We are GDPR Assist® UK Ltd., a company registered in England (company registration number 13281423) and our registered office is: Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, England, BL6 6HG, UK.
This privacy notice describes our processing of personal data as a Data Controller. We are registered with the Information Commissioner’s Office as a Data Controller, reference number ZB035230.
You can contact us at the above address, email us using paul@gdprassist.co.uk, or call us on 07860 692645.
We do not collect any personal data directly from our website. All contact with the business is via email and telephone. We will maintain records of customer contact which falls under the lawful basis of legitimate interest (maintaining records for business management) and potentially under the lawful basis of being necessary for the performance of a contract with you where you are acting as an individual rather than as a representative of your organisation.
Personal Data is processed entirely for the purpose of maintaining contact between us in order to deliver our service and fulfil any contracts which exist between us.
Some personal data require greater protection than others. The General Data Protection Regulation (GDPR) defines these special category data as relating to race/ethnicity, beliefs, the body (health and biometrics data) and sexuality. We do not collect any special category data about you.
We collect no personal data directly from the website. Should you contact us we will record:
· Your name,
· Your email address,
· Your place of work,
· Your role,
· Your telephone number
We will share your personal data with law enforcement agencies if we receive a legitimate request from them to do so.
We use a number of cloud based systems to manage our business, specifically:
· Microsoft Office 365 (business management)
· FreeAgent (accounting)
· Zoom (video calls)
· Frama RMail (encrypted email and document signing)
We ensure that we have appropriate data protection agreements in place with these third parties.
We take sensible steps to keep your data secure:
· We use modern software and always keep it up to date,
· We follow National Cyber Security Centre guidelines on the creation and management of passwords,
· We utilise encryption technologies where available,
· We maintain appropriate records of processing activities which record any data processors we use and we ensure that appropriate contracts are in place to protect your rights, that the processors take appropriate security measures to safeguard your data, and that any international transfers are done correctly under UK data protection laws,
You have a number of rights relating to the processing of your data, if you would like to use them or have any questions then please contact us.
We won’t charge you for doing any of the following, however we may make a charge in the case of frequent repeat or unfounded requests:
· Awareness: You have the right to be fully informed about why and how we process your information. This privacy notice is intended to meet that requirement, but please do contact us if you have any questions,
· Access: You have the right to a copy of the data we hold about you
· Rectification: If you think some of the data we hold is wrong then you have the right to ask us to correct it,
· Erasure: You have the right to ask us to delete the data we hold about you. Where we are holding the data to fulfil a contract with you then we will need to retain the data in accordance with the data retention requirements shown below,
· Restriction: You have the right to ask us to restrict the processing of personal data whilst we check its accuracy, if you think the processing is unlawful, if you believe we no longer need to process the data but you need us to store it due to pending legal claims, or when you object to our processing based upon our legitimate interests and we are assessing the validity of that,
· Object: Where we are processing your personal data based upon our legitimate interests you have the right to object to that. If your objection is valid (for instance in the case of any direct marketing activity) then we will stop processing your personal data for that purpose,
· Data portability: You can request a copy of your data in a digital format which you can then supply to another provider when we ae processing your personal data under the lawful basis of performing a contract with you or because we have your consent,
· Automated decisions and profiling: You have the right, in certain circumstances, not to be subject to decisions based on automated processing (including profiling) if it has a significant or legal impact on you. We do not use any technology to make automated decisions about you.
We will retain personal data for a period of 7 years from last contact. If you would like us to delete your data sooner then please contact us.
Cookies are small text files that are placed on your computer when you access a website. These allow websites to do several important things, including remembering what’s in your shopping basket and which pages you have visited.
We use no cookies on our website, nor do we intend to change that stance.
If you follow links to other sites from our website your data will be subject to the privacy notices of those sites. You should refer to these policies before providing your data.
We process data in the UK. We do utilise cloud computing applications which may transfer data outside of the UK, specifically:
· Microsoft Office 365 – USA (using Standard Contractual Clauses)
· Freeagent – Ireland (has adequacy status for transfers from UK)
· Zoom – USA (using Standard Contractual Clauses)
· Frama RMail – Switzerland (has adequacy status for transfers from UK)
You can contact us at the above address, alternatively the supervisory authority in the UK for data protection matters is the Information Commissioner’s Office (ICO). If you think your data protection rights have been breached in any way by us, you are able to make a complaint to the ICO, their helpline number is 0303 123 1113.
You can download a copy of our standard terms and conditions here. For clients these should be read alongside the letter of engagement provided by us.
Copyright © 2022 GDPR Assist® UK Ltd. all rights reserved. GDPR Assist® UK Ltd is a company registered in England and Wales, company registration number 13281423, Registered office Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton , BL6 6HG.