GDPR Compliance
Your data protection rights under the UK General Data Protection Regulation
Our Commitment to Data Protection
Meadow Kestrel Ltd is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains your rights and how we protect your personal data.
Data Controller
Meadow Kestrel Ltd acts as the data controller for personal information collected through our website and services. This means we determine how and why your personal data is processed.
Contact Details:
Meadow Kestrel Ltd
47 Thornbury Gardens
Bristol BS8 2QP
United Kingdom
Email: [email protected]
Your Rights Under UK GDPR
Right to Be Informed
You have the right to know how we collect and use your personal data. Our Privacy Policy provides detailed information about our data practices.
Right of Access
You can request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond within one month of receiving your request.
Right to Rectification
If any personal data we hold is inaccurate or incomplete, you have the right to have it corrected. Contact us with the correct information and we will update our records.
Right to Erasure
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances:
- The data is no longer necessary for its original purpose
- You withdraw consent and there is no other legal basis
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Note: We may need to retain some data for legal or contractual obligations.
Right to Restrict Processing
You can request that we limit how we use your data while:
- The accuracy of data is being verified
- We assess an objection you have made
- Processing is unlawful but you do not want deletion
- We no longer need the data but you require it for legal claims
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you can request your data in a commonly used, machine-readable format to transfer to another service.
Right to Object
You can object to processing based on legitimate interests or direct marketing at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
Rights Related to Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. If this changes, you will have the right to human intervention.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with your request. Please provide:
- Your full name
- Email address associated with your account
- Details of your request
- Any relevant information to help us locate your data
We will verify your identity before processing requests. There is no fee for most requests, though we may charge a reasonable fee for manifestly unfounded or excessive requests.
Response Times
We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by up to two additional months. We will inform you of any extension and the reasons for it.
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: Where you have given clear consent for specific purposes
- Contract: Where processing is necessary to perform our contract with you
- Legal Obligation: Where we must comply with the law
- Legitimate Interests: Where processing is necessary for our legitimate business interests, provided these do not override your rights
Data Protection Principles
We adhere to the UK GDPR principles, ensuring personal data is:
- Processed lawfully, fairly, and transparently
- Collected for specified, explicit, and legitimate purposes
- Adequate, relevant, and limited to what is necessary
- Accurate and kept up to date
- Retained only as long as necessary
- Processed securely with appropriate technical measures
International Data Transfers
When we transfer personal data outside the UK, we ensure adequate protection through:
- Transfers to countries with adequacy decisions
- Standard Contractual Clauses approved by the ICO
- Other approved transfer mechanisms
Data Breach Procedures
We have procedures to detect, report, and investigate personal data breaches. Where a breach is likely to result in high risk to your rights and freedoms, we will notify you without undue delay.
Complaints
If you are dissatisfied with how we handle your personal data, you have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
We encourage you to contact us first so we can address your concerns directly.
Updates to This Information
We may update this GDPR information as our practices or legal requirements change. Please check this page periodically for updates.