Privacy policy
1. Who we are
Voisins Department Store Limited (Jersey company registration number 108372), trading under the Fotosound brand (“Fotosound”, “we”, “us” or “our”), is the controller of the personal data described in this Privacy Policy for the purposes of the Data Protection (Jersey) Law 2018.
Our contact details are:
Fotosound
22 King Street
St Helier
Jersey
JE2 4WP
Email: fotosound@voisins.com
Telephone: 01534 759990
This Privacy Policy applies to personal data collected through:
- www.fotosound.je;
- our physical store;
- customer accounts;
- online and in-store orders;
- collection services;
- returns, refunds, repairs and warranty enquiries;
- customer-service communications;
- email marketing;
- online advertising;
- cookies, pixels and similar technologies;
- competitions, promotions and website forms; and
- CCTV and other in-store security systems.
Separate services linked from our website, including the Fujifilm photo-ordering portal and third-party finance providers, operate under their own privacy notices.
2. Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data.
Identity and contact information
This may include:
- your name;
- billing address and collection contact details;
- email address;
- telephone number; and
- customer account identifier.
Account information
This may include:
- your customer profile;
- securely managed login credentials;
- account preferences;
- marketing preferences; and
- order history.
We do not have access to your password in readable form.
Order and transaction information
This may include:
- products ordered or returned;
- order number;
- order date;
- prices, discounts and taxes;
- collection method;
- billing and collection information;
- payment status;
- transaction references;
- refunds and credits;
- correspondence about the order; and
- fraud or chargeback information.
We do not normally receive or store your complete payment-card or bank-account details. These are processed by the payment service selected at checkout.
Customer-service, repair and warranty information
This may include:
- enquiries and complaints;
- cancellation and return requests;
- repair or warranty details;
- photographs or videos you provide;
- product serial numbers;
- diagnostic information;
- evidence of purchase;
- information about product faults or damage; and
- correspondence between you and Fotosound.
If you provide a device for assessment or repair, it may contain personal information. You should back up and remove personal information from the device where reasonably possible before providing it to us. We will access information on a device only where reasonably necessary to provide the requested service, investigate a fault or meet a legal obligation.
Marketing information
This may include:
- your email-marketing subscription status;
- the date, time and method of consent;
- marketing preferences;
- records of withdrawal, objection or unsubscribe;
- emails delivered or bounced;
- links clicked;
- campaign interactions; and
- email-opening information where this feature is enabled and lawfully used.
Website and technical information
This may include:
- IP address;
- browser and device type;
- operating system;
- cookie and device identifiers;
- approximate location derived from an IP address;
- referral source;
- pages and products viewed;
- website searches;
- basket and checkout activity;
- session information;
- purchase and conversion events;
- dates and times of visits; and
- interactions with website features, forms, banners and popups.
Advertising information
This may include:
- advertising and cookie identifiers;
- advertising campaign and referral information;
- pages and products viewed;
- basket and checkout events;
- purchase events;
- order value and currency;
- conversion information;
- Meta Pixel and Conversions API events;
- Google Ads conversion events; and
- securely hashed customer information used for conversion matching.
Consent information
This may include:
- your cookie and tracking preferences;
- the categories you accepted or rejected;
- the date and time of your choice;
- the page on which the choice was made;
- a consent or browser identifier;
- IP address and technical information; and
- records showing when a preference was later changed or withdrawn.
CCTV information
This may include:
- video images of customers, employees, contractors and visitors;
- movements and activities visible within a camera’s field of view;
- the date, time and location of a recording; and
- information relating to a security incident, accident, disputed transaction or investigation.
Our routine CCTV system is intended to record video only and does not intentionally record audio unless this is specifically identified on our signage and in this Privacy Policy.
Security and fraud-prevention information
This may include:
- account activity;
- transaction-risk information;
- device and browser information;
- IP address;
- attempted or completed payments;
- chargebacks;
- login and security logs;
- suspected misuse; and
- information required to investigate theft, fraud or other unlawful conduct.
Special-category personal data
We do not intentionally collect information about health, ethnicity, religion, political opinions, sexual orientation, biometric identity or other special-category personal data through our ordinary retail activities.
Please do not provide this information unless it is genuinely necessary for us to deal with your request. Where special-category information is provided, we will process it only where a lawful condition applies.
3. How we obtain personal data
We obtain personal data:
- directly from you when you place an order, create an account, contact us, visit our store, request a return or repair, subscribe to marketing, enter information into a form or set cookie preferences;
- automatically from your browser or device through Shopify and permitted cookies, pixels, web events and similar technologies;
- from Shopify and applications connected to our Shopify store;
- from payment providers, including PayPal where selected;
- from collection, repair, warranty and fraud-prevention providers;
- from Google and Meta in connection with advertising and campaign measurement;
- from AVADA in connection with cookie and consent management;
- from Pop Convert when you interact with a popup, banner, form or website notification;
- from social-media platforms when you interact with our pages, advertisements or messages;
- from CCTV systems when you visit our premises; and
- from law-enforcement authorities, insurers, professional advisers or other lawful sources where necessary to protect people, property or legal rights.
4. Why we use personal data and our lawful bases
We process personal data only where we have a lawful basis under the Data Protection (Jersey) Law 2018.
Processing orders and providing services
We use identity, contact, account, order, payment-status and communications information to:
- create and administer your customer account;
- process and fulfil an order;
- take or confirm payment;
- arrange collection;
- send order and service communications;
- handle cancellations;
- administer returns and refunds;
- assess products;
- arrange repairs or replacements;
- manage warranties; and
- provide after-sales support.
Our lawful basis is that the processing is necessary to take steps at your request before entering into a contract or to perform our contract with you.
Legal and regulatory requirements
We process relevant information to:
- maintain accounting, GST and taxation records;
- comply with consumer-protection obligations;
- manage product-safety issues and recalls;
- respond to courts, regulators and lawful authorities;
- comply with data-protection duties; and
- meet other legal and regulatory requirements.
Our lawful basis is compliance with a legal obligation.
Customer service and business administration
We use identity, contact, order and communications information to:
- answer general enquiries;
- investigate complaints;
- maintain accurate records;
- improve customer service;
- administer our business; and
- understand and resolve recurring service issues.
Where the matter relates to an existing or proposed order, our lawful basis is contract.
For general enquiries and business administration, we rely on our legitimate interests in providing effective customer service and operating an efficient retail business.
Security, fraud prevention and legal claims
We use account, transaction, device, technical, CCTV and security information to:
- protect customer accounts;
- secure our website and systems;
- prevent and investigate theft and fraud;
- prevent unauthorised transactions;
- manage chargebacks;
- investigate misuse;
- respond to security incidents;
- protect people, stock and property;
- obtain legal advice; and
- establish, exercise or defend legal claims.
We rely on our legitimate interests in protecting our customers, employees, systems, stock, premises and business. Processing may also be necessary to comply with a legal obligation.
Website analytics
With your consent, we use Google Analytics, Shopify analytics and similar non-essential technologies to understand:
- how visitors find and use our website;
- which pages and products are viewed;
- how visitors move through basket and checkout;
- whether website functions operate properly;
- whether advertising results in visits or purchases; and
- how we can improve website performance and customer experience.
Non-essential analytics technologies will be activated only where the required consent has been provided.
Email marketing
We use Shopify Email to send news, offers, product information and promotional communications to people who have consented to receive them.
We may use:
- your name and email address;
- subscription and consent status;
- purchasing interests;
- customer segments;
- email delivery and bounce information;
- links clicked;
- unsubscribe information; and
- email-opening information where this feature is enabled and lawfully used.
Our lawful basis for promotional email marketing is consent.
Email-marketing consent is optional and is not required to place an order.
You may withdraw consent at any time by:
- selecting the unsubscribe link in a marketing email;
- changing your account preferences where available; or
- contacting us.
Withdrawing marketing consent will not prevent us from sending necessary service messages about an order, account, return, repair, security issue or legal notice.
Google Analytics, Google Ads and enhanced conversions
With your consent, we use Google services that may include:
- Google Analytics 4;
- Google Ads;
- Google Merchant Center;
- Google conversion tracking;
- Google Consent Mode; and
- Google Ads enhanced conversions.
Google Analytics may receive:
- cookie and device identifiers;
- session and website-event information;
- pages and products viewed;
- basket, checkout and purchase events;
- approximate location;
- browser and device information;
- referral and campaign information; and
- consent signals.
Google Ads receives advertising interactions and conversion events to measure whether advertising resulted in website visits or purchases.
We use Google enhanced conversions. When a purchase or other configured conversion occurs, first-party customer information provided during the transaction may be normalised and securely hashed before being sent to Google.
Depending on the information provided and our configuration, this may include:
- email address;
- telephone number;
- first and last name; and
- postal address information.
Google compares the hashed information with hashed information associated with signed-in Google accounts. This helps measure conversions resulting from Google advertising and improves conversion reporting.
Google does not receive this information from us in ordinary readable form through enhanced conversions. Hashing is a security measure, but hashed information remains personal data where it can be used for matching.
Our lawful basis for Google Analytics, Google Ads tracking and enhanced conversions is consent.
If you reject marketing or analytics technologies, we will not intentionally activate the relevant non-essential Google tracking or enhanced-conversion processing for your visit.
Google Merchant Center also receives information about our products and stock. Product-feed information will not usually identify an individual, although click and conversion information may be processed through the connected Google advertising services.
Meta Pixel and Conversions API
With your consent, we use Meta Pixel and Meta Conversions API in connection with advertising on Facebook and Instagram.
Meta Pixel operates through the website. Meta Conversions API provides a server-to-server connection between Shopify or Fotosound systems and Meta.
These tools may provide Meta with information including:
- IP address;
- browser and device information;
- Meta cookie identifiers;
- pages and products viewed;
- website searches;
- basket and checkout activity;
- purchase events;
- order value and currency;
- advertising campaign information;
- transaction or event identifiers; and
- securely hashed customer information used to improve event matching.
Depending on our configuration and the information you provide, hashed matching information may include:
- email address;
- telephone number;
- first and last name;
- town, postcode and country; and
- other permitted contact information associated with an order.
Meta uses this information to:
- measure advertising performance;
- attribute purchases or other actions to advertisements;
- improve the matching of website events;
- optimise advertising campaigns;
- create advertising reports; and
- deliver or personalise advertisements according to Meta’s terms and the individual’s Meta settings.
We use Meta Pixel and Conversions API together to improve the reliability of conversion measurement.
Our lawful basis for the use of Meta Pixel, Conversions API and non-essential personalised advertising is consent.
We configure these tools so that non-essential advertising events and customer-matching information are sent only where the required consent has been given.
You may withdraw your consent through our cookie-preference control. Withdrawal will stop future non-essential processing but will not affect processing that took place before withdrawal.
We may also run broad advertising campaigns using general criteria selected within Meta, such as location, age range or interests, without supplying Meta with a customer contact list.
Cookie and consent management
We use AVADA to provide our cookie banner and record customer consent choices.
AVADA may process:
- consent categories accepted or rejected;
- date and time;
- page location;
- IP address;
- browser or consent identifier;
- device and browser information; and
- changes to a previous choice.
We use this information to:
- implement your preferences;
- prevent non-essential technologies from operating without the required consent;
- provide a way to change or withdraw consent; and
- demonstrate that consent choices have been recorded.
Our lawful bases are compliance with our legal and data-protection obligations and our legitimate interests in maintaining an accurate record of customer preferences.
Pop Convert
We use Pop Convert to provide website popups, banners, forms and similar website features.
Depending on the feature used, Pop Convert may process:
- IP address;
- browser, device and operating-system information;
- time zone;
- cookie or visitor identifier;
- pages viewed;
- referral and exit pages;
- clicks and website interactions; and
- information entered into a popup or form.
Information entered into a form may include:
- name;
- email address;
- telephone number; and
- marketing preference.
Where Pop Convert is used to collect an email address for marketing, the address will be added to our Shopify email-marketing list only where valid consent has been provided.
Completing a general enquiry or customer-service form does not automatically subscribe you to marketing.
Our lawful basis is:
- consent for email marketing and non-essential tracking;
- contract where the form relates to an order or requested service; or
- legitimate interests where we use a form to answer a general enquiry or provide a website function requested by the visitor.
CCTV and in-store surveillance
We operate CCTV at our Fotosound premises for the purposes of:
- protecting customers, employees, contractors and visitors;
- protecting stock and property;
- preventing and detecting theft, fraud, criminal activity and antisocial behaviour;
- investigating accidents and security incidents;
- investigating complaints and disputed transactions;
- supporting the safe operation of our premises; and
- establishing, exercising or defending legal and insurance claims.
CCTV may cover:
- entrances and exits;
- sales floors;
- till and transaction areas;
- stockrooms and storage areas; and
- other appropriate areas within or immediately around our premises.
Cameras are not positioned in toilets, changing areas or other locations where individuals would reasonably expect a high level of privacy.
Our lawful basis is our legitimate interests in protecting people, stock and property and preventing or investigating crime, fraud and other incidents.
We have considered these interests against the rights and freedoms of individuals and limit camera locations, recording areas, access and retention accordingly.
CCTV signs are displayed at appropriate entrances and monitored areas.
CCTV footage may be viewed or disclosed only where reasonably necessary. Recipients may include:
- authorised Fotosound or Voisins personnel;
- CCTV installation, maintenance or security providers acting on our instructions;
- the States of Jersey Police or another law-enforcement authority;
- insurers and loss adjusters;
- lawyers and professional advisers;
- courts, tribunals and regulators; and
- an individual exercising a lawful data-protection right, subject to the rights of other people shown in the footage.
Business transactions and legal rights
We may disclose relevant information to professional advisers, potential purchasers or investors where this is reasonably necessary in connection with a genuine sale, merger, restructuring or transfer of the business.
We rely on our legitimate interests in managing the business and protecting our legal and commercial position. Appropriate confidentiality and data-protection safeguards will be applied.
5. When providing information is required
We need certain identity, contact, collection and transaction information to accept and fulfil an order.
If required information is not provided, we may be unable to:
- process an order;
- take or confirm payment;
- arrange collection;
- provide a customer account;
- process a cancellation or refund;
- investigate a repair or warranty request; or
- respond properly to an enquiry.
Email-marketing consent, personalised-advertising consent and consent to non-essential cookies are optional.
6. Shopify and Shopify Email
Our online store, customer records, checkout, customer accounts and email-marketing platform are provided through Shopify.
Depending on the Shopify services used, Shopify may process:
- customer names and contact information;
- billing addresses and collection contact details;
- account information;
- order and transaction information;
- payment status;
- products viewed, placed in a basket or purchased;
- returns and refunds;
- customer preference and consent signals;
- IP address;
- device, browser and network information;
- website activity; and
- email subscription and campaign-interaction information.
For most services provided to operate our store, Shopify processes customer information on our instructions.
Shopify may act as a separate controller when an individual chooses to use a consumer service provided directly by Shopify, such as:
- Shop;
- Shop Pay;
- a Shopify account; or
- another Shopify consumer service.
Shopify’s own privacy notice applies to those separate activities.
We use Shopify Email to manage our subscriber list and send promotional communications. Shopify records whether a customer has consented to marketing and processes information needed to deliver, suppress, unsubscribe and report on email campaigns.
7. PayPal and other payment providers
If you select PayPal, we provide PayPal with the information necessary to initiate, authorise and complete the transaction.
This may include:
- order number;
- order value and currency;
- product or transaction description;
- name and contact information;
- billing address;
- collection information; and
- transaction status.
PayPal separately collects and processes information such as:
- PayPal account details;
- card or bank information;
- identity-verification information;
- device and network information;
- payment activity; and
- security and fraud-prevention information.
PayPal normally provides us with:
- a transaction reference;
- payment status;
- payer information;
- collection information where relevant; and
- refund or dispute information.
We do not normally receive your complete PayPal payment-card or bank-account details.
PayPal generally acts as a separate controller for its regulated payment, fraud-prevention, compliance and account activities. PayPal’s own privacy notice applies to those activities.
Other payment methods offered at checkout may operate in a similar way and provide their own privacy information.
8. Other organisations that may receive personal data
Where necessary for the purposes described in this policy, we may provide personal data to:
- Shopify and Shopify subprocessors;
- PayPal and other payment providers;
- Google;
- Meta;
- AVADA;
- Pop Convert;
- collection and fulfilment providers;
- repair centres, suppliers and manufacturers;
- fraud-prevention and cybersecurity providers;
- IT, hosting and technical-support providers;
- accountants, auditors, lawyers, insurers and other professional advisers;
- a purchaser, investor or adviser involved in a genuine business transaction;
- the States of Jersey Police and other law-enforcement organisations;
- courts, tribunals and regulators; and
- other authorities where disclosure is required or permitted by law.
These organisations may act:
- as processors working on our instructions;
- as separate controllers responsible for their own processing; or
- in limited circumstances, as joint controllers with us.
Where an organisation acts as a separate controller, its own privacy notice applies.
We do not sell customer personal data.
9. International transfers
Shopify, Google, Meta, AVADA, Pop Convert, PayPal and their affiliates and subprocessors operate internationally.
Personal data may therefore be stored, accessed or otherwise processed outside Jersey, including, depending on the provider and service, within:
- the European Economic Area;
- the United Kingdom;
- Canada;
- the United States; and
- other countries in which the provider or its approved subprocessors operate.
Where Jersey law requires additional protection for an international transfer, we use an appropriate transfer mechanism.
This may include:
- a finding that the destination provides an adequate level of protection;
- approved or recognised contractual safeguards;
- binding corporate rules; or
- another lawful transfer mechanism.
We do not treat acceptance of this Privacy Policy as consent to an otherwise unlawful international transfer.
You may contact us for further information about the safeguards relevant to your personal data.
10. How long we retain personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected.
We consider:
- legal and regulatory requirements;
- tax and accounting obligations;
- consumer and warranty rights;
- product-safety obligations;
- fraud and security risks;
- the length of our relationship with the customer;
- whether an account remains active;
- whether consent remains valid;
- limitation periods for legal claims; and
- whether a dispute, investigation or legal hold applies.
Our principal retention periods are set out below.
Orders, invoices and financial records
Full order, invoice, payment-reference, collection and accounting records are normally retained for six years after the end of the financial or tax period to which they relate.
After that period, we review the information and remove or minimise personal data that is no longer required. A limited record of the contract and relevant communications may be retained for up to ten years after the order was completed where reasonably necessary to establish, exercise or defend contractual rights.
Shopify does not permit the deletion of every type of completed order. Where an order cannot be deleted from Shopify after our normal retention period, we will take proportionate steps to minimise its continued processing. These steps may include:
- deleting copies held in emails, spreadsheets, exports and connected applications;
- removing the information from active marketing, advertising, customer-segmentation and analytics activities;
- restricting access to personnel who require it for accounting, legal, security or data-protection purposes;
- redacting customer identity and contact information through Shopify’s personal-data erasure process where legally appropriate; and
- retaining only the minimum transaction information that Shopify requires to remain in the order history.
Following redaction, Shopify may continue to display limited information such as the products sold and the date and time of the transaction.
We review this technical limitation and the safeguards applied to retained Shopify orders at least annually. We do not retain identifiable personal data merely because a system permits or requires it to remain. Where there is no continuing lawful reason for identifiable information to be used, we will delete it, anonymise it, redact it or otherwise put it beyond ordinary operational use as far as reasonably and technically possible.
Retention or deletion may be suspended where a particular record is subject to an active complaint, warranty matter, fraud investigation, legal claim, regulatory requirement or documented legal hold.
Returns, repairs, warranties and complaints
Records relating to a return, repair, warranty, complaint, disputed transaction or product-safety matter may be retained for up to ten years after the matter is finally closed where reasonably necessary for legal claims, consumer obligations or product-safety purposes.
Information that is not required for these purposes will be removed earlier.
Customer accounts
Customer profile information is retained while the account remains active.
Where an account has had no meaningful activity, we will normally delete or anonymise the profile within 24 months after the last activity, unless it remains linked to records that must be retained for legal, tax, accounting, warranty, security or claims purposes.
Order records are retained separately according to the periods above.
General enquiries
General enquiries not connected with an order, complaint or legal matter are normally retained for no more than three years after the enquiry is closed.
Abandoned baskets and checkouts
Abandoned basket and checkout information is normally retained for no more than 12 months, unless:
- the checkout results in an order;
- the information is required for a fraud or security investigation;
- a dispute arises; or
- separate marketing consent has been provided.
Email marketing
Email contact information is retained while:
- consent remains valid;
- the individual remains subscribed; and
- we continue to provide the relevant marketing service.
We periodically review inactive marketing records and may remove subscribers who have shown no meaningful engagement for an extended period.
Evidence of marketing consent and withdrawal is normally retained for up to three years after consent is withdrawn or expires.
We retain a minimal suppression record for as long as we continue the relevant marketing activity so that we can respect an unsubscribe or objection and avoid adding the person back to a marketing list.
Shopify Email campaign information
Email campaign, delivery, bounce, click, unsubscribe and related reporting information is retained for as long as reasonably necessary to manage campaigns, demonstrate consent and resolve deliverability or complaint issues.
Detailed campaign-interaction records will normally be deleted or anonymised within 24 months, unless needed for an active complaint, investigation or legal claim.
Google Analytics
Where Google Analytics user and event retention settings apply, we configure retention to no more than 14 months.
Aggregated and genuinely anonymised statistical reports may be retained for longer because they no longer identify an individual.
Google enhanced conversions
We do not normally create a separate customer file for Google enhanced conversions.
Customer information is transmitted through the relevant website tag or Shopify integration at or around the time of the conversion, after being securely hashed where required.
Our original order and customer records remain subject to the retention periods described elsewhere in this policy.
Google retains and processes enhanced-conversion information according to its applicable terms and retention arrangements.
Meta Pixel and Conversions API
Website and advertising event information may be retained within Meta’s business systems for up to 24 months, subject to Meta’s applicable terms, settings and controls.
We periodically review advertising configurations and no longer use event information where it is not required for campaign measurement, optimisation, security or compliance.
Our original order and customer records remain subject to the retention periods described elsewhere in this policy.
Cookie and consent records
AVADA cookie-consent records are normally retained for three years after the latest consent choice.
This allows us to demonstrate what choice was made and when.
A replacement record may be created when the individual changes or renews a preference.
Pop Convert information
Visitor interaction information processed through Pop Convert is normally retained for no more than 12 months after the relevant interaction.
Information collected through a form is retained according to the purpose of the form:
- email-marketing information follows the marketing schedule;
- order or service information follows the relevant contractual schedule; and
- general enquiries follow the three-year enquiry schedule.
CCTV
Routine CCTV footage is normally retained for no longer than 31 days and is then automatically overwritten or securely deleted.
Footage relating to a particular:
- theft;
- suspected crime;
- accident;
- complaint;
- disputed transaction;
- disciplinary matter;
- insurance claim;
- police request; or
- legal proceeding
may be isolated and retained for longer.
Incident footage will be kept only for as long as reasonably necessary to investigate and resolve the matter or establish, exercise or defend legal rights. Its continued retention will be reviewed periodically.
Security logs and fraud investigations
Routine website, account and technical security logs are normally retained for no more than 12 months.
Information relating to a suspected fraud, chargeback, security incident or unlawful activity may be retained for up to:
- three years after the investigation is closed; or
- ten years where it is necessary for a contractual or legal claim.
Data-protection requests
Records of privacy requests, identity verification, decisions and responses are normally retained for three years after the request is closed.
PayPal records
Transaction references and payment-status information received by Fotosound are retained with the associated order.
PayPal determines its own retention periods for information it controls.
Backups
Information deleted from active systems may remain temporarily in restricted backups until the relevant backup is securely overwritten through the normal backup cycle.
Backup information is not used for ordinary business purposes.
Legal holds
Where information is relevant to litigation, a regulatory investigation, a police matter or another legal hold, deletion may be suspended until the matter is finally resolved.
When the retention period expires, personal data will be deleted, anonymised or restricted.
Genuinely anonymised information may be retained for longer because it no longer identifies an individual.
11. Cookies and similar technologies
Necessary cookies and similar technologies are used to operate:
- customer accounts;
- basket and checkout;
- payments;
- fraud prevention;
- website security;
- consent preferences; and
- other functions requested by the visitor.
With your consent, we also use:
- analytics technologies;
- advertising technologies;
- Meta Pixel;
- Meta Conversions API;
- Google Analytics;
- Google Ads conversion tracking;
- Google enhanced conversions; and
- Pop Convert tracking and personalisation features.
You can use our cookie-preference control to:
- accept or reject non-essential categories;
- review your current choice; and
- withdraw or change a previous choice.
Withdrawing consent does not affect processing that took place before withdrawal.
Further information about individual cookies, providers, purposes and durations is provided in our Cookie Policy.
12. CCTV rights and requests
Individuals may request access to CCTV footage containing their personal data.
To help us locate footage, a request should include:
- the approximate date;
- the approximate time;
- the area or location;
- a description of the individual; and
- information about the relevant incident or visit.
We may request information to verify the requester’s identity.
When responding, we may need to:
- blur or mask other people;
- provide still images rather than the full video;
- withhold information where a lawful exemption applies; or
- preserve footage that is relevant to an investigation or legal claim.
Once we receive a valid request concerning particular footage, we will take reasonable steps to prevent that footage from being routinely overwritten while the request is being handled.
13. Your data-protection rights
Subject to the conditions and exemptions in the Data Protection (Jersey) Law 2018, you may have the right to:
- be informed about how we process your personal data;
- ask whether we process your personal data;
- obtain access to your personal data;
- correct inaccurate or incomplete information;
- request erasure;
- request restriction of processing;
- receive certain information in a structured, commonly used and machine-readable format;
- ask us to transmit portable information to another controller where technically feasible;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing;
- withdraw consent at any time where processing is based on consent; and
- challenge certain decisions made solely through automated processing.
To exercise a right, contact:
Fotosound
22 King Street
St Helier
Jersey
JE2 4WP
Email: fotosound@voisins.com
Telephone: 01534 759990
Please explain your request clearly.
We may request proportionate information to confirm:
- your identity;
- your authority to act for another person; and
- the personal data to which the request relates.
We will normally respond without undue delay and within four weeks.
Where permitted because of the complexity or number of requests, this period may be extended by up to eight further weeks. If an extension is required, we will notify you within the initial four-week period and explain the reason.
Rights are not absolute. We will explain any lawful restriction, exemption or refusal.
14. Direct-marketing objections
You have an absolute right to object to the use of your personal data for direct marketing.
Once we receive an objection, we will stop the relevant direct-marketing processing.
We may retain a minimal suppression record, such as your email address or a securely generated representation of it, to ensure that your objection continues to be respected.
15. Automated decision-making
Fotosound does not currently make decisions about website customers based solely on automated processing that produce legal or similarly significant effects.
Payment, fraud-prevention, advertising and finance providers may carry out automated assessments for their own purposes.
Where those providers act as separate controllers, their own privacy notices explain:
- their processing;
- their lawful basis;
- any automated decision-making; and
- the rights available to individuals.
16. Children
Our online store is intended for adults, and online orders may be placed only by people aged 18 or over.
We do not knowingly collect personal data from children for online purchases, email marketing or personalised advertising.
If you believe that a child has provided personal data improperly, please contact us.
17. Security
We use proportionate technical and organisational measures intended to protect personal data against:
- unauthorised access;
- unlawful disclosure;
- alteration;
- accidental loss;
- destruction; and
- misuse.
Measures may include:
- access controls;
- staff confidentiality;
- secure passwords and authentication;
- encrypted transmission;
- secure service providers;
- system monitoring;
- CCTV access restrictions;
- audit and access logs;
- backup and recovery procedures; and
- staff policies and training.
No website, payment service or internet transmission can guarantee absolute security.
Customers should use a unique password and contact us promptly if they believe that an account, payment or communication has been compromised.
18. Complaints
Please contact us first so that we have an opportunity to investigate and resolve your concern.
You also have the right to raise a concern or complaint with:
Jersey Office of the Information Commissioner
2nd Floor
5 Castle Street
St Helier
Jersey
JE2 3BT
Telephone: 01534 716530
Email: enquiries@jerseyoic.org
19. Changes to this Privacy Policy
We may update this Privacy Policy when:
- our services change;
- we introduce or remove a provider;
- our processing activities change;
- retention periods change; or
- legal or regulatory requirements change.
The current version and its effective date will be published on our website.
Where required, we will provide additional notice or obtain fresh consent before making a material change to a consent-based purpose.
Last updated: 14 September 2026.
