GDPR Compliance
Our commitment to protecting your personal data under the General Data Protection Regulation
Last updated: January 2024
1. Our Commitment to GDPR
Sprout Port is committed to compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We respect your privacy and are dedicated to protecting your personal data. This page explains how we fulfil our obligations under data protection legislation.
2. Data Controller
For the purposes of GDPR, Sprout Port acts as the data controller for personal data collected through our website and services. Our contact details are:
Sprout Port
47 Greenfield Lane
Bristol, BS8 2QT
United Kingdom
Email: [email protected]
3. Lawful Basis for Processing
We process personal data based on the following lawful bases:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes, such as marketing communications
- Contract: Where processing is necessary for the performance of a contract with you, such as providing access to courses you have enrolled in
- Legitimate Interests: Where processing is necessary for our legitimate business interests, provided these do not override your rights and interests
- Legal Obligation: Where processing is necessary for compliance with legal obligations to which we are subject
4. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete personal data we hold about you.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purpose for which it was collected, or where you withdraw consent.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects.
5. How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month. In certain circumstances, we may extend this period by up to two additional months, in which case we will inform you of the extension and the reasons for it.
We may request specific information from you to help us confirm your identity and ensure your right to access your personal data or exercise any of your other rights.
6. Data Security Measures
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular testing and evaluation of security measures
- Access controls to limit who can view personal data
- Staff training on data protection requirements
- Procedures for handling data breaches
7. International Data Transfers
We primarily process and store personal data within the United Kingdom. Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the relevant authorities.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. Specific retention periods vary depending on the type of data and the purpose of processing.
9. Data Breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
10. Complaints
If you have concerns about how we handle your personal data, we encourage you to contact us first so we can address your concerns. You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
11. Updates to This Information
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.