GDPR Compliance Statement
Last updated: July 13, 2026
Our Commitment to Data Protection
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.
Data Controller
For the purposes of data protection legislation, the data controller is:
basin-gazelle
42 Castle Street
Liverpool
L2 9UH
United Kingdom
Lawful Basis for Processing
We process personal data under the following lawful bases as defined in Article 6 of the GDPR:
- Consent: when you voluntarily provide information through our contact forms
- Contract: when processing is necessary to provide services you've requested
- Legal obligation: when we must process data to comply with legal requirements
- Legitimate interests: when processing is necessary for our business operations and does not override your rights
Data Subject Rights
Under the GDPR, you have the following rights regarding your personal data:
Right to Access
You can request confirmation of whether we process your personal data and access to that data.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You can request that we limit how we use your personal data in certain situations.
Right to Data Portability
You can request a copy of your personal data in a structured, commonly used, and machine-readable format.
Right to Object
You can object to processing of your personal data where we rely on legitimate interests as the legal basis.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements.
When determining retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which we process the data
- Legal obligations requiring retention
- Limitation periods for legal claims
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls limiting who can view personal data
- Staff training on data protection practices
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach.
International Data Transfers
We do not routinely transfer personal data outside the United Kingdom. If such transfers become necessary, we will ensure appropriate safeguards are in place as required by the GDPR.
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: www.ico.org.uk
Updates to This Statement
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. Please check this page periodically for updates.
The information provided on this website is for general guidance purposes only and should not be considered as legal advice. Individual circumstances vary, and outcomes cannot be guaranteed. We strongly recommend consulting with a qualified professional before making any decisions regarding benefit claims or pension applications. Results may differ based on personal eligibility and documentation.