Our commitment to data protection under the UK GDPR
Last updated: October 2024
Velvet-thicket is committed to protecting the personal data of individuals in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides information about how we comply with data protection requirements.
Velvet-thicket acts as a data controller for personal information collected through our website and business operations. As data controller, we determine the purposes and means of processing personal data.
Contact details:
Velvet-thicket
47 Fargate Street
Sheffield, S1 2HD
United Kingdom
Email: [email protected]
We only process personal data when we have a lawful basis to do so. The lawful bases we rely on include:
As a data subject, you have the following rights in relation to your personal data:
You have the right to request a copy of the personal information we hold about you. We will respond to your request within one month.
You have the right to request that we correct any personal information you believe is inaccurate or complete any information you believe is incomplete.
You have the right to request that we erase your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to request that we transfer the personal data you have provided to us to another organisation, or to you, in certain circumstances.
You have the right to object to our processing of your personal data where we are relying on legitimate interests as the lawful basis for processing.
You have rights in relation to automated decision-making and profiling. We do not currently use automated decision-making that produces legal or similarly significant effects.
To exercise any of your rights, please contact us using the details provided above. We may need to verify your identity before processing your request. We will respond to your request within one month, though this may be extended by two further months in complex cases.
You will not normally have to pay a fee to exercise your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
We primarily process personal data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the Information Commissioner's Office.
If you have concerns about how we handle your personal data, we encourage you to contact us first so that we can address your concerns. You also have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated effective date.