GDPR Compliance
Your data protection rights under UK GDPR
Data Controller Information
wise-hollow is the data controller responsible for your personal information. We are committed to complying with the UK General Data Protection Regulation and Data Protection Act 2018.
Contact details:
wise-hollow
Manchester, United Kingdom
[email protected]
Legal Basis for Processing
We process your personal data under the following legal bases:
Consent
When you submit a consultation request or contact form, you provide explicit consent for us to process your information to deliver requested services.
Contractual Necessity
Processing is necessary to fulfill our contractual obligations when providing financial education and consultation services.
Legitimate Interests
We process certain data based on legitimate business interests, such as improving our services and maintaining website security, balanced against your rights and interests.
Legal Obligations
We process and retain certain information to comply with legal and regulatory requirements.
Your Rights Under GDPR
Right to Access
You have the right to request copies of your personal data. We will provide this information within one month of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal information we hold about you.
Right to Erasure
You may request deletion of your personal data in certain circumstances, including:
- The data is no longer necessary for its original purpose
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Right to Restrict Processing
You can request that we limit how we use your data in specific situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller where technically feasible.
Right to Object
You can object to processing of your personal data when it is based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request" and specify which right you wish to exercise.
We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two additional months and will inform you accordingly.
We may need to verify your identity before processing certain requests to ensure we are disclosing information to the correct person.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Contact information: Retained while you are an active client plus two years
- Financial information shared during consultations: Retained for seven years to comply with financial record-keeping requirements
- Website analytics: Retained for 26 months
- Communication records: Retained for three years
After retention periods expire, data is securely deleted or anonymized.
International Data Transfers
We primarily store and process data within the United Kingdom. If we transfer data outside the UK, we ensure adequate safeguards are in place, including:
- Transfers to countries with adequacy decisions
- Use of standard contractual clauses approved by the UK Information Commissioner's Office
- Other legally approved transfer mechanisms
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of sensitive data
- Regular security assessments
- Access controls and authentication requirements
- Employee training on data protection
- Secure backup procedures
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by GDPR.
Third-Party Processors
We work with carefully selected third-party service providers who process data on our behalf. All processors are bound by data processing agreements that ensure GDPR compliance and appropriate security measures.
We do not share your personal data with third parties for their own marketing purposes.
Children's Data
Our services are not directed at children under 18. We do not knowingly process data of minors without appropriate parental or guardian consent.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk
Updates to This Notice
We may update this GDPR compliance notice periodically. Changes will be posted on this page with an updated effective date. We encourage you to review this page regularly to stay informed about how we protect your data.