GDPR Compliance and Data Protection Rights
Last updated: June 19, 2026
We are committed to protecting your personal data in accordance with UK GDPR (General Data Protection Regulation) and the Data Protection Act 2018. This document outlines your data protection rights and how we fulfill our obligations.
Legal Basis for Processing
We process personal data only when we have a lawful basis for doing so. The legal grounds we rely on include:
- Consent: When you provide explicit permission for specific processing activities
- Contract: When processing is necessary to fulfill our service agreement with you
- Legal obligation: When we must process data to comply with legal requirements
- Legitimate interests: When processing serves our legitimate business interests while respecting your rights and freedoms
We will always inform you which legal basis applies to specific processing activities when we collect your information.
Data Controller Information
For the purposes of UK GDPR, the data controller is:
blossom-wave
47 Wellington Street
Leeds, West Yorkshire
LS1 4JG
United Kingdom
Email: [email protected]
Your Data Protection Rights
Under UK GDPR, you have comprehensive rights regarding your personal data. These rights are not absolute and may have limitations in certain circumstances, but we are committed to facilitating their exercise whenever possible.
Right to Access
You have the right to request copies of your personal data. This is commonly known as a "data subject access request." We will provide this information free of charge, though we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Right to Rectification
You have the right to request correction of personal data you believe is inaccurate. You also have the right to request completion of information you believe is incomplete.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal ground for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
This right is not absolute. We may need to retain certain information to comply with legal obligations or establish, exercise, or defend legal claims.
Right to Restrict Processing
You have the right to request restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to request transfer of your personal data to another organization or directly to you in a commonly used, machine-readable format. This right applies when processing is based on consent or contract and carried out by automated means.
Right to Object
You have the right to object to processing of your personal data when we rely on legitimate interests as our legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making of this nature.
Exercising Your Rights
To exercise any of your data protection rights, contact us via email at [email protected] or by post at the address listed above.
We will respond to your request within one month of receipt. If your request is particularly complex or you have made multiple requests, we may extend this period by two additional months. We will inform you of any extension within one month of receiving your request.
We may request specific information from you to confirm your identity and ensure we only provide personal data to the correct individual.
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls limiting data access to authorized personnel only
- Staff training on data protection and confidentiality
- Secure backup procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the Information Commissioner's Office within 72 hours of becoming aware of the breach when required by law.
International Data Transfers
We primarily store and process data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:
- Transfer to countries with adequacy decisions from the UK government
- Use of standard contractual clauses approved by UK authorities
- Implementation of binding corporate rules where applicable
Data Protection Impact Assessments
When introducing new processing activities that are likely to result in high risk to individuals' rights and freedoms, we conduct data protection impact assessments to identify and mitigate those risks.
Consent Management
When we rely on consent as our legal basis for processing, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
We make it as easy to withdraw consent as it was to give it initially. Contact us via email to withdraw previously granted consent.
Children's Data
We do not knowingly process personal data of individuals under eighteen years of age. If we become aware that we have collected such data without appropriate parental consent, we will take steps to delete it promptly.
Complaints and Supervisory Authority
If you believe we have not handled your personal data appropriately or violated your data protection rights, you have the right to lodge a complaint with the supervisory authority.
In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk
We encourage you to contact us first so we can address your concerns directly. However, you have the right to contact the ICO at any time.
Updates to This Document
We may update this GDPR compliance document periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated via email to active clients.