Last updated: January 2026
Our Commitment
reef-deer is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have implemented a data protection policy and procedures to ensure the effective and consistent handling of personal data.
About UK GDPR
The UK General Data Protection Regulation (UK GDPR) is the United Kingdom's data protection framework following Brexit. It works alongside the Data Protection Act 2018 to provide a comprehensive data protection regime. The UK GDPR is largely based on the EU GDPR and provides individuals with rights regarding their personal data.
Data Controller Information
reef-deer acts as a data controller for the personal information we collect and process. As a data controller, we determine the purposes and means of processing personal data.
Contact details:
reef-deer
42 Queensway Business Centre
Birmingham B3 2HJ
United Kingdom
Email: [email protected]
Lawful Bases for Processing
Under UK GDPR, we must have a valid lawful basis to process personal data. We rely on the following lawful bases:
Consent
Where you have provided clear consent for us to process your personal data for a specific purpose. You have the right to withdraw consent at any time.
Contractual Necessity
Where processing is necessary for the performance of a contract with you, such as delivering a training programme you have enrolled in.
Legitimate Interests
Where processing is necessary for our legitimate business interests, such as improving our services, provided these interests do not override your fundamental rights and freedoms.
Legal Obligation
Where processing is necessary to comply with a legal obligation to which we are subject.
Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
Right to Be Informed
You have the right to be informed about the collection and use of your personal data. This privacy information is provided through this GDPR page and our Privacy Policy.
Right of Access
You have the right to obtain confirmation that your data is being processed and to access your personal data. You may request a copy of your data by contacting us.
Right to Rectification
You have the right to have inaccurate personal data corrected or completed if it is incomplete.
Right to Erasure
Also known as the "right to be forgotten", you have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You have the right to request the restriction or suppression of your personal data in certain circumstances.
Right to Data Portability
You have the right to obtain and reuse your personal data for your own purposes across different services. This applies to data you have provided to us based on consent or contractual necessity.
Right to Object
You have the right to object to processing based on legitimate interests, direct marketing, and processing for research or statistical purposes.
Rights Related to Automated Decision Making
You have rights related to automated decision making and profiling. We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects.
Exercising Your Rights
To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
We may need to verify your identity before processing your request. There is generally no fee for exercising your rights, though we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Data Protection Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data where appropriate
- Regular testing and evaluation of security measures
- Staff training on data protection
- Access controls to limit who can access personal data
- Procedures for handling data breaches
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
International Transfers
Where we transfer personal data outside the United Kingdom, we ensure that appropriate safeguards are in place. This may include:
- Transfers to countries with an adequacy decision
- Standard contractual clauses approved by the ICO
- Binding corporate rules for intra-group transfers
Supervisory Authority
The supervisory authority for data protection in the United Kingdom is the Information Commissioner's Office (ICO). If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the ICO.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Updates to This Information
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.