Information on this site is advertising in nature

Last updated: January 2026

Our Commitment

reef-deer is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have implemented a data protection policy and procedures to ensure the effective and consistent handling of personal data.

About UK GDPR

The UK General Data Protection Regulation (UK GDPR) is the United Kingdom's data protection framework following Brexit. It works alongside the Data Protection Act 2018 to provide a comprehensive data protection regime. The UK GDPR is largely based on the EU GDPR and provides individuals with rights regarding their personal data.

Data Controller Information

reef-deer acts as a data controller for the personal information we collect and process. As a data controller, we determine the purposes and means of processing personal data.

Contact details:

reef-deer
42 Queensway Business Centre
Birmingham B3 2HJ
United Kingdom

Email: [email protected]

Lawful Bases for Processing

Under UK GDPR, we must have a valid lawful basis to process personal data. We rely on the following lawful bases:

Consent

Where you have provided clear consent for us to process your personal data for a specific purpose. You have the right to withdraw consent at any time.

Contractual Necessity

Where processing is necessary for the performance of a contract with you, such as delivering a training programme you have enrolled in.

Legitimate Interests

Where processing is necessary for our legitimate business interests, such as improving our services, provided these interests do not override your fundamental rights and freedoms.

Legal Obligation

Where processing is necessary to comply with a legal obligation to which we are subject.

Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

Right to Be Informed

You have the right to be informed about the collection and use of your personal data. This privacy information is provided through this GDPR page and our Privacy Policy.

Right of Access

You have the right to obtain confirmation that your data is being processed and to access your personal data. You may request a copy of your data by contacting us.

Right to Rectification

You have the right to have inaccurate personal data corrected or completed if it is incomplete.

Right to Erasure

Also known as the "right to be forgotten", you have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose it was collected.

Right to Restrict Processing

You have the right to request the restriction or suppression of your personal data in certain circumstances.

Right to Data Portability

You have the right to obtain and reuse your personal data for your own purposes across different services. This applies to data you have provided to us based on consent or contractual necessity.

Right to Object

You have the right to object to processing based on legitimate interests, direct marketing, and processing for research or statistical purposes.

Rights Related to Automated Decision Making

You have rights related to automated decision making and profiling. We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects.

Exercising Your Rights

To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.

We may need to verify your identity before processing your request. There is generally no fee for exercising your rights, though we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

Data Protection Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data where appropriate
  • Regular testing and evaluation of security measures
  • Staff training on data protection
  • Access controls to limit who can access personal data
  • Procedures for handling data breaches

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

International Transfers

Where we transfer personal data outside the United Kingdom, we ensure that appropriate safeguards are in place. This may include:

  • Transfers to countries with an adequacy decision
  • Standard contractual clauses approved by the ICO
  • Binding corporate rules for intra-group transfers

Supervisory Authority

The supervisory authority for data protection in the United Kingdom is the Information Commissioner's Office (ICO). If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the ICO.

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF

Website: ico.org.uk

Updates to This Information

We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.