Your data protection rights under UK GDPR
glen-wolf is committed to ensuring the protection of personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our data protection responsibilities seriously and have implemented measures to ensure compliance.
glen-wolf acts as the data controller for personal information collected through this website and in connection with our educational services. This means we determine the purposes and means of processing personal data.
Contact details:
glen-wolf
42 Commerce Street
Liverpool, L2 3PQ
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so. The lawful bases we rely upon include:
The UK GDPR provides you with several rights regarding your personal data:
You have the right to be informed about the collection and use of your personal data. This GDPR page and our Privacy Policy provide this information.
You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond to your request within one month.
You have the right to request that we correct any inaccurate personal data we hold about you. We will respond to your request within one month.
Also known as the "right to be forgotten", you can request the deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purpose it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You have the right to object to the processing of your personal data where we are relying on legitimate interests as our lawful basis. You also have an absolute right to object to processing for direct marketing purposes.
You have rights related to automated decision making, including profiling. We do not currently use automated decision making that produces legal or similarly significant effects.
To exercise any of your data protection rights, please contact us using the details provided above. We may need to verify your identity before processing your request. We will respond to all legitimate requests within one month. In complex cases, we may extend this period by a further two months, in which case we will inform you of this extension.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office within 72 hours. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
We primarily process personal data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues. You can contact the ICO at ico.org.uk or by calling their helpline.
However, we would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page. We encourage you to review this page periodically.