GDPR Compliance

Your data protection rights under UK GDPR

Our Commitment to Data Protection

Lotus-beaver.com is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller Information

The data controller responsible for your personal information is:

Lotus-beaver
15 Ashford Lane
Bristol BS2 9JH
United Kingdom
Email: [email protected]

Your Rights Under GDPR

You have the following rights regarding your personal data:

1. Right to Access

You have the right to request access to your personal data. We will provide you with a copy of the information we hold about you within one month of your request.

2. Right to Rectification

You can request that we correct any inaccurate or incomplete personal data we hold about you.

3. Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

4. Right to Restriction of Processing

You can request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data.

5. Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.

6. Right to Object

You can object to the processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.

7. Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected] with:

  • Your full name and contact details
  • Details of the specific right you wish to exercise
  • Any relevant information to help us locate your data
  • Proof of identity (we may request this for security purposes)

We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the reasons for the extension.

Lawful Basis for Processing

We process your personal data under the following lawful bases:

  • Consent: When you have given clear consent for us to process your personal data for a specific purpose
  • Contract: When processing is necessary for the performance of a contract with you
  • Legal obligation: When we need to comply with the law
  • Legitimate interests: When processing is necessary for our legitimate interests or the legitimate interests of a third party, unless your interests and fundamental rights override those interests

Data Security Measures

We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication procedures
  • Staff training on data protection principles
  • Incident response procedures

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

International Data Transfers

When we transfer your personal data outside the United Kingdom, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the UK authorities
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding corporate rules for intra-group transfers

Third-Party Processors

We work with trusted third-party service providers who process personal data on our behalf. We ensure that:

  • Processors are bound by written contracts meeting GDPR requirements
  • Processors provide sufficient guarantees of technical and organizational security measures
  • We regularly assess and audit processor compliance

Complaints and Supervisory Authority

If you believe we have not handled your personal data in accordance with data protection law, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk

Updates to This Information

We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. We will notify you of any significant changes.

Contact Us

For any questions regarding GDPR compliance or to exercise your data protection rights, please contact us at [email protected]