General Data Protection Regulation Information
We are committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This page explains how we comply with GDPR requirements and what rights you have regarding your personal information.
We process your personal data under the following legal bases:
For the purposes of GDPR, the data controller is agile-mist, operating from our Birmingham office. We are responsible for ensuring that your personal data is processed lawfully, fairly, and transparently.
You have the right to request access to the personal data we hold about you. We will provide you with a copy of your data within one month of receiving your request.
If you believe that any information we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it.
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to our processing of your personal data where we are relying on legitimate interests as the legal basis for processing.
Where we are processing your data based on your consent, you have the right to withdraw that consent at any time.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
We do not transfer your personal data outside the United Kingdom or European Economic Area. If circumstances require such transfers in the future, we will ensure appropriate safeguards are in place.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children.
To exercise any of your GDPR rights, please contact us using the information provided on our contact page. We will respond to your request within one month, though this period may be extended by two further months where necessary.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.