Information on this site is advertising in nature

GDPR Compliance

General Data Protection Regulation

Our Commitment

Sepia Harbor is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and your rights under this regulation.

Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: When you submit an enquiry form or subscribe to updates
  • Contract Performance: To provide route documentation and services you have requested
  • Legitimate Interests: To improve our services and respond to enquiries

Your GDPR Rights

Under GDPR, you have the following rights:

  • Right to Access: You can request a copy of the personal data we hold about you
  • Right to Rectification: You can request correction of inaccurate personal data
  • Right to Erasure: You can request deletion of your personal data in certain circumstances
  • Right to Restriction: You can request we restrict processing of your personal data
  • Right to Data Portability: You can request transfer of your data to another service
  • Right to Object: You can object to processing of your personal data
  • Right to Withdraw Consent: You can withdraw consent at any time where we rely on consent

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.

Data Processing Activities

We process personal data for the following purposes:

  • Providing route documentation and customer service
  • Responding to enquiries and requests
  • Improving our website and services
  • Maintaining business records

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. When data is no longer needed, we securely delete or anonymize it. Specific retention periods depend on the type of data and legal requirements.

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.

International Data Transfers

We primarily process data within the United Kingdom. If we transfer data outside the UK or EEA, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.

Complaints

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your local data protection authority.

Contact Information

For any questions regarding GDPR compliance or to exercise your rights, please contact us at [email protected].