Updated 7 October 2019.

In this Data Protection and Privacy Policy (“Privacy Policy”), Caryn Mandabach Productions Limited (company number: 05379177), with registered office at 39A Berwick Street, London W1F 8RU, UK, tel: + 44 207 929 8030, email: [email protected]  (the “Company”, “we”, “our” or “us) informs you about how we collect, store, use and disclose your personal information. 


Who does this Privacy Policy apply to?

This Privacy Policy applies to all Individuals.

“Individuals” for the purposes of this Privacy Policy includes anyone who uses the Company’s website (“Website”).

When we refer to Individuals in this Notice, we will say “you” or “your”. 

What is the purpose of this Privacy Policy?

The Company is committed to protecting the privacy and security of your personal information.

This Privacy Policy describes how we collect and use personal information about you in accordance with the General Data Protection Regulation (GDPR).

It applies to all our Individuals as defined above.

The Company is a “data controller”. This means that we are responsible for deciding how we hold and use personal information about you. We are required under data protection legislation to notify you of the information contained in this Privacy Policy.

This Privacy Policy does not form part of any contract for services or engagement.

We may update this Privacy Policy at any time.

It is important that you read this Privacy Policy, when we are collecting or processing personal information about you, so that you are aware of how and why we are using such information.

Data protection principles

We will comply with data protection law. This says that the personal information we hold about you must be:

The kind of information we hold about you

“Personal data”, or “personal information”, means any information about an Individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

There are “special categories” of more sensitive personal data which require a higher level of protection.

We will generally collect, store, and use the following categories of personal information about you:

Use of your personal information

The Company may use your personal information (subject in each case to the requirements of the GDPR) for the following purposes:
a. administering your website account(s) and otherwise in connection with any service for which you have provided your information, including any email alerts, transactions with us and competitions and promotions that you take part in;
b. responding to any enquiry you make;
c. subject to your consent, sending you newsletters and/or alerts and information regarding the Company’s or any third party’s future services; and
d. for generating aggregated statistics about users, traffic patterns etc of the Website and other services and developing the Company’s marketing plans.

The Company may also disclose your information (subject in each case to the requirements of the GDPR) as follows:
a. if you have given your consent for the Company to do so, to other selected organisations to enable them to contact you or send you information by post, telephone and/or email;
b. to any service providers, sub-contractors and agents appointed by the Company to perform the above functions on its behalf and in accordance with its instructions;
c. to third parties selected by the Company as part of aggregated and anonymised statistics about users, traffic patterns etc of the Website;
d. to such individuals and/or bodies as necessary to ensure the Company’s compliance with any applicable law, regulation, legal proceeding or governmental request;
e. (where you post material that does or may constitute a criminal offence, breach the rights of a third party, give rise to a civil action or breach the terms of the Website and as otherwise necessary to protect the rights, property or safety of the Company and its customers), to any relevant authority or third party requiring the Company to disclose the identity of or locate anyone posting such material on the Website; and f.  to any individual making a subject information request to the Company

In the event that the Company (or a relevant part of the Company) is acquired by or merges with another company, your personal information may be passed to the purchasing/merging company amongst the transferred business assets. This will enable your relationship to continue with the relevant Company business despite the change of ownership. Your personal information may also be passed (on a confidential basis) to companies with whom the Company is negotiating such a sale/merger as part of the verification exercise carried out on the Company by the third party.

In processing your information in accordance with the above, the Company may (to the extent permitted by the GDPR) send it outside the European Economic Area (“EEA”). The Company will take all reasonable steps to ensure that in such circumstances your data is treated securely and in accordance with this Privacy Policy but your attention is drawn to the fact that the laws of countries outside the EEA may provide lesser protection to your information than the UK.

When you submit your personal information to the Company you consent to the transfer of your information outside the EEA unless you specifically indicate otherwise.


To access certain parts of the Website, the Company may require you to register and provide certain information about yourself.

You are reminded that in addition to the provisions of this Privacy Notice, where you register you also agree to:
a. provide true, accurate, current and complete information about yourself as prompted by the relevant registration form (such information being the “Registration Data”); and
b. maintain and promptly update the Registration Data to keep it fully up to date.

Change of purpose

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

Automated decision-making

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.

How secure is my information with third-party service providers?

All our third-party service providers are required to take appropriate security measures to protect your personal information in line with the GDPR. We do not allow our third-party service providers to use your personal data for their own purposes. We only permit them to process your personal data for specified purposes and in accordance with our instructions.

Data security and retention

The Company will keep your information on a secure server. The technology that the Company uses and the security policies which the Company has implemented are intended to safeguard your information from  unauthorised access and improper use.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.

The Company will keep your information (to the extent permitted by the GDPR) to enable the Company to use it for the purposes described in this Privacy Policy. 

How long will you use my information for?

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements and other criteria as is relevant.

We also take into account the limitation periods applicable for making any claims against us which features in our decision- making on retention.

In some circumstances we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.

Once we no longer need your information we will securely destroy your personal information in accordance with our policies.

Your individual rights

Under certain circumstances, by law you have the right to:

If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact Susan Waddell, Commercial Director at [email protected] or using the Company contact details above.

No fee usually required

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

Right to withdraw consent

In the limited circumstances where we have relied on your consent for the collection, processing and transfer of your personal information for a specific purpose (which will be rare), you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact Susan Waddell, Commercial Director at the email or company address indicated above. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

Person responsible for data protection in our Company

Susan Waddell, Commercial Director oversees compliance with this Privacy Policy. If you have any questions about this privacy policy or how we handle your personal information, please contact Susan Waddell using the Company contact information above. You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.

Changes to this privacy policy 

We reserve the right to update this privacy policy at any time. We may also notify you in other ways from time to time about the processing of your personal information.

© Caryn Mandabach Productions Limited 2019