GDPR Information
Last updated: January 2024
QuidbridgeTechAI Ltd is committed to ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides detailed information about your rights under these regulations and how we fulfil our obligations as a data controller.
Your Data Protection Rights
Under the UK GDPR, you have several rights regarding your personal data. We are committed to facilitating the exercise of these rights in a transparent and timely manner.
Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR). Upon receiving a valid request, we will provide:
- Confirmation that your data is being processed
- A copy of your personal data
- Information about the purposes of processing
- Categories of personal data concerned
- Recipients or categories of recipients
- The retention period or criteria used to determine it
- Information about your rights
We will respond to SAR requests within one month of receipt. This period may be extended by two months for complex requests, in which case we will inform you within the initial month.
Right to Rectification
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request its correction. We will respond to rectification requests within one month and inform any third parties with whom the data has been shared.
Right to Erasure
Also known as the "right to be forgotten," you may request the deletion of your personal data in certain circumstances:
- The data is no longer necessary for its original purpose
- You withdraw consent and no other legal basis applies
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Erasure is required for compliance with a legal obligation
Please note that this right is not absolute; we may need to retain certain data for legal, regulatory, or legitimate business purposes.
Right to Restrict Processing
You may request that we limit how we use your data in certain situations:
- While we verify the accuracy of contested data
- If processing is unlawful but you prefer restriction to erasure
- If we no longer need the data but you require it for legal claims
- While we consider an objection to processing
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format. You may also request that we transmit this data directly to another controller where technically feasible.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. If you object to direct marketing, we will cease such processing immediately. For other objections, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects. We do not currently engage in such automated decision-making.
How We Process Your Data
Data Controller
QuidbridgeTechAI Ltd acts as the data controller for personal data collected through our website and services. This means we determine the purposes and means of processing personal data.
Lawful Bases for Processing
We only process personal data when we have a lawful basis to do so. The specific basis depends on the context and purpose:
- Contractual necessity: Processing required to provide our services to you
- Legitimate interests: Processing for our business purposes where these don't override your rights
- Consent: Processing you have explicitly agreed to, particularly for marketing communications
- Legal obligation: Processing required by law
Data Minimisation
We collect only the personal data necessary for the specified purposes. We regularly review our data collection practices to ensure we are not gathering excessive information.
Accuracy
We take reasonable steps to ensure personal data is accurate and kept up to date. We encourage you to inform us of any changes to your personal information.
Storage Limitation
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our data retention schedules are reviewed annually.
Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
Data Protection Officer
Given the nature and scale of our processing activities, we are not required to appoint a Data Protection Officer. However, we take data protection seriously and have designated responsibility for compliance to our management team. For any data protection queries, please contact us at [email protected].
Data Breach Notification
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours where feasible. If the breach is likely to result in a high risk to your rights, we will also inform you directly.
International Data Transfers
We primarily process data within the United Kingdom. Should we need to transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Government or adequacy decisions recognising equivalent data protection standards.
Exercising Your Rights
To exercise any of your data protection rights, please contact us:
- Email: [email protected]
- Post: QuidbridgeTechAI Ltd, 47 Northgate Street, Chester, CH1 2HQ
We may need to verify your identity before processing your request. We aim to respond to all requests within one month.
Complaints
If you are dissatisfied with how we have handled your personal data or responded to your request, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: quidbridgetechai.uk
Updates to This Information
We may update this page periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.