What is the purpose of this notice?
To describe how we collect and use personal data about you by the General Data Protection Regulation (GDPR).
What we need
WeAreGrayFox Limited will be what is known as the “Controller” of the personal data you provide to us. We only collect basic personal data about you which does not include any special categories of personal information about you (known as Special Category Data). This does, however, include name, address, e-mail, telephone number.
Why we need it
We need to know your basic personal data to maintain a relationship with you and store information about the projects and services we provide for you. We will not collect any personal data from you we do not need to provide and oversee this service to you.
What we do with it
We only ever use your personal data with your consent, or where it is necessary:
In any event, we’ll only use your information for the purpose or purposes it was collected for (or for closely related purposes). We may process personal information for certain legitimate business purposes, which include some or all of the following:
Whenever we process data for these purposes we will ensure that we always keep your personal data rights in high regard and take account of these rights at all times. When we process your personal data for our legitimate interests, we will make sure that we consider and balance any potential impact on you (both positive and negative), and your rights under data protection laws. Our legitimate business interests do not automatically override your interests - we will not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
You have the right to object to this processing if you wish, and if you wish to do so please contact firstname.lastname@example.org. Please bear in mind that if you object this may affect our ability to carry out tasks above for your benefit.
Where we keep it
We are based in the UK and we store our data within the EU. Some organisations which provide services to us may transfer personal data outside of the EU, but we will only allow them to do if your data is adequately protected. For example, some of our systems use Microsoft products. As a US company, it may be that using their products result in personal data being transferred to or accessible from the US. However, we will allow this as we are certain personal data will still be adequately protected (as Microsoft is certified under the USA’s Privacy Shield scheme).
How long we keep it
We will only use and store information for so long as it is required for the purposes it was collected for. How long information will be stored depends on the information in question and what it is being used for. For example, if you ask us not to send you marketing e-mails, we will stop storing your e-mails for marketing purposes (though we’ll keep a record of your preference not to be e-mailed).We continually review what information we hold and delete what is no longer required. We never store payment card information. We will not retain your data for any longer than necessary and the longest time that we will hold your data will be six years.
What are your rights?
We want to ensure that you remain in control of your personal data. Part of this is making sure you understand your legal rights, which are as follows:
Please keep in mind that there are exceptions to the rights above and, though we will always try to respond to your satisfaction, there may be situations where we are unable to do so.
If you wish to raise a complaint on how we have handled your personal data, you can contact email@example.com
If you are not satisfied with our response or believe we are processing your personal data not by the law you can complain to the Information Commissioner’s Office, the UK supervisory authority for data protection issues.