Your data protection rights under UK GDPR
gentle-lynx is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we comply with these regulations and outlines your rights as a data subject.
gentle-lynx acts as the data controller for personal information collected through this website and our services. We determine the purposes and means of processing your personal data.
Contact details:
gentle-lynx
47 Ecclesall Road
Sheffield, S11 8PR
United Kingdom
Email: [email protected]
We process personal data under the following lawful bases:
When you enrol in a course, we process your data to fulfil our contractual obligations, including registration, course delivery, and related communications.
We may process data for our legitimate business interests, such as improving our services, provided this does not override your rights and freedoms.
Where required, we obtain your explicit consent before processing certain types of data. You may withdraw consent at any time.
We process data where necessary to comply with legal requirements, such as financial record-keeping obligations.
Under UK GDPR, you have the following rights:
You have the right to request a copy of the personal data we hold about you. We will respond to your request within one month.
You can request that we correct any inaccurate or incomplete personal data.
You can request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You can request that we limit the processing of your data in specific situations.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You can object to processing based on legitimate interests or for direct marketing purposes.
We do not make decisions based solely on automated processing that significantly affect you.
To exercise any of these rights, please contact us at [email protected] with your request. We may need to verify your identity before processing your request.
We will respond to all legitimate requests within one month. If your request is complex or we receive numerous requests, we may extend this period by a further two months, and we will notify you accordingly.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
We primarily store and process data within the United Kingdom. If any data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours where feasible. If the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
United Kingdom
Website: ico.org.uk
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.