Your data protection rights under UK GDPR
Last updated: January 2024
glossy-sprout is committed to protecting the privacy and security of your personal information. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains your rights and how we handle your personal data.
glossy-sprout is the data controller responsible for your personal data. If you have any questions about how we process your information, please contact us using the details provided at the bottom of this page.
We may collect the following categories of personal data:
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
You have the following rights regarding your personal data:
Right to Access: You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
Right to Rectification: You have the right to request that we correct any personal data that is inaccurate or incomplete.
Right to Erasure: You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object: You have the right to object to the processing of your personal data where we are relying on legitimate interests as the legal basis for processing.
Rights Related to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
To exercise any of your rights, please contact us using the contact details below. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.
You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
We do not routinely transfer your personal data outside the United Kingdom. If we do transfer data internationally, we will ensure that appropriate safeguards are in place to protect your personal data.
If you have any complaints about how we handle your personal data, please contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
ICO website: ico.org.uk
For any questions regarding this GDPR compliance notice or to exercise your data protection rights:
Email: [email protected]
Address: 47 Meadow Lane, Guildford, Surrey, GU2 7PQ, United Kingdom