Our Commitment to Data Protection
reed-path is committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We recognize the importance of data privacy and implement appropriate measures to safeguard the personal information of our website visitors and clients.
Data Controller
reed-path acts as the data controller for personal information collected through this website and in the course of providing professional museum services. We determine the purposes and means of processing your personal data.
Contact details:
reed-path
27 Marlborough Street
Bristol BS1 3NX
United Kingdom
Email: contact@reed-path.com
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so under UK GDPR. The lawful bases we rely on include:
- Consent: You have given clear consent for us to process your personal data for specific purposes, such as when you submit an inquiry form
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legal obligation: Processing is necessary to comply with legal or regulatory requirements
- Legitimate interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms
Your GDPR Rights
Under UK GDPR, you have the following rights regarding your personal data:
Right to Be Informed
You have the right to clear, transparent information about how we use your personal data. This information is provided through our Privacy Policy and this GDPR statement.
Right of Access
You have the right to request access to the personal data we hold about you. This is commonly known as a "subject access request." We will provide a copy of your personal data free of charge within one month of your request.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data we hold about you. We will correct verified inaccuracies within one month.
Right to Erasure
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, including when:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data was unlawfully processed
Right to Restrict Processing
You have the right to request restriction of processing your personal data in certain situations, such as when you contest the accuracy of the data or object to processing based on legitimate interests.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller where technically feasible.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects. We do not engage in automated decision-making or profiling.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us in writing:
- Email: contact@reed-path.com
- Post: 27 Marlborough Street, Bristol BS1 3NX, United Kingdom
We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two months and will notify you of the extension.
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest where appropriate
- Regular security assessments and updates
- Access controls limiting data access to authorized personnel only
- Staff training on data protection principles and practices
- Confidentiality agreements with third-party processors
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also report the breach to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it, where required by law.
Third-Party Processing
When we engage third-party service providers to process personal data on our behalf, we ensure they provide sufficient guarantees regarding security and confidentiality through written data processing agreements that comply with UK GDPR requirements.
Complaints
If you believe we have not handled your personal data in accordance with UK GDPR, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
We encourage you to contact us first so we can address your concerns directly.
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Any updates will be posted on this page with a revised date.