Last Updated: January 2024
Toree Diffi Designs is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines your rights and how we ensure compliance.
Toree Diffi Designs is the data controller responsible for your personal data. If you have any questions about how we handle your data, please contact us at:
Email: [email protected]
Address: Unit 7, Cotswold Business Park, Cirencester, GL7 1YG
You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond to your request within one month.
If you believe the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it.
Also known as the "right to be forgotten", you can request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You can request that we limit how we use your personal data while we verify its accuracy or consider your objection to its use.
You have the right to receive your personal data in a structured, commonly used format and to transfer it to another organisation.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
We do not use automated decision-making or profiling that produces legal effects concerning you.
To exercise any of these rights, please contact us at [email protected]. We will verify your identity before processing your request and respond within one month. If your request is complex, we may extend this period by two months, but we will inform you of this.
We process your personal data only when we have a lawful basis to do so:
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
We do not routinely transfer your personal data outside the United Kingdom. If such a transfer becomes necessary, we will ensure appropriate safeguards are in place.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and notify the Information Commissioner's Office (ICO) within 72 hours.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Telephone: 0303 123 1113
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.