{"version":"1.0","provider_name":"RethinkTrends","provider_url":"https:\/\/rethinktrends.com\/rethink-new","title":"GDPR Data Protection Policy - RethinkTrends","type":"rich","width":600,"height":338,"html":"<blockquote class=\"wp-embedded-content\" data-secret=\"xYpmk7btSZ\"><a href=\"https:\/\/rethinktrends.com\/rethink-new\/gdpr-data-protection-policy\/\">GDPR Data Protection Policy<\/a><\/blockquote><iframe sandbox=\"allow-scripts\" security=\"restricted\" src=\"https:\/\/rethinktrends.com\/rethink-new\/gdpr-data-protection-policy\/embed\/#?secret=xYpmk7btSZ\" width=\"600\" height=\"338\" title=\"&#8220;GDPR Data Protection Policy&#8221; &#8212; RethinkTrends\" data-secret=\"xYpmk7btSZ\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" class=\"wp-embedded-content\"><\/iframe><script>\n\/*! This file is auto-generated *\/\n!function(d,l){\"use strict\";l.querySelector&&d.addEventListener&&\"undefined\"!=typeof URL&&(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&&!\/[^a-zA-Z0-9]\/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll('iframe[data-secret=\"'+t.secret+'\"]'),o=l.querySelectorAll('blockquote[data-secret=\"'+t.secret+'\"]'),c=new RegExp(\"^https?:$\",\"i\"),i=0;i<o.length;i++)o[i].style.display=\"none\";for(i=0;i<a.length;i++)s=a[i],e.source===s.contentWindow&&(s.removeAttribute(\"style\"),\"height\"===t.message?(1e3<(r=parseInt(t.value,10))?r=1e3:~~r<200&&(r=200),s.height=r):\"link\"===t.message&&(r=new URL(s.getAttribute(\"src\")),n=new URL(t.value),c.test(n.protocol))&&n.host===r.host&&l.activeElement===s&&(d.top.location.href=t.value))}},d.addEventListener(\"message\",d.wp.receiveEmbedMessage,!1),l.addEventListener(\"DOMContentLoaded\",function(){for(var e,t,s=l.querySelectorAll(\"iframe.wp-embedded-content\"),r=0;r<s.length;r++)(t=(e=s[r]).getAttribute(\"data-secret\"))||(t=Math.random().toString(36).substring(2,12),e.src+=\"#?secret=\"+t,e.setAttribute(\"data-secret\",t)),e.contentWindow.postMessage({message:\"ready\",secret:t},\"*\")},!1)))}(window,document);\n\/\/# sourceURL=https:\/\/rethinktrends.com\/rethink-new\/wp-includes\/js\/wp-embed.min.js\n<\/script>\n","description":"GDPR: Data Protection Policy Introduction The purpose of this policy is to outline how Rethink Trends Business Solutions has established measures to maintain compliance with the EU General Data Protection Regulation (also known as the GDPR). For business purposes, provision of our services, marketing, and business administration, we at Rethink Trends collect and process individual information. This includes personal data that relates to our customers, suppliers, business contracts, employees and other people our organization has a relationship with or may need to contact. In order to ensure that personal data remains safe, business operations are secure and the rights of individuals are respected, compliance with data protection law is essential. Rethink Trends is a controller under data protection law, meaning we decide how and why we will use personal data. In relation to personal data, this policy explains our procedures for complying with data protection law and sets out the obligations we have when processing any personal data during the course of our employment. Specific training regarding data protection procedures will be given to the staff that routinely handles individuals\u2019 personal data. As set out in this policy, our obligations will be supplemented by this training. Apart from this policy, there will be other policies that will be implemented that will impact the way we deal with personal data and data protection. We expect all of our employees to comply with our Electronic Communications Policy, where relevant. Who does this policy apply to? This policy applies to current, former and prospective employees, workers, volunteers, apprentices, and consultants. Those who fall into one of these categories are known as \u2018data subject\u2019 for the purposes of this policy. This policy should be read alongside the employment contract or service contract and any other notice the Company issues from time to time in relation to data. Who is responsible for data protection at Rethink Trends? Rethink Trends has appointed a Data Protection Officer (DPO) who is responsible for overseeing, advising and administering Rethink Trends\u2019 compliance with this policy and data protection law. It is the responsibility of each department head to ensure full compliance of this policy and data protection law by all staff members in their department\/team. All Rethink Trends employees have a certain modicum of responsibility for the security of personal data and to ensure the data is processed in a lawful manner. Why is data protection compliance important? In the UK, data protection law is regulated and enforced by the Information Commissioner\u2019s Office (ICO). There will be serious legal liabilities for Rethink Trends, and in some cases individual employees, if there is any failure in complying with the data protection law. These can include criminal offenses and fines of up to EUR20 million (approximately \u00a318 million) or 4% of total worldwide annual turnover, whichever is higher. Under data protection law, if rights are breached, an individual can seek damages from us in the courts. There will also be severe damage to our brand and reputation in the event of a breach in the data protection law. What is personal data? Personal data can be defined as any information that relates to an identified or identifiable person (data subject). This information contains identifiers like a name, an identification number, location data, an online identifier or other factors that are specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person. The personal data we gather may include an individuals\u2019 phone number, email address, educational background, financial and payment details, details of certificates and diplomas, education and skills, marital status, nationality, job title, and CV. Relevant individuals can include colleagues, consumers, members of the public, business contacts, etc. Personal data can be factual (e.g. contact details or date of birth), an opinion about a person\u2019s behaviour, or information that may otherwise impact that individual \u2013 personal or business related. Personal data may be stored through an automated process e.g. electronic records such as computer files or in emails or in manual records which are part of a filing system or are intended to form part of a filing system e.g. structured paper files and archives. What does \u2018processing\u2019 personal data mean? \u2018Processing\u2019 personal data is defined as any activity that involves the use of personal data \u2013 obtaining, recording or holding the data, amending, retrieving, using, disclosing, sharing, erasing or destroying. Processing also includes sending or transferring personal data to third parties. Data Protection Obligations Rethink Trends is responsible for and must be able to demonstrate compliance with data protection law. To ensure that responsibilities are met when processing personal data, it is essential that Rethink Trends employees comply with the data protection law and any other Rethink Trends policies, guidelines or instructions that relate to personal data. We have set out below the key obligations under data protection law and details of how Rethink Trends expects employees to comply with these requirements. Personal data should be processed in a fair, lawful and transparent manner Legal grounds for processing According to the data protection law personal data can be processed only when there are fair and legal grounds that justify using the information. Where consent is relied upon, it must be freely given, specific, informed and unambiguous, and Rethink Trends must effectively demonstrate that consent has been given. In most standard business activities that involve the use of customer or supplier data, consent is not required, but it may be needed for activities not required when managing the main business relationship, such as direct marketing activities. Transparency According to the data protection law, we are required to process personal data in a transparent manner by providing individuals with appropriate, clear and concise information about how we process their personal data. We usually provide basic information to individuals about how we use their data via data collection forms such as application forms or website forms, and in longer privacy notices we set out details that include: the types of personal data that we hold about them, how we"}