GDPR & Your Data Rights
Under the GDPR, you hold specific rights regarding your personal data. At business-utility.com, we fully support and facilitate your ability to exercise the following rights:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Ask us to correct inaccurate or incomplete information.
Right to Erasure ("Right to be Forgotten")
Request that we permanently delete your data when it is no longer required.
Right to Restrict or Object
Object to or limit how we process your personal data under certain conditions.
Right to Data Portability
Request the transfer of your data to another organization in a structured format.
Right to Withdraw Consent
Easily withdraw your consent at any time if we rely on it to process your data.
Documented Policy Mapping & Summaries
The policies and procedures below govern how we protect personal data across every part of our organisation — from how information is classified and accessed, to how incidents are handled and vendors are assessed.
Data Classification and Handling Policy
Defines how data is categorised within our organisation based on sensitivity (e.g., Public, Internal, Confidential, Restricted/PII). It outlines specific technical controls and handling requirements for each tier, including mandatory encryption protocols for data at rest and in transit.
Physical and Environmental Security Policy
Outlines the physical safeguards established to protect our facilities, data centres, and corporate offices. It regulates visitor access management, clean-desk standards, security camera surveillance, and the physical locking of server rooms or cabinets containing hardware that processes personal data.
Acceptable Use Policy (AUP)
Establishes the rules governing the acceptable use of all company assets, networks, systems, and devices. It explicitly details employee obligations regarding the prevention of unauthorised data sharing, password hygiene, and prohibitions against using unapproved third-party software for corporate work.
Access Control Policy
Grounded in the principles of "least privilege" and "need-to-know", this framework dictates how user access is provisioned, modified, and revoked. It enforces the use of Multi-Factor Authentication (MFA), role-based access controls (RBAC), and mandates quarterly access reviews for critical environments housing personal data.
Incident Response Plan (IRP)
Provides a structured operational framework for detecting, containing, investigating, and recovering from security incidents. It outlines the specific roles of our Incident Response Team (IRT) and includes dedicated procedures for evaluating and executing regulatory and consumer notification obligations in the event of a personal data breach.
Data Retention and Disposal Policy
Defines the maximum and minimum retention periods for various categories of personal data based on legal, regulatory, and business requirements. It mandates secure destruction methods, such as certified cryptographic erasure for digital assets and cross-cut shredding for physical documentation.
Data Subject Rights (DSR) Procedure
Provides step-by-step instructions for internal teams to verify, process, and respond to data subject requests (such as access, deletion, correction, and portability requests) within legally mandated timeframes.
Employee Privacy and Security Awareness Code
Embedded within our employee handbook and mandatory annual training, this document outlines the ethical and contractual duties of staff. It covers confidentiality obligations, social engineering awareness, and the direct disciplinary actions associated with policy non-compliance or negligent data handling.
Vendor Risk Management Policy
Governs our procurement and vendor management lifecycle. It requires all third-party vendors and processors handling personal data to undergo rigorous security assessments, sign Data Processing Agreements (DPAs) containing standard contractual clauses, and submit to periodic security audits.
Third-Party Data Disclosures
We do not sell, rent, or trade your personal data. We only share information with trusted third-party service providers (such as hosting partners or analytics platforms) who are contractually bound by rigorous Data Processing Agreements (DPAs) to ensure your data stays safe and compliant.
Contact Our Privacy Team
If you have any questions about this statement, want to exercise your data rights, or need to contact our Data Protection Officer (DPO), please reach out to us directly:
Submit a data request
Use this form to request access to your data, ask us to correct or delete it, restrict processing, export it, or withdraw your consent. You will receive a confirmation email with your reference number.
To exercise any of the rights listed above, submit a request through our data request form above or email us at privacy@business-utility.com and we will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters.
Last updated: 5 September 2026
