GDPR Information
Your data protection rights under the General Data Protection Regulation
The General Data Protection Regulation (GDPR) provides comprehensive data protection rights for individuals in the European Economic Area. At breeze-perch.com, we are committed to full compliance with GDPR requirements and protecting your personal information.
Who We Are
breeze-perch.com operates as the data controller for personal information collected through our website and services. We determine how and why your personal data is processed.
Contact Details:
breeze-perch
42 Ashford Gardens, Kensington
London SW7 4DH
United Kingdom
Email: [email protected]
Your GDPR Rights Explained
1. Right to Be Informed
You have the right to clear, transparent information about how we collect and use your personal data. This information is provided through our Privacy Policy and this GDPR page.
2. Right of Access
You can request confirmation of whether we process your personal data and obtain a copy of that data. This is commonly known as a "subject access request." We will provide this information free of charge within one month of your request.
When requesting access, we may need to verify your identity to protect your information from unauthorized disclosure.
3. Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to have it corrected. We will update your information within one month and notify any third parties with whom we have shared your data where appropriate.
4. Right to Erasure
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
Note that this right is not absolute. We may need to retain certain information for legal obligations, such as professional record-keeping requirements.
5. Right to Restrict Processing
You can request that we limit how we use your personal data in certain situations:
- You contest the accuracy of the data while we verify it
- Processing is unlawful but you prefer restriction over erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing while we verify legitimate grounds
During restriction, we can store your data but not use it without your consent, except for legal claims or protecting others' rights.
6. Right to Data Portability
You can obtain and reuse your personal data for your own purposes across different services. This right applies when:
- Processing is based on consent or contract
- Processing is carried out by automated means
We will provide your data in a structured, commonly used, machine-readable format, or transfer it directly to another controller where technically feasible.
7. Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
For direct marketing, you have an absolute right to object, and we will cease such processing immediately upon request.
8. Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making of this nature.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with the following information:
- Your full name and contact details
- Clear description of the right you wish to exercise
- Any relevant details that help us locate your information
- Proof of identity (if required for security purposes)
We will respond to your request within one month. If your request is particularly complex or you have made multiple requests, we may extend this period by two additional months. We will inform you of any such extension within one month of receiving your request.
Data Processing Activities
What Data We Process
We process the following categories of personal data:
- Identity data: name, title
- Contact data: email address, physical address
- Technical data: IP address, browser type, device information
- Usage data: how you interact with our website
- Service data: information provided during service delivery
Why We Process Data
We process personal data for these purposes:
- Providing and managing services you request
- Communicating with you about enquiries and services
- Improving our website and user experience
- Complying with legal and professional obligations
- Protecting our rights and interests
Legal Basis for Processing
We rely on these legal grounds for processing:
- Consent: When you explicitly agree to processing
- Contract: When necessary to fulfill services you requested
- Legal Obligation: When required by law
- Legitimate Interests: For business operations, balanced against your rights
Data Protection Principles
We adhere to the GDPR data protection principles, ensuring that personal data is:
- Lawful, fair, and transparent: Processed legally with clear information provided
- Purpose limited: Collected for specified, explicit, legitimate purposes only
- Data minimized: Adequate, relevant, and limited to what is necessary
- Accurate: Kept up to date with mechanisms for correction
- Storage limited: Retained only as long as necessary
- Secure: Protected with appropriate technical and organizational measures
- Accountable: We demonstrate compliance with these principles
International Data Transfers
Your data is primarily stored within the European Economic Area. If we need to transfer data outside the EEA, we will ensure appropriate safeguards are in place, such as:
- European Commission adequacy decisions
- Standard contractual clauses
- Binding corporate rules
- Certification schemes
Data Breach Notification
In the event of a data breach likely to result in risk to your rights and freedoms, we will notify you without undue delay. We will also report breaches to the relevant supervisory authority within 72 hours of becoming aware.
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
We would appreciate the opportunity to address your concerns before you contact the ICO, so please contact us first if possible.
Updates to GDPR Information
We may update this information periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website. The last update date appears at the top of this page.