2. Our responsibilities
3. How we collect, use and disclose your personal data
Generally, we collect your personal data when you interact with us (for example, when entering into a relationship with us as Talent, a Client or one of our People). However, from time to time we also need to collect personal data from other third parties in connection with our relationship with you. We also look at how our users access and use our Website, so we can offer the best possible experience. The following table summarises how we collect, use and disclose your personal data:
Talent (including prospective Talent)
Clients (including prospective Clients)
Subscribers to our promotional material
Users of our Website
4. Your rights
Personal data must be processed in line with an individual’s rights, including the right to:
• request a copy of their personal data;
• request that their inaccurate personal data is corrected;
• request that their personal data is deleted and destroyed when causing damage or distress; and
• opt out of receiving electronic communications from us.
Information security is a key element of data protection. We take appropriate measures to secure personal data and protect it from loss or unauthorised disclosure or damage. Our policy and approach to information security is contained within our Data Protection Policy.
7. Contacts and complaints
Clients: any person, business or other organisation who engages, or is looking to engage, the services of our Talent.
Controller: a personal/organisation who determines the purpose for which, and the manner in which, any personal data is processed.
Data Protection Policy: our internal data protection policy which sets out how we keep personal data secure, including technical measures (e.g. encryption of personal data, restricted access to personal data, monitoring and testing systems for unauthorised access, backups of personal data), roles and responsibilities of individuals and the scope of protection.
People: all people providing services to or working for us, including but not limited to our employees, directors, members, and contractors.
Personal data: information (including opinions) which relates to an individual and from which he or she can be identified either directly or indirectly through other data which we have or are likely to have in our possession. These individuals are sometimes referred to as data subjects.
Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed by an organisation electronically. A personal data breach may mean someone outside the organisation gets unauthorised access to personal data, but a breach can occur if there is unauthorised access within the organisation or if an employee accidentally alters or deletes personal data.
Principles: the core data protection principles underlying the Data Protection Legislation, which specify personal data should be: processed lawfully, fairly and in a transparent manner; collected for specified, explicit and legitimate purposes; adequate, relevant and limited to what is necessary; accurate and, where necessary, kept up to date; kept for no longer than is necessary; processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. Additionally, organisations must adhere to the principle of accountability.
Process: the ‘processing’ of personal data captures a wide range of activities, and includes obtaining, recording and holding personal data and performing any operation of the personal data (including erasure/destruction).
Processor: any person (other than an employee of the data controller) who processes the data on behalf of the data controller.
Talent: models and/or other talent who have engaged, or are looking to engage, our modelling and/or talent agency services and are or are considering being, represented by us.
Third party: a person, organisation or other body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.