Last updated: January 2024
1. Our Commitment to GDPR
ravine-quartz is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We recognise the importance of protecting personal data and have implemented comprehensive measures to ensure compliance across all our operations.
This page provides information about how we process personal data in accordance with GDPR requirements and explains your rights as a data subject.
2. Data Controller Information
For the purposes of UK data protection legislation, ravine-quartz acts as the data controller for personal information collected through this website and during the provision of our services.
Contact details:
ravine-quartz
47 Commerce House
Bishopsgate
London EC2M 3TN
United Kingdom
Email: [email protected]
3. Lawful Basis for Processing
We process personal data only when we have a valid lawful basis to do so. The lawful bases we rely upon include:
3.1 Contract Performance
Processing personal data when necessary for the performance of a contract with you, or to take steps at your request before entering into a contract. This includes processing required to deliver our payment services.
3.2 Legitimate Interests
Processing based on our legitimate business interests, provided these interests do not override your fundamental rights and freedoms. Our legitimate interests include:
- Operating and improving our services
- Ensuring network and information security
- Preventing fraud and financial crime
- Marketing our services to existing clients
3.3 Legal Obligation
Processing required to comply with legal obligations, including financial regulations, anti-money laundering requirements, and tax legislation.
3.4 Consent
Where we rely on consent, we will obtain your clear, affirmative consent before processing. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
4. Your Rights Under GDPR
The UK GDPR provides you with the following rights regarding your personal data:
4.1 Right of Access
You have the right to obtain confirmation that your data is being processed and to access your personal data along with supplementary information about how it is used.
4.2 Right to Rectification
You have the right to have inaccurate personal data rectified, or completed if it is incomplete.
4.3 Right to Erasure
You have the right to have personal data erased in certain circumstances, such as when the data is no longer necessary for its original purpose or when you withdraw consent.
4.4 Right to Restrict Processing
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.
4.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
4.6 Right to Object
You have the right to object to processing based on legitimate interests, direct marketing, and processing for research or statistical purposes.
4.7 Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, with certain exceptions.
5. How to Exercise Your Rights
To exercise any of your rights under GDPR, please submit a request to us using the contact details provided above. We will respond to your request within one month of receipt. In complex cases or where we receive multiple requests, this period may be extended by up to two additional months.
We may need to verify your identity before processing your request. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
6. Data Protection Measures
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing personal data. These measures include:
- Encryption of data in transit and at rest
- Access controls and authentication mechanisms
- Regular security assessments and penetration testing
- Staff training on data protection practices
- Incident response and breach notification procedures
- Data processing agreements with third-party processors
7. International Data Transfers
When we transfer personal data outside the United Kingdom, we ensure appropriate safeguards are in place. These safeguards may include:
- Adequacy decisions by the UK government
- Standard contractual clauses approved by the ICO
- Binding corporate rules
- Certification mechanisms
8. Data Breach Procedures
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where there is a high risk to individuals, we will also notify affected data subjects without undue delay.
9. Record Keeping
We maintain records of our processing activities as required by Article 30 of the UK GDPR. These records include information about processing purposes, data categories, recipients, retention periods, and security measures.
10. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We would, however, appreciate the opportunity to address your concerns before you contact the ICO, so please contact us in the first instance.
11. Updates to This Information
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically for the latest information on our GDPR compliance.