spray-flash
  • Home
  • About
  • Services
  • Contact
  • Home
  • About
  • Services
  • Contact

GDPR Compliance

Last updated: January 2024

Our Commitment to Data Protection

spray-flash is committed to protecting your personal data and respecting your privacy. We comply fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller

spray-flash acts as the data controller for personal information collected through our website and in the course of providing our ecological consultancy services.

Contact:
spray-flash
Unit 14, Langford Business Park
Langford Lane, Kidlington
Oxfordshire OX5 1GE
Email: [email protected]

Your Rights Under GDPR

The UK GDPR provides you with the following rights regarding your personal data:

Right to Be Informed

You have the right to be informed about how we collect and use your personal data. This information is provided in our Privacy Policy and this GDPR statement.

Right of Access

You can request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond within one month of receiving your request.

Right to Rectification

If personal data we hold is inaccurate or incomplete, you have the right to have it corrected. Please contact us to update your information.

Right to Erasure

Also known as the "right to be forgotten", you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.

Right to Restrict Processing

You can request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds.

Rights Related to Automated Decision Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.

How to Exercise Your Rights

To exercise any of your data protection rights, please contact us at:

  • Email: [email protected]
  • Post: spray-flash, Unit 14, Langford Business Park, Langford Lane, Kidlington, Oxfordshire OX5 1GE

We will respond to your request within one month. If your request is complex, we may extend this by up to two additional months, but we will inform you of any extension within the first month.

Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contract: When processing is necessary to fulfil a contract with you or take pre-contractual steps at your request.
  • Legitimate Interests: When processing is necessary for our legitimate business interests, provided these do not override your rights.
  • Consent: When you have given clear consent for us to process your personal data for specific purposes.
  • Legal Obligation: When processing is necessary to comply with UK law.

Data Security Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular testing and evaluation of security measures
  • Staff training on data protection
  • Access controls and authentication procedures
  • Secure backup and recovery procedures

Data Breach Procedures

In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will:

  • Notify the Information Commissioner's Office within 72 hours of becoming aware
  • Notify affected individuals if the breach is likely to result in a high risk to their rights and freedoms
  • Document all breaches and our response actions

International Data Transfers

We primarily store and process data within the United Kingdom. Where international transfers are necessary, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Government.

Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk

Updates to This Statement

We may update this GDPR statement periodically. Any changes will be posted on this page with an updated revision date.

spray-flash

Independent ecological consultants providing expert environmental services across the United Kingdom since 2009.

Services

  • Ecological Surveys
  • Biodiversity Net Gain
  • Habitat Management
  • EIA Support

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use

Legal

  • GDPR
  • Cookies Policy

© 2024 spray-flash. All rights reserved. Registered in England and Wales.

We use cookies to enhance your browsing experience and analyse site traffic. By continuing, you agree to our Cookies Policy.