GDPR Compliance
Our commitment to data protection
General Data Protection Regulation
wraithslayer-hollow is committed to complying with the General Data Protection Regulation (GDPR) and protecting the personal data of individuals in the European Union and United Kingdom.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract: Processing necessary to perform our educational services
- Consent: Where you have given explicit consent for specific purposes
- Legitimate Interests: For improving our services and communicating with you about relevant programmes
- Legal Obligation: Where processing is required to comply with legal requirements
Your GDPR Rights
Under GDPR, you have the following rights:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format.
Right to Rectification
You can request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
You may request deletion of your personal data in certain circumstances, including when it is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You can request that we limit how we use your personal data in certain situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects.
Data Protection Officer
For questions about data protection or to exercise your GDPR rights, you may contact our data protection representative at [email protected].
How to Exercise Your Rights
To exercise any of your GDPR rights, please submit a written request to:
Email: [email protected]
Address: Cathedral Road, Cardiff CF11 9HA, United Kingdom
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of such extension.
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls limiting who can view personal data
- Staff training on data protection responsibilities
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay.
International Data Transfers
We primarily process data within the United Kingdom. If we transfer data outside the UK or EU, we ensure appropriate safeguards are in place as required by GDPR.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom.
ICO Website: ico.org.uk
Updates to This Notice
We may update this GDPR compliance notice to reflect changes in our data processing practices or legal requirements. We will notify you of significant changes.