GDPR Compliance
Last updated: January 2025
1. Introduction to UK GDPR
The UK General Data Protection Regulation (UK GDPR) is the UK's data protection law that governs how personal data is processed and protected. At SpinLife.co.uk, we are committed to full compliance with UK GDPR and the Data Protection Act 2018.
This page explains your rights under UK GDPR and how we protect your personal data in accordance with these regulations.
2. Your Data Protection Rights
Under UK GDPR, you have the following rights regarding your personal data:
Right of Access (Article 15)
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and access to that data.
Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected and incomplete personal data completed.
Right to Erasure (Article 17)
You have the right to have your personal data erased in certain circumstances, also known as the "right to be forgotten."
Right to Restrict Processing (Article 18)
You have the right to restrict the processing of your personal data in certain circumstances.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object (Article 21)
You have the right to object to the processing of your personal data in certain circumstances.
Rights Related to Automated Decision Making (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling.
3. How to Exercise Your Rights
To exercise any of your data protection rights, please contact us using the following methods:
- Email: privacy@spinlife.co.uk
- Subject Line: "Data Protection Rights Request"
- Include: Your full name, email address, and specific request
Response Time
We will respond to your request within one month of receipt. In complex cases, we may extend this period by up to two additional months, and we will inform you of any such extension.
4. Data Controller Information
Data Controller: SpinLife.co.uk
Contact Details:
- Email: privacy@spinlife.co.uk
- Address: SpinLife.co.uk, Data Protection Officer, United Kingdom
5. Lawful Basis for Processing
We process your personal data under the following lawful bases as defined in UK GDPR Article 6:
6. Data Categories We Process
We process the following categories of personal data:
- Identity Data: Name, username, and similar identifiers
- Contact Data: Email address, postal address, and telephone numbers
- Technical Data: IP address, browser type, operating system, and device information
- Usage Data: Information about how you use our website and services
- Marketing Data: Your preferences for receiving marketing communications
- Profile Data: Username, password, preferences, and feedback
7. Data Retention Periods
We retain your personal data for the following periods:
- Account Information: Until account deletion or 3 years of inactivity
- Marketing Data: Until you withdraw consent or 2 years of inactivity
- Analytics Data: 26 months (Google Analytics default retention period)
- Legal Compliance Data: As required by applicable laws (typically 6-7 years)
- Cookies: As specified in our Cookie Policy
8. Data Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption: SSL/TLS encryption for data transmission
- Access Controls: Limited access to personal data on a need-to-know basis
- Regular Updates: Keeping systems and software up to date
- Staff Training: Regular training on data protection principles
- Incident Response: Procedures for handling data breaches
9. International Data Transfers
If we transfer your personal data outside the UK, we ensure appropriate safeguards are in place:
- Adequacy Decisions: Transfers to countries with adequate data protection
- Standard Contractual Clauses: EU-approved contractual clauses for transfers
- Binding Corporate Rules: Internal data protection policies for multinational transfers
- Certification Schemes: Approved certification mechanisms
10. Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours
- Inform you without undue delay if the breach poses a high risk
- Provide clear information about the nature of the breach
- Explain the likely consequences and measures taken
11. Children's Data Protection
Our services are not directed to children under 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such information promptly.
12. Your Right to Complain
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
- Website: ico.org.uk
- Phone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
13. Changes to This GDPR Information
We may update this GDPR information from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated information on this page.
14. Contact Us
If you have any questions about our GDPR compliance or your data protection rights, please contact us:
Data Protection Officer
- Email: privacy@spinlife.co.uk
- Address: SpinLife.co.uk, Data Protection Officer, United Kingdom
- Response Time: We aim to respond within 48 hours