Last updated: January 2024
Our Commitment to GDPR
trichconve is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines your rights and our obligations regarding the protection of your personal data.
Data Controller
trichconve acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing your personal data.
Contact details:
trichconve
47 Merchants Row
Bristol, BS1 4QT
United Kingdom
Email: [email protected]
Your Rights Under UK GDPR
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
Right to Rectification
You have the right to request correction of any inaccurate personal data we hold about you, and to have incomplete data completed.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for its original purpose or when you withdraw consent.
Right to Restrict Processing
You have the right to request that we limit the processing of your personal data in certain situations, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to the processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects. We do not currently make automated decisions of this nature.
Lawful Bases for Processing
We process personal data under the following lawful bases:
- Contractual necessity: Processing required to fulfil bookings and deliver services
- Legitimate interests: Processing for business purposes that do not override your rights
- Consent: Processing based on your explicit agreement, particularly for marketing
- Legal obligation: Processing required to comply with applicable laws
Data Protection Principles
We adhere to the following principles when processing personal data:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Data Security Measures
We implement appropriate technical and organisational measures to ensure data security, including:
- Secure data transmission protocols
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and inform affected individuals without undue delay.
International Data Transfers
When transferring personal data outside the UK, we ensure adequate protection through:
- Adequacy decisions by the UK government
- Standard contractual clauses approved by the ICO
- Binding corporate rules where applicable
Exercising Your Rights
To exercise any of your data protection rights, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases, this period may be extended by two further months, and we will inform you of any such extension.
Complaints
If you are unsatisfied with our handling of your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk