GDPR Compliance

General Data Protection Regulation compliance statement

Our Commitment to Data Protection

We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and UK data protection laws. This page outlines your rights and how we fulfill our obligations as a data controller.

Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract performance: Processing necessary to fulfill service agreements and respond to service requests
  • Legitimate interests: Maintaining service records and improving our repair services
  • Consent: Marketing communications, where you have explicitly opted in

Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data, subject to legal retention requirements
  • Right to restrict processing: Request limitation of how we use your data
  • Right to data portability: Receive your data in a structured, commonly used format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent for processing at any time

Data Retention

We retain personal data only as long as necessary for the purposes outlined in our privacy policy. Service records are typically maintained for seven years to comply with business record keeping requirements and to provide warranty and service history documentation.

International Data Transfers

Your personal data is stored and processed within the United Kingdom. We do not transfer data outside the UK except when necessary to obtain parts or technical support from equipment manufacturers, in which case appropriate safeguards are in place.

Exercising Your Rights

To exercise any of your GDPR rights, contact us at info at hazy-bamboo.store with your request. We will respond within one month of receiving a valid request. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.