GDPR Compliance Statement
Last Updated: June 2026
Our Commitment to GDPR
peak-swan is committed to compliance with the General Data Protection Regulation (GDPR) and UK data protection laws. This document outlines how we meet our obligations under these regulations.
Lawful Basis for Processing
We process personal data based on the following lawful grounds:
- Consent: When you provide explicit permission to process your data
- Contract: When processing is necessary to fulfil our service agreement
- Legal Obligation: When we must process data to comply with legal requirements
- Legitimate Interests: When processing serves our legitimate business purposes without overriding your rights
Your GDPR Rights
Under GDPR, you have comprehensive rights regarding your personal data:
Right to Access
You can request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used format within one month of your request.
Right to Rectification
If you believe any information we hold is inaccurate or incomplete, you have the right to request correction.
Right to Erasure
You can request deletion of your personal data when it is no longer necessary for the purposes it was collected, or if you withdraw consent.
Right to Restrict Processing
You may request that we limit how we use your data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a portable format and to transmit it to another controller.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that significantly affects you.
Data Protection Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication requirements
- Staff training on data protection principles
- Incident response procedures
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
International Data Transfers
We primarily process data within the United Kingdom. If we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the UK authorities.
Data Protection Officer
For questions about our GDPR compliance or to exercise your rights, please contact us at [email protected].
Supervisory Authority
You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Children's Privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.