Privacy, Data and Cookie Policy

1.0 Our Core Beliefs On User Privacy and Data Protection

We respect your privacy and collect only the personal information reasonably required to operate this website, fulfil orders, provide services, communicate with you and meet our legal obligations.

We do not sell or rent personal information. We share it only where necessary with service providers, payment providers, professional advisers, public authorities or other recipients described in this policy.

We process personal information lawfully, fairly and transparently, keep it secure and retain it only for as long as it is reasonably required.

2.0 Applicable Legislation

This policy is governed principally by:

  • the UK General Data Protection Regulation (“UK GDPR”);
  • the Data Protection Act 2018;
  • the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), as amended; and
  • the Data (Use and Access) Act 2025.

The EU General Data Protection Regulation may also apply where we specifically offer services to, or monitor the behaviour of, individuals in the European Economic Area.

We do not claim that compliance with UK law automatically establishes compliance with every privacy law worldwide. Where another mandatory law applies, we will respect the rights it provides.

3.0 Information We Collect and Why:

This website collects and uses personal information for the following reasons. Depending on the activity concerned, we process personal information using one or more of the following lawful bases:

  • Contract: where processing is necessary to answer a request made before entering into a contract, fulfil an order or provide a purchased service.
  • Legal obligation: where information must be retained or disclosed for tax, accounting, regulatory, fraud-prevention or other legal purposes.
  • Legitimate interests: where necessary to operate and secure the website, administer the business, respond to enquiries, maintain appropriate records, establish or defend legal claims and improve our services, provided those interests are not overridden by your rights.
  • Consent: for optional analytics, usability technologies, advertising cookies, email newsletters and any other processing for which consent is required.

We usually obtain information directly from you. We may also receive it from Digistore24, payment providers, delivery companies, commercial clients, professional advisers, website analytics services, publicly available sources or somebody acting with your authority.
Where we rely on consent, you may withdraw it at any time without affecting processing already carried out lawfully.

3.1 Site Visitor Tracking

We use Google Analytics to understand how visitors find and use this website. It may process information including your IP address, approximate location, device, browser, operating system, referring website, pages viewed, interactions and pseudonymous identifiers.

We do not use this information to identify you directly. Google may process information on our behalf and under its own privacy terms.

Google Analytics and its associated cookies will be activated only after you consent through our cookie controls. The lawful basis for placing or accessing these technologies is consent under PECR. The lawful basis for processing the resulting personal information is consent under the UK GDPR.

You may withdraw consent at any time through Cookie Settings. Withdrawal will prevent future analytics collection but will not affect information processed lawfully before withdrawal.
Analytics information accessible to us will normally be retained for no longer than 14 months, unless a shorter period is configured.

3.2 Usability Improvements

Where enabled, we use Hotjar to understand how visitors interact with this website through tools such as heatmaps, interaction data and session recordings.

Hotjar may process information including device type, browser, approximate location, IP-derived information, pages visited and interactions with page elements. Form fields and sensitive page content should be masked from recordings.

Hotjar will be activated only after you consent through our cookie controls. The lawful basis for using Hotjar technologies and processing the resulting information is consent. You may withdraw consent at any time through Cookie Settings.

3.3 Site Security and Protection

We use encryption in transit and security services, including Wordfence services provided by Defiant, Inc., to protect the website, detect malicious activity and prevent unauthorised access.

These services may process IP addresses, browser and device information, requested URLs, timestamps, login attempts and other security-event data. IP addresses are personal information and are treated accordingly.

Our lawful basis is our legitimate interest in protecting the website, our customers and our systems. Security technologies that are strictly necessary for this purpose may operate without consent under PECR.

Routine security logs will normally be retained for no longer than 90 days. Information connected with suspected fraud, abuse, litigation or a security incident may be retained for longer where reasonably necessary.

3.4 Customer Orders

When you place an order, we may collect your name, email address, telephone number, billing and delivery addresses, account details, products ordered, transaction references, delivery instructions, correspondence and information used for fraud prevention.

We process this information to administer the order, take or reconcile payment, produce invoices, deliver products, provide customer support, operate warranties and meet tax, accounting and legal obligations.

Our lawful bases are performance of the contract, compliance with legal obligations and our legitimate interests in preventing fraud, maintaining accurate business records and handling customer enquiries.

Payments may be processed by WooPayments and its payment partners, PayPal or another provider identified at checkout. These providers receive the information required to process and verify the transaction. We do not normally receive or store complete payment-card details.

Where Digistore24 is identified as the seller or reseller, Digistore24 processes payment, invoicing, tax, fraud-prevention and buyer-support information under its own privacy notice. It shares with us the customer and order information required to provide the purchased service.

We may also share relevant order details with printers, framers, couriers, delivery companies, accounting providers and other suppliers necessary to fulfil the order.

Order, invoice and payment records will normally be retained for at least six years after the end of the relevant tax or accounting period. Minimal product, ownership and delivery records may be retained for longer where required to administer an expressly stated warranty, edition record or certificate of authenticity.

If you create an account, the account information will be retained until you delete the account or ask us to close it, subject to any transaction records we must retain separately.

Deleting information required to verify ownership or eligibility under a lifetime warranty may prevent us from administering that warranty. We will explain this before acting on an erasure request.

3.5 Our Blog

If you submit a blog comment, we collect the name, email address, comment, IP address, submission date and any other information you choose to provide.

We use this information to publish and administer comments, identify contributors, prevent spam and abuse and protect the website. Our lawful basis is our legitimate interest in operating and protecting the blog.

Your chosen display name and comment will be public. If your email address is linked to Gravatar, an encoded version of that address may be sent to Automattic’s Gravatar service to determine whether a profile image is available.

Comments will normally remain published until the relevant post or comment is removed. Associated security and moderation information will be retained only while reasonably required.

You may request removal by emailing privacy@paulreiffer.com and identifying the relevant comment. Removal remains subject to any information we must retain for legal, security or dispute purposes.

This website is not directed at children under 16. Anybody under 16 should not submit a comment or other personal information without permission from a parent or guardian.

Do not include unnecessary personal, confidential or sensitive information within a public comment.

3.6 Contact forms and email links

When you contact us through a form or email, we may collect your name, email address, telephone number, message, IP address, submission details and any files or other information you provide.

Contact-form information may be processed by the website, hosting provider, security services and email systems used to deliver and retain the message. It is therefore incorrect to assume that form information exists only as an email or is never processed by another provider.

We process enquiries to respond to your request, take steps towards a possible contract, provide customer support and maintain appropriate business records. Our lawful bases are steps taken at your request before entering into a contract, performance of a contract and our legitimate interests in administering correspondence.

General enquiries will normally be retained for up to 24 months after the last meaningful contact. Correspondence connected with an order, contract, dispute or legal obligation may be retained for longer.

Email is encrypted in transit where the sending and receiving systems support appropriate encryption, but no email service is completely secure. Do not send passwords, complete payment-card details or unnecessary sensitive information by email.

3.7 Live Chat Facility

[Removed]

3.8 Email Newsletter

If you subscribe to our newsletter, we collect your email address and, where supplied, your name and subscription preferences.

We use Mailchimp to manage subscriptions and distribute newsletters. Subscription information is therefore transferred to and processed by Mailchimp.

Our lawful basis is consent. We use a double-opt-in process and retain records showing when and how consent was obtained.
You may withdraw consent at any time by using the unsubscribe link in any newsletter or emailing us from the subscribed address. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.

After unsubscribing, limited information may remain on a suppression list so that we can respect your request and avoid sending further marketing. It will not be used to continue marketing.

This newsletter is not intended for children under 16. Anybody under 16 should subscribe only with permission from a parent or guardian.

3.9 Access Products & Advisory services

When you purchase or enquire about an Access product, we may process your name, contact details, order information, appointment details, correspondence and the photographs, raw files, websites, documents, proposals, analytics, business figures or other material you choose to submit.

We use this information to assess suitability, provide the purchased review, editing, planning or advisory service, arrange sessions, prepare deliverables, provide support and maintain necessary contractual records.

Our lawful bases are steps taken at your request before entering into a contract, performance of the contract, compliance with legal obligations and our legitimate interests in administering and evidencing the service.

Where Digistore24 is the seller, it shares the order and customer information necessary for us to provide the service.

Customer material is treated confidentially and will not be published, used in marketing or used to train a generative artificial-intelligence model without separate written permission.

Uploaded and working service files may be deleted from active storage 90 days after completion. Contractual, financial and correspondence records may be retained for up to six years, or longer where reasonably required for a legal claim.

3.10 Commercial Clients, Suppliers and Professional Contacts

We may process names, business contact details, correspondence, contracts, call sheets, licences, model releases, invoices and other information relating to clients, prospective clients, suppliers, representatives and professional contacts.

We use this information to discuss and deliver commissions, administer contracts, license images, arrange production, make payments, maintain accounts and establish or defend legal rights.

Our lawful bases are steps taken before entering into a contract, performance of a contract, compliance with legal obligations and our legitimate interests in operating and developing the business.

Relevant records will normally be retained for the duration of the relationship and for up to six years afterwards. Copyright, image-licensing and release records may be retained for longer where necessary to document continuing rights.

4.0 How We Store Your Personal Information

Personal information may be stored within our website, email systems, business devices, cloud services, order systems, accounting records, file-transfer services and backup systems.

We use appropriate technical and organisational measures designed to protect it, including access controls, strong authentication, encryption in transit, security monitoring, restricted staff access, backups and software maintenance.

Access is limited to people and providers who reasonably require the information for their work.

No system can be guaranteed completely secure. If we become aware of a breach, we will assess and respond to it in accordance with section 9.

Retention periods vary according to the purpose, legal requirements, continuing contractual obligations, warranty administration and whether information is required to establish or defend legal claims. The principal retention periods are stated in the relevant sections above.

5.0 About This Website’s Server

This website and its associated databases, content-delivery systems, security services and backups are operated using professional hosting and technology providers.

We require providers to use appropriate physical, technical and organisational security measures. These may include controlled data-centre access, encryption, network monitoring, backups, vulnerability management and recognised security standards.

Data is encrypted in transit between supported browsers and this website using HTTPS.

Some providers may process information outside the United Kingdom. International transfers are addressed in section 6.

6.0 Service Providers, Other Recipients and International Transfers

We use third parties to help operate the website, communicate, process payments, fulfil orders, deliver services, protect our systems and meet legal obligations.

Depending on the service and legal context, these organisations may act as our processors, joint controllers or independent controllers.

Current categories and principal providers include:

  • website hosting, content-delivery, backup and technical-support providers;
  • Google, for analytics, advertising and related services where consent has been given;
  • Meta, for advertising measurement where consent has been given;
  • Hotjar, for optional usability analysis;
  • Defiant, Inc., providing Wordfence security services;
  • Mailchimp, providing email-marketing services;
  • Automattic services, including WooPayments and Gravatar;
  • PayPal and other payment providers identified at checkout;
  • Digistore24, where it acts as the seller or reseller of an Access product;
  • email, file-transfer, video-meeting and appointment-scheduling providers;
  • printers, framers, laboratories, couriers and delivery companies;
    accountants, insurers, legal advisers and other professional advisers; and
  • regulators, courts, law-enforcement bodies or public authorities where disclosure is required or permitted by law.

Some recipients process personal information outside the United Kingdom. Where a restricted transfer occurs, we use an applicable UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework where the recipient is appropriately certified, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another safeguard permitted by law.

Further information about a relevant transfer mechanism can be requested from privacy@paulreiffer.com.7.0 Links to other websites

Our website may contain links to other sites. Please be aware that Reiffer Media Ltd is not responsible for the privacy practices or the content of such third-party websites as well as any information they might collect, even though our name or logo may appear on those sites. We encourage you to be aware when you leave our site and to read the Privacy statements of each and every website that you visit, as the privacy policy of those sites may differ from ours.

7.0 Links to other websites

Our website may contain links to websites and services operated by other organisations. We are not responsible for their privacy practices, security or content, even where our name or logo appears on the linked page.

We encourage you to be aware when you leave our site and to read the Privacy statements of each and every website that you visit, as the privacy policy of those sites may differ from ours.

8.0 Cookies and Similar Technologies

This website uses cookies and similar technologies, including pixels, scripts, local storage and comparable device-access technologies.

Strictly necessary technologies are used for functions such as security, shopping baskets, checkout, account access and remembering privacy choices. These may operate without consent where the PECR exemption applies.

Analytics, usability and advertising technologies are optional and will not be activated unless you consent. These may include services provided by Google, Meta and Hotjar.

You can accept or reject optional categories through the cookie banner and change or withdraw your consent at any time by opening Cookie Settings. Rejecting optional technologies will not prevent you from using the core website.

You can also remove existing cookies through your browser settings. Browser controls do not replace the consent controls provided on this website.

Our cookie controls provide current information about each technology’s provider, purpose, category and duration.

9.0 Data Breaches

We record and assess personal-data breaches in accordance with applicable law.

Where a breach is likely to result in a risk to people’s rights and freedoms, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours after becoming aware of it.

Where a breach is likely to result in a high risk to an affected person, we will also inform that person without undue delay unless a lawful exception applies.

A breach does not need to involve stolen identifiable information before these obligations can apply.

10.0 Data Controller

The controller responsible for this website and the processing described in this policy is:

Paul Reiffer, trading as Paul Reiffer - Photographer

PO Box 9390
Portland
DT5 9AT
United Kingdom

Email: privacy@paulreiffer.com

Telephone: +44 (0)208 123 0257

11.0 Privacy Contact and Complaints

Privacy enquiries, requests and complaints should be directed to:

Victoria Boast
Privacy Contact
Email: privacy@paulreiffer.com
Telephone: +44 (0)208 123 0257

If you make a complaint about our use of personal information, we will acknowledge it within 30 days and respond without undue delay. We may ask for information reasonably required to understand the complaint and verify your identity.

You also have the right to complain to the Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113

We ask that you contact us first where appropriate so that we have an opportunity to resolve the issue.

 

12.0 Your Data Protection Rights

Depending on the circumstances and lawful basis, you may have the right to:

  • request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request erasure of information;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • receive certain information in a portable format;
  • withdraw consent at any time;
  • complain about our use of your information; and
  • request safeguards where a significant decision has been made solely by automated means.

We do not currently use personal information to make solely automated decisions producing legal or similarly significant effects.

Send a request to privacy@paulreiffer.com. We may ask for information reasonably necessary to verify your identity and locate the relevant records.

We will respond without undue delay and normally within one month. Complex or numerous requests may take longer where the law permits, in which case we will explain the extension.

For an access request, we are required to carry out searches that are reasonable and proportionate. Rights may be restricted where an exemption applies or where information must be retained for tax, legal, fraud-prevention, contractual or legal-claims purposes.

You should make requests to us rather than contacting our processors individually. Independent controllers, including payment providers and Digistore24, handle requests relating to information for which they are separately responsible.

Erasing information required to verify ownership or eligibility under a continuing warranty may prevent us from administering that warranty. We will explain the practical consequence before completing the request.

13.0 Changes To Our Privacy, Data and Cookie Policy

We may update this policy to reflect changes in our services, providers, technology or legal obligations.

The current version will always be published on this page. Where a change materially affects how we use information already collected, we will provide additional notice where reasonably appropriate or legally required.

This policy was last updated on 16 August 2026.

14.0 Governing Law

This policy and our handling of personal information are governed by the laws of England and Wales, subject to any mandatory data-protection rights or regulatory jurisdiction that applies regardless of that choice.