GDPR Compliance
Your data protection rights under the UK General Data Protection Regulation.
Last updated: 26 June 2026
Our Commitment
spry-cedar is committed to protecting your personal data and respecting your privacy rights in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This page explains your rights under data protection law and how you can exercise them.
Data Controller
spry-cedar is the data controller responsible for your personal data collected through this website and our services.
Contact details:
spry-cedar
14 Park Square East
Leeds, LS1 2LH
United Kingdom
Email: [email protected]
Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
Right to Be Informed
You have the right to be informed about how we collect and use your personal data. Our Privacy Policy provides detailed information about our data processing activities.
Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR). We will respond to valid requests within one month.
Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you. You also have the right to have incomplete data completed.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including:
- When the data is no longer necessary for its original purpose
- When you withdraw consent (where consent was the legal basis)
- When you object to processing and there are no overriding legitimate grounds
- When the data has been unlawfully processed
Right to Restrict Processing
You have the right to request that we restrict processing of your personal data in certain circumstances, such as:
- While we verify the accuracy of data you have challenged
- When processing is unlawful but you prefer restriction over erasure
- When we no longer need the data but you need it for legal claims
- While we consider your objection to processing
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision Making
You have rights related to automated decision making and profiling. spry-cedar does not currently use automated decision making that produces legal or similarly significant effects.
Exercising Your Rights
To exercise any of your rights, please contact us at:
Email: [email protected]
Or write to us at our postal address.
We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any extension within one month of your request.
We may ask you to verify your identity before processing your request to protect your privacy and security.
No Fee Usually Required
You will not have to pay a fee to exercise your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
Lawful Bases for Processing
We process personal data under the following lawful bases:
- Consent: Where you have given clear consent for specific purposes
- Contract: Where processing is necessary for performance of a contract with you
- Legitimate Interests: Where processing is necessary for our legitimate interests and does not unduly affect your rights
- Legal Obligation: Where processing is necessary to comply with the law
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular testing of security measures
- Staff training on data protection
- Access controls limiting who can view personal data
Data Breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
International Transfers
Your personal data is primarily processed within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
Complaints
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We would appreciate the opportunity to address your concerns before you approach the ICO. Please contact us first so we can attempt to resolve any issues.
Updates
We may update this page periodically to reflect changes in our practices or legal requirements. Please check back regularly for updates.