GDPR Compliance
Your data protection rights under UK GDPR regulations.
Our Commitment to Data Protection
canopy-civet is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We take our data protection responsibilities seriously and have implemented appropriate measures to ensure your personal information is processed lawfully, fairly, and transparently.
Data Controller Information
For the purposes of UK GDPR, canopy-civet is the data controller responsible for your personal information.
Contact details:
Email: [email protected]
Address: 42 Wellington Street, Leicester, LE1 6HL, United Kingdom
Your Rights Under UK GDPR
Right to Be Informed
You have the right to clear, transparent information about how we use your personal data. This information is provided through our Privacy Policy and this GDPR page.
Right of Access
You can request access to the personal data we hold about you. We will provide you with a copy of your data free of charge within one month of your request.
Right to Rectification
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected.
Right to Erasure
In certain circumstances, you have the right to request deletion of your personal data. This applies when:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
Right to Restrict Processing
You can request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal or similarly significant effects.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with your request.
When making a request, please provide:
- Your full name
- The email address associated with your account or consultation
- A clear description of the data or action you are requesting
- Proof of identity (if we need to verify your identity)
We will respond to your request within one month. In complex cases, this may be extended by two additional months, and we will inform you of any such extension.
Lawful Basis for Processing
We process your personal data based on the following lawful bases:
- Contract: Processing is necessary for performing our contract with you or to take steps at your request before entering into a contract
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided those interests do not override your fundamental rights
- Legal Obligation: Processing is necessary to comply with the law
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.
Specifically:
- Consultation records: 7 years after last consultation
- Email correspondence: 3 years
- Website analytics data: 26 months
- Marketing consent records: Until consent is withdrawn plus 3 years
After the retention period, we securely delete or anonymize your personal data.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls limiting who can view personal data
- Staff training on data protection
- Secure backup procedures
Data Breach Notification
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay, and within 72 hours of becoming aware of the breach.
We will inform you about:
- The nature of the breach
- The likely consequences
- The measures we have taken or propose to take
International Data Transfers
Your personal data is stored and processed within the United Kingdom. We do not transfer your data outside the UK except when necessary to provide our services, and only with appropriate safeguards in place.
Complaints
If you believe we have not handled your personal data in accordance with UK GDPR, you have the right to lodge a complaint with the supervisory authority.
Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Telephone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
However, we encourage you to contact us first so we can address your concerns directly.
Updates to This Page
We may update this GDPR information from time to time to reflect changes in our practices or legal requirements. The current version was last updated on June 19, 2026.