Last Updated: June 2026
Our Commitment to Data Protection
Periwinkle Cove is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we comply with these regulations and your rights under them.
Data Controller Information
Periwinkle Cove acts as the data controller for personal information collected through our website and services. We are responsible for ensuring your data is processed lawfully, fairly, and transparently.
Contact Details:
Periwinkle Cove
127 Colmore Row
Birmingham, B3 3AG
United Kingdom
Email: [email protected]
Your Rights Under GDPR
Right to Access
You have the right to request access to the personal data we hold about you. We will provide a copy of your data free of charge, though we may charge a reasonable fee for additional copies or manifestly unfounded requests.
Right to Rectification
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction or completion of that data.
Right to Erasure
Also known as the "right to be forgotten," you can request deletion of your personal data when:
- The data is no longer necessary for its original purpose
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Legal obligations require erasure
Right to Restriction of Processing
You can request that we restrict how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects. We do not currently use automated decision-making processes.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before consent was withdrawn.
How to Exercise Your Rights
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month, though this may be extended by two months for complex requests. We will inform you of any extension within the first month.
We may request specific information from you to verify your identity before processing your request, ensuring we do not disclose data to unauthorized parties.
Lawful Basis for Processing
We process personal data only when we have a lawful basis:
- Consent: You have given clear consent for us to process your data for a specific purpose
- Contract: Processing is necessary to fulfill a contract with you
- Legal obligation: Processing is necessary to comply with the law
- Legitimate interests: Processing is necessary for our legitimate interests or those of a third party, except where overridden by your rights
Data Protection Principles
We adhere to the following principles when processing personal data:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Pseudonymization and encryption of personal data
- Ongoing confidentiality, integrity, availability, and resilience of systems
- Regular testing and evaluation of security measures
- Staff training on data protection responsibilities
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also report breaches to the Information Commissioner's Office where required.
International Data Transfers
We primarily process data within the United Kingdom. Should we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
Children's Privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children. If we become aware of such collection, we will take steps to delete the information promptly.
Complaints
If you believe we have not complied with data protection law, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
Updates to This Policy
We may update our GDPR compliance information to reflect changes in law or our practices. We encourage you to review this page periodically. The date at the top indicates when this page was last revised.