Advertising Content

Last Updated: January 2024

Our Commitment to Data Protection

dawn-ocelot Ltd is committed to ensuring that all personal data processing activities comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines our approach to data protection and explains your rights as a data subject.

Key Principles We Follow

In accordance with Article 5 of the UK GDPR, we adhere to the following data protection principles:

Lawfulness, Fairness, and Transparency

We process personal data lawfully and fairly, providing clear information about how we use your data. Our Privacy Policy and this compliance page aim to be transparent about our data practices.

Purpose Limitation

We collect personal data for specified, explicit, and legitimate purposes. We do not process your data in ways that are incompatible with those original purposes without informing you.

Data Minimisation

We only collect personal data that is necessary for the purposes we have identified. We regularly review our data collection practices to ensure we are not gathering excessive information.

Accuracy

We take reasonable steps to ensure personal data is accurate and up to date. Members can update their information through the member portal or by contacting our support team.

Storage Limitation

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our retention schedule is detailed in our Privacy Policy.

Integrity and Confidentiality

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction.

Your Rights Under UK GDPR

The UK GDPR grants you several rights regarding your personal data:

Right of Access (Article 15)

You have the right to obtain confirmation that your data is being processed and to access a copy of your personal data. We will respond to access requests within one month.

Right to Rectification (Article 16)

If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will make corrections promptly upon verification.

Right to Erasure (Article 17)

Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the original purpose or when you withdraw consent.

Right to Restrict Processing (Article 18)

You may request that we limit how we process your data in specific situations, such as while we verify accuracy or consider an objection to processing.

Right to Data Portability (Article 20)

Where processing is based on consent or contract performance and carried out by automated means, you have the right to receive your data in a structured, commonly used format.

Right to Object (Article 21)

You have the right to object to processing based on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that significantly affect you. Our fraud detection systems involve human oversight before any action is taken.

How to Exercise Your Rights

To exercise any of your data protection rights, please submit a request to:

Email: [email protected]
Post: Data Protection Officer, dawn-ocelot Ltd, 47 Victoria Street, Birmingham, B1 3PE

We may need to verify your identity before processing your request. We will respond within one month, though this period may be extended by two months for complex requests.

Lawful Bases for Processing

We rely on the following lawful bases for processing personal data:

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) when introducing new processing activities that are likely to result in high risk to individuals. This ensures we identify and mitigate privacy risks before they materialise.

Data Breach Procedures

We maintain procedures for detecting, reporting, and investigating personal data breaches. In the event of a breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and inform affected individuals without undue delay.

International Data Transfers

When we transfer personal data outside the UK, we ensure appropriate safeguards are in place. These may include:

Our Data Protection Officer

While not legally required to appoint a DPO, we have designated a data protection lead responsible for overseeing compliance. Contact them at [email protected] for any data protection concerns.

Supervisory Authority

If you are dissatisfied with our handling of your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113

Updates to This Information

We review our data protection practices regularly and may update this page to reflect changes in our operations or legal requirements. Significant changes will be communicated to members directly.