Home Privacy Policy
Privacy Policy
A plain account of what we do with personal data — what we collect, why, on what lawful basis, who sees it, how long we keep it, and how you can control it. This policy covers mapmakersopera.com and every commission, enquiry and application we handle.
1. Who we are and the scope of this policy
ASPIRE STUDIOS LTD, a company registered in England and Wales with its registered office at 5 Torrington Gardens, Thingwall, Wirral, England, CH61 7US, trading as Mapmakers Opera ("we", "us", "our"), is the data controller for the personal data described in this policy. This means we decide why and how your personal data is processed.
This policy explains what personal data we collect when you visit mapmakersopera.com, enquire about a commission, buy goods or services from us, apply for a job with us, or otherwise deal with us; why we collect it; what we do with it; who we share it with; how long we keep it; and the rights you have over it.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR). Where we deal with individuals in the European Economic Area, we process their data in accordance with EU Regulation 2016/679 (EU GDPR).
Contact us about anything in this policy at [email protected], or by post to the address in section 13.
2. The personal data we collect
2.1 Data you give us directly
- Identity and contact data — your name, the name of your club, company or venue, your job title, email address, telephone number, billing address and delivery address.
- Enquiry data — the content of the enquiry form on this website or our contact page, including the service you are interested in, seat count, room dimensions, timber and cloth preferences, budget indications, timescales and any free-text description of your project.
- Order and contract data — quotations issued to you, approved drawings and specifications, deposit and payment schedules, delivery and fitting arrangements, correspondence and site notes.
- Artwork data — logos, crests, colour references and other material you supply for reproduction on chips, inlays or plaques, together with the contact details of any designer acting for you.
- Correspondence data — emails, letters, notes of telephone calls, and photographs of your room or existing table that you send us.
- Recruitment data — where you apply to join us: your CV, covering letter, employment and training history, references, right-to-work documentation and interview notes.
- Feedback data — reviews, testimonials, survey responses and complaints.
2.2 Data we collect automatically
- Technical data — your IP address, browser type and version, device type, operating system, screen size, language setting, the pages you view on our site, the time and date of your visit and the referring page. This data is generated by our hosting provider's server logs.
- Cookie and storage data — see our Cookie Policy for the full picture. This website does not use advertising, profiling or cross-site tracking cookies.
2.3 Data we receive from others
- Referrals — where an architect, interior designer, venue operator or existing client passes your contact details to us in connection with a project.
- Service providers — delivery contractors confirming a delivery, payment providers confirming a transaction, and credit reference agencies where we offer trade credit to a business customer.
- Public sources — Companies House, business websites and professional directories, used to verify the identity and standing of business customers.
2.4 Data we do not want
We do not seek special category data (such as health, religion, political opinion, biometric or trade-union data) and we ask you not to send it. Where you volunteer health or access information relevant to a workshop visit or a site survey, we process it on the basis of your explicit consent and delete it when the visit is complete. We do not knowingly collect data about children; our services are directed at adults and businesses. If you believe a child has provided us with personal data, contact us and we will delete it.
3. Why we use your data and our lawful bases
We only process personal data where the law allows it. The table below sets out each purpose, the categories of data involved and the lawful basis on which we rely.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to enquiries and preparing quotations, drawings and sample boxes | Identity, contact, enquiry | Steps taken at your request prior to entering a contract; legitimate interests in answering business enquiries |
| Performing a commission — manufacture, chip pressing, delivery, installation and fitting | Identity, contact, order, artwork, correspondence | Performance of a contract with you |
| Taking payment, issuing invoices and chasing overdue amounts | Identity, contact, order, transaction | Performance of a contract; legitimate interests in recovering sums owed |
| Providing warranty, aftercare, service visits and chip reorders | Identity, contact, order, archive records | Performance of a contract; legal obligation under consumer law; legitimate interests in supporting products we made |
| Keeping an archive of past commissions so future reorders match | Order, artwork, specification | Legitimate interests in continuity of supply and honouring our ten-year reorder guarantee |
| Sending service messages about an active order | Identity, contact, order | Performance of a contract |
| Sending occasional marketing about new work, offers and events | Identity, contact | Consent, or the soft opt-in permitted by PECR for existing customers of similar goods |
| Publishing testimonials and portfolio entries | Name, role, venue, quote, photographs | Consent |
| Recruiting and assessing candidates | Recruitment | Steps prior to an employment contract; legitimate interests in assessing suitability; legal obligation for right-to-work checks |
| Maintaining security, preventing fraud and diagnosing faults on this website | Technical, cookie | Legitimate interests in keeping our site and business secure |
| Keeping accounting, tax and statutory records | Identity, contact, order, transaction | Legal obligation (Companies Act 2006, Value Added Tax Act 1994, Taxes Management Act 1970) |
| Establishing, exercising or defending legal claims | Any relevant data | Legitimate interests in protecting our legal position; legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and are satisfied that our interests are not overridden by your interests or fundamental rights. You may ask us for a summary of that assessment at any time.
4. Marketing and your control over it
We send marketing sparingly — typically a small number of messages each year showing recent commissions and announcing seasonal offers. We will only send it where you have opted in, or where you have bought from us or negotiated a purchase and we are contacting you about similar goods and services under the PECR soft opt-in.
Every marketing message contains a one-click unsubscribe link. You may also withdraw consent at any time by writing to [email protected]. Withdrawal is free of charge, takes effect within five working days, and does not affect the lawfulness of processing before withdrawal.
Opting out of marketing does not stop service messages about an order in progress, a booked service visit, a safety notice or an invoice — these are necessary to perform our contract with you.
We do not sell, rent or trade personal data. We do not build advertising profiles and we do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
6. International transfers
We keep personal data within the United Kingdom and the European Economic Area wherever we can. Where a supplier processes data outside those areas — for example a hosting or email provider with infrastructure abroad, or a freight agent handling a delivery to a customer outside the UK — we make sure at least one of the following safeguards is in place:
- the destination country is covered by UK adequacy regulations;
- the transfer is governed by the ICO's International Data Transfer Agreement, or by the EU Standard Contractual Clauses together with the UK Addendum, supported by a transfer risk assessment; or
- a specific derogation in Article 49 UK GDPR applies — for example, where the transfer is necessary to perform a contract with you, such as delivering a table to an address outside the UK.
You may request a copy of the safeguards applying to a particular transfer by writing to [email protected].
7. How long we keep data
We keep personal data only for as long as we need it for the purpose we collected it for, plus any period required by law or needed to defend a claim. Our standard periods are:
| Record | Retention period | Reason |
|---|---|---|
| Enquiries that do not become orders | 24 months from last contact | Enquiries commonly revive after a season; deleted automatically thereafter |
| Contract, order and delivery records | 7 years from completion | Limitation Act 1980 and tax record-keeping |
| Accounting and VAT records | 7 years from end of accounting period | Companies Act 2006; Value Added Tax Act 1994 |
| Warranty and aftercare records | 10 years from delivery | Duration of our structural warranty |
| Chip artwork, moulds and colour formulas | 10 years from last order | Our published reorder guarantee |
| Marketing consents and opt-out records | Until withdrawn, then 6 years | Evidence that we honoured your choice |
| Unsuccessful job applications | 12 months from decision | Legitimate interests; equality monitoring and future vacancies, with consent |
| Website server logs | Up to 12 months | Security, fault diagnosis and abuse prevention |
| Complaint files | 6 years from resolution | Defence of potential claims |
At the end of the applicable period we securely delete electronic data and cross-shred paper records. Where data must be retained for one purpose but not another, we restrict access so it is used only for the surviving purpose. In limited cases we retain anonymised information — such as the dimensions and species of a past build with all identifying details removed — indefinitely for design reference; anonymised data is no longer personal data.
8. How we protect your data
We maintain technical and organisational measures appropriate to the risk, including:
- encryption of the website in transit using HTTPS/TLS;
- access to customer records restricted to staff who need it for their role, with individual accounts and multi-factor authentication on email and cloud services;
- encrypted backups, held separately from live systems and tested for restoration;
- written confidentiality obligations in staff contracts and in every subcontractor agreement;
- staff training on data protection at induction and annually thereafter;
- secure disposal of paper drawings, sample notes and printed correspondence by cross-shredding;
- a documented breach procedure requiring internal escalation within 24 hours of detection.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and we will tell you directly without undue delay where the risk to you is high. No transmission over the internet can be guaranteed completely secure; please do not send us payment card details by email.
9. Your rights
Under the UK GDPR you have the following rights in relation to your personal data:
- Access — to be told whether we process data about you and to receive a copy of it, together with information about how it is used.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have data deleted where we no longer need it, where you withdraw the consent it relied on, or where it has been processed unlawfully. This right does not apply where we must keep the data for a legal obligation or for legal claims.
- Restriction — to have processing paused while an accuracy dispute or an objection is resolved.
- Portability — to receive data you provided to us, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Objection — to object to processing based on legitimate interests, and an absolute right to object to direct marketing at any time.
- Withdrawal of consent — where processing is based on consent, to withdraw it at any time without affecting prior lawful processing.
- Not to be subject to solely automated decisions producing legal or similarly significant effects. We do not make such decisions.
How to exercise a right
Write to [email protected] or to the postal address in section 13, telling us which right you wish to exercise. We may ask for proof of identity so that we do not disclose data to the wrong person. We respond within one month; where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse the request, explaining our reasons.
11. Third-party links
Our website may link to third-party sites — for example a supplier of certified timber, a trade association, or a venue that hosts a tournament we have equipped. We do not control those sites and are not responsible for their content or their privacy practices. Read the privacy policy of any site you visit through a link from ours.
12. Complaints
If you are unhappy with how we have handled your personal data, tell us first at [email protected]. We take every complaint seriously and will investigate it under the procedure in our Legal Information page.
You also have the right to complain to the supervisory authority at any time. In the United Kingdom this is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113, website ico.org.uk. If you are in the EEA, you may complain to the supervisory authority in your country of residence, place of work or the place of the alleged infringement.
13. Contacting us about data protection
Data protection enquiries, rights requests and complaints should be addressed to:
Data Protection Lead
ASPIRE STUDIOS LTD (trading as Mapmakers Opera)
5 Torrington Gardens
Thingwall
Wirral
England
CH61 7US
Email: [email protected]
We have assessed that we are not required to appoint a statutory Data Protection Officer, because our core activities do not consist of large-scale regular and systematic monitoring or large-scale processing of special category data. The Data Protection Lead named above is accountable for compliance and is your point of contact.
14. Changes to this policy
We review this policy at least once a year and whenever our processing changes materially. The version number and date at the top of this page show the current edition. Where a change materially affects how we use data you have already given us, we will notify you directly by email before it takes effect, and where the law requires it we will ask for fresh consent. Continuing to use this website after a revised policy is published means you accept the revised policy in relation to your use of the site.