1. Data Protection Principles
We adhere to the following data protection principles:
- Lawfulness, Fairness, and Transparency: We process personal data lawfully, fairly, and transparently.
- Purpose Limitation: We collect personal data for specified, legitimate purposes.
- Data Minimization: We collect only necessary personal data.
- Accuracy: We ensure personal data is accurate and up-to-date., legitimate purposes.
- Storage Limitation: We store personal data for no longer than necessary.
- Integrity and Confidentiality: We protect personal data from unauthorized access, disclosure, alteration, or destruction.
2. Data Subject Rights
We recognize the following data subject rights:
- Right to Access: Individuals can request access to their personal data.
- Right to Rectification: Individuals can request correction of inaccurate personal data
- Right to Erasure: Individuals can request deletion of their personal data
- Right to Restriction of Processing: Individuals can request restriction of processing their personal data.
- Right to Data Portability: Individuals can request transfer of their personal data.
- Right to Object: Individuals can object to processing their personal data.
3. Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee data protection compliance.
4. Data Breach
In the event of a data breach, we will:
- Notify the ICO: We will notify the Information Commissioner's Office (ICO) within 72 hours.
- Notify Data Subjects: We will notify affected individuals without undue delay.
5. Data Processing
We process personal data for the following purposes:
- Service Provision: Providing services to clients
- Communication: Communicating with clients and stakeholders
- Improvement: Improving our services.
6. Data Sharing
- Service Providers: Third-party service providers who help us provide our services.
- Regulatory Bodies: Regulatory bodies, such as the ICO.
7. Data Security
We implement technical and organizational measures to protect personal data, including:
- Encryption: Encrypting personal data in transit and at rest.
- Access Controls: Implementing access controls to restrict access to personal data.
- Training: Providing training to employees on data protection..
8. Changes to Policy
We may update this Data Protection Policy to reflect changes in law or our practices.