This content is advertising

Our Commitment to GDPR

aspenlark is committed to complying with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We take data protection seriously and have implemented measures to ensure your personal data is handled lawfully, fairly, and transparently.

Data Controller

aspenlark acts as the data controller for personal information collected through our website and course enrolment process. We determine the purposes and means of processing personal data.

Contact details:
aspenlark
47 Queen Square
Bristol BS1 4LH
United Kingdom
[email protected]

Lawful Basis for Processing

We process your personal data under the following lawful bases:

  • Contract: Processing necessary for the performance of a contract with you (course enrolment and delivery)
  • Legitimate Interests: Processing necessary for our legitimate business interests (improving our services, security)
  • Consent: Where you have given clear consent for us to process your data for a specific purpose
  • Legal Obligation: Processing necessary for compliance with a legal obligation

Your Rights Under GDPR

Under the GDPR, you have the following rights:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request that we correct any inaccurate or incomplete data.
  • Right to Erasure: You can request that we delete your personal data in certain circumstances.
  • Right to Restrict Processing: You can request that we limit how we use your data.
  • Right to Data Portability: You can request to receive your data in a structured, commonly used format.
  • Right to Object: You can object to certain types of processing, such as direct marketing.
  • Rights Related to Automated Decision Making: You have rights regarding automated decision-making and profiling.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Course enrolment records are retained for seven years after course completion for legal and accounting purposes. Marketing consent records are retained until consent is withdrawn.

International Transfers

We do not routinely transfer personal data outside the United Kingdom. If such transfers become necessary, we will ensure appropriate safeguards are in place in accordance with GDPR requirements.

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encrypted data transmission, secure server infrastructure, and regular security assessments.

Data Breach Procedures

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. We will also inform affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month. There is no fee for most requests, though we may charge a reasonable fee for repetitive, unfounded, or excessive requests.

Complaints

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
ico.org.uk