GDPR Compliance and Data Protection Rights

Last updated: June 19, 2026

We are committed to protecting your personal data in accordance with UK GDPR (General Data Protection Regulation) and the Data Protection Act 2018. This document outlines your data protection rights and how we fulfill our obligations.

Legal Basis for Processing

We process personal data only when we have a lawful basis for doing so. The legal grounds we rely on include:

  • Consent: When you provide explicit permission for specific processing activities
  • Contract: When processing is necessary to fulfill our service agreement with you
  • Legal obligation: When we must process data to comply with legal requirements
  • Legitimate interests: When processing serves our legitimate business interests while respecting your rights and freedoms

We will always inform you which legal basis applies to specific processing activities when we collect your information.

Data Controller Information

For the purposes of UK GDPR, the data controller is:

blossom-wave
47 Wellington Street
Leeds, West Yorkshire
LS1 4JG
United Kingdom
Email: [email protected]

Your Data Protection Rights

Under UK GDPR, you have comprehensive rights regarding your personal data. These rights are not absolute and may have limitations in certain circumstances, but we are committed to facilitating their exercise whenever possible.

Right to Access

You have the right to request copies of your personal data. This is commonly known as a "data subject access request." We will provide this information free of charge, though we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

Right to Rectification

You have the right to request correction of personal data you believe is inaccurate. You also have the right to request completion of information you believe is incomplete.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, including when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal ground for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • The data must be erased to comply with a legal obligation

This right is not absolute. We may need to retain certain information to comply with legal obligations or establish, exercise, or defend legal claims.

Right to Restrict Processing

You have the right to request restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to request transfer of your personal data to another organization or directly to you in a commonly used, machine-readable format. This right applies when processing is based on consent or contract and carried out by automated means.

Right to Object

You have the right to object to processing of your personal data when we rely on legitimate interests as our legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making of this nature.

Exercising Your Rights

To exercise any of your data protection rights, contact us via email at [email protected] or by post at the address listed above.

We will respond to your request within one month of receipt. If your request is particularly complex or you have made multiple requests, we may extend this period by two additional months. We will inform you of any extension within one month of receiving your request.

We may request specific information from you to confirm your identity and ensure we only provide personal data to the correct individual.

Data Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and updates
  • Access controls limiting data access to authorized personnel only
  • Staff training on data protection and confidentiality
  • Secure backup procedures

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the Information Commissioner's Office within 72 hours of becoming aware of the breach when required by law.

International Data Transfers

We primarily store and process data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:

  • Transfer to countries with adequacy decisions from the UK government
  • Use of standard contractual clauses approved by UK authorities
  • Implementation of binding corporate rules where applicable

Data Protection Impact Assessments

When introducing new processing activities that are likely to result in high risk to individuals' rights and freedoms, we conduct data protection impact assessments to identify and mitigate those risks.

Consent Management

When we rely on consent as our legal basis for processing, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

We make it as easy to withdraw consent as it was to give it initially. Contact us via email to withdraw previously granted consent.

Children's Data

We do not knowingly process personal data of individuals under eighteen years of age. If we become aware that we have collected such data without appropriate parental consent, we will take steps to delete it promptly.

Complaints and Supervisory Authority

If you believe we have not handled your personal data appropriately or violated your data protection rights, you have the right to lodge a complaint with the supervisory authority.

In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk

We encourage you to contact us first so we can address your concerns directly. However, you have the right to contact the ICO at any time.

Updates to This Document

We may update this GDPR compliance document periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated via email to active clients.