General Data Protection Regulation (GDPR) Compliance
Last Updated: August 23, 2024
Introduction
Hedlusk is committed to protecting your personal data and respecting your privacy rights. This GDPR Compliance Notice explains how we collect, use, store, and protect your personal information in accordance with the General Data Protection Regulation.
Data Controller
Hedlusk acts as the data controller for personal information collected through our services. You can contact us at:
Hedlusk
Holloway Hall, Court Passage
Netherton, Dudley DY1 1EX
United Kingdom
Email: ralemi@hotmail.com
Phone: +441902454771
Legal Basis for Processing
We process your personal data based on one or more of the following legal grounds:
Consent: You have given clear consent for us to process your personal data for specific purposes.
Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
Legal Obligation: Processing is necessary for us to comply with the law.
Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not overridden by your rights and interests.
Personal Data We Collect
We may collect and process the following categories of personal data:
Identity Data: Name, username, title, date of birth, and other identifiers.
Contact Data: Email address, telephone number, billing address, and delivery address.
Technical Data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our services.
Usage Data: Information about how you use our website, products, and services.
Marketing and Communications Data: Your preferences in receiving marketing from us and your communication preferences.
Transaction Data: Details about payments to and from you and other details of services you have purchased from us.
How We Use Your Personal Data
We use your personal data for the following purposes:
To provide and deliver our services to you
To process your registration and manage your account
To communicate with you about our services
To process payments and prevent fraudulent transactions
To improve our website, services, and customer experience
To send you marketing communications where you have requested or consented to receive them
To comply with legal obligations and protect our legal rights
To analyse usage patterns and optimise our services
Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights:
Right of Access
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time.
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us using the details provided above. We will respond to your request within one month. If your request is complex or you have made multiple requests, we may extend this period by two further months, in which case we will inform you and explain the reason for the delay.
Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process your personal data, whether we can achieve those purposes through other means, and the applicable legal requirements.
Data Security
We have implemented appropriate technical and organisational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
While we strive to protect your personal data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but we continuously review and enhance our security procedures.
International Data Transfers
We may transfer your personal data outside the European Economic Area. When we do so, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements. These safeguards may include:
Transferring data to countries that have been deemed to provide an adequate level of protection
Using specific contracts approved by the European Commission which give personal data the same protection it has in Europe
Transferring data to organisations that are part of Privacy Shield framework
Automated Decision Making and Profiling
We do not use automated decision making or profiling in ways that produce legal effects concerning you or similarly significantly affect you, unless we have obtained your explicit consent or it is necessary for entering into or performing a contract with you.
Third Party Data Processors
We may share your personal data with third party service providers who perform services on our behalf. These processors are contractually obligated to use your personal data only as necessary to provide the requested services and in a manner consistent with this notice and GDPR requirements.
We require all third party processors to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from a child without verification of parental consent, we will take steps to remove that information from our servers.
Complaints
You have the right to lodge a complaint with a supervisory authority if you believe we have processed your personal data in a manner that does not comply with GDPR. We would appreciate the opportunity to address your concerns before you approach a supervisory authority, so please contact us first.
Changes to This Notice
We may update this GDPR Compliance Notice from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new notice on our website and updating the date at the top of this notice.
Contact Information
If you have any questions about this GDPR Compliance Notice, how we handle your personal data, or wish to exercise any of your rights, please contact us:
Email: ralemi@hotmail.com
Phone: +441902454771
Address: Holloway Hall, Court Passage, Netherton, Dudley DY1 1EX, United Kingdom