Brithaventech

BritHaven Tech Header
GDPR Compliance โ€” BritHaven Tech
Legal & Compliance

GDPR Compliance

BritHaven Tech is committed to processing personal data responsibly, lawfully, and transparently. This page sets out our approach to compliance with the UK GDPR and the Data Protection Act 2018.

๐Ÿ“… Last Updated: 27 May 2025
๐Ÿ›๏ธ Governing Law: England & Wales
๐Ÿ›ก๏ธ Framework: UK GDPR ยท DPA 2018 ยท PECR
UK GDPR Compliant
Data Protection Act 2018
ICO Registered
Privacy by Design
DPA Agreements in Place
PECR Compliant
Annual Review
About This Page
TThis page sets out BritHaven Tech Limited's approach to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is intended to provide transparency about our data protection practices and to help our clients, partners, and website visitors understand how we uphold their rights.
01

Our Commitment to Data Protection

BritHaven Tech Limited is committed to processing personal data responsibly, lawfully, and transparently. As an authorised UK technology reseller, we handle personal data in the course of our day-to-day commercial activities, including managing client accounts, processing orders, and operating our website.

We recognise that data protection is not merely a legal obligation but a fundamental aspect of the trust our clients and partners place in us. We are committed to embedding a culture of privacy across our organisation and to continually reviewing and improving our data protection practices. We do not sell personal data. We process only what is necessary. We are transparent about how and why we process data. We uphold the rights of every individual whose data we handle.

โœ… Our Core Pledge
We do not sell personal data. We process only what is necessary. We are transparent about how and why we process data. We uphold the rights of every individual whose data we handle.
02

Our Legal Framework

BritHaven Tech Limited processes personal data in accordance with the following legislation and regulatory guidance:

  • the primary legislative framework governing the processing of personal data in the United Kingdom following the UK's exit from the European Union.
  • Data Protection Act 2018 (DPA 2018) โ€” the UK statute that supplements and gives effect to the UK GDPR and governs certain processing activities not covered by it.
  • Privacy and Electronic Communications Regulations 2003 (PECR) โ€” which govern electronic marketing, the use of cookies, and related communications.
  • Network and Information Systems (NIS) Regulations 2018 โ€” relevant to our obligations as a technology service provider in respect of cybersecurity and incident reporting.

We monitor regulatory guidance issued by the Information Commissioner's Office (ICO) and update our practices accordingly.

03

Our Role as Data Controller

BritHaven Tech Limited acts as the data controller in respect of personal data collected through our website, quote request process, and direct commercial relationships. As data controller, we determine the purposes and means of processing and bear

primary responsibility for ensuring that processing is lawful. In certain circumstances โ€” for example, where we process personal data on behalf of a client organisation โ€” we may act as a data processor. In such cases, processing is governed by a written Data Processing Agreement (DPA) in accordance with Article 28 of the UK GDPR.

ICO Registration
BritHaven Tech is registered with the ICO as a data controller.
๐Ÿ”ข
ICO Registration Number:[Z0000000]
๐ŸŒ
ico.org.uk
04

Lawful Bases for Processing

We process personal data only where we have identified a valid lawful basis under Article 6 of the UK GDPR. The lawful bases we rely upon are as follows:

Lawful Basis Article Ref. How We Use It
Performance of a Contract Article 6(1)(b) We process personal data where it is necessary to perform a contract to which the data subject is party, or to take steps at their request prior to entering into a contract. This applies to the processing of client contact details, order information, invoice management, and account administration.
Legitimate Interests Article 6(1)(f) We process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by the rights and freedoms of the data subject. We conduct Legitimate Interests Assessments (LIAs) in respect of all processing activities where this basis is relied upon, including direct marketing to existing business contacts and website analytics.
Legal Obligation Article 6(1)(c) We process personal data where necessary to comply with a legal obligation to which we are subject, including tax reporting, VAT record-keeping, anti-money laundering checks, and compliance with court orders or regulatory requirements.
Consent Article 6(1)(a) Where we rely on consent โ€” for example, in respect of non-essential cookies or certain marketing communications โ€” we ensure that consent is freely given, specific, informed, and unambiguous. Data subjects may withdraw consent at any time without detriment.
05

Data Minimisation and; Core Principles

We apply all seven data protection principles set out in Article 5 of the UK GDPR to every processing activity we undertake:

โš–๏ธ
Lawfulness, Fairness & Transparency
We process data lawfully, fairly, and in a transparent manner. We tell individuals how and why we use their data. .
๐ŸŽฏ
Purpose Limitation
We collect data for specified, explicit, and legitimate purposes and do not process it in ways incompatible with those purposes.
โœ‚๏ธ
Data Minimisation
We collect only data that is adequate, relevant, and limited to what is necessary for the stated purpose.
โœ…
Accuracy
We take reasonable steps to ensure personal data is accurate and kept up to date, correcting inaccuracies promptly.
๐Ÿ—“๏ธ
Storage Limitation
We retain personal data only for as long as is necessary, governed by our documented Data Retention Schedule.
๐Ÿ”’
Integrity & Confidentiality
We implement appropriate technical and organisational measures to protect data against unauthorised access and accidental loss.
๐Ÿข
Accountability
We are responsible for, and able to demonstrate, compliance with all of the above principles. Accountability for data protection rests at Board level.

All new data processing activities are reviewed by our Privacy team prior to implementation to ensure compliance with these principles.

06

Data Subject Rights

We respect and uphold the rights of all data subjects under the UK GDPR. We have established documented procedures for handling rights requests and aim to respond to all valid requests within one (1) calendar month. We do not charge a fee for exercising rights except in cases of manifestly unfounded or excessive requests.

๐Ÿ‘๏ธ
Right of Access
Individuals may request a copy of the personal data we hold about them (Subject Access Request).
โœ๏ธ
Right to Rectification
Individuals may request correction of any inaccurate or incomplete personal data we hold.
๐Ÿ—‘๏ธ
Right to Erasure
Individuals may request deletion of their data where there is no longer a lawful basis for retention, subject to applicable legal exceptions.
โธ๏ธ
Right to Restriction of Processing
Individuals may request that we restrict processing of their data in certain defined circumstances, for example whilst the accuracy of data is contested.
๐Ÿ“ค
Right to Data Portability
Individuals may request their data in a structured, commonly used, and machine-readable format where processing is based on consent or contract and is carried out by automated means.
๐Ÿšซ
Right to Object
Individuals may object to processing based on legitimate interests. Objections to direct marketing are always honoured immediately and without question.
๐Ÿค–
Rights in Relation to Automated Decision-Making
Individuals have the right not to be subject to decisions based solely on automated processing that produce significant legal or similarly significant effects. BritHaven Tech does not currently carry out such processing.
โ†ฉ๏ธ
Right to Withdraw Consent
Where processing is based on consent, individuals may withdraw that consent at any time without detriment to any prior lawful processing
๐Ÿ“ฌ How to Submit a Rights Request
To submit a data subject rights request, please contact: privacy@brithaven.co.uk If an extension beyond one month is required to respond, we will notify the individual within the first month and provide a clear explanation as to why.
07

Data Retention

We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable law.

All personal data is subject to our Data Retention Schedule, which defines retention periods across all data categories and is reviewed at least annually.

๐Ÿ“‹ Retention Schedule
Full details of our retention periods by data category are set out in our Privacy Policy, which includes a comprehensive retention table covering quote data, order records, marketing data, analytics, legal claims data, and correspondence.

Our standard retention periods are as follows:

  • Quote request data (where no Order follows): 12 months from the date of the request.
  • Order and contract records: 7 years from the end of the contractual relationship, in accordance with our legal and tax obligations.
  • Marketing contact data: Until you withdraw consent or opt out, or until we determine the data is no longer relevant to our legitimate interests.
  • Website analytics data: Up to 26 months, in line with standard analytics practice.
  • Legal claims data: For the duration of any proceedings and up to 6 years thereafter, in accordance with the Limitation Act 1980.
  • General correspondence and emails: 3 years, for business records and dispute resolution purposes.

Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with our documented disposal procedures. We conduct periodic audits of retained data to ensure ongoing compliance.

08

Data Security

We implement appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include:

๐Ÿ”
Encryption
Data in transit is protected using SSL/TLS encryption. Sensitive data at rest is encrypted using industry-standard protocols.
๐Ÿ”‘
Access Controls
Access to personal data is restricted on a role-based, need-to-know basis. All staff with access to personal data are subject to appropriate confidentiality obligations.
๐Ÿ“ก
Security Monitoring
We maintain logging and monitoring of access to systems containing personal data and conduct regular security assessments and penetration testing.
๐ŸŽ“
Staff Training
All staff who handle personal data receive regular, role-appropriate data protection training and awareness updates.
๐Ÿšจ
Incident Response
We maintain a documented Personal Data Breach Response Procedure. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO within 72 hours and affected individuals without undue delay, in accordance with Articles 33 and 34 of the UK GDPR.
๐Ÿค
Vendor Due Diligence
All third-party processors are subject to due diligence checks and are required to enter into Data Processing Agreements prior to processing any personal data on our behalf.
09

Third-Party Processors & Vendor Relationships

As a technology reseller, BritHaven Tech operates within a supply chain that involves a number of third-party Vendors and service providers. We manage these relationships as follows:

9.1 Sub-Processors

Where we engage third-party processors (sub-processors) to process personal data on our behalf, we conduct appropriate due diligence and enter into written Data Processing Agreements in accordance with Article 28 of the UK GDPR. Sub-processors are permitted to process personal data only in accordance with our documented instructions and for no other purpose.

9.2 Vendor Data Controllers

Where our Vendor partners act as independent data controllers in respect of data shared with them โ€” for example, to provision licences or activate cloud services โ€” we ensure that such sharing is disclosed in our Privacy Policy and that an appropriate lawful basis exists. Clients are directed to the relevant Vendor's privacy policy for details of their own processing activities.

9.3 Sub-Processor Register

We maintain an internal register of all sub-processors engaged in the processing of personal data. This register is reviewed and updated periodically. Clients who have entered into a Data Processing Agreement with us may request details of our current sub-processors by contacting dpo@brithaven.co.uk .

10

International Data Transfers

Where personal data is transferred outside the United Kingdom โ€” for example, to Vendor partners or cloud service providers based in other countries โ€” we ensure that appropriate safeguards are in place before any transfer takes place. The safeguards we rely upon include:

  • UK Adequacy Regulations where the destination country has been assessed as offering an adequate level of data protection by the UK Secretary of State.
  • UK International Data Transfer Agreement (IDTA) for transfers to countries without a UK adequacy decision, ensuring that equivalent protections apply contractually.
  • UK Addendum to EU Standard Contractual Clauses where applicable, as an alternative transfer mechanism approved by the Information Commissioner's Office (ICO).
  • Binding Corporate Rules (BCRs) where a Vendor has approved BCRs in place that cover transfers to the United Kingdom.

We do not transfer personal data to countries or territories that do not offer an adequate level of protection without first implementing one of the safeguards described above. Details of the specific safeguards applicable to any transfer are available upon request from dpo@brithaven.co.uk .

11

Records of Processing Activities

In accordance with Article 30 of the UK GDPR, BritHaven Tech maintains a Record of Processing Activities (RoPA). This document sets out, in respect of each processing activity:

  • The categories of personal data processed and the categories of data subjects affected.
  • The specific purpose of processing and the lawful basis relied upon.
  • Any third-party recipients of the data, including sub-processors.
  • Details of any international transfers and the safeguards in place.
  • Applicable retention periods and disposal methods.
  • A general description of the technical and organisational security measures in place.

Our RoPA is reviewed and updated at least annually, and whenever a new processing activity is introduced or an existing activity is materially changed.

12

Privacy by Design & Default

BritHaven Tech adopts a Privacy by Design and by Default approach in accordance with Article 25 of the UK GDPR. This means that data protection considerations are embedded into the design of new systems, processes, and products from the outset, rather than being applied retrospectively.

By default, we process only the minimum amount of personal data necessary for each specific purpose, and data is not made accessible to third parties without explicit justification. All new systems and processes undergo a privacy review prior to implementation. Our Privacy team is consulted at the design stage of any project involving personal data. Default settings across our systems are configured to collect and share the minimum data necessary.

Data Protection Impact Assessments (DPIAs) are conducted for any processing activity that is likely to result in a high risk to the rights and freedoms of individuals.

๐Ÿ—๏ธ How We Implement This
All new systems and processes undergo a privacy review prior to implementation. Our Privacy team is consulted at the design stage of any project involving personal data. Default settings across our systems are configured to collect and share the minimum data necessary.
13

Cookies & Electronic Marketing

We use cookies and similar technologies in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR. Non-essential cookies are only placed on users' devices with their prior, informed consent. Full details of the cookies we use and how consent is managed are set out in our Cookie Policy.

In respect of electronic marketing, we comply with PECR requirements by ensuring that marketing communications are sent only to individuals who have provided prior consent, or who are existing business contacts and have not opted out, in accordance with the soft opt-in exemption for B2B communications. All marketing emails include a clear and prominent unsubscribe mechanism.

14

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) prior to undertaking any processing that is likely to result in a high risk to the rights and freedoms of data subjects. This includes, but is not limited to:

  • The introduction of new technologies or significant changes to existing systems that process personal data.
  • Large-scale processing of personal data, particularly where special category data is involved.
  • Systematic monitoring of individuals, including through website analytics or tracking technologies.
  • Processing activities involving vulnerable individuals or children.

Where a DPIA indicates a high residual risk that cannot be mitigated through reasonable organisational or technical measures, we consult the ICO prior to commencing the relevant processing activity, in accordance with Article 36 of the UK GDPR.

15

Complaints & Regulatory Contact

If you have a concern about our data protection practices, we encourage you to contact us in the first instance so that we can seek to resolve the matter directly and promptly.

Information Commissioner's Office
We aim to acknowledge all complaints within two (2) business days and to resolve them within one (1) calendar month. If you remain dissatisfied following our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent data protection supervisory authority:
๐ŸŒ
www.ico.org.uk
๐Ÿ“ž
0303 123 1113
๐Ÿ“ฎ
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
16

Review & Governance

This GDPR Compliance page, together with our Privacy Policy, Cookie Policy, and associated internal documentation, is reviewed at least annually by our Privacy team and updated to reflect any changes in applicable law, regulatory guidance, or our business practices.

This page was last reviewed and updated on 27 May 2025. BritHaven Tech's commitment to data protection is endorsed at Board level. Accountability for GDPR compliance rests with our designated Data Protection Officer / Privacy Contact, who reports directly to senior management and has the authority and resource necessary to carry out their responsibilities effectively. An out-of-cycle review is triggered by any material change to applicable law, ICO guidance, or our processing activities.

๐Ÿ“… Review Schedule
This page is reviewed annually as a minimum. It was last reviewed and updated on 27 May 2025. An out-of-cycle review is triggered by any material change to applicable law, ICO guidance, or our processing activities.