GDPR Compliance
Your data protection rights under the General Data Protection Regulation
Our Commitment to GDPR
aspenlark is committed to complying with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We take data protection seriously and have implemented measures to ensure your personal data is handled lawfully, fairly, and transparently.
Data Controller
aspenlark acts as the data controller for personal information collected through our website and course enrolment process. We determine the purposes and means of processing personal data.
Contact details:
aspenlark
47 Queen Square
Bristol BS1 4LH
United Kingdom
[email protected]
Lawful Basis for Processing
We process your personal data under the following lawful bases:
- Contract: Processing necessary for the performance of a contract with you (course enrolment and delivery)
- Legitimate Interests: Processing necessary for our legitimate business interests (improving our services, security)
- Consent: Where you have given clear consent for us to process your data for a specific purpose
- Legal Obligation: Processing necessary for compliance with a legal obligation
Your Rights Under GDPR
Under the GDPR, you have the following rights:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate or incomplete data.
- Right to Erasure: You can request that we delete your personal data in certain circumstances.
- Right to Restrict Processing: You can request that we limit how we use your data.
- Right to Data Portability: You can request to receive your data in a structured, commonly used format.
- Right to Object: You can object to certain types of processing, such as direct marketing.
- Rights Related to Automated Decision Making: You have rights regarding automated decision-making and profiling.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Course enrolment records are retained for seven years after course completion for legal and accounting purposes. Marketing consent records are retained until consent is withdrawn.
International Transfers
We do not routinely transfer personal data outside the United Kingdom. If such transfers become necessary, we will ensure appropriate safeguards are in place in accordance with GDPR requirements.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encrypted data transmission, secure server infrastructure, and regular security assessments.
Data Breach Procedures
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. We will also inform affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month. There is no fee for most requests, though we may charge a reasonable fee for repetitive, unfounded, or excessive requests.
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
ico.org.uk