GDPR Compliance
Our commitment to protecting your data rights
Our GDPR Commitment
solar-synth is committed to full compliance with the General Data Protection Regulation (GDPR) and UK data protection laws. We take your privacy seriously and have implemented comprehensive measures to protect your personal data.
Your Data Protection Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Be Informed
You have the right to clear, transparent information about how we collect and use your personal data. This information is provided in our Privacy Policy.
Right of Access
You can request access to your personal data and receive a copy of the information we hold about you. We will provide this within one month of your request.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to have it corrected. Contact us and we will update your information promptly.
Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected, or when you withdraw consent.
Right to Restrict Processing
You can ask us to restrict how we use your data in specific situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
We do not use automated decision making or profiling that produces legal effects or similarly significantly affects you.
How We Protect Your Data
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and audits
- Access controls limiting who can view personal data
- Staff training on data protection principles
- Secure backup and recovery procedures
- Incident response procedures for data breaches
Legal Basis for Processing
We only process your personal data when we have a lawful basis to do so:
- Consent: You have given clear consent for us to process your data for a specific purpose
- Contract: Processing is necessary for a contract we have with you
- Legal obligation: Processing is necessary for us to comply with the law
- Legitimate interests: Processing is necessary for our legitimate interests, provided your rights don't override those interests
Data Retention
We only retain personal data for as long as necessary to fulfill the purposes we collected it for, including legal, accounting, or reporting requirements. Specific retention periods depend on the type of data and purpose:
- Program participant data: Retained for 7 years after completion
- Inquiry and contact data: Retained for 2 years if no enrollment occurs
- Marketing consent data: Retained until consent is withdrawn
- Website analytics: Anonymized after 26 months
Third-Party Data Processors
We work with carefully selected third-party service providers who process data on our behalf. All processors are bound by data processing agreements that ensure GDPR compliance and protect your rights.
We conduct due diligence on all processors to ensure they implement appropriate security measures and only process data according to our instructions.
International Data Transfers
Your personal data is primarily stored within the United Kingdom. If we transfer data internationally, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the relevant authority
- Standard contractual clauses approved by the relevant authority
- Binding corporate rules
Data Breach Procedures
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware
- Inform affected individuals without undue delay if there is a high risk
- Document the breach, its effects, and remedial actions taken
- Take immediate steps to mitigate any harm
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us:
- Email: [email protected]
- Address: 47 Merchant Square, Glasgow G1 4BL, United Kingdom
We will respond to your request within one month. In complex cases, we may extend this by an additional two months, but we will inform you if this is necessary.
We will verify your identity before processing requests to ensure your data security.
Complaints
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
In the UK, the relevant authority is:
Information Commissioner's Office (ICO)
Website: solar-synth.com
Helpline: 0303 123 1113
Updates to Our GDPR Practices
We regularly review our GDPR compliance procedures and update them as necessary. Changes to how we handle your data will be reflected in our Privacy Policy, with the updated date clearly indicated.
Contact Our Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you can contact our designated data protection contact:
Email: [email protected]
Subject: GDPR Inquiry