Last updated: January 2024
Our Commitment
Teal Valley is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take the protection of personal data seriously and have implemented appropriate measures to ensure compliance with data protection legislation.
Data Controller
Teal Valley acts as the data controller for personal information collected through our website and services. This means we determine how and why your personal data is processed.
Contact details:
Address: 47 Ecclesall Road, Sheffield S11 8PR
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by the UK GDPR:
- Article 6(1)(a) - Consent: Where you have given clear consent for us to process your personal data for specific purposes
- Article 6(1)(b) - Contract: Where processing is necessary for the performance of a contract or to take steps prior to entering into a contract
- Article 6(1)(c) - Legal Obligation: Where processing is necessary for compliance with legal obligations
- Article 6(1)(f) - Legitimate Interests: Where processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms
Your Rights Under UK GDPR
The UK GDPR provides you with the following rights regarding your personal data:
Right to be Informed (Articles 13-14)
You have the right to be informed about how we collect and use your personal data. This information is provided in our Privacy Policy and this GDPR statement.
Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR). We will respond to such requests within one month.
Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure (Article 17)
Also known as the "right to be forgotten", you have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing (Article 18)
You have the right to request that we limit the way we use your personal data in certain circumstances.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit this data to another controller.
Right to Object (Article 21)
You have the right to object to certain types of processing, including processing for direct marketing purposes and processing based on legitimate interests.
Rights Related to Automated Decision Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently engage in such automated decision making.
Exercising Your Rights
To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.
We will not charge a fee for most requests, but may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. We may also refuse to comply with requests in these circumstances.
Data Protection Principles
We adhere to the data protection principles outlined in Article 5 of the UK GDPR:
- Lawfulness, fairness and transparency: We process data lawfully and transparently
- Purpose limitation: We collect data for specified, explicit and legitimate purposes
- Data minimisation: We collect only what is necessary for our purposes
- Accuracy: We keep data accurate and up to date
- Storage limitation: We retain data only as long as necessary
- Integrity and confidentiality: We ensure appropriate security of personal data
- Accountability: We take responsibility for compliance with these principles
Data Breach Procedures
We have procedures in place to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours. We will also notify affected individuals directly where required.
International Data Transfers
We primarily process data within the United Kingdom. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements.
Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
Updates to This Statement
We may update this GDPR statement from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically.