General Data Protection Regulation Information
cove-whale is committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR). This document outlines our compliance practices and your rights under this regulation.
We process personal data based on the following legal grounds:
The data controller responsible for your personal information is:
cove-whale
42 Victoria Street
London, SW1H 0TL
United Kingdom
Email: [email protected]
We collect and process the following categories of personal data:
Under GDPR, you have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data along with supplementary information about processing activities.
If personal data we hold is inaccurate or incomplete, you have the right to request correction or completion of that information.
Under certain circumstances, you can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected or when you withdraw consent.
You can request that we limit how we use your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
Where technically feasible, you can request to receive personal data you provided to us in a structured, commonly used format and transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significant impacts. We do not currently engage in such automated decision-making.
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements.
Typical retention periods include:
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
Personal data is processed and stored within the United Kingdom. Should we need to transfer data outside the UK or European Economic Area, we will ensure appropriate safeguards are in place as required by GDPR.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR.
To exercise any of your GDPR rights, submit a request to [email protected]. We will respond within one month of receiving your request. In complex cases, this period may be extended by two additional months with notification.
You also have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR.
This GDPR compliance document may be updated to reflect changes in our data processing practices or legal obligations. Significant changes will be communicated through website notices.