Last updated: August 2024
Our Commitment to Data Protection
Basin-point is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides information about how we handle personal data in accordance with these regulations.
Data Controller
Basin-point acts as the data controller for personal information collected through this website and in the course of providing our services. As the data controller, we determine the purposes and means of processing personal data.
Contact details:
Basin-point
47 Grey Street
Newcastle upon Tyne
NE1 6EE
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by the GDPR:
Consent
When you submit an enquiry form or subscribe to communications, you provide consent for us to process your data for the stated purposes. You may withdraw consent at any time by contacting us.
Contract
When you engage our services, processing is necessary for the performance of the contract between us.
Legitimate Interests
We may process data based on our legitimate business interests, such as improving our services and communicating relevant information, provided these interests do not override your fundamental rights and freedoms.
Your Rights Under GDPR
The GDPR provides you with specific rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will respond to such requests within one month.
Right to Rectification
If you believe the personal data we hold is inaccurate or incomplete, you have the right to request correction.
Right to Erasure
In certain circumstances, you have the right to request deletion of your personal data. This right applies when the data is no longer necessary for its original purpose, when you withdraw consent, or when processing is unlawful.
Right to Restrict Processing
You may request that we limit how we use your data in certain situations, such as when you contest its accuracy or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and to transmit it to another controller where technically feasible.
Right to Object
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
Data Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit
- Regular security assessments
- Access controls limiting data access to authorised personnel
- Secure storage of physical documents
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware. Where the breach is likely to result in high risk, we will also notify affected individuals without undue delay.
Data Protection Impact Assessments
We conduct Data Protection Impact Assessments for processing activities that are likely to result in high risk to individuals, ensuring that we identify and minimise data protection risks.
International Data Transfers
If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions, to protect your data.
Supervisory Authority
If you are not satisfied with our response to any data protection concern, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We aim to respond to all legitimate requests within one month.