This website contains information of an advertising nature

GDPR Compliance Statement

Last updated: 1 September 2026

Our Commitment to GDPR Compliance

We are committed to full compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This statement outlines how we meet our obligations under these regulations and explains your rights as a data subject.

Data Controller Information

For the purposes of GDPR, the data controller is:

brisk-cypress
42 Bloomsbury Square
London WC1A 2RP
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. The legal grounds we rely on include:

Consent (Article 6(1)(a))

When you voluntarily provide information through our contact forms, subscribe to communications, or accept cookies, you give us consent to process your data for specified purposes. You may withdraw this consent at any time.

Contract Performance (Article 6(1)(b))

Processing is necessary to fulfil our contractual obligations when you engage our research services. This includes delivering requested materials, communicating about your project, and providing customer support.

Legitimate Interests (Article 6(1)(f))

We may process data based on our legitimate business interests, such as improving our services, preventing fraud, and maintaining network security. We balance these interests against your rights and freedoms.

Legal Obligation (Article 6(1)(c))

We process personal data when required to comply with legal obligations, including tax requirements, accounting regulations, and responses to lawful requests from authorities.

Your Rights Under GDPR

Right to Access (Article 15)

You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. We will provide this information in a commonly used electronic format.

Right to Rectification (Article 16)

If your personal data is inaccurate or incomplete, you have the right to request correction or completion. We will make necessary amendments without undue delay.

Right to Erasure (Article 17)

Under certain circumstances, you may request deletion of your personal data. This right applies when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and no other legal ground applies
  • You object to processing and no overriding legitimate grounds exist
  • The data has been unlawfully processed
  • Erasure is required to comply with legal obligations

Right to Restriction of Processing (Article 18)

You may request restriction of processing when:

  • You contest the accuracy of personal data
  • Processing is unlawful but you oppose erasure
  • We no longer need the data but you require it for legal claims
  • You have objected to processing pending verification

Right to Data Portability (Article 20)

You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format. You may also request that we transmit this data directly to another controller where technically feasible.

Right to Object (Article 21)

You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right Not to be Subject to Automated Decision-Making (Article 22)

We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. Please include:

  • Your full name and contact details
  • Description of your request and which right you wish to exercise
  • Any relevant information to help us locate your data

We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two months, in which case we will inform you.

Data Protection Principles

We adhere to the GDPR data protection principles, ensuring that personal data is:

  • Processed lawfully, fairly, and transparently
  • Collected for specified, explicit, and legitimate purposes
  • Adequate, relevant, and limited to what is necessary
  • Accurate and kept up to date
  • Kept only as long as necessary
  • Processed securely with appropriate safeguards

Data Security Measures

We implement technical and organisational measures to ensure appropriate security of personal data, including protection against unauthorised or unlawful processing and accidental loss, destruction, or damage. These measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security testing and vulnerability assessments
  • Staff training on data protection and security
  • Incident response procedures

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also communicate the breach directly to you without undue delay.

International Data Transfers

We primarily store and process data within the United Kingdom and European Economic Area. If we transfer personal data outside these regions, we ensure appropriate safeguards are in place, such as:

  • Adequacy decisions by the European Commission
  • Standard contractual clauses
  • Binding corporate rules
  • Appropriate certification mechanisms

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and purpose:

  • Service delivery records: Duration of service plus 6 years
  • Marketing communications: Until consent is withdrawn
  • Website analytics: 26 months
  • Email correspondence: 3 years from last contact

Children's Data

We do not knowingly process personal data of individuals under 16 years of age without parental consent. If we become aware of such processing, we will delete the data promptly.

Complaints and Supervisory Authority

If you believe we have not complied with GDPR requirements, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom, the relevant authority is:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website with an updated revision date.

Contact Us

For questions about our GDPR compliance or to exercise your data protection rights, please contact us at [email protected]