Introduction
The General Data Protection Regulation (GDPR) establishes comprehensive data protection rights for individuals in the European Economic Area. As a business operating in the United Kingdom and serving international clients, we maintain full compliance with GDPR requirements and UK data protection law.
Data Controller
ingoisfacc acts as the data controller for personal information collected through our website and service delivery. We determine the purposes and means of processing your personal data.
Lawful Basis for Processing
We process personal data only when we have a lawful basis:
- Consent: You have explicitly consented to processing for specific purposes
- Contract: Processing is necessary to fulfill our service obligations
- Legal Obligation: Processing is required to comply with legal requirements
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights
Your GDPR Rights
Right to Access
You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to request correction or completion of that data.
Right to Erasure
Under certain circumstances, you have the right to request deletion of your personal data. This right applies when:
- The data is no longer necessary for its original purpose
- You withdraw consent and no other legal basis exists
- You object to processing and no overriding legitimate grounds exist
- The data has been unlawfully processed
- Legal obligations require erasure
Right to Restriction of Processing
You may request that we restrict processing of your personal data when:
- You contest the accuracy of the data
- Processing is unlawful but you prefer restriction over erasure
- We no longer need the data but you require it for legal claims
- You have objected to processing pending verification of legitimate grounds
Right to Data Portability
You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format. You may also request that we transmit this data directly to another controller where technically feasible.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Upon objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your data appropriately.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though complex requests may require up to three months with notification of the extension.
We may request specific information from you to confirm your identity before processing rights requests. This security measure ensures we do not disclose personal data to unauthorized parties.
Data Protection Principles
We adhere to the following data protection principles:
- Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and transparently
- Purpose Limitation: We collect data for specified, explicit, and legitimate purposes
- Data Minimization: We collect only data adequate, relevant, and necessary for our purposes
- Accuracy: We take reasonable steps to ensure data accuracy
- Storage Limitation: We retain data only as long as necessary
- Integrity and Confidentiality: We implement appropriate security measures
- Accountability: We can demonstrate compliance with these principles
Data Security
We implement technical and organizational measures to ensure data security appropriate to the risks involved. These measures include:
- Encryption of data in transit and at rest
- Access controls limiting data access to authorized personnel
- Regular security assessments and updates
- Staff training on data protection obligations
- Incident response procedures for data breaches
Data Breach Notification
In the event of a personal data breach that poses risks to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in risk to your rights.
Third-Party Processing
When we engage third-party service providers who process personal data on our behalf, we ensure appropriate contracts are in place requiring them to maintain GDPR compliance and implement appropriate security measures.
International Transfers
If we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions recognizing equivalent data protection standards
- Standard contractual clauses approved by the European Commission
- Binding corporate rules
- Approved certification mechanisms
Contact and Complaints
For questions regarding GDPR compliance or to exercise your rights:
Email: [email protected]
Address: 15 Berkeley Square, Mayfair, London W1J 6EH, United Kingdom
If you are unsatisfied with our response, you may contact the Information Commissioner's Office:
Website: ico.org.uk
Telephone: 0303 123 1113