Information presented on this website is advertising in nature

Last updated: September 2024

Our Commitment to Data Protection

Rustic-lotus is committed to protecting the personal data of our website visitors and clients in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we comply with these regulations and explains your rights regarding your personal data.

Data Controller Information

Rustic-lotus acts as the data controller for personal data collected through this website and in the course of providing our services.

Contact details:
Email: [email protected]
Address: 47 Victoria Street, Manchester, M3 2QW, United Kingdom

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:

Consent

Where you have given clear consent for us to process your personal data for a specific purpose, such as receiving marketing communications or using non-essential cookies.

Contract

Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.

Legitimate Interests

Where processing is necessary for our legitimate interests or those of a third party, provided those interests do not override your fundamental rights and freedoms. Our legitimate interests include:

  • Improving our services and website
  • Protecting our business from fraud
  • Ensuring network and information security

Legal Obligation

Where processing is necessary to comply with a legal obligation to which we are subject.

Your Data Protection Rights

Under the UK GDPR, you have the following rights:

Right to Access

You have the right to request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR). We will respond to your request within one month.

Right to Rectification

You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.

Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, including:

  • The data is no longer necessary for the purpose it was collected
  • You withdraw consent (where consent was the basis for processing)
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Right to Restrict Processing

You have the right to request that we restrict processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have challenged.

Right to Data Portability

Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds.

Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond within one month, though this period may be extended by two months for complex requests.

Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular security assessments and testing
  • Access controls limiting data access to authorised personnel
  • Staff training on data protection
  • Incident response procedures for data breaches

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Retention periods are determined based on:

  • The nature of the data and purposes of processing
  • Legal and regulatory requirements
  • Legitimate business needs

International Transfers

If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:

  • Transfers to countries with adequate data protection laws
  • Standard contractual clauses approved by the ICO
  • Other legally approved transfer mechanisms

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where required, notify affected individuals without undue delay.

Complaints

If you are not satisfied with how we handle your personal data or your data protection requests, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk

We encourage you to contact us first so we can try to resolve your concerns.

Changes to This Information

We may update this GDPR information from time to time. Any changes will be posted on this page with an updated date.