Our commitment to protecting your data under the General Data Protection Regulation
Last updated: January 2024
storitracc is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have implemented this GDPR Compliance Statement to demonstrate our commitment to meeting the requirements of the General Data Protection Regulation (GDPR).
For the purposes of the GDPR, storitracc acts as a data controller when processing your personal data. As a data controller, we determine the purposes and means of processing personal data.
Our contact details are:
storitracc
47 Park Row
Leeds, LS1 5JL
United Kingdom
Email: [email protected]
We process personal data under the following lawful bases:
The GDPR provides you with the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a small fee for this service in certain circumstances.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data, under certain conditions.
You have the right to request that we restrict the processing of your personal data, under certain conditions.
You have the right to object to our processing of your personal data, under certain conditions.
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
We adhere to the principles relating to processing of personal data set out in the GDPR which require personal data to be:
When we arrange travel to destinations outside the United Kingdom and European Economic Area, we may need to transfer your personal data to travel suppliers in those countries. In such cases, we ensure appropriate safeguards are in place to protect your data.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
We may update this GDPR Compliance Statement from time to time. Any changes will be posted on this page with an updated revision date.