GDPR Compliance
Last updated: January 2024
Our Commitment to Data Protection
magenta-root is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we comply with these regulations and explains your rights.
Data Controller
magenta-root acts as the data controller for personal information collected through our website and services. Our contact details are:
magenta-root
47 Castle Street
Liverpool, L2 9SH
United Kingdom
Email: [email protected]
Categories of Personal Data
We process the following categories of personal data:
- Identity Data: Name, title
- Contact Data: Email address, postal address
- Transaction Data: Course enrolments, payment records
- Technical Data: IP address, browser type, device information
- Usage Data: Information about how you use our website
- Communications Data: Your correspondence with us
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Performance of Contract: To deliver courses and services you have enrolled in
- Consent: For marketing communications, which you can withdraw at any time
- Legitimate Interests: For website improvement, fraud prevention, and service enhancement
- Legal Obligation: To comply with applicable laws and regulations
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access
You can request a copy of the personal data we hold about you. We will respond within one month of receiving your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected.
Right to Restrict Processing
You can request that we limit how we use your data while concerns are being investigated.
Right to Data Portability
You can request to receive your data in a structured, commonly used format, or to have it transferred to another controller.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have rights concerning automated decision-making and profiling. We do not currently use automated decision-making that produces legal or similarly significant effects.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond to valid requests within one month, though this may be extended by two months for complex requests.
Data Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication procedures
- Staff training on data protection
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
International Data Transfers
We primarily process data within the UK and EEA. Any international transfers are conducted with appropriate safeguards in place, such as Standard Contractual Clauses or adequacy decisions.
Complaints
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Updates to This Information
We may update this GDPR compliance information periodically to reflect changes in our practices or legal requirements. The date at the top indicates when this page was last revised.