Our commitment to protecting your data rights under the General Data Protection Regulation.
Last updated: January 2024
Branch-atom is committed to complying with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page explains how we ensure compliance and outlines your rights as a data subject.
Branch-atom acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.
Contact details for data protection enquiries:
Email: [email protected]
Address: 47 Innovation Way, Canary Wharf, London E14 5AB, United Kingdom
We process personal data on the following lawful bases:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will respond to your request within one month.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You have the right to request that we limit the processing of your personal data in certain circumstances.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects. We do not use automated decision-making in our services.
To exercise any of your data rights, please contact us using the details provided above. We will respond to your request within one month. In complex cases, we may extend this period by up to two months, in which case we will inform you of the extension and the reasons for it.
We may request verification of your identity before processing your request to ensure we protect your data appropriately.
We implement appropriate technical and organisational measures to protect personal data, including:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our retention periods are based on:
We primarily store and process data within the United Kingdom and European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place as required by GDPR.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in high risk to you, we will also notify you directly.
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
We may update this GDPR information from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically.