General Data Protection Regulation Information
We are committed to protecting your personal data in accordance with the General Data Protection Regulation and the UK Data Protection Act 2018. This page explains how we comply with GDPR principles and how you can exercise your data protection rights.
We process your personal data under the following lawful bases: consent when you submit forms or accept cookies, legitimate interests for website analytics and service improvement, contractual necessity when delivering infrastructure services you have requested, and legal obligation for compliance with financial services regulations.
Under GDPR, you have several rights regarding your personal data:
To exercise any of your GDPR rights, send a request to [email protected] with the subject line "GDPR Request." Include your name, email address, and specify which right you wish to exercise. We will verify your identity before processing your request and respond within 30 days.
For questions about our data protection practices or to escalate concerns, contact our data protection team at [email protected]. While we do not have a designated Data Protection Officer as we fall below the threshold requiring one, our compliance team handles all data protection matters.
When we transfer your data outside the UK or European Economic Area, we ensure appropriate safeguards are in place. This includes using standard contractual clauses approved by the European Commission or transferring data to countries with adequacy decisions recognizing equivalent data protection standards.
We retain personal data only as long as necessary for the purposes we collected it. Assessment requests are retained for seven years to comply with financial services record-keeping requirements. Website analytics data is aggregated and anonymized after six months. Marketing consent records are kept until you withdraw consent or for three years of inactivity, whichever comes first.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include encryption, access controls, regular security assessments, and staff training on data protection.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also notify you directly without undue delay.
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR. In the United Kingdom, the relevant authority is the Information Commissioner's Office (ICO). You can contact them at ico.org.uk or by calling 0303 123 1113.
Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will delete that information promptly.
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website. We recommend reviewing this page periodically to stay informed about how we protect your data.