GDPR Compliance
Last updated: August 4, 2026
Our Commitment to Data Protection
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page explains how we comply with these regulations and what rights you have regarding your personal information.
Data Controller
For the purposes of data protection legislation, the data controller is bear-dash, located at 47 Hanover Street, Edinburgh, EH2 2PJ, United Kingdom. You can contact us at [email protected].
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
- Consent: where you have given clear consent for us to process your personal data for specific purposes
- Contract: where processing is necessary to perform a contract we have with you
- Legal obligation: where we must process your data to comply with the law
- Legitimate interests: where processing is necessary for our legitimate business interests, provided this does not override your rights
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a subject access request.
Right to Rectification
You can ask us to correct any personal data that is inaccurate or incomplete.
Right to Erasure
You can request that we delete your personal data in certain circumstances, such as when it is no longer necessary for the purpose it was collected or you withdraw consent.
Right to Restrict Processing
You can ask us to limit how we use your personal data in certain situations, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and to transmit it to another organisation.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
We do not use automated decision making or profiling in our services. All assessments and decisions are made by qualified professionals.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this may be extended in complex cases.
You will not have to pay a fee to exercise your rights unless your request is clearly unfounded or excessive. In such cases, we may charge a reasonable fee or refuse to comply with the request.
Data Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Staff training on data protection principles
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also report the breach to the Information Commissioner's Office where required by law.
International Data Transfers
We do not routinely transfer personal data outside the United Kingdom or European Economic Area. If such transfers become necessary, we will ensure appropriate safeguards are in place as required by GDPR.
Supervisory Authority
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data in accordance with GDPR. Contact details for the ICO:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk
Updates to This Information
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.