Data Protection
This page summarises how we approach data protection under UK GDPR and the Data Protection Act 2018. It sits alongside our privacy policy.
LEGAL NOTICE: These documents are website templates and should be reviewed and approved by the company's UK legal adviser before publication.
Data minimisation
Our website forms only ask for what is needed to prepare a quotation. Passport, identity and payment details are never requested through website forms.
Consent records
Where we rely on consent — for marketing or for non-essential cookies — we keep a record of what was consented to and when, and make it easy to withdraw.
Requests from individuals
Send subject access or other rights requests to [dataprotection@example.co.uk]. We will respond within one month, or explain if an extension applies.
Personal data breaches
We maintain an internal process for recording breaches and, where the threshold is met, reporting to the ICO within 72 hours and informing affected individuals.
Registration
[Confirm the company's ICO registration reference and insert it here once registered.]
Last updated: [date to be set on publication]. Questions about this document can be sent to [enquiries@example.co.uk].
Still have a question?
Our UK team can talk you through how our packages, payments and policies work.