Last updated: January 2024
Our Commitment to GDPR
tranquil-sprout is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities as a data controller seriously and have implemented appropriate measures to ensure the protection of personal data.
Data Controller Information
tranquil-sprout acts as the data controller for personal information collected through our website and services. Our contact details are:
tranquil-sprout
47 Commerce Street
Manchester, M2 4LQ
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by Article 6 of the GDPR:
Consent
Where you have provided clear consent for us to process your personal data for specific purposes, such as receiving marketing communications or newsletter subscriptions.
Contract
Where processing is necessary to perform a contract with you or to take steps at your request prior to entering into a contract, such as responding to service enquiries.
Legitimate Interests
Where we have a legitimate business interest in processing your data, provided this does not override your fundamental rights. This includes improving our services and website functionality.
Legal Obligation
Where processing is necessary to comply with legal or regulatory requirements.
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
Right to be Informed
You have the right to be informed about how we collect and use your personal data. This information is provided in our Privacy Policy and this GDPR statement.
Right of Access
You have the right to request a copy of the personal data we hold about you. We will respond to such requests within one month.
Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you.
Right to Erasure
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You have the right to request that we limit how we use your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to certain types of processing, including processing for direct marketing purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that significantly affect you.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. There is no fee for making a request, unless the request is manifestly unfounded or excessive.
Data Security Measures
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular assessment and evaluation of our security measures
- Staff training on data protection obligations
- Access controls to limit who can access personal data
- Regular backups and disaster recovery procedures
Data Breach Procedures
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where a breach is likely to result in a high risk to affected individuals, we will also notify them directly.
International Data Transfers
Where we transfer personal data outside the United Kingdom, we ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the relevant authorities, to protect your data.
Data Protection Officer
For any questions or concerns regarding our data protection practices, or to exercise your GDPR rights, please contact us at [email protected].
Complaints
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk