Our commitment to protecting your personal data under the General Data Protection Regulation.
Last updated: January 2024
fornisghin is committed to ensuring compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We recognise the importance of protecting your personal data and take our responsibilities seriously.
For the purposes of the GDPR, fornisghin acts as the data controller for personal data collected through our website and services. This means we determine the purposes and means of processing your personal data.
Contact details:
fornisghin
47 Greenfield Lane
Bristol, BS1 4QR
United Kingdom
Email: [email protected]
We process the following categories of personal data:
We only process personal data where we have a lawful basis to do so. The lawful bases we rely on include:
The GDPR provides you with the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
You have the right to request that we correct any inaccurate personal data we hold about you. We will respond to rectification requests within one month.
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
You have the right to request that we limit the way we use your personal data in certain circumstances.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by up to two months, in which case we will inform you.
We have implemented appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
We do not routinely transfer personal data outside of the United Kingdom. If we need to transfer data internationally, we will ensure appropriate safeguards are in place in accordance with GDPR requirements.
You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data violates the GDPR. In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO).
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: www.ico.org.uk
We may update this GDPR compliance information from time to time. We encourage you to review this page periodically to stay informed about our data protection practices.