GDPR Compliance
Last Updated: January 2026
Our Commitment to Data Protection
We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we meet our obligations under these regulations and how you can exercise your rights.
Data Controller Information
For the purposes of data protection legislation, grand-glade acts as the data controller for personal information we collect and process. We determine how and why your personal data is processed.
Lawful Basis for Processing
We only process your personal data when we have a lawful basis to do so. The specific lawful basis depends on the purpose for which we are processing your data:
- Consent: When you provide explicit consent for us to process your data for a specific purpose
- Contract: When processing is necessary to fulfill our service agreement with you
- Legal Obligation: When we must process your data to comply with the law
- Legitimate Interests: When processing is necessary for our legitimate interests in providing professional services, provided these interests do not override your rights
Data Minimization
We adhere to the principle of data minimization by collecting only the personal information that is necessary for the specific purpose for which it is being processed. We do not collect excessive or irrelevant data.
Your Rights Under GDPR
The UK GDPR provides you with specific rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format unless you request otherwise. There is no charge for this service unless your request is manifestly unfounded or excessive.
Right to Rectification
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it. We will respond to your request within one month.
Right to Erasure
In certain circumstances, you have the right to request that we delete your personal data. This right applies when:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
Please note that this right is not absolute. We may need to retain certain information to comply with legal obligations or to establish, exercise, or defend legal claims.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing based on legitimate interests.
Right to Data Portability
Where technically feasible, you have the right to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data where we are relying on legitimate interests as the legal basis for processing. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right to Withdraw Consent
Where we are processing your data based on consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Exercising Your Rights
To exercise any of your rights under the GDPR, please contact us using the details provided on our contact page. We will respond to your request without undue delay and in any event within one month of receipt. In complex cases, we may extend this period by a further two months and will inform you of any such extension.
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication procedures
- Staff training on data protection obligations
- Incident response procedures for data breaches
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also report qualifying breaches to the Information Commissioner's Office within 72 hours of becoming aware of the breach.
International Data Transfers
We do not routinely transfer personal data outside the United Kingdom. If we need to transfer your data internationally for any reason, we will ensure appropriate safeguards are in place to protect your information in accordance with UK GDPR requirements.
Automated Decision-Making
We do not use automated decision-making or profiling in ways that produce legal effects or similarly significant effects on individuals.
Data Protection Officer
While we are not legally required to appoint a Data Protection Officer, we have designated personnel responsible for overseeing data protection compliance. You can contact our data protection contact through the details provided on our contact page.
Complaints
If you are not satisfied with how we have handled your personal data or responded to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Updates to This Statement
We may update this GDPR compliance statement from time to time to reflect changes in our data processing practices or legal requirements. We encourage you to review this page periodically.