General Data Protection Regulation information
calm-leaf is committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area and the United Kingdom. This page outlines how we fulfill our obligations under GDPR.
We process personal data under the following lawful bases:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data along with supplementary information about how it is processed.
You may request correction of inaccurate personal data or completion of incomplete personal data we hold about you.
Under certain circumstances, you have the right to request deletion of your personal data. This right is not absolute and may be limited by legal obligations requiring us to retain certain information.
You may request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in such automated decision making.
To exercise any of the rights outlined above, please submit a request to [email protected]. We will respond to your request within one month, though this period may be extended by two additional months where necessary, taking into account the complexity and number of requests.
For questions regarding our GDPR compliance or data protection practices, you may contact our data protection representative at [email protected].
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. In the United Kingdom, the relevant supervisory authority is the Information Commissioner's Office (ICO).
We primarily operate within the United Kingdom. Should we need to transfer personal data outside the UK or EEA, we will ensure appropriate safeguards are in place as required by GDPR, such as standard contractual clauses or adequacy decisions.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay, providing information about the nature of the breach and measures taken to address it.
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Material changes will be communicated through prominent notice on our website.