Personal Data Protection Policy 1. Introduction Josephine Koh Piano Academy is committed to protecting the privacy and security of personal information. This policy outlines how we collect, store, process, and protect personal data in accordance with the General Data Protection Regulation (GDPR), or any other relevant local laws. By enrolling in our programs or interacting with our services, you agree to the terms outlined in this policy. 2. Types of Personal Data We Collect We collect personal data from our students in connection with our educational services. This data may include, but is not limited to:
Name, address, and contact details (e.g., phone number, email address)
Date of birth and age
Financial information (e.g., payment details for tuition or purchases)
Medical or emergency contact information
Audio and video recordings (e.g., for performances, lessons, or recitals)
Academic records and progress reports
Parental or guardian information (for students under the age of 18)
3. Purpose of Collecting Personal Data We collect and process personal data for the following purposes:
To provide educational services and courses to our students
To manage student registrations and attendance
To communicate with students, parents, and staff regarding class schedules, events, and updates
To process payments and manage tuition fees
To ensure the safety and well-being of students, particularly in case of medical emergencies
To comply with legal, regulatory, and insurance requirements\
4. How We Store and Protect Personal Data We implement physical, technical, and administrative safeguards to protect personal data from unauthorized access, loss, or misuse. Personal data is stored securely in both digital and physical formats. We use encrypted systems for electronic data storage and implement access controls to ensure that only authorized personnel have access to sensitive information. 5. Sharing Personal Data We may share personal data with third parties in specific situations, including:
With service providers: We may share information with contractors or third-party service providers (ABRSM, concert venues etc) who help us operate our school's needs (e.g., payment processors, email platforms, or software providers).
For legal or compliance purposes: We may disclose personal data if required by law or in response to legal processes, such as subpoenas, warrants, or investigations.
With insurance providers: In case of emergencies or incidents, we may share information with our insurance company.
We will never sell, rent, or lease personal data to third parties for marketing purposes. 6. Data Retention Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. After this period, data will be securely deleted or anonymized. 7. Your Rights Regarding Personal Data Under data protection laws, individuals have the following rights with regard to their personal data:
Right to Access: You have the right to request copies of the personal data we hold about you.
Right to Rectification: You have the right to request corrections to any inaccurate or incomplete data we hold.
Right to Erasure: In certain circumstances, you can ask us to delete your personal data, subject to legal exceptions.
Right to Restrict Processing: You can request that we limit how we process your personal data in certain situations.
Right to Data Portability: You have the right to request a copy of your personal data in a commonly used format, to transfer it to another organization.
Right to Object: You can object to the processing of your data for certain purposes, such as direct marketing.
To exercise any of these rights, please contact us at [insert contact details]. 8. Cookies and Online Tracking If we use cookies or other tracking technologies on our website (for instance, to improve user experience or analyze traffic), we will provide a clear notice and obtain your consent where required by law. For more information, please see our Cookie Policy. 9. Security Measures We take data security seriously and implement appropriate measures to protect personal information from unauthorized access, loss, alteration, or destruction. This includes the use of secure servers, encryption, firewalls, and regular security audits. 10. Contact Information If you have any questions or concerns about how your personal data is handled, or if you wish to exercise your rights, please contact us. 11. Changes to This Policy We may update this policy from time to time to reflect changes in our practices or legal obligations. Any updates will be posted on our website, and we will notify affected individuals where appropriate.