GDPR Compliance
Last updated: August 2024
1. Data Controller
For the purposes of the General Data Protection Regulation (GDPR), the data controller is disamdeluc, located at Unit 7, Riverside Creative Quarter, 142 Kingsland Road, London E2 8DY, United Kingdom.
2. Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities
- Contract: When processing is necessary to fulfil our contractual obligations to you
- Legal Obligation: When we must process data to comply with legal requirements
- Legitimate Interests: When processing serves our legitimate business interests while respecting your rights
3. Data Subject Rights
Under GDPR, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of how we use your data
- Right to Data Portability: Receive your data in a structured, commonly used format
- Right to Object: Object to processing based on legitimate interests
- Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing
4. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- Programme booking and attendance records: 7 years for accounting purposes
- Marketing communications data: Until consent is withdrawn or the data becomes inactive
- Enquiry data: 2 years from last contact
5. International Data Transfers
We do not routinely transfer personal data outside the European Economic Area. If such transfers become necessary, we will ensure appropriate safeguards are in place as required by GDPR.
6. Data Protection Officer
For questions regarding data protection or to exercise your rights, please contact us at: [email protected]
7. Right to Lodge a Complaint
You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues. Visit www.ico.org.uk for more information.
8. Changes to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Updates will be posted on this page with a revised date.