Skip to content
BritonOne Technology
Legal

GDPR Policy

This policy sets out how BritonOne Technology Ltd meets its obligations under the UK GDPR, the Data Protection Act 2018, and the EU GDPR for our EU-resident contacts. It complements our Privacy Policy, which describes the personal data we hold in more detail.

01

Scope and roles

This policy applies to all personal data BritonOne Technology Ltd processes, whether we determine the purposes and means of processing (as a controller) or process on documented instructions from a client (as a processor).

We are a controller for our own enquiry, client, supplier, and candidate data. We are a processor when we operate inside a client's environment on an engagement, in which case the client remains the controller and our obligations are governed by a written data-processing agreement.

02

The principles we apply

We process personal data in line with the GDPR principles set out in Article 5:

  • Lawfulness, fairness, and transparency: we process data only where we have a lawful basis and tell people how their data is used.
  • Purpose limitation: we collect data for specified, explicit purposes and do not repurpose it incompatibly.
  • Data minimisation: we collect only what is adequate, relevant, and necessary.
  • Accuracy: we keep data up to date and correct or erase inaccurate data without delay.
  • Storage limitation: we retain data only as long as necessary for the purpose or as required by law.
  • Integrity and confidentiality: we protect data with appropriate technical and organisational measures.
03

Lawful bases for processing

As a controller we rely on the following lawful bases under UK GDPR Article 6, depending on the context:

  • Contract (Article 6(1)(b)): to perform an engagement or take pre-contract steps at your request.
  • Legitimate interest (Article 6(1)(f)): for ordinary business correspondence, internal recruiting, and aggregate analytics.
  • Legal obligation (Article 6(1)(c)): for tax, employment, anti-money-laundering, and KYC processing.
  • Consent (Article 6(1)(a)): only where you have explicitly opted in, for example to marketing communications.
04

Your rights as a data subject

Under the UK and EU GDPR you have the following rights over your personal data. We honour them free of charge for ordinary requests and respond within one calendar month.

  • Right of access: to obtain a copy of the personal data we hold about you.
  • Right to rectification: to have inaccurate or incomplete data corrected.
  • Right to erasure: to have your data deleted where there is no overriding lawful reason to keep it.
  • Right to restriction: to limit how we process your data in defined circumstances.
  • Right to data portability: to receive your data in a structured, machine-readable format.
  • Right to object: to object to processing based on legitimate interest, and to direct marketing at any time.
  • Rights around automated decisions: we do not make solely automated decisions that produce legal or similarly significant effects.
05

How to exercise your rights

To exercise any of these rights, email our data-protection contact below. We may ask you to verify your identity before we act, to protect your data from unauthorised disclosure.

If you are unhappy with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.

06

When we act as a processor

When we process personal data on behalf of a client, we do so only on the client's documented instructions and under a written data-processing agreement that reflects Article 28. In that role we commit to:

  • Processing personal data only on the controller's documented instructions.
  • Ensuring everyone authorised to process the data is bound by confidentiality.
  • Applying appropriate technical and organisational security measures.
  • Engaging sub-processors only with the controller's authorisation and equivalent contractual terms.
  • Assisting the controller with data-subject requests and breach obligations.
  • Deleting or returning personal data at the end of the engagement, as instructed.
07

Sub-processors

We use a small, vetted set of sub-processors to operate: cloud and SaaS providers for storage, communication, and CRM, and payroll and background-check providers for our own staff and candidates. Each is engaged under a written agreement with GDPR-equivalent terms.

Where we act as a processor, we engage sub-processors only with the client's authorisation and give notice of any intended change so the client can object.

08

International transfers

We primarily process personal data inside the UK and EU. Where data is transferred outside the UK or EEA (for example to a US-based cloud provider), we rely on adequacy decisions where they exist, or on UK GDPR-approved Standard Contractual Clauses and the UK International Data Transfer Addendum, with additional safeguards where needed.

09

Personal data breach notification

We maintain an incident-response process for personal data breaches. As a controller, we notify the ICO within 72 hours of becoming aware of a breach that poses a risk to individuals, and we inform affected individuals without undue delay where the risk is high.

As a processor, we notify the relevant controller without undue delay after becoming aware of a breach affecting their data, and support them in meeting their own notification obligations.

10

Retention

We retain personal data only as long as necessary for the purpose for which it was collected or as required by law. Detailed retention periods for each category of data are set out in our Privacy Policy.

11

Accountability and governance

We keep records of our processing activities, carry out data-protection impact assessments for higher-risk processing, and apply data protection by design and by default to new systems and features. Our security posture is certified to ISO 27001 and SOC 2 Type II.

Data protection contact

Email: hello@britonone.co.uk

Data Protection · BritonOne Technology Ltd134 Westbourne TerraceLondon W2 6QBUnited Kingdom

This is one of BritonOne Technology’s published legal and governance documents. The others are linked from the footer on every page.

← Back to home