GDPR Compliance Statement
vale-osprey is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This statement outlines how we comply with data protection requirements and respect your privacy rights.
Our Commitment to GDPR Compliance
We recognize the importance of protecting personal information and have implemented comprehensive measures to ensure compliance with GDPR principles. Our data protection practices are designed to give you control over your personal information and ensure transparency in how we process data.
Data Controller Information
For the purposes of data protection law, vale-osprey is the data controller responsible for your personal information. Our contact details are:
vale-osprey
42 Heritage Lane
Bloomsbury, London WC1B 3DG
United Kingdom
Email: [email protected]
Your Rights Under GDPR
Under the General Data Protection Regulation, you have specific rights regarding your personal data. We respect these rights and have established procedures to ensure you can exercise them effectively.
Right to Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. We will provide this information free of charge within one month of your request.
Right to Rectification
If you believe any personal information we hold about you is inaccurate or incomplete, you have the right to request correction. We will respond to rectification requests promptly and update our records accordingly.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data under certain circumstances, including:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required to comply with a legal obligation
Right to Restrict Processing
You may request that we limit how we use your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller when processing is based on consent or contract performance.
Right to Object
You may object to processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right to Withdraw Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significant effects. We do not currently engage in automated decision-making of this nature.
How to Exercise Your Rights
To exercise any of the rights described above, please contact us using the contact information provided in this statement. We will respond to requests within one month, though this may be extended by two additional months for complex requests. We will inform you of any extension and the reasons for delay.
We may request specific information from you to help us confirm your identity and ensure your right to access personal data or exercise other rights. This security measure ensures that personal data is not disclosed to unauthorized persons.
Lawful Basis for Processing
We only process personal data when we have a lawful basis for doing so. The legal bases we rely on include:
- Consent: You have given clear consent for specific processing purposes
- Contract: Processing is necessary to fulfill contractual obligations
- Legal Obligation: Processing is necessary to comply with legal requirements
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms
Data Protection Principles
Our data processing activities adhere to the GDPR principles. We ensure that personal data is:
- Processed lawfully, fairly, and transparently: We are open about how we collect and use personal data
- Collected for specified, explicit, and legitimate purposes: We clearly communicate why we collect data
- Adequate, relevant, and limited: We collect only the minimum data necessary
- Accurate and kept up to date: We take reasonable steps to ensure data accuracy
- Kept for no longer than necessary: We retain data only as long as required
- Processed securely: We implement appropriate security measures
Data Security Measures
We employ technical and organizational security measures designed to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls limiting who can view or process personal data
- Staff training on data protection responsibilities
- Secure backup and recovery procedures
Data Breach Notification
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR. If the breach poses a high risk to your rights, we will also notify you directly without undue delay.
International Data Transfers
When we transfer personal data outside the United Kingdom or European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by regulatory authorities, adequacy decisions, or other lawful transfer mechanisms.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with data protection requirements. The relevant supervisory authority in the United Kingdom is:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Helpline: 0303 123 1113
Website: www.ico.org.uk
Updates to This Statement
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. The updated version will be posted on this page with a revised effective date.
Questions and Concerns
If you have questions about our GDPR compliance or wish to exercise your rights, please contact us using the information provided at the beginning of this statement. We are committed to addressing your concerns and protecting your privacy rights.