Privacy Policy
This privacy policy has been created by FRAY Studio. We take your privacy very seriously therefore we urge to read this policy very carefully because it contains important information about:
- who we are,
- how and why we collect, store, use and share personal information,
- your rights in relation to your personal information, and
- how to contact us and supervisory authorities in the event that you have a complaint.
Who we are
FRAY Studio ('we' or 'us') collect, use and are responsible for certain personal information about you. When we do so we are regulated under the General Data protection Regulations which apply across the European Union (including the United Kingdom) and we are responsible as 'controller' of that personal information for the purposes of those laws.
The personal information we collect and use may include:
1) Personal information you provide to us
We collect the following personal information that you provide to us: 
- Name
- Date of Birth
- Address
- Telephone Number
- Email Address
- National Insurance Number
- Company Number (if Applicable)
- VAT Number (if Applicable)
- Emergency Contact
- Nationality
- The gender you most identify with
- Preferred Pronoun
- Ethnic Identity
- Sexual Orientation
- Disability Status
- Career Status
2) Sensitive personal information
Sensitive personal information includes any information which relates to the following:
- your ethnic origin
- your political opinions
- your religious beliefs
- whether you belong to a trade union
- your physical or mental health or condition whether you have committed a criminal offence
Some examples of the types of personal sensitive personal information we process include:
- Your ethnic identity
- Your sexuality
- Your Nationality
- Your Disability Status
- The gender to which you most identify
3) Personal information you provide about third parties
If you give us information about another person, you confirm that the other person has appointed you to act on their behalf and agreed that you:
- shall consent on their behalf to the processing of their personal data;
- shall receive any data protection notices on their behalf;
- shall consent on their behalf to the transfer of their personal data abroad; and shall consent on their behalf to the processing of their sensitive personal data.
How we use your personal information
We may process personal data and sensitive personal data concerning you in our manual and computerised/automated filing systems internally and, so far as is reasonably necessary, externally, for the purposes of complying with statutory requirements, meeting the our legitimate interests, properly conducting the our business, complying with the terms of your employment and for all purposes in connection with your employment with us.
Who your information may be shared with
We may share your information with:
- Professional advisors;
- Any third party providing services to us for the benefit of its employees;
- HM Revenue and Customs or other authorities;
- Prospective purchasers of all or any part of our business in return for suitable confidentiality undertakings regardless of the country to which the data is to be transferred;
- Law enforcement agencies in connection with any investigation to help prevent unlawful activity;
 Government bodies for the purposes of accounting, tax and regulatory compliance; We will not share you personal information with any other 3rd parties.
How long your personal information will be kept
We will hold your personal information for the following periods:
- Your Name and Address for 6 years to satisfy UK TAX Law
- All other information will be permanently deleted at the end of employment contract, freelance work period, paid internship or termination of employment.
- These periods are no longer than necessary in each case.
Reasons we can collect and use your personal information
We rely on the following as the lawful basis on which we collect and use your personal information:
- consent
- legal obligation
The basis on which we process your sensitive information (i.e. special category as in the GDPR) is that:
- Consent
Allow FRAY to monitor how we are implementing Statement & Strategy on Diversity & Inclusion
Consequence of our use of your personal information
The consequence to you of our use of your personal information is:
Data will be used internally to monitor the progress Statement & Strategy on Diversity & Inclusion and to allow us to adapt it as is necessary to ensure its success.
If requested data will be passed to HMRC in relation only to your employment with us.
Keeping your information secure
We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We will also use technological and organisation measures to keep your information secure. These measures may include the following examples:
Data in all storage locations is only accessible by user name and password by appropriate persons.
Data is held in 2 places with the following security practices: AirTable
Transit: 256-bit SSL/TLS encryption
Storage:256-bit AES encryption
Xero
ISO/IEC 27001:2013
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Your obligations to safeguard personal data of others
In the course of your duties you may have access to the personal data of other individuals during the course of your employment. You must undertake any mandatory FRAY Studio data protection training, and ensure that you do not inappropriately obtain, retain, amend, use, delete, transmit or compromise the security of the personal data of others.
Failure to comply with your data protection obligations puts at risk the individuals whose personal information is being processed, carries the risk of significant civil and criminal sanctions for you and FRAY Studio and may, in some circumstances, amount to a criminal offence for which you are personally liable. Because of the importance of data protection obligations, it may lead to disciplinary action under our procedures, up to and including dismissal for gross misconduct.
If at any time you have any queries, you should contact us immediately.
Transfers of your information out of the EEA
We will not transfer your personal information outside of the EEA at any time.
What rights do you have?
Under the General Data Protection Regulation you have a number of important rights free of charge. In summary, those include rights to:
- fair processing of information and transparency over how we use your use personal information
- access to your personal information and to certain other supplementary information that this Privacy Notice is already designed to address
- require us to correct any mistakes in your information which we hold
- require the erasure of personal information concerning you in certain situations receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- object at any time to processing of personal information concerning you for direct marketing
 object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
- object in certain other situations to our continued processing of your personal information
 otherwise restrict our processing of your personal information in certain circumstances
 claim compensation for damages caused by our breach of any data protection laws
For further informaiton on each of those rights, including the circumstances in
which they apply, see the Guidance from the UK Information Commissioner's Office (ICO) on individual's rights under the General Data Protection Regulations
If you would like to exercise any of these rights please:
- email, call or write to us
- let us have enough information to identify you
- let us know the information to which your request relates
Do you need extra help?
If you would like this policy in another format (for example: audio, large print, braille) please contact us using the details below.
How to complain
We hope that we can resolve any query or concern you raise about our use of your information.
The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns/ or telephone: 0303 123 1113.
Changes to the privacy policy
This privacy policy was published on 14/07/2020 and last updated on 14/07/2020. We may change this privacy policy from time to time and will notify all employees of any changes by:
By Email
Contacting us
Our data protection officer is Finn Ross.
If you have any questions about this policy or the information we hold about you, please contact us by:
e-mail: [email protected] or
telephone: 07717743902