Your information
What we collect, why we use it and your choices.
We only use personal data where there is a clear reason to do so. This Notice explains what information may be collected when you use The GDPR Studio and how you can stay in control.
1
Who we are
The GDPR Studio Ltd is the controller of personal data collected through this website and in connection with our services.
Registered office:
Suite A, 82 James Carter Road, Mildenhall, IP28 7DE
Company number: 13546270
Email: letstalk@thegdprstudio.co.uk
We have not appointed a Data Protection Officer.
For privacy questions or data rights requests, email letstalk@thegdprstudio.co.uk and use the subject line Privacy Request.
2
Personal data we collect
We only collect personal data that is relevant to our business, services and communications with you.
Information you provide directly
Name, email address and telephone number.
Business or company name, business address, job title or role.
Information included in an enquiry, live chat message, booking, application or form.
Booking details, intake-form information, correspondence and service-administration information.
Invoice details and payment-status information.
Forms, bookings and sensitive information
When you download a resource, join a waitlist, make an enquiry, apply for support or book a Clarity Call, we may collect the information requested in the relevant form.
Some fields may be optional. Please only provide information necessary for your enquiry, booking or support request.
Please avoid unnecessary sensitive information.
Do not include health information, criminal allegations, trade union membership, religious beliefs, sexual orientation or similar information unless we have specifically asked for it and it is necessary for the support requested.
Please also avoid including identifiable information about staff, customers, clients or other individuals unless it is necessary and relevant.
Information collected automatically
Our website hosting, security and technical systems may collect limited technical information when you visit the website.
IP address, browser type and device type.
Operating system, pages requested and date or time of access.
Technical security, error-log and troubleshooting information.
We use this information for website operation, security, troubleshooting and preventing misuse.
Website analytics
We use privacy-friendly, cookieless website analytics to understand aggregated website usage, such as which pages are visited and how people find the website.
This analytics does not use cookies or track you across websites.
3
How we use your data and our lawful bases
UK data protection law requires us to have a lawful basis for using personal data. The main ways we use information are set out below.
Responding to enquiries and live chat messages
We use your name, email address, chat messages, enquiry content and correspondence to respond to questions and manage communications with you.
Lawful basis: Legitimate interests, running and developing our business, responding to enquiries and providing useful support.
Providing requested resources
We use your name, email address and resource-download details to send the checklist, guide, resource or information you requested.
Lawful basis: Consent or legitimate interests, depending on how the resource is requested and delivered.
Managing bookings and paid services
We use contact details, business details, booking information, intake information, correspondence, invoice details and payment status to arrange and deliver Clarity Calls, assess Clarity Sprint applications and manage agreed support.
Lawful basis: Contract, where processing is necessary to take steps at your request before entering into a contract or to provide an agreed service.
Business administration and legal obligations
We use contact details, correspondence, invoices, payments and service records to manage our business, meet accounting obligations and protect our legal position where needed.
Lawful basis: Legitimate interests and legal obligation.
Automated decision-making
We do not use personal data to make solely automated decisions that have legal or similarly significant effects on you.
4
Marketing choices
Where you download a resource or complete a form, we may ask whether you would like to receive occasional GDPR guidance, resources and updates from The GDPR Studio.
Marketing consent is separate from requesting a free resource or making an enquiry. You do not need to agree to marketing to receive a requested checklist, guide or response.
Where you opt in, you can withdraw consent at any time.
We may also contact relevant business contacts about services that may be of legitimate professional interest, where permitted by law.
Every marketing email will include a clear way to unsubscribe.
5
Cookies and similar technologies
We use cookies and similar technologies to make the website work and to provide optional features, such as live chat.
Some cookies are strictly necessary for the website to function.
Optional cookies support tools such as live chat and will only be used if you choose to allow them.
Cookieless website analytics does not use cookies or track you across websites.
You can manage your cookie preferences through our cookie banner or by selecting the Cookie Policy link on the website.
6
Who we share data with
We may share personal data with trusted service providers where this is necessary to operate our website, manage our business or provide services to you.
Website hosting, website platform and website-maintenance providers.
Microsoft 365 email and business-administration systems.
Microsoft Bookings and Microsoft Teams for appointments and video meetings.
Zoho Forms and Zoho CRM for forms, resource delivery, enquiries and contact management.
Tidio for live chat functionality.
Mettle and Payit, or other relevant payment and invoice providers.
Accountants, legal advisers, insurers or other professional advisers where required.
Regulators, law-enforcement bodies or public authorities where we are legally required to share information.
We do not sell your personal data.
Some providers process data on our behalf. Others, such as payment providers or professional advisers, may act as independent controllers for their own legal and regulatory purposes.
7
International transfers
Some of our service providers may process personal data outside the United Kingdom.
Where this happens, we take appropriate steps to ensure personal data is protected in line with UK data protection law.
UK adequacy regulations.
The UK International Data Transfer Agreement.
The UK Addendum to the European Commission’s Standard Contractual Clauses.
Other appropriate safeguards permitted by law.
Contact us if you would like more information about safeguards used for a particular provider.
8
How long we keep your data
We keep personal data only for as long as reasonably necessary for the purpose it was collected, including to meet legal, accounting or reporting obligations.
General enquiries and live-chat records: up to 24 months after the last meaningful contact.
Checklist, guide and resource-download records: up to 24 months after collection, unless you remain subscribed to marketing communications.
Marketing records: until you unsubscribe, withdraw consent or the information is no longer relevant.
Booking, service-delivery and client-support records: up to 6 years after the service ends.
Invoices, payment records and accounting records: up to 6 years after the end of the relevant accounting period.
Applications that do not proceed: normally up to 24 months after the final communication.
We may retain information for longer where necessary to establish, exercise or defend legal claims, or where the law requires us to do so.
9
Your rights
You have rights over your personal data. Depending on the circumstances, these may include the right to:
request access to your personal data;
ask us to correct inaccurate or incomplete personal data;
request deletion of your personal data;
object to certain processing;
ask us to restrict certain processing;
withdraw consent where we rely on consent;
request data portability in certain circumstances; and
complain to the Information Commissioner’s Office.
To make a request:
Email letstalk@thegdprstudio.co.uk
Subject line: Privacy Request
We may need to verify your identity before acting on a request.
10
Complaints
We would appreciate the opportunity to address any concern first. Please contact us at letstalk@thegdprstudio.co.uk if you are unhappy with how we have handled your personal data.
You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator.
ICO telephone: 0303 123 1113
11
Links to other websites
Our website may contain links to external websites or third-party services.
We are not responsible for the privacy practices, content or security of those websites. Please read their privacy information before providing personal data.
12
Changes to this Privacy Notice
We may update this Privacy Notice from time to time.
Any updated version will be published on this page, and the “Last updated” date will show when this Notice was most recently revised.