Our Commitment to Data Protection
tranquil-crater is committed to protecting the personal data of individuals in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We process personal data lawfully, fairly, and transparently, and we implement appropriate technical and organizational measures to ensure data security.
This statement explains how we comply with GDPR principles and outlines your rights as a data subject.
Data Controller Information
For the purposes of data protection legislation, tranquil-crater acts as the data controller for personal information collected through our website and services.
Data Controller: tranquil-crater
Address: 42 Wellington Road, Manchester M14 6EQ, United Kingdom
Email: contact@tranquil-crater.com
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: When you submit a consultation request, you provide explicit consent for us to process your personal information to deliver the services you have requested.
- Contractual Necessity: Processing is necessary to fulfill our contractual obligations when providing fuel analysis and consulting services.
- Legitimate Interests: We process certain data for legitimate business interests, such as website analytics and security, provided these interests do not override your fundamental rights and freedoms.
- Legal Obligations: We retain certain records to comply with legal and regulatory requirements, including tax and accounting obligations.
Your Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data. This allows you to understand what information we hold about you and verify that we are processing it lawfully.
Right to Rectification
You may request correction of inaccurate or incomplete personal data. We will take reasonable steps to ensure that inaccurate information is corrected or deleted.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
Right to Restriction of Processing
You may request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
Where processing is based on consent or contractual necessity and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with data protection legislation, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
ICO Contact Information:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Exercising Your Rights
To exercise any of your data subject rights, please contact us at contact@tranquil-crater.com. Include sufficient details to allow us to identify you and specify which right you wish to exercise.
We will respond to your request within one month of receipt. In complex cases or where we receive multiple requests, we may extend this period by an additional two months, in which case we will inform you of the extension and the reasons for the delay.
We do not charge a fee for processing rights requests unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse to act on the request.
Data Security Measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit and at rest
- Access controls limiting who can view personal information
- Regular security assessments and vulnerability testing
- Staff training on data protection and security practices
- Incident response procedures to address potential data breaches
- Regular backup procedures to prevent data loss
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Our standard retention periods are:
- Consultation request data: three years following project completion
- Technical usage data: twelve months
- Financial records: six years (for tax and accounting purposes)
- Marketing consent records: until consent is withdrawn or two years of inactivity
At the end of the retention period, personal data is securely deleted or anonymized.
Third-Party Processors
Where we engage third-party service providers to process personal data on our behalf, we ensure they provide sufficient guarantees of GDPR compliance. We maintain written contracts with all processors that specify the subject matter, duration, nature, and purpose of processing, as well as the obligations and rights of both parties.
We conduct due diligence on processors to verify their security measures and compliance capabilities before engagement.
International Transfers
Personal data is processed and stored within the United Kingdom. If circumstances require transfer of data to countries outside the UK or European Economic Area, we will ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or transfers to countries with adequacy decisions.
Children's Data
Our services are intended for businesses and commercial operations. We do not knowingly process personal data of children under the age of eighteen. If we become aware that we have collected data from a child without appropriate parental consent, we will delete it promptly.
Automated Decision-Making
We do not use personal data for automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals.
Updates to This Statement
We may update this GDPR Compliance Statement periodically to reflect changes in our practices or applicable legislation. The "Last updated" date indicates when the statement was most recently revised. Material changes will be communicated through a notice on our website.
Contact Us
For questions about GDPR compliance or data protection practices, or to exercise your data subject rights, contact us at:
tranquil-crater
42 Wellington Road
Manchester M14 6EQ
United Kingdom
Email: contact@tranquil-crater.com