Our Commitment to Data Protection
We are committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This page explains your rights and how we comply with GDPR requirements.
Legal Basis for Processing
We process your personal data under the following legal bases:
Consent: When you submit forms or agree to communications, you provide explicit consent for us to process your data for specified purposes.
Contractual Necessity: Processing necessary to fulfill service agreements or respond to service inquiries.
Legitimate Interests: Processing necessary for our legitimate business interests, such as improving services and maintaining website security, provided these interests don't override your rights.
Your Rights Under GDPR
Right to Access
You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to request correction or completion of your information.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there's no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Right to Restriction of Processing
You may request that we limit how we use your personal data in certain situations, such as while we verify data accuracy or assess whether we have legitimate grounds for processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to Object
You may object to processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal doesn't affect the lawfulness of processing before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. In the UK, the relevant authority is the Information Commissioner's Office (ICO).
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected] with your request. Please include:
- Clear description of your request
- Sufficient information to verify your identity
- Specific details about the data concerned (if applicable)
We will respond to verified requests within one month. In complex cases, we may extend this by two additional months and will inform you of any delay.
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations. Specific retention periods depend on the type of data and purpose:
- Inquiry data: Retained for two years from last contact
- Client service data: Retained for duration of service plus three years
- Website analytics: Anonymized after fourteen months
Data Transfers
We primarily process and store data within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
Automated Decision-Making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you may contact us at:
Email: [email protected]
Address: 127 Kensington Church Street, London W8 7LP, United Kingdom
Updates to This Information
We may update this GDPR information periodically to reflect changes in regulation or our practices. Significant changes will be communicated through prominent notice on our website.