GDPR Compliance
Our commitment to data protection and your rights
Our Commitment to Data Protection
cloud-kudu is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take the protection of your personal data seriously and have implemented measures to ensure your information is handled responsibly and transparently.
Data Controller
cloud-kudu acts as the data controller for personal information collected through our website and services. As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with data protection law.
Lawful Basis for Processing
We only process personal data when we have a lawful basis to do so. Our processing activities are based on:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose, such as receiving communications or submitting enquiries.
- Contract: Where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Where processing is necessary to comply with a legal obligation to which we are subject.
- Legitimate Interests: Where processing is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests do not override your fundamental rights and freedoms.
Your Data Subject Rights
Under the UK GDPR, you have several rights regarding your personal data:
Right to Be Informed
You have the right to be informed about how we collect and use your personal data. This information is provided in our Privacy Policy.
Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR).
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You have the right to request that we limit the processing of your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to the processing of your personal data in certain circumstances, including processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have rights related to automated decision-making and profiling. We do not currently use automated decision-making that produces legal or similarly significant effects.
Exercising Your Rights
To exercise any of your data protection rights, please contact us using the details below. We will respond to your request within one month. In certain circumstances, we may extend this period by a further two months, in which case we will inform you of this extension and the reasons for it.
We may ask you to verify your identity before processing your request. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Data Security
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk associated with our processing activities. These measures include:
- Encryption of data where appropriate
- Regular security assessments
- Access controls and authentication procedures
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
International Data Transfers
If we transfer your personal data outside the United Kingdom, we will ensure that appropriate safeguards are in place to protect your data. This may include transferring data to countries that have been deemed to provide an adequate level of protection, or using standard contractual clauses approved by the relevant authorities.
Complaints
If you are not satisfied with how we handle your personal data or believe we have not complied with data protection law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Contact Us
For any questions regarding our GDPR compliance or to exercise your data protection rights, please contact us:
cloud-kudu
47 Clerkenwell Road
London EC1M 5RS
United Kingdom
Email: [email protected]