Last updated: January 2024
pearly-class is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. This page outlines our approach to GDPR compliance.
What is GDPR?
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy. Although the United Kingdom has left the European Union, the UK GDPR (UK General Data Protection Regulation) applies similar protections to personal data processed in the UK.
Data Controller
pearly-class acts as the Data Controller for personal information we collect directly from you. As the Data Controller, we are responsible for determining the purposes and means of processing personal data.
Contact details:
pearly-class
42 Greenwood Lane
Guildford, Surrey
GU1 4PQ
Email: [email protected]
Lawful Basis for Processing
We process personal data on the following lawful bases:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legitimate Interest: Where processing is necessary for our legitimate interests or those of a third party, provided your fundamental rights do not override those interests.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation.
Your Rights Under GDPR
Under the GDPR and UK GDPR, you have the following rights regarding your personal data:
Right to be Informed
You have the right to be informed about how we collect and use your personal data. This is provided through our Privacy Policy and this GDPR page.
Right of Access
You have the right to request access to your personal data. You can request a copy of the personal data we hold about you.
Right to Rectification
You have the right to have inaccurate personal data corrected or completed if it is incomplete.
Right to Erasure
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
Right to Restrict Processing
You have the right to request that we limit the way we use your data in certain circumstances.
Right to Data Portability
You have the right to obtain and reuse your personal data for your own purposes across different services.
Right to Object
You have the right to object to certain types of processing, including processing for direct marketing.
Rights Related to Automated Decision Making
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you. We do not currently engage in automated decision-making.
Exercising Your Rights
To exercise any of these rights, please contact us using the details above. We will respond to your request within one month of receipt. If your request is complex or you have made multiple requests, we may extend this period by a further two months, in which case we will inform you.
There is no fee for exercising your rights in most cases. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Data Security
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular testing and evaluation of the effectiveness of security measures
- Staff training on data protection responsibilities
- Access controls to limit who can access personal data
Data Breach Procedures
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
International Transfers
We do not routinely transfer personal data outside the United Kingdom. If such transfers become necessary, we will ensure appropriate safeguards are in place in accordance with data protection law.
Complaints
If you are not satisfied with how we handle your personal data or your request to exercise your rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Updates to This Information
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.