Our Commitment to Data Protection

fox-leap is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We process personal data lawfully, fairly, and transparently.

This page explains our GDPR compliance measures and your rights under data protection law.

Data Controller Information

Data Controller: fox-leap
Address: 47 Whitechapel Road, London E1 1DU, United Kingdom
Contact: [email protected]

As the data controller, we determine how and why your personal data is processed. We are responsible for ensuring that data processing complies with applicable data protection laws.

Lawful Bases for Processing

We process personal data only when we have a valid lawful basis. The lawful bases we rely on include:

Contract Performance

We process your data to fulfill our contractual obligations when you request services, enter into service contracts, or make purchases from us. This includes scheduling visits, performing repairs, and maintaining service records.

Legitimate Interests

We have legitimate business interests in:

We balance these interests against your rights and only process data where our legitimate interests do not override your fundamental rights and freedoms.

Legal Obligation

We process certain data to comply with legal requirements including tax regulations, financial record-keeping obligations, and health and safety laws.

Consent

Where required by law, we obtain your explicit consent before processing your data. You have the right to withdraw consent at any time.

Your GDPR Rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of Access

You can request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this information free of charge within one month of your request.

Right to Rectification

If your personal data is inaccurate or incomplete, you can request that we correct or complete it. We will make corrections within one month of your request.

Right to Erasure

You can request deletion of your personal data in certain circumstances, including:

Note that we may need to retain certain data to comply with legal obligations or establish legal claims.

Right to Restriction of Processing

You can request that we restrict processing of your data in specific situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

For data processed based on consent or contract performance, you can request that we provide your data in a structured, commonly used, machine-readable format or transmit it directly to another controller.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us:

Email: [email protected]
Subject Line: GDPR Data Rights Request

In your request, please specify:

We may need to verify your identity before processing your request. We will respond within one month, or two additional months for complex requests.

Data Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

We maintain incident response procedures to detect, investigate, and respond to potential data breaches promptly.

International Data Transfers

We primarily process data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:

We will inform you if your data will be transferred internationally and explain the safeguards in place.

Data Protection Impact Assessments

For processing activities that are likely to result in high risk to individuals' rights and freedoms, we conduct Data Protection Impact Assessments (DPIAs) to:

Children's Privacy

Our services are directed at businesses, not individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate consent, we will take steps to delete that information.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Our retention periods are detailed in our Privacy Policy.

When data is no longer required, we securely delete or anonymize it in accordance with our data retention and disposal procedures.

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will notify you of significant changes through our website or direct communication where appropriate.

Questions and Complaints

If you have questions about our GDPR compliance or wish to exercise your rights, contact us at [email protected].

If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom

Website: ico.org.uk
Helpline: 0303 123 1113