GDPR Compliance
Information about how we comply with the General Data Protection Regulation.
Our Commitment to Data Protection
ochre-tide is committed to ensuring that all personal data we collect and process is handled in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We take our responsibilities as a data controller seriously and have implemented appropriate measures to protect your information.
Data Controller Information
ochre-tide acts as the data controller for personal information collected through this website and during the provision of our consultation services. We determine the purposes and means of processing personal data in connection with our services.
Principles We Follow
We adhere to the core principles of data protection:
- Lawfulness, Fairness and Transparency: We process personal data lawfully and are transparent about how we use it.
- Purpose Limitation: We collect data only for specified, explicit purposes and do not process it in ways incompatible with those purposes.
- Data Minimisation: We collect only the personal data necessary for our stated purposes.
- Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date.
- Storage Limitation: We retain personal data only for as long as necessary for the purposes it was collected.
- Integrity and Confidentiality: We implement appropriate security measures to protect personal data.
- Accountability: We take responsibility for our data processing activities and can demonstrate compliance.
Your Rights Under GDPR
As a data subject, you have the following rights:
- Right to be Informed: You have the right to clear information about how we use your data, which is provided in our Privacy Policy.
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate personal data or complete incomplete data.
- Right to Erasure: In certain circumstances, you can request that we delete your personal data.
- Right to Restrict Processing: You can request that we limit how we use your data.
- Right to Data Portability: You can request your data in a structured, commonly used format.
- Right to Object: You can object to certain types of processing, including direct marketing.
- Rights Related to Automated Decision Making: You have rights in relation to automated decision making and profiling.
Exercising Your Rights
To exercise any of your data protection rights, please contact us using the details provided on our Contact page. We will respond to your request within one month. In complex cases or if we receive numerous requests, we may extend this period by a further two months, and we will inform you if this is necessary.
We will not charge a fee for responding to your request unless your request is clearly unfounded or excessive. In such cases, we may charge a reasonable fee or refuse to act on the request.
Data Breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
International Transfers
We do not routinely transfer personal data outside the United Kingdom. If circumstances require such transfers, we will ensure appropriate safeguards are in place in accordance with GDPR requirements.
Complaints
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Contact Us
For any questions about our GDPR compliance or to exercise your data protection rights, please contact us via the details on our Contact page.