Last updated: January 2024
Our Commitment to Data Protection
noble-canopy is fully committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take your privacy seriously and have implemented robust measures to protect your personal data.
Data Controller Information
For the purposes of data protection legislation, the data controller is:
noble-canopy
47 Westbury Road
London, SW12 8PH
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by the UK GDPR:
Consent (Article 6(1)(a))
When you submit an enquiry form or subscribe to communications, you provide explicit consent for us to process your data for the stated purposes. You may withdraw consent at any time by contacting us.
Contract Performance (Article 6(1)(b))
Processing necessary for the performance of a contract with you, including providing installation services, scheduling appointments, and ongoing support.
Legitimate Interests (Article 6(1)(f))
Processing necessary for our legitimate business interests, such as improving our services and website functionality, provided these interests are not overridden by your rights.
Legal Obligation (Article 6(1)(c))
Processing necessary to comply with legal obligations, including tax and accounting requirements.
Your Data Protection Rights
Under the UK GDPR, you have the following rights:
Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you. We will respond to your request within one month.
Right to Rectification (Article 16)
You have the right to request correction of any inaccurate personal data we hold about you.
Right to Erasure (Article 17)
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing (Article 18)
You have the right to request that we limit how we use your personal data in certain circumstances.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format.
Right to Object (Article 21)
You have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing.
Data Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest where appropriate
- Regular security assessments and updates
- Access controls limiting who can view personal data
- Staff training on data protection responsibilities
- Secure disposal of data when no longer required
Data Breach Procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where required, notify affected individuals without undue delay.
International Transfers
We do not routinely transfer personal data outside the United Kingdom. If any transfer becomes necessary, we will ensure appropriate safeguards are in place as required by data protection legislation.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our standard retention periods are:
- Enquiry records: 3 years from last contact
- Client records: 7 years after service completion
- Financial records: As required by tax legislation
Exercising Your Rights
To exercise any of your data protection rights, please contact us using the details above. We will respond to all legitimate requests within one month. We may need to verify your identity before processing your request.
Complaints
If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk