Our commitment to data protection under UK GDPR
Last updated: January 2024
dapper-tale is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities as a data controller seriously and have implemented appropriate measures to ensure the protection of personal data.
dapper-tale acts as the data controller for personal information collected through our website and educational services. Our contact details are:
dapper-tale
47 Whiteladies Road
Clifton, Bristol BS8 2LY
United Kingdom
Email: [email protected]
In accordance with UK GDPR, we ensure that personal data is:
As a data subject, you have the following rights:
You have the right to request a copy of the personal information we hold about you. We will respond to your request within one month of receipt.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it.
In certain circumstances, you have the right to request that we delete your personal data. This applies when the data is no longer necessary for its original purpose, you withdraw consent, or there is no overriding legitimate interest for continued processing.
You may request that we limit how we use your personal data while we verify its accuracy, assess the legitimacy of our processing, or consider your objection to processing.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You have the right to object to processing based on legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.
To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases or where we receive numerous requests, we may extend this by up to two months, but we will inform you of any extension within the first month.
We may ask you to verify your identity before processing your request to ensure the security of your personal data.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
We do not routinely transfer personal data outside the United Kingdom. Should any transfer be necessary, we will ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
If you are dissatisfied with how we have handled your personal data or your rights request, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated revision date.