Information on this site is advertising in nature.

Last updated: January 2024

Our Commitment to Data Protection

racchcondi is fully committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We recognise the importance of protecting your personal information and have implemented robust measures to ensure your data is handled securely and lawfully.

Data Controller Information

For the purposes of data protection legislation, racchcondi is the data controller responsible for your personal information. Our contact details are:

racchcondi
18 Cathedral Road
Cardiff CF11 9LJ
United Kingdom

Email: [email protected]

Your Rights Under UK GDPR

The UK GDPR provides you with specific rights regarding your personal data. We are committed to helping you exercise these rights:

Right to Be Informed

You have the right to be informed about how we collect and use your personal data. This is provided through this GDPR notice and our Privacy Policy, which explain what data we collect, why we collect it, and how we use it.

Right of Access

You have the right to request a copy of the personal information we hold about you. This is commonly known as a Subject Access Request (SAR). We will respond to valid requests within one month and provide the information free of charge in most cases.

Right to Rectification

If you believe any personal information we hold about you is inaccurate or incomplete, you have the right to request that we correct it. We will make corrections within one month of receiving your request.

Right to Erasure

Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances, such as:

Please note that we may need to retain certain information for legal or regulatory purposes.

Right to Restrict Processing

You have the right to request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or object to our processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller, where technically feasible.

Right to Object

You have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing purposes. If you object to direct marketing, we will stop processing your data for that purpose immediately.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.

Lawful Basis for Processing

We process personal data under the following lawful bases as defined by UK GDPR:

Special Category Data

When handling sensitive data such as health information for disability benefit claims, we rely on your explicit consent and apply enhanced security measures. We only collect such data when it is necessary for providing our services to you.

Data Minimisation

We adhere to the principle of data minimisation, meaning we only collect and process personal data that is necessary for the specific purpose it is collected for. We do not collect excessive or irrelevant information.

Data Accuracy

We take reasonable steps to ensure that personal data we hold is accurate and up to date. We encourage you to inform us if any of your details change so we can update our records accordingly.

Storage Limitation

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our data retention policy specifies retention periods for different categories of data.

Data Security

We have implemented appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or damage. These measures include:

International Transfers

We primarily process and store data within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place as required by UK GDPR, such as adequacy decisions or standard contractual clauses.

Data Breach Procedures

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and inform affected individuals without undue delay where required.

Exercising Your Rights

To exercise any of your rights under UK GDPR, please contact us using the details above. We may need to verify your identity before processing your request. We will respond to valid requests within one month, though this may be extended by two months for complex requests.

Making a Complaint

If you are not satisfied with how we handle your personal data or respond to your rights requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF

Website: ico.org.uk

Updates to This Notice

We may update this GDPR compliance notice from time to time. We will post any changes on this page and update the "Last updated" date. We encourage you to review this notice periodically.