Our policies set out our commitment to protecting personal data and how we implement that commitment with regards to the collection and use of personal data.
We are committed to:
We need to gather and use certain information about individuals. These can include customers, suppliers, business contacts, employees and other people the organisation has a relationship with or may need to contact. This policy describes how personal data must be collected, handled and stored to meet the Funeral Wishes Register data protection standards and to comply with the law.
This data protection policy (“DP Policy”) ensures Funeral Wishes Register:
The Data Protection Act 1998 (“the Act”) describes how organisations, including Funeral Wishes Register, must collect, process and store personal information belonging to individuals. The Act sets out obligations which apply regardless of whether personal data is stored electronically, on paper or other material. To comply with the law, personal data must be collected and used fairly, stored safely and not disclosed unlawfully.
The Act is underpinned by eight important principles. These say that personal data must:
The DP Policy applies to all personal data that Funeral Wishes Register holds relating to identifiable individuals, even if that data falls outside of the provisions of the Act. Relevant personal data may include
This DP Policy helps to protect Funeral Wishes Register from significant data security risks, including:
Everyone who works for or with Funeral Wishes Register has some degree of responsibility for ensuring that personal data is collected, stored and handled appropriately. Each team that handles personal data must ensure that such data is handled and processed in line with this DP Policy and all relevant data protection principles.However, the following persons have the key areas of responsibility as follows:
The provisiosn of this DP Policy set out how and where personal data should be safely stored and dealt with. Questions about storing personal data safely can be directed to the Operations Director or the Data Protection Officer. When personal data is stored on paper, it should be kept in a secure place where unauthorised persons cannot see or access it. The provisions of this DP Policy also apply to personal data that is usually stored electronically but has been printed. In those circumstances:
When personal data is stored electronically it must be protected from unauthorised access, accidental deletion and malicious hacking attempts as follows:
Personal data is of no value to Funeral Wishes Register. However, the greatest risk of loss, corruption or theft to personal data exists when it is accessed and used. As such:
The law requires Funeral Wishes Register to take reasonable steps to ensure that personal data is kept accurate and up to date. Funeral Wishes Register shall at all times use appropriate measures to ensure the safety and security of personal data.
The more important it is that the personal data is accurate, the greater the effort Funeral Wishes Register should put into ensuring its accuracy.
It is the responsibility of all employees of Funeral Wishes Register who work with personal data to take reasonable steps to ensure that it is kept as accurately and up to date as possible.
Personal data will be held in the least number of places necessary to enable Funeral Wishes Register to process such personal data. Employees of Funeral Wishes Register may not create any unnecessary additional copies of personal data beyond that required for Funeral Wishes Register to meet its obligations under the Act and any business requirements.
Employees of Funeral Wishes Register should take every opportunity to ensure that personal data is updated as necessary, for example, by confirming a customer’s details when they call.
Funeral Wishes Register will make it as easy as possible for data subjects to update the personal data that Funeral Wishes Register holds about them (for example,, via Funeral Wishes Register website).
Personal data should be updated as and when inaccuracies are discovered. For example, if a customer can no longer be reached on their stored telephone number, this number should be removed from Funeral Wishes Register database at the earliest opportunity.
It is the Marketing Director’s responsibility to ensure that marketing databases are checked against industry suppression files at least once every six months.
All individuals who have personal data held by Funeral Wishes Register are entitled to:
If an individual contacts Funeral Wishes Register requesting the information above, this is called a “subject access request”. Subject access requests from individuals should be made by email, addressed to the Data Protection Officer at hello@redapplelaw.com. The Data Protection Officer can supply a standard request form for individuals to complete, although that form does not have to be used for a subject access request to be valid. Individuals will be charged £10 per subject access request. The Data Protection Officer will aim to provide the relevant personal data requested within 14 days of receipt of a subject access request. The Data Protection Officer will always verify the identity of anyone making a subject access request before providing them with any information.
In certain circumstances, the Act allows personal data to be disclosed to law enforcement agencies without the consent of the data subject. Under these circumstances, Funeral Wishes Register will disclose requested personal data. However, the Data Protection Officer will endeavour to ensure that each request is legitimate and genuine, seeking assistance from the Board of Directors and from external legal advisers where necessary.
Funeral Wishes Register aims to ensure that individuals are aware that their personal data is being processed, and that they understand:
As such, Funeral Wishes Register has a privacy statement (below) setting out how data relating to individuals is used by Funeral Wishes Register.
This privacy policy governs the collection, storage and use of personal information collected by Funeral Wishes Register Limited. This privacy policy provides you with details about the personal information we collect from you, how we use your personal information and your rights to control personal information we hold about you. Please read this privacy policy carefully. By accessing or browsing this website (“Website”) and/or our services, you confirm and agree that you have read, understood and agree to the terms of this privacy policy in its entirety. If you do not agree to this privacy policy in its entirety, you must not use this Website and / or our services. This privacy policy was last updated on 10th March 2015. Please check back regularly to keep informed of updates to this privacy policy. We respect your right to privacy and will only process personal information you provide to us in accordance with the Data Protection Act 1998, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and other applicable privacy laws.
If you have any questions about how we collect, store and use personal information, or if you have any other privacy-related questions, please contact us by any of the following means:
When you access and browse this Website and/or use our services (including when you submit personal information to us through data entry fields on the Website), we may collect the following information from you:
We (or third party data processors acting on our behalf) may collect, store and use your personal information listed above for the following purposes:
Other than disclosures we make to third parties that we engage to act on our behalf, we will not disclose, sell or rent your personal information to any third party for commercial or other purposes. However, if a third party acquires all (or substantially all) of our business and/or assets, we may disclose your personal information to that third party in connection with the acquisition. We may also disclose your personal information where we are required to do so by applicable law, by a governmental body or by a law enforcement agency. In addition, we may also carry out credit and fraud prevention checks with licensed credit reference and fraud prevention agencies and they will retain a copy of the search. Information from your application and payment details of your account may be recorded by these agencies and may be shared with other organisations to help make credit and insurance decisions about you and members of your household and for debt collection and fraud prevention purposes. Finally, we may also collect anonymised details about visitors to our Website and / or our service for the purposes of aggregate statistics, reporting purposes and monitoring the Website and/or our service usage. However, no single individual will be identifiable from the anonymised details we collect for these purposes.
Whilst we take appropriate technical and organisational measures to safeguard the personal information that you provide to us, no transmission over the Internet can ever be guaranteed to be secure. Consequently, please note that we cannot guarantee the security of any personal information that you transfer to us over the Internet.
You have the following rights:
If you wish to exercise any of the above rights, please contact us (either by post or by e-mail) at the address specified above.
This Website contains links to other websites operated by third parties. Please note that this privacy policy applies only to the personal information that we collect through our Website and we cannot be responsible for personal information that third parties may collect, store and use through their websites. You should always read the privacy policy of each website you visit carefully. Electronic Communications Policy
These regulations apply to the use of all local IT facilities at the Registered Office and to facilities provided by Funeral Wishes Register to its employees for use at home or off site (“the Network”). Please note that breaches of this electronic communications policy (“EC Policy”) will be considered to be gross misconduct in respect of which you may be dismissed. The Network provided or made available by Funeral Wishes Register for use by its employees may be used only in connection with employees’ work for Funeral Wishes Register. The Network must not be used for work of undeclared financial benefit to employees or the transmission of unsolicited commercial material without the express permission, in writing, of the Managing Director of Funeral Wishes Register.
Employees must not interfere with the work of others or the system itself. The Network must be used in a responsible manner at all times. In particular, employees must not:
You must not gain unauthorised access to or violate the privacy of other peoples’ files, corrupt or destroy other peoples’ data or disrupt the work of other people. It is your responsibility to prevent inappropriate access to your files. Your password must be kept safe, changed regularly and not be disclosed to anyone. You must not send electronic mail from the Network which is irresponsible, or likely to cause offence nor use network messaging without authority. “Irresponsible” use includes unsolicited postings to large numbers of people or indiscriminate postings. Email to clients and customers must follow Funeral Wishes Register designated house style, which will be supplied to authorised users. Failure to follow house style is a disciplinary matter and will be dealt with under Funeral Wishes Register disciplinary procedure (“Disciplinary Procedure”). It is easy for viruses to enter the Network. Therefore, you should never open attachments from an unknown source.
Never use the Internet to transmit confidential personal or business sensitive information. A small amount of personal email use on the Network during working hours is acceptable, but not where the perusal and sending of such emails impnges upon your work either in terms of denial of service or in loss of working time to Funeral Wishes Register. The use of instant messaging is expressly prohibited at work. Employees are also prohibited from using emails to circulate any non- business material. Not only does excessive time spent online lead to loss of productivity and constitute unauthorised use of Funeral Wishes Register time, but also sexist, racist or other offensive remarks, statements, materials and/or jokes sent by email are capable of amounting to unlawful harassment. Employees who are discovered contravening these rules may face serious disciplinary action under the Disciplinary Procedure. Funeral Wishes Register does not normally examine the contents of email or files belonging to computer users, but it reserves the right to do so if necessary, in Funeral Wishes Register opinion, in order to maintain the functionality of IT system or where Funeral Wishes Register has reason to believe that the provisions of this EC Policy are being breached. Users are therefore advised that such monitoring can and may occur. Please note, email messages, even when they have been deleted from the Company’s email system can be traced, retrieved and the person or persons involved in creating or forwarding any offending email identified. Emails are admissible as evidence in a court of law. Funeral Wishes Register recognises that it is not always possible to control incoming mail. Any material which would be considered as non-businesslike, sexually explicit, indecent, inappropriate or offensive should be deleted at once. Any member of staff who finds that they are receiving such communication from known sources is responsible for contacting that source in order to request that such communication is not repeated. Funeral Wishes Register will hold individual employees personally liable if Funeral Wishes Register or any of their customer or clients suffer any loss, cost, expenses or damage to its reputation or goodwill as a result of any breach of this EC Policy. You must comply with the requirements of all relevant legislation when using the Network. Funeral Wishes Register are guardians of considerable amounts of sensitive data and it is vital for our business integrity that care is taken to safeguard both the information and the database systems themselves.
No email may be sent using the contain any references to other individuals which might be construed as libelous. No email communication which might be regarded as harassing or insulting may be sent using the Network. Complaints about the performance or service of other departments or individuals within Funeral Wishes Register must be made on a face to face basis as is normal courteous practice. Funeral Wishes Register recognises that it is not always possible to control incoming mail. Any material which would reasonably be considered not to be businesslike, sexually explicit, indecent, inappropriate or offensive should be deleted immediately without opening any attachments. Any employee of Funeral Wishes Register who finds that they are receiving such communication from known sources is responsible for contacting that source in order to request that such communication is not repeated. If employees of Funeral Wishes Register receive virus warnings via emai, they should take no action whatsoever other than informing Funeral Wishes Register IT staff immediately. Emails sent internally may be sent in an informal style, but staff are asked to observe the normal courtesy that they would extend in written memos in accordance with Funeral Wishes Register house style. Emails which are sent to recipients outside Funeral Wishes Register should be composed in a businesslike manner. A guideline for suitable styles is available on Funeral Wishes Register Intranet and this should be followed at all times. Any attachments (such as letters) must be headed and written accordingly to the normal house style. Unsolicited emails may not be sent from the Network at any time. Any ‘junk’ email received must be deleted immediately. Any attachments received within an email must be checked for viruses before opening. Funeral Wishes Register email address book will be maintained by it’s IT staff to whom changes should be notified immediately. Email addresses and passwords for all employees will be issued by IT staff and may not be changed without their authorisation. It is a disciplinary offence to access another individual’s email facility by using their password without express permission.
Funeral Wishes Register licences the use of computer software from a variety of outside companies. Funeral Wishes Register does not own this software and, unless authorised by the software developer, neither Funeral Wishes Register nor any of its employees have the right to reproduce it. To do so constitutes an infringement of copyright. Contravention of these provisions is a disciplinary matter and will be dealt with in accordance with the Disciplinary Procedure.
Funeral Wishes Register Network makes it vulnerable to viruses. Therefore, only duly authorised personnel have the authority to load new software onto the Network. Software may be loaded onto the Network only after having been checked for viruses by authorised personnel. Any employee found to be contravening this provision will face disciplinary action under the Disciplinary Procedure. Employees may only access any computer games that are on the Network outside their normal working hours. Funeral Wishes Register may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This policy is effective from 1st January 2016.