GDPR Compliance

Our commitment to data protection under the General Data Protection Regulation

Data Controller

For the purposes of GDPR, tutelammel acts as the data controller for personal information collected through this website and in the course of providing environmental consulting services.

Legal Basis for Processing

We process personal data under the following legal bases:

  • Consent: When you submit a consultation request, you provide explicit consent for us to process your personal information for the stated purpose
  • Contractual necessity: Processing is necessary for the performance of consulting services you have engaged us to provide
  • Legitimate interests: We may process data where necessary for our legitimate business interests, such as maintaining professional records and complying with professional indemnity insurance requirements
  • Legal obligation: We process data to comply with legal and regulatory requirements applicable to environmental consulting practices

Data Subject Rights

Under GDPR, you have comprehensive rights regarding your personal data:

Right of Access

You may request confirmation of whether we process your personal data and obtain a copy of that data along with information about how it is processed.

Right to Rectification

You may request correction of inaccurate personal data and completion of incomplete personal data.

Right to Erasure

You may request deletion of your personal data in certain circumstances, though this right is subject to exceptions where we have legal obligations to retain records.

Right to Restriction

You may request restriction of processing in specific situations, such as when you contest the accuracy of data or object to processing.

Right to Data Portability

You may request transfer of your personal data in a structured, commonly used, and machine-readable format.

Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision Making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.

How to Exercise Your Rights

To exercise any of these rights, please contact us using the details provided on our contact page. We will respond to requests within one month, though this period may be extended by two additional months for complex requests.

Data Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Staff training on data protection principles

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and will communicate the breach to affected individuals without undue delay where required by GDPR.

International Data Transfers

Your personal data is processed and stored within the United Kingdom. We do not transfer personal data outside the UK except where necessary to fulfill contractual obligations, and only with appropriate safeguards in place.

Supervisory Authority

You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters, if you believe your data protection rights have been violated.

Updates to This Notice

We may update this GDPR compliance information to reflect changes in our practices or applicable regulations. Material changes will be communicated through updates to this page.