GDPR Compliance
Your data rights under the General Data Protection Regulation
Our Commitment to GDPR
flashy grid is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page explains your rights under GDPR and how we fulfill our obligations as a data controller.
Data Controller Information
flashy grid
47 Westbourne Grove
London W2 4UA
United Kingdom
Email: [email protected]
Your Rights Under GDPR
1. Right to Be Informed
You have the right to know what personal data we collect, how we use it, and who we share it with. This information is detailed in our Privacy Policy.
2. Right of Access
You can request a copy of the personal data we hold about you. We will provide this within one month of your request, free of charge.
3. Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to have it corrected. We will update your information within one month.
4. Right to Erasure (Right to Be Forgotten)
You can request deletion of your personal data under certain circumstances, including:
- The data is no longer necessary for its original purpose
- You withdraw consent and there's no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Note: We may retain certain information where required by law (e.g., tax records).
5. Right to Restrict Processing
You can request that we limit how we use your data in certain situations, such as when:
- You contest the accuracy of the data
- Processing is unlawful but you don't want the data erased
- We no longer need the data but you need it for legal claims
- You've objected to processing pending verification
6. Right to Data Portability
You can request to receive your personal data in a structured, commonly used, and machine-readable format. You can also request that we transfer this data to another organization.
7. Right to Object
You have the right to object to:
- Processing based on legitimate interests
- Direct marketing (including profiling)
- Processing for research or statistical purposes
8. Rights Related to Automated Decision Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: [email protected]
- Post: flashy grid, 47 Westbourne Grove, London W2 4UA, United Kingdom
We will respond to your request within one month. In complex cases, we may extend this by up to two months and will inform you of the extension and reasons.
Verification Process
To protect your privacy, we may need to verify your identity before processing requests related to your personal data. We may ask for additional information to confirm your identity.
No Fee Usually Required
You will not normally be charged for exercising your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract: To fulfill our agreement with you (enrollment and program delivery)
- Consent: For marketing communications and optional data uses
- Legitimate Interests: To improve our services, prevent fraud, and ensure security
- Legal Obligation: To comply with tax, accounting, and regulatory requirements
Data Protection Officer
For questions about data protection or to exercise your rights, contact our Data Protection Officer at [email protected].
Right to Lodge a Complaint
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Phone: 0303 123 1113
Website: ico.org.uk
However, we encourage you to contact us first so we can address your concerns directly.
International Data Transfers
When we transfer your personal data outside the UK or European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with adequacy decisions
- Other legally approved transfer mechanisms
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Enrollment records: 7 years (tax and legal compliance)
- Marketing consent: Until withdrawn or 3 years of inactivity
- Website analytics: 26 months
Updates to This Information
We may update this GDPR compliance information as regulations evolve. Significant changes will be communicated through our website and, where appropriate, via email.
Questions?
If you have questions about GDPR compliance or your data rights, please contact us at [email protected].