Last Updated: July 2026
Our Commitment to Data Protection
tide-vector is committed to complying with the UK General Data Protection Regulation and the Data Protection Act 2018. We take our data protection responsibilities seriously and have implemented appropriate policies, procedures, and technical measures to ensure your personal information is processed lawfully, fairly, and transparently.
Data Controller Information
For the purposes of data protection legislation, tide-vector acts as the data controller for personal information collected through our website and business operations.
Contact Details:
Email: [email protected]
Address: 127 Riverside Quarter, Birmingham, B4 7RN, United Kingdom
Principles of Data Processing
We adhere to the following data protection principles when processing personal data:
- Lawfulness, Fairness, and Transparency: We process data lawfully and inform you how we use your information
- Purpose Limitation: We collect data for specific, explicit purposes and do not use it for incompatible purposes
- Data Minimization: We collect only the data necessary for our stated purposes
- Accuracy: We take reasonable steps to ensure personal data is accurate and up to date
- Storage Limitation: We retain data only as long as necessary for the purposes collected
- Integrity and Confidentiality: We implement appropriate security measures to protect your data
- Accountability: We maintain records demonstrating our compliance with data protection obligations
Your Data Protection Rights
Under UK GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a "subject access request." We will provide this information within one month of receiving your request, free of charge.
Right to Rectification
If you believe the personal data we hold about you is inaccurate or incomplete, you have the right to request correction or completion of that data.
Right to Erasure
Also known as the "right to be forgotten," this allows you to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected, or when you withdraw consent.
Right to Restriction of Processing
You can request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or object to our processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.
Rights Related to Automated Decision Making
We do not engage in automated decision making or profiling that produces legal effects or similarly significant effects.
How to Exercise Your Rights
To exercise any of the rights described above, please contact us using the details provided. We will respond to your request within one month, though this may be extended by two additional months for complex requests.
We may need to verify your identity before processing your request to ensure we are disclosing information to the correct person. This is a security measure to protect your personal data.
You will not have to pay a fee to exercise your rights unless your request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse to comply with the request.
Legal Bases for Processing
We process personal data under the following legal bases:
Contract
Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. This applies when you engage our renovation or design services.
Legitimate Interests
Processing is necessary for our legitimate business interests, such as:
- Responding to enquiries about our services
- Improving our website and services
- Maintaining business records
- Protecting against fraud or security threats
We balance our legitimate interests against your rights and freedoms, and we do not process data in ways you would not reasonably expect.
Consent
In some cases, we rely on your explicit consent for specific processing activities. You have the right to withdraw consent at any time, though this will not affect the lawfulness of processing prior to withdrawal.
Legal Obligation
Processing is necessary to comply with legal obligations, such as tax reporting requirements or responding to lawful requests from authorities.
Data Security Measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and vulnerability testing
- Staff training on data protection and information security
- Incident response procedures for data breaches
- Secure backup and recovery systems
Data Breach Notification
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also report the breach to the Information Commissioner's Office within 72 hours of becoming aware of it, where required by law.
Third-Party Processing
When we share personal data with third parties, we ensure they provide sufficient guarantees regarding the security and confidentiality of your data. We enter into data processing agreements with third parties who process data on our behalf, ensuring they process data only according to our instructions and comply with GDPR requirements.
International Data Transfers
We primarily store and process personal data within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as:
- Transfers to countries with adequacy decisions
- Standard contractual clauses approved by the UK authority
- Binding corporate rules
- Other legally recognized transfer mechanisms
Data Protection Officer
While not legally required to appoint a Data Protection Officer, we have designated internal responsibility for data protection compliance. Queries regarding data protection should be directed to [email protected].
Complaints and Supervisory Authority
If you believe we have not handled your personal data in accordance with data protection legislation, you have the right to lodge a complaint with the supervisory authority.
UK Supervisory Authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Children's Data
Our services are not directed at children under 16 years of age. We do not knowingly collect or process personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.
Updates to This Information
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Updates will be posted on this page with a revised date.
Further Information
For detailed information about how we process your personal data, please refer to our Privacy Policy. If you have specific questions about our GDPR compliance or data protection practices, please contact us using the details provided above.