GDPR Compliance
Last Updated: August 2026
Our Commitment to Data Protection
grand-wave is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in all aspects of our data processing activities.
This page outlines how we meet our obligations under GDPR and describes your rights as a data subject.
Data Controller Information
For the purposes of UK GDPR, the data controller is:
grand-wave
142 Kingsland Road
London, E2 8DY
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so:
- Contract: Processing is necessary to perform our contractual obligations when you engage our services
- Legal Obligation: Processing is required to comply with legal or regulatory requirements
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your rights and freedoms
- Consent: You have given explicit consent for specific processing activities
Data Protection Principles
We adhere to the following data protection principles:
- Lawfulness, fairness, and transparency: We process data lawfully, fairly, and in a transparent manner
- Purpose limitation: We collect data for specified, explicit, and legitimate purposes only
- Data minimization: We collect only the data necessary for our stated purposes
- Accuracy: We take reasonable steps to ensure personal data is accurate and up to date
- Storage limitation: We retain data only for as long as necessary
- Integrity and confidentiality: We implement appropriate security measures to protect personal data
- Accountability: We take responsibility for our data processing activities and can demonstrate compliance
Your GDPR Rights
As a data subject, you have the following rights under UK GDPR:
Right to Be Informed
You have the right to clear, transparent information about how we collect and use your personal data.
Right of Access
You can request a copy of the personal data we hold about you. We will provide this information within one month of your request, free of charge.
Right to Rectification
If you believe any information we hold about you is inaccurate or incomplete, you can request that we correct or complete it.
Right to Erasure
In certain circumstances, you can request that we delete your personal data. This right is not absolute and may be limited by legal obligations to retain certain information.
Right to Restrict Processing
You can request that we limit how we use your data in specific situations, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit this data to another controller.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently engage in automated decision making.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with the following information:
- Your full name and contact details
- A description of the right you wish to exercise
- Any relevant details or documentation to verify your identity
We will respond to your request within one month. In complex cases, we may extend this period by up to two additional months, and we will inform you of any such extension.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection and security
- Incident response and breach notification procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
We will also notify the Information Commissioner's Office (ICO) as required by law.
International Data Transfers
We primarily process data within the United Kingdom. If we transfer personal data outside the UK, we will ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the ICO
- Transfers to countries with adequacy decisions
- Other legally recognized transfer mechanisms
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal, regulatory, or professional obligations.
Client files are typically retained for six years following case closure, after which they are securely destroyed unless legal requirements mandate longer retention.
Third-Party Processors
When we engage third-party service providers who process personal data on our behalf, we ensure they:
- Provide sufficient guarantees of appropriate technical and organizational security measures
- Process data only on our documented instructions
- Maintain confidentiality and security of personal data
- Assist us in meeting our GDPR obligations
Complaints and Supervisory Authority
If you have concerns about how we handle your personal data, please contact us first so we can address your concerns.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Updates to This Policy
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.