Data Protection Policy
Last updated: 24 September 2026. This is a draft prepared to reflect the actual website as built. It should be reviewed by a qualified professional before the site goes live.
1. Purpose
This policy explains how Valendra complies with the UK GDPR and the Data Protection Act 2018. This is designed with UK privacy and data protection requirements in mind; we do not claim any specific certification.
2. Principles
We handle personal data lawfully, fairly and transparently, for specific purposes, limited to what is needed, kept accurate, retained no longer than necessary, and kept secure. We are responsible for being able to show this.
3. Our role
For our own enquiries and client contacts, we act as controller. Where we handle a client's customer data on their behalf, we act as a processor, only on documented instructions.
4. Security measures
We use multi-factor authentication and password management, keep devices updated and locked, limit access to those who need it, and remove access promptly when no longer needed.
5. Suppliers and AI tools
We choose providers with appropriate data protection terms, including our form provider Web3Forms. We do not enter personal data into public AI tools without appropriate safeguards.
6. International transfers
Where personal data is transferred outside the UK, we rely on UK adequacy regulations or approved safeguards.
7. Individual rights
We log and respond to requests to access, correct, erase, restrict or transfer personal data, within one month.
8. Data breaches
We record and assess any data breach. Where required, we report to the ICO within 72 hours and tell affected individuals without undue delay where there is a high risk to them.
9. Retention and deletion
We follow the retention periods set out in our Privacy Notice, and securely delete or return client data when a contract ends, on request.
10. Marketing messages
We only send marketing emails to people who have given valid consent, always include a way to opt out, and act on opt-outs promptly.
11. Review
This policy is reviewed at least once a year.