GDPR Compliance
Last Updated: September 1, 2026
General Data Protection Regulation
fell-flow is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). This page explains how we process your personal data in accordance with GDPR requirements.
Data Controller
fell-flow is the data controller responsible for your personal information. Our contact details are:
fell-flow
142 Caledonian Road
London N1 9RD
United Kingdom
Email: [email protected]
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you submit forms or provide information voluntarily
- Contract: To fulfill our contractual obligations when providing services
- Legitimate Interest: To improve our services and communicate relevant information
- Legal Obligation: To comply with applicable laws and regulations
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a small fee for this service.
Right to Rectification
You have the right to request correction of any information you believe is inaccurate or incomplete.
Right to Erasure
You have the right to request deletion of your personal data under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions.
Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you under certain conditions.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Service delivery and client relationship management
- Legal and regulatory compliance requirements
- Resolution of disputes or enforcement of agreements
When personal data is no longer required, we securely delete or anonymize it.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection practices
International Transfers
Your personal data is primarily processed within the United Kingdom. If we transfer data outside the UK or EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay.
Automated Decision Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
Complaints
If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Updates to This Policy
We may update this GDPR compliance statement from time to time. Any changes will be posted on this page with an updated revision date.