Our Commitment to Data Protection
maple-bison is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides information about how we handle personal data in accordance with these regulations.
Data Controller
maple-bison is the data controller for personal information collected through this website and in the course of providing our property services. As data controller, we determine the purposes and means of processing personal data and are responsible for ensuring compliance with data protection laws.
Contact details:
maple-bison
47 Duke Street
Liverpool L1 5AP
United Kingdom
Email: [email protected]
Lawful Bases for Processing
Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:
Contractual Necessity
We process personal data where necessary to perform our contract with you. This includes processing your requirements to search for suitable properties, coordinating viewings, and facilitating tenancy agreements.
Legitimate Interests
We may process personal data where necessary for our legitimate business interests, provided these interests do not override your fundamental rights. Our legitimate interests include:
- Improving and developing our services
- Maintaining records for business administration
- Ensuring the security of our systems and data
- Analysing website usage to enhance user experience
Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw consent at any time. We will clearly inform you when consent is required and provide easy mechanisms to withdraw it.
Legal Obligation
We may process personal data where necessary to comply with legal obligations, such as anti-money laundering requirements or responding to lawful requests from authorities.
Your Rights Under UK GDPR
UK GDPR provides you with specific rights regarding your personal data:
Right to be Informed
You have the right to be informed about the collection and use of your personal data. This page and our Privacy Policy provide this information.
Right of Access
You have the right to request a copy of the personal data we hold about you. We will respond to such requests within one month of receipt.
Right to Rectification
You have the right to have inaccurate personal data corrected or incomplete data completed. We aim to respond to rectification requests within one month.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for its original purpose, where you withdraw consent, or where you object to processing based on legitimate interests.
Right to Restrict Processing
You have the right to request restriction of processing in certain circumstances, such as while we verify the accuracy of contested data or consider an objection to processing.
Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to processing for direct marketing, we will cease such processing immediately.
Rights Related to Automated Decision-Making
You have rights related to automated decision-making and profiling. We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects.
Exercising Your Rights
To exercise any of these rights, please contact us using the details above. We may need to verify your identity before fulfilling your request. There is no fee for most requests, though we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests.
We will respond to your request within one month. This period may be extended by two further months where requests are complex or numerous, in which case we will inform you within one month of receipt and explain the reason for the extension.
Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) where processing is likely to result in a high risk to individuals' rights and freedoms. This helps us identify and minimise data protection risks associated with new projects or changes to our operations.
Data Breaches
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where a breach is likely to result in a high risk, we will also notify affected individuals directly.
International Transfers
Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place. This may include transfer to countries with adequate data protection laws or the use of standard contractual clauses approved by the Information Commissioner.
Supervisory Authority
The supervisory authority for data protection in the UK is the Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO if you believe your data protection rights have been violated.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Updates to This Information
We review our data protection practices regularly and may update this page to reflect changes in our operations or legal requirements. We encourage you to review this information periodically.