GDPR Compliance
How we comply with UK GDPR requirements
Our Commitment to Data Protection
fox-leap is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We process personal data lawfully, fairly, and transparently.
This page explains our GDPR compliance measures and your rights under data protection law.
Data Controller Information
Data Controller: fox-leap
Address: 47 Whitechapel Road, London E1 1DU, United Kingdom
Contact: [email protected]
As the data controller, we determine how and why your personal data is processed. We are responsible for ensuring that data processing complies with applicable data protection laws.
Lawful Bases for Processing
We process personal data only when we have a valid lawful basis. The lawful bases we rely on include:
Contract Performance
We process your data to fulfill our contractual obligations when you request services, enter into service contracts, or make purchases from us. This includes scheduling visits, performing repairs, and maintaining service records.
Legitimate Interests
We have legitimate business interests in:
- Maintaining service history records to inform future maintenance recommendations
- Communicating with clients about scheduled services and follow-up support
- Improving our services based on feedback and usage patterns
- Detecting and preventing fraud or misuse of our services
We balance these interests against your rights and only process data where our legitimate interests do not override your fundamental rights and freedoms.
Legal Obligation
We process certain data to comply with legal requirements including tax regulations, financial record-keeping obligations, and health and safety laws.
Consent
Where required by law, we obtain your explicit consent before processing your data. You have the right to withdraw consent at any time.
Your GDPR Rights
Under UK GDPR, you have the following rights regarding your personal data:
Right of Access
You can request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this information free of charge within one month of your request.
Right to Rectification
If your personal data is inaccurate or incomplete, you can request that we correct or complete it. We will make corrections within one month of your request.
Right to Erasure
You can request deletion of your personal data in certain circumstances, including:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent on which processing is based
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Note that we may need to retain certain data to comply with legal obligations or establish legal claims.
Right to Restriction of Processing
You can request that we restrict processing of your data in specific situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
For data processed based on consent or contract performance, you can request that we provide your data in a structured, commonly used, machine-readable format or transmit it directly to another controller.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us:
Email: [email protected]
Subject Line: GDPR Data Rights Request
In your request, please specify:
- Which right you wish to exercise
- Your full name and contact information
- Details to help us locate your data (such as service dates or reference numbers)
We may need to verify your identity before processing your request. We will respond within one month, or two additional months for complex requests.
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data both in transit and at rest
- Regular security testing and vulnerability assessments
- Access controls limiting data access to authorized personnel only
- Staff training on data protection obligations and security practices
- Incident response procedures for potential data breaches
- Regular backups with secure storage
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay if the breach poses a high risk
- Document all data breaches, including facts, effects, and remedial actions taken
We maintain incident response procedures to detect, investigate, and respond to potential data breaches promptly.
International Data Transfers
We primarily process data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:
- Transfers to countries with adequacy decisions from the UK government
- Standard contractual clauses approved by the UK authority
- Other legally recognized transfer mechanisms
We will inform you if your data will be transferred internationally and explain the safeguards in place.
Data Protection Impact Assessments
For processing activities that are likely to result in high risk to individuals' rights and freedoms, we conduct Data Protection Impact Assessments (DPIAs) to:
- Identify and assess risks to personal data
- Determine measures to mitigate those risks
- Document our decision-making process
- Consult with the ICO where necessary
Children's Privacy
Our services are directed at businesses, not individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate consent, we will take steps to delete that information.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Our retention periods are detailed in our Privacy Policy.
When data is no longer required, we securely delete or anonymize it in accordance with our data retention and disposal procedures.
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will notify you of significant changes through our website or direct communication where appropriate.
Questions and Complaints
If you have questions about our GDPR compliance or wish to exercise your rights, contact us at [email protected].
If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
Helpline: 0303 123 1113