GDPR

General Data Protection Regulation commitment.

We uphold UK GDPR requirements to keep personal data safe, secure, and processed transparently.

Data controller

void-mirror, Glasgow, United Kingdom.

Lawful bases for processing.

We process data only when a lawful basis applies.

Contractual necessity

To deliver advisory services and meet agreed commitments.

Legitimate interests

For service improvement, scheduling, and operational records.

Consent

For optional communications and analytics cookies.

Your data rights.

You stay in control of your personal data.

Clients can request access, corrections, portability, or deletion of their personal data. We respond to verified requests within statutory timeframes.

Right to access

Request a copy of the data we hold about you.

Right to rectification

Correct inaccurate or incomplete records.

Right to erasure

Ask us to delete your data when lawful to do so.

Security and storage.

We protect data with layered safeguards.

Client information is stored in encrypted systems with restricted access. We review data access permissions quarterly and conduct internal audits to maintain compliance.

International transfers

We store data in UK-based systems. If a transfer is required, we use approved safeguards.

Complaints and inquiries.

We welcome feedback and questions about data protection.

Email [email protected] to raise a concern or request information. You also have the right to lodge a complaint with the UK Information Commissioner’s Office.