GDPR Compliance
Your data protection rights under the General Data Protection Regulation
Last updated: January 2024
1. Our Commitment to GDPR
Willow-quest is committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page outlines your rights and how we ensure compliance.
2. Data Controller
Willow-quest is the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.
Contact details:
Willow-quest
47 Greenfield Lane
Bristol, BS1 4QR
United Kingdom
Email: [email protected]
3. Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
3.1 Right to Be Informed
You have the right to be informed about how we collect and use your personal data. Our Privacy Policy provides detailed information about our data processing activities.
3.2 Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR). We will respond to valid requests within one month.
3.3 Right to Rectification
You have the right to have inaccurate personal data corrected or completed if it is incomplete. Contact us to request corrections to your data.
3.4 Right to Erasure
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, including:
- The data is no longer necessary for its original purpose
- You withdraw consent (where consent is the legal basis)
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
3.5 Right to Restrict Processing
You can request that we limit how we use your data in certain situations, such as when you contest the accuracy of the data or object to our processing.
3.6 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit that data to another controller without hindrance.
3.7 Right to Object
You have the right to object to:
- Processing based on legitimate interests or public interest
- Direct marketing
- Processing for research or statistical purposes
3.8 Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect you. Willow-quest does not engage in automated decision-making that would trigger this right.
4. How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. Include the following information:
- Your full name
- Contact information
- Description of the right you wish to exercise
- Any relevant details to help us locate your data
We may need to verify your identity before processing your request. We will respond to valid requests within one month, though this may be extended by two months for complex requests.
5. Legal Bases for Processing
Under GDPR, we must have a lawful basis for processing your personal data. We rely on the following legal bases:
- Consent: Where you have given clear consent for specific processing activities
- Contract: Where processing is necessary to perform a contract with you
- Legal obligation: Where processing is necessary to comply with the law
- Legitimate interests: Where processing is necessary for our legitimate business interests, provided these do not override your rights
6. Data Protection Principles
We adhere to the GDPR data protection principles:
- Lawfulness, fairness, and transparency: We process data lawfully and are transparent about how we use it
- Purpose limitation: We collect data for specified, explicit purposes
- Data minimisation: We only collect data that is necessary
- Accuracy: We keep data accurate and up to date
- Storage limitation: We retain data only as long as necessary
- Integrity and confidentiality: We keep data secure
- Accountability: We take responsibility for compliance
7. Data Security
We implement appropriate technical and organisational measures to ensure the security of your personal data, including:
- Secure data storage and transmission
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
- Incident response procedures
8. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours. If the breach is likely to result in a high risk, we will also notify affected individuals directly.
9. International Transfers
Your data is primarily stored and processed within the UK and EEA. If we transfer data outside these areas, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
10. Complaints
If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We encourage you to contact us first so we can address your concerns directly.
11. Updates to This Page
We may update this GDPR information from time to time. Changes will be posted on this page with an updated revision date.