Our commitment to data protection under UK GDPR
comet-plover is committed to ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. As a provider of banking infrastructure services, we recognise the critical importance of data protection in the financial sector.
For the purposes of UK GDPR, the data controller is:
comet-plover
47 Finsbury Square
London EC2A 1PQ
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so. The legal bases we rely upon include:
Where you have given clear consent for us to process your personal data for specific purposes, such as receiving marketing communications or submitting enquiry forms.
Where processing is necessary for the performance of a contract to which you are party, or to take steps at your request prior to entering into a contract.
Where processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights. Our legitimate interests include:
Where processing is necessary for compliance with a legal obligation to which we are subject, such as financial regulations or tax requirements.
Under UK GDPR, you have the following rights regarding your personal data:
You have the right to request copies of the personal data we hold about you. We will provide this information free of charge within one month of your request.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, in certain circumstances.
You have the right to object to processing of your personal data where we are relying on legitimate interests as our lawful basis.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
When we transfer personal data outside the United Kingdom, we ensure that appropriate safeguards are in place, such as:
We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to individuals' rights and freedoms, particularly when implementing new technologies or processing sensitive data.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
For any questions regarding our GDPR compliance or to exercise your data protection rights, please contact us at [email protected].