Last updated: October 2024
Our Commitment to Data Protection
Ravine-caribou is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we handle your personal information and outlines your rights under data protection law.
Data Controller
Ravine-caribou is the data controller for the personal information we collect and process. This means we are responsible for deciding how we hold and use personal information about you.
Contact details:
Ravine-caribou
47 Botanic Avenue
Belfast BT7 1JL
Northern Ireland
Email: [email protected]
Personal Data We Process
We may collect and process the following categories of personal data:
- Identity Data: Name, title
- Contact Data: Email address, postal address
- Service Data: Information about services requested or provided
- Technical Data: IP address, browser type, device information
- Usage Data: Information about how you use our website
Lawful Basis for Processing
We only process your personal data when we have a lawful basis to do so. The lawful bases we rely on include:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights
Your Rights Under UK GDPR
Under the UK GDPR, you have the following rights in relation to your personal data:
Right to Be Informed
You have the right to be informed about how we collect and use your personal data. This information is provided through this page and our Privacy Policy.
Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a "subject access request". We will respond to such requests within one month.
Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete data.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, or where you withdraw your consent.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or object to our processing of it.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to the processing of your personal data in certain circumstances, including processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
How to Exercise Your Rights
To exercise any of these rights, please contact us using the details provided above. We may need to verify your identity before processing your request. We will respond to your request within one month, although this period may be extended by a further two months where necessary, taking into account the complexity and number of requests.
There is no fee required to exercise your rights in most circumstances. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Data Security
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit and at rest where appropriate
- Regular security assessments and updates
- Access controls limiting who can access personal data
- Staff training on data protection
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The retention period may vary depending on the context and our legal obligations.
International Transfers
If we transfer your personal data outside the United Kingdom, we will ensure that appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements.
Data Breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Changes to This Information
We may update this GDPR information from time to time. We will notify you of any significant changes by posting the updated information on our website with a new "Last updated" date.