solar-synth
Our Story Programs Get in Touch

GDPR Compliance

Our commitment to protecting your data rights

Our GDPR Commitment

solar-synth is committed to full compliance with the General Data Protection Regulation (GDPR) and UK data protection laws. We take your privacy seriously and have implemented comprehensive measures to protect your personal data.

Your Data Protection Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Be Informed

You have the right to clear, transparent information about how we collect and use your personal data. This information is provided in our Privacy Policy.

Right of Access

You can request access to your personal data and receive a copy of the information we hold about you. We will provide this within one month of your request.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to have it corrected. Contact us and we will update your information promptly.

Right to Erasure (Right to be Forgotten)

You can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected, or when you withdraw consent.

Right to Restrict Processing

You can ask us to restrict how we use your data in specific situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision Making

We do not use automated decision making or profiling that produces legal effects or similarly significantly affects you.

How We Protect Your Data

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls limiting who can view personal data
  • Staff training on data protection principles
  • Secure backup and recovery procedures
  • Incident response procedures for data breaches

Legal Basis for Processing

We only process your personal data when we have a lawful basis to do so:

  • Consent: You have given clear consent for us to process your data for a specific purpose
  • Contract: Processing is necessary for a contract we have with you
  • Legal obligation: Processing is necessary for us to comply with the law
  • Legitimate interests: Processing is necessary for our legitimate interests, provided your rights don't override those interests

Data Retention

We only retain personal data for as long as necessary to fulfill the purposes we collected it for, including legal, accounting, or reporting requirements. Specific retention periods depend on the type of data and purpose:

  • Program participant data: Retained for 7 years after completion
  • Inquiry and contact data: Retained for 2 years if no enrollment occurs
  • Marketing consent data: Retained until consent is withdrawn
  • Website analytics: Anonymized after 26 months

Third-Party Data Processors

We work with carefully selected third-party service providers who process data on our behalf. All processors are bound by data processing agreements that ensure GDPR compliance and protect your rights.

We conduct due diligence on all processors to ensure they implement appropriate security measures and only process data according to our instructions.

International Data Transfers

Your personal data is primarily stored within the United Kingdom. If we transfer data internationally, we ensure appropriate safeguards are in place, such as:

  • Adequacy decisions by the relevant authority
  • Standard contractual clauses approved by the relevant authority
  • Binding corporate rules

Data Breach Procedures

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware
  • Inform affected individuals without undue delay if there is a high risk
  • Document the breach, its effects, and remedial actions taken
  • Take immediate steps to mitigate any harm

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us:

  • Email: [email protected]
  • Address: 47 Merchant Square, Glasgow G1 4BL, United Kingdom

We will respond to your request within one month. In complex cases, we may extend this by an additional two months, but we will inform you if this is necessary.

We will verify your identity before processing requests to ensure your data security.

Complaints

You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.

In the UK, the relevant authority is:

Information Commissioner's Office (ICO)
Website: solar-synth.com
Helpline: 0303 123 1113

Updates to Our GDPR Practices

We regularly review our GDPR compliance procedures and update them as necessary. Changes to how we handle your data will be reflected in our Privacy Policy, with the updated date clearly indicated.

Contact Our Data Protection Officer

For questions specifically related to data protection and GDPR compliance, you can contact our designated data protection contact:

Email: [email protected]
Subject: GDPR Inquiry

solar-synth

Building financial foundations for the next generation.

Quick Links

  • About
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

© 2026 solar-synth. All rights reserved.