Our commitment to protecting your personal data under UK GDPR
Last updated: September 2024
teal-reef is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take the protection of your personal data seriously and have implemented appropriate measures to ensure compliance with data protection laws.
teal-reef acts as the data controller for personal information collected through this website and in connection with our services. As data controller, we determine the purposes and means of processing personal data.
Contact details:
teal-reef
47 Northumberland Street
Newcastle upon Tyne, NE1 7DE
United Kingdom
Email: [email protected]
We adhere to the following data protection principles:
As a data subject, you have the following rights:
You have the right to receive clear information about how we collect and use your personal data. This information is provided through this compliance statement and our Privacy Policy.
You can request a copy of the personal data we hold about you. We will respond to valid requests within one month and provide the information free of charge in most circumstances.
If personal data we hold is inaccurate or incomplete, you have the right to have it corrected. We will respond to rectification requests within one month.
Also known as the "right to be forgotten," you can request deletion of your personal data where there is no compelling reason for its continued processing. This right is not absolute and applies only in certain circumstances.
You can request that we limit the way we use your data while concerns about its accuracy or our legal basis for processing are resolved.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently use automated decision-making processes.
To exercise any of your data protection rights, please contact us using the details above. We may need to verify your identity before processing your request. We aim to respond to all valid requests within one month, though complex requests may require an extension of up to two additional months.
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
Where we use third-party service providers to process personal data on our behalf, we ensure appropriate contracts are in place requiring them to comply with data protection requirements and implement adequate security measures.
Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the relevant authorities, to protect your data.
This GDPR compliance statement may be updated periodically to reflect changes in our practices or legal requirements. The date of the last update is shown at the top of this page.
If you are dissatisfied with how we have handled your personal data or any data protection request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk