Our Commitment to Data Protection
Loom-blossom is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page outlines how we comply with these regulations and explains your rights.
Data Controller Information
For the purposes of data protection legislation, the data controller is:
Loom-blossom Consultancy
47 Thornhill Square
London N1 1BE
United Kingdom
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
- Consent: You have given clear consent for us to process your personal data for a specific purpose
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal Obligation: Processing is necessary for us to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual's personal data which overrides those legitimate interests
Your Rights Under GDPR
Under the GDPR, you have the following rights:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of receiving a valid request.
Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete data completed.
Right to Erasure
In certain circumstances, you have the right to request that we delete your personal data. This right applies when:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent (where consent was the legal basis)
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
Right to Restriction
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transferred to another controller where technically feasible.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you.
Exercising Your Rights
To exercise any of these rights, please contact us using the details above. We will respond to your request within one month. In complex cases, we may extend this period by up to two months, but we will inform you of any extension within the first month.
There is no fee for making a request. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular testing and evaluation of security measures
- Staff training on data protection
- Access controls limiting who can view personal data
- Secure data storage and backup procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
International Data Transfers
When we transfer personal data outside the UK or European Economic Area, we ensure adequate safeguards are in place, such as:
- Transfers to countries with adequate data protection levels
- Standard contractual clauses approved by the relevant authority
- Other appropriate safeguards as recognised under applicable law
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority. In the UK, the relevant authority is:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Updates to This Information
We may update this GDPR compliance information from time to time. We will notify you of significant changes by posting a notice on our website.