Understanding your data protection rights under UK GDPR.
Last updated: January 2024
coral-pebble is committed to ensuring that your personal data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we comply with these regulations and explains your rights as a data subject.
coral-pebble acts as the data controller for the personal information collected through this website and our services. As data controller, we are responsible for determining the purposes and means of processing your personal data.
Contact Details:
coral-pebble
47 Colmore Row
Birmingham, B3 2AA
United Kingdom
Email: [email protected]
We only process personal data where we have a valid lawful basis to do so. The lawful bases we rely upon include:
Where you have given explicit consent for us to process your personal data for specific purposes. You have the right to withdraw consent at any time by contacting us.
Where processing is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract. This includes processing necessary to arrange and deliver our consultation services.
Where processing is necessary for our legitimate business interests or those of a third party, except where such interests are overridden by your fundamental rights and freedoms. Our legitimate interests include:
Where processing is necessary to comply with a legal obligation to which we are subject.
As a data subject, you have the following rights regarding your personal data:
You have the right to receive clear, transparent information about how we use your personal data. This is provided through our Privacy Policy and this GDPR page.
You can request a copy of the personal data we hold about you. We will respond to your request within one month and provide the information free of charge in most circumstances.
If the personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. We will respond to rectification requests within one month.
Also known as the "right to be forgotten", you can request deletion of your personal data in certain circumstances, including:
You can request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you prefer restriction over erasure.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making that falls within this category.
To exercise any of your rights, please submit a request to us at [email protected]. We may need to verify your identity before processing your request. We aim to respond to all legitimate requests within one month. If your request is particularly complex or you have made multiple requests, we may extend this period by up to two months, in which case we will notify you.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
We primarily process and store your personal data within the United Kingdom. If we transfer personal data outside the UK, we will ensure appropriate safeguards are in place to protect your data, such as adequacy decisions, standard contractual clauses, or binding corporate rules.
Given our size and the nature of our processing activities, we are not required to appoint a formal Data Protection Officer. However, data protection matters are overseen by our management team. For any data protection queries, please contact us at [email protected].
If you are unhappy with how we have handled your personal data or believe we have not complied with data protection law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk
We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first if possible.
We may update this GDPR information from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on this page with a revised date.