GDPR Compliance
Last updated: 19 June 2026
Our Commitment to Data Protection
grove-vector.com is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller
grove-vector acts as the data controller for personal information collected through this website and our services. We determine how and why your personal data is processed.
Data Controller: grove-vector
Address: 42 Wellington Street, Leeds, West Yorkshire, LS1 4AB, United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process your personal data under the following lawful bases:
Consent
When you submit consultation requests or contact forms, we process your data based on your explicit consent. You may withdraw consent at any time by contacting us.
Contractual Necessity
Processing is necessary to perform services you have requested or to take steps prior to entering into a service agreement.
Legitimate Interests
We process certain data based on our legitimate business interests, such as:
- Improving our website and services
- Analyzing usage patterns
- Preventing fraud and ensuring security
- Internal administrative purposes
Legal Obligation
We process data when required to comply with legal and regulatory obligations applicable to financial services.
Your Rights Under GDPR
Right to Access
You have the right to request a copy of the personal data we hold about you. This is known as a subject access request.
Right to Rectification
You can request that we correct inaccurate personal data or complete incomplete data.
Right to Erasure
You can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You can request that we limit how we use your personal data in specific situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transfer it to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected] with the following information:
- Your full name
- Contact details
- Description of your request
- Proof of identity (if required)
We will respond to your request within one month of receipt. In complex cases, this period may be extended by up to two additional months, and we will inform you of any such extension.
Data Security Measures
We implement appropriate technical and organizational security measures including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
International Data Transfers
Your personal data is primarily processed within the United Kingdom. If we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the UK authorities.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Financial records are typically retained for seven years in accordance with regulatory requirements.
Third-Party Processors
When we engage third-party service providers to process data on our behalf, we ensure they:
- Provide sufficient guarantees of data security
- Process data only according to our instructions
- Maintain appropriate technical and organizational measures
- Comply with GDPR requirements
Children's Data
Our services are not directed at children under 18. We do not knowingly collect or process personal data from children.
Changes to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.
Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
Contact Us
For questions about GDPR compliance or to exercise your rights, contact us at [email protected].