Information on this site is advertising in nature London, United Kingdom

Last updated: January 2024

Our Commitment to Data Protection

lucid-swan is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides detailed information about how we handle your personal data and your rights under data protection law.

Data Controller

lucid-swan is the data controller responsible for your personal data. This means we determine the purposes and means of processing your personal information.

Contact details:

Email: [email protected]

Address: 47 Chancery Lane, London WC2A 1PL

Lawful Bases for Processing

We only process personal data when we have a lawful basis to do so. The lawful bases we rely on include:

Consent

Where you have given clear consent for us to process your personal data for a specific purpose. For example, when you submit an enquiry form on our website.

Contract

Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. This applies when you engage our consultation services.

Legitimate Interests

Where processing is necessary for our legitimate interests or those of a third party, provided your fundamental rights and freedoms do not override those interests. Examples include improving our services and maintaining website security.

Legal Obligation

Where processing is necessary to comply with a legal obligation. For example, keeping financial records or responding to regulatory requirements.

Your Rights Under GDPR

Under the UK GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request. We will provide this information free of charge within one month of receiving your request.

Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you. We will respond to your request within one month.

Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected. This is sometimes called the "right to be forgotten."

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to request that we transfer this data directly to another controller where technically feasible.

Right to Object

You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.

Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or significantly affects you. We do not currently use automated decision-making in our services.

Exercising Your Rights

To exercise any of your rights, please contact us using the details above. We may need to verify your identity before processing your request. We will respond to all legitimate requests within one month, though this period may be extended for complex requests.

You will not normally be charged a fee for exercising your rights, but we may charge a reasonable fee if your request is clearly unfounded or excessive.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our standard retention periods are:

  • Enquiry records: 2 years from last contact
  • Client consultation records: 6 years after engagement ends
  • Financial records: 7 years as required by law
  • Website analytics: 26 months

Data Security

We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include:

  • Encrypted data transmission
  • Secure storage systems with access controls
  • Regular security assessments
  • Staff training on data protection
  • Incident response procedures

Data Breaches

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights, we will also notify you directly.

International Transfers

We process and store personal data within the United Kingdom. If any international transfer becomes necessary, we will ensure appropriate safeguards are in place in accordance with UK GDPR requirements.

Special Category Data

Due to the nature of our services, we may process special category data such as health information. This is done with your explicit consent and only where necessary to provide our advisory services. Additional safeguards are in place for this sensitive information.

Complaints

If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve your concerns.

You also have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office

Wycliffe House, Water Lane

Wilmslow, Cheshire SK9 5AF

Website: ico.org.uk

Updates to This Information

We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.