GDPR Policy
Our Commitment to Your Data Protection.
Last Updated: October 26, 2023
1.Our Commitment to Data Protection
CSSENTIAL ("we", "us", "our") is fully committed to protecting the privacy and personal data of our clients and website visitors in compliance with the General Data Protection Regulation (GDPR). This policy outlines our practices concerning the collection, use, and protection of personal data for individuals within the European Economic Area (EEA).
2.Data Controller
For the purpose of GDPR, the data controller is CSSENTIAL, located in the Lake District, UK. You can contact us regarding any data protection matters at [email protected].
3.Legal Basis for Processing Data
We process personal data on the following legal bases:
- Consent: Where you have given us clear consent to process your personal data for a specific purpose (e.g., by submitting our contact form).
- Contract: Where processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
- Legitimate Interest: Where processing is necessary for our legitimate interests, such as analyzing website usage to improve our services, provided these interests do not override your fundamental rights and freedoms.
4.Your Rights as a Data Subject
Under GDPR, you have several rights regarding your personal data, which we are committed to upholding:
- The Right of Access: You have the right to request a copy of the personal data we hold about you.
- The Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or incomplete.
- The Right to Erasure (The "Right to be Forgotten"): You have the right to request the deletion of your personal data, under certain conditions.
- The Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- The Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
- The Right to Object: You have the right to object to our processing of your personal data, under certain conditions.
To exercise any of these rights, please contact us at our designated email address.
5.Data Security & Retention
We implement robust technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. This includes the use of SSL encryption for data in transit and secure server environments. We will retain your personal data only for as long as is necessary for the purposes set out in this policy and to comply with our legal obligations.
6.International Data Transfers
Your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place.
7.Contact Information for Data Protection
For any questions, concerns, or requests related to your data protection and rights under GDPR, please contact our data protection representative at:
- Email: [email protected]