Effective date: January 2024

Our Commitment to GDPR Compliance

Branch-cypress is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our data protection responsibilities seriously and have implemented comprehensive measures to ensure the lawful, fair, and transparent processing of personal data.

Data Controller Information

Branch-cypress acts as the data controller for personal information collected through our website and service delivery. As the data controller, we determine the purposes and means of processing personal data and are responsible for ensuring compliance with data protection legislation.

Contact details:
Email: [email protected]
Address: Heritage House, 14 Church Lane, Stow-on-the-Wold, Gloucestershire GL54 1AB

Lawful Basis for Processing

We process personal data only where we have a lawful basis to do so. The legal bases we rely upon include:

Consent

Where you have given explicit consent for us to process your personal data for specific purposes, such as subscribing to communications or agreeing to cookies. You may withdraw consent at any time by contacting us.

Contractual Necessity

Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes processing data to deliver heritage services you have booked.

Legitimate Interests

Where processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your interests, rights, and freedoms. Our legitimate interests include operating and improving our business, fraud prevention, and security.

Legal Obligation

Where processing is necessary for compliance with a legal obligation to which we are subject, such as retaining financial records for tax purposes.

Your Rights Under GDPR

The UK GDPR provides you with the following rights regarding your personal data:

Right to Be Informed

You have the right to be informed about the collection and use of your personal data. This GDPR Statement and our Privacy Policy fulfil this obligation.

Right of Access

You have the right to request a copy of the personal data we hold about you. We will respond to access requests within one month of receipt.

Right to Rectification

You have the right to request correction of personal data that is inaccurate or incomplete. We will respond within one month of receiving a rectification request.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, or where you withdraw consent.

Right to Restrict Processing

You have the right to request restriction of processing in certain circumstances, such as while we verify the accuracy of data following a rectification request.

Right to Data Portability

Where we process personal data based on consent or contract, and processing is carried out by automated means, you have the right to receive your data in a structured, commonly used, machine-readable format.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.

Rights Related to Automated Decision Making

You have rights related to automated decision-making and profiling. We do not currently use automated decision-making processes that produce legal or similarly significant effects.

Data Protection Measures

We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of security measures
  • Staff training on data protection responsibilities
  • Access controls limiting data access to authorised personnel
  • Procedures for handling data breaches

Data Breach Procedures

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

International Data Transfers

We primarily store and process personal data within the United Kingdom. Where we transfer personal data to countries outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) where processing is likely to result in a high risk to individuals' rights and freedoms, particularly when using new technologies or processing sensitive data.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us using the details provided above. We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.

We do not charge a fee for processing most requests. However, we may charge a reasonable fee if requests are manifestly unfounded or excessive.

Complaints

If you believe we have not handled your personal data in accordance with data protection law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Website: ico.org.uk
Telephone: 0303 123 1113

We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.

Updates to This Statement

We review and update this GDPR Statement periodically to reflect changes in our data processing activities or legal requirements. The effective date at the top of this page indicates when this statement was last revised.