
Reason |
Data type |
Legal basis |
|
Customer registration |
Identity and contact information |
To carry out a contract we’ve made with you |
|
Processing and/or delivering your order |
Identity, contact information, financial information, financial and transactional data |
To carry out a contract we’ve made with you and to exercise our legitimate interests to recover debts owed |
|
To manage our customer relationship with you |
Identity, contact information, marketing and communications preferences |
To carry out a contract we’ve made with you, to comply with legal obligations and to exercise our legitimate interests to keep our records updated |
Marketing and communications
KC Multimedia Ltd may send you marketing communications if you have given us your contact details and opted-in to marketing communications.
You can opt-out of these marketing communications and manage your preferences at any time.
Our company obligations
As a data controller, KC Multimedia Ltd is legally responsible for the data you provide us with. In honouring that responsibility, we pledge to uphold our commitments under GDPR and the Data Protection Act 2018.
We will only ever use your data:
- In ways that are both fair and legal
- As described within this policy
- In ways that are necessary for the purposes described
In addition, KC Multimedia Ltd processes the personal data you submit to us or we collect as a data processor. As part of this role, KC Multimedia Ltd takes all necessary precautions to secure the personal data we collect, process and store.
We may occasionally use the data you provide us with for marketing, relationship management or account management activities. These activities are designed to ensure you have adequate information about other products and/or services we offer, that we have reason to believe you may be interested in. You have the right to opt-out of these activities at any time.
Third-Parties
KC Multimedia Ltd never shares your personal data with third-parties unless those parties have been explicitly mentioned within our privacy statement.
Our security
As part of our ongoing commitment to GDPR, KC Multimedia Ltd will report any security breaches or attempted breaches to the relevant authorities within 24 hours. We will subsequently contact all those affected by the breach within 72 hours of its occurrence.
Legitimate interests
As part of the Data Protection Act 2018, KC Multimedia Ltd observes the right to share selected information with third-parties that use data for non-marketing purposes. This could include (but is not limited to) organisations that provide credit assessments, identification services and fraud prevention activities.
Contact us
KC Multimedia Ltd is committed to upholding your rights. If you have any questions, comments or concerns about this privacy policy or wish to exercise your rights in relation to your personal data, please contact Ken Cope at KC Multimedia Ltd.
We will process any request within 30 days. Subject Access Requests are normally performed free of charge, but we may need to charge individuals for excessive or unreasonable data requests.
Complaints
If you are not happy with how your personal data has been processed, you should contact Ken Cope in the first instance by using the contact details listed above. If Ken Cope is unable to satisfy your concerns, you have the right to apply to the Information Commissioner’s Office for a resolution.
You can contact the Information Commissioner’s Office at the following address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Here at KC Multimedia Ltd, we take privacy seriously. That is why we take every possible precaution to protect personal data, and actively work to avoid any data protection breaches which could compromise our data security, or the personal rights of our clients, customers, stakeholders or anyone else associated with our company.
To mitigate the risk that any such data compromise could pose, we have developed the following data breach policy. It is an integral part of our compliance responsibilities under the General Data Protection Regulation and Data Protection Act 2018, and is designed to develop clear lines of responsibility and processes that must be followed to adequately mitigate and manage data breach and security incidents.
What does this policy cover?
The scope of this data breach policy encompasses all personal and sensitive data our company holds. This data breach policy applies to everyone at our company – including employees, temporary or casual staff, consultants, suppliers, contractors, freelance workers or other data processors who are storing or processing data on the behalf of our company.
What is the purpose of this policy?
The purpose of this data breach policy is to contain all data breaches and to minimise the risks associated with any breaches. It also outlines the actions that should be taken in the event of a breach to ensure data is secure and to prevent further breaches.
About data breaches
A data breach is defined as any incident, event or action that has the potential to compromise the availability of data, the integrity of data, confidentiality or our company’s data systems. This includes incidents or events that happen by accident or deliberately. Both confirmed and suspected incidents may qualify as a data breach.
For the purposes of this data breach policy, an incident may include (but is not limited to) any of the following:
- Unauthorised use or accessing of data
- Unauthorised modification of data
- Loss of personal or sensitive data
- Theft of personal or sensitive data
- Loss or theft of equipment on which data has been stored
- Individual error
- Any attempts to gain access to data or our company IT systems (both successful or failed)
- Defacement of web property
- Physical incidents, like a fire, which could compromise IT systems
How to report a data breach
All employees who access, manage or use data in any way are responsible for reporting a data breach or any other type of security incident. This report should be made immediately to the employee’s line manager, using the data breach reporting form.
This report must include full details of the incident or breach, when it occurred, who the data relates to and how. It must also include details about the individual reporting the incident.
If a data breach or a data security incident occurs outside of normal company hours, or a data breach or data security incident is discovered outside of normal company hours, it must be reported as soon as possible.
Any violation of this data breach policy could result in disciplinary action procedures taking place for company employees.
Data breach containment and data recovery
All necessary steps must be immediately carried out to minimise the effects of any data security breach or data security incident. This process of containment should begin with an initial assessment designed to establish the severity of the incident. The initial assessment should also include analysing whether there is any way to recover the lost data, and mitigate further risks associated with the incident.
Your initial assessment should include the following information:
- The data involved
- Whether the data involved is sensitive in nature
- The individuals affected
- The security measures that are in place to protect the data
- What has happened to the data
- Whether the data involved could be used in an illegal or otherwise inappropriate way
- Any perceived wider consequences associated with the breach or incident
Data breach notification
KC Multimedia Ltd will determine which individuals must be notified in the event of a data breach or data security incident. Each incident must be assessed on a case-by-case basis. In every instance, the following considerations will be made:
- Any contractual notification requirements
- Any legal notification requirements
- How many people are affected
- What consequences may occur as a result of the data breach or data security incident
- Whether notification of a breach or incident would help the individual to mitigate risks associated with the incident
- Whether notification could assist the company in meeting its legal obligations under GDPR and Data Protection Act 2018
- Whether notifying an individual could prevent the unauthorised or illegal use of data
- Whether KC Multimedia Ltd must notify the Information Commissioner’s Office
All data breaches and data security incidents, both suspected and verified, must be recorded, to assist in further analysis and to help prevent further breaches.
The danger of notifying too many individuals
There will be data security incidents in which a large number of individuals will need to be notified. However, there will be other incidents in which notifying a large number of individuals may have the potential to cause disproportionate enquiries.
Whenever we notify an individual whose personal data has been affected by an incident or breach, that notification must include a description of when the breach occurred, how the breach occurred and what data was involved. Notifications must also include explicit guidance concerning what said individual can do to protect themselves. We should also outline to concerned individuals what steps our company has already taken to mitigate risks.
Data breach evaluation and response
After the data breach or data security incident has been contained by carrying out all necessary measures, KC Multimedia Ltd will conduct an extensive review detailing:
- The cause(s) of the breach
- The effectiveness of any responses
- Whether changes to existing IT systems, company procedures or policies must be implemented
All existing protocols must be reviewed to analyse their adequacy. Any necessary amendments to protocols must be identified and carried out as soon as possible.
