GDPR Compliance
Last updated: January 2024
Our Commitment
seed-gate is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we handle personal data in accordance with these regulations.
Data Controller
seed-gate is the data controller for personal information collected through this website and our services. Our contact details are:
seed-gate
47 Deansgate
Manchester, M3 2AY
[email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contract: Processing necessary to fulfil travel booking services you have requested
- Legitimate interests: Processing necessary for our legitimate business interests, such as improving our services and website, provided these interests do not override your rights
- Consent: Where you have given clear consent for specific processing activities, such as receiving marketing communications
- Legal obligation: Processing necessary to comply with legal requirements
Your Rights Under GDPR
Under UK GDPR, you have the following rights:
- Right of access: You can request a copy of the personal data we hold about you
- Right to rectification: You can ask us to correct inaccurate or incomplete data
- Right to erasure: In certain circumstances, you can ask us to delete your data
- Right to restrict processing: You can ask us to limit how we use your data
- Right to data portability: You can request your data in a structured, commonly used format
- Right to object: You can object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making: You have rights regarding decisions made solely by automated means
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. If your request is complex or we receive many requests, we may extend this period by up to two additional months, but we will inform you of any extension within the first month.
There is no fee for making a request unless it is manifestly unfounded or excessive.
Data Transfers
When we share your personal data with travel suppliers located outside the UK, we ensure appropriate safeguards are in place. This may include:
- Transfers to countries with adequate data protection laws as determined by the UK government
- Standard contractual clauses approved for international transfers
- Other legally recognised transfer mechanisms
Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Secure storage systems with access controls
- Staff training on data protection
- Regular review of security practices
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to you, we will also notify you directly.
Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first.