GDPR Compliance
Last updated: January 2024
base-atoll is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines our approach to data protection and your rights under these regulations.
Data Controller
base-atoll acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing personal data in accordance with applicable law.
Principles of Data Processing
We adhere to the core principles of the GDPR:
- Lawfulness, fairness, and transparency: We process data lawfully and openly
- Purpose limitation: We collect data only for specified, explicit purposes
- Data minimisation: We collect only data that is necessary
- Accuracy: We keep personal data accurate and up to date
- Storage limitation: We retain data only as long as necessary
- Integrity and confidentiality: We protect data through appropriate security measures
- Accountability: We demonstrate compliance with these principles
Lawful Bases for Processing
We process personal data under the following lawful bases as defined in Article 6 of the GDPR:
- Contract: Processing necessary for the performance of a contract with you
- Consent: Where you have given clear consent for specific processing
- Legal obligation: Processing necessary for compliance with a legal obligation
- Legitimate interests: Processing necessary for our legitimate business interests, where not overridden by your rights
Special Category Data
Where we process special category data such as health information for disability benefit applications, we do so under Article 9(2)(a) with your explicit consent, or where necessary for the establishment, exercise, or defence of legal claims.
Your Rights Under GDPR
The GDPR provides you with the following rights:
- Right of access (Article 15): You may request a copy of the personal data we hold about you
- Right to rectification (Article 16): You may request correction of inaccurate data
- Right to erasure (Article 17): You may request deletion of your data in certain circumstances
- Right to restriction (Article 18): You may request limited processing of your data
- Right to data portability (Article 20): You may receive your data in a structured, machine-readable format
- Right to object (Article 21): You may object to processing based on legitimate interests
- Rights related to automated decision-making (Article 22): You have rights concerning profiling and automated decisions
Exercising Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond to your request within one month. In complex cases, this period may be extended by two further months, and we will inform you accordingly.
Data Protection Officer
For matters relating to data protection and GDPR compliance, you may contact our designated data protection lead at [email protected].
Supervisory Authority
If you are not satisfied with our response to a data protection concern, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
International Transfers
We do not routinely transfer personal data outside the United Kingdom. Should any transfer become necessary, we will ensure appropriate safeguards are in place as required by Chapter V of the GDPR.
Data Breach Procedures
We maintain procedures for detecting, reporting, and investigating personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify you and the ICO as required by Articles 33 and 34 of the GDPR.