GDPR Compliance
Last Updated: September 2026
Our Commitment to Data Protection
Vertex-willow is committed to protecting your personal data in accordance with the UK General Data Protection Regulation and Data Protection Act 2018. This page outlines how we comply with these regulations.
Data Controller Information
Vertex-willow acts as the data controller for personal information collected through this website and our business operations.
Contact: [email protected]
Address: 42 Kingsway Boulevard, Manchester M4 7JH, United Kingdom
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: When you submit forms or accept cookies
- Contract: To fulfill service agreements
- Legitimate Interests: For business operations and website improvement
- Legal Obligation: To comply with accounting and tax requirements
Your Rights Under GDPR
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this within one month of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent.
Right to Restrict Processing
You can request that we limit how we use your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with your request. We will respond within one month and may request verification of your identity to protect your data.
Data Security Measures
We implement appropriate technical and organizational measures including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
- Secure data storage and backup procedures
Data Retention
We retain personal data only as long as necessary:
- Inquiry data: 2 years
- Client contract data: 7 years (accounting requirements)
- Cookie consent records: 12 months
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.
International Data Transfers
We process data within the United Kingdom. Any data transfers outside the UK are protected by appropriate safeguards such as standard contractual clauses.
Children's Privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children.
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
ICO Website: ico.org.uk
Helpline: 0303 123 1113
Updates to Compliance Practices
We regularly review our data protection practices to ensure ongoing compliance with GDPR and UK data protection law.