Our commitment to data protection and your rights under UK GDPR
Last Updated: January 2024
Spire Juniper is committed to ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides information about how we protect your data and uphold your rights.
Spire Juniper acts as the data controller for personal information collected through our website and in the course of providing our consultancy services. As such, we are responsible for determining the purposes and means of processing your personal data.
We adhere to the following principles when processing personal data:
You have the right to know how we collect and use your personal data. Our Privacy Policy provides this information in a clear and accessible manner.
You can request a copy of the personal data we hold about you. We will respond to valid requests within one month.
If you believe the personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected.
In certain circumstances, you can request that we delete your personal data. This applies when:
You can request that we limit how we use your data in certain circumstances, such as when you contest its accuracy or object to processing.
Where processing is based on consent or contract and carried out by automated means, you can request your data in a commonly used, machine-readable format.
You can object to processing based on legitimate interests or for direct marketing purposes.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, please contact us at:
Email: [email protected]
Post: Spire Juniper, 47 Clerkenwell Road, London EC1M 5RS
We will respond to your request within one month. In complex cases, this may be extended by a further two months, in which case we will inform you.
To protect your data, we may ask you to verify your identity before responding to requests. This helps ensure that personal data is not disclosed to unauthorised persons.
Given the scale and nature of our data processing activities, we are not required to appoint a Data Protection Officer. However, our management team maintains responsibility for data protection compliance.
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware. Where the breach is likely to result in a high risk to individuals, we will also notify affected persons directly.
We primarily process data within the United Kingdom. Where transfers to third countries are necessary, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the UK Government.
If you are dissatisfied with our handling of your data or believe we have not complied with data protection law, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk
We review our GDPR compliance procedures regularly and may update this page accordingly. Material changes will be communicated through our website.