GDPR Compliance
How SWAMITIME SOLUTIONS LTD complies with UK and EU data protection regulations.
1. Our Commitment to Data Protection
At SWAMITIME SOLUTIONS LTD, we are dedicated to protecting the privacy and personal data of our clients, partners, and website visitors. We understand the importance of data protection in today's digital landscape and are fully committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and where applicable, the EU General Data Protection Regulation (EU GDPR).
Data protection is not merely a legal obligation for us—it is a fundamental aspect of how we conduct business. We have implemented comprehensive technical and organisational measures to ensure that all personal data we process is handled lawfully, fairly, and transparently. Our commitment extends across every facet of our operations, from our workforce management consulting services to our digital solutions and website management.
We regularly review and update our data protection policies, procedures, and practices to ensure continued compliance with evolving regulatory requirements and industry best practices. All staff members receive appropriate training on data protection principles and their responsibilities under the GDPR.
2. Data Controller Information
For the purposes of the UK GDPR and the Data Protection Act 2018, the data controller responsible for your personal data is:
Data Controller: SWAMITIME SOLUTIONS LTD
Company Registration: Registered in England and Wales
Registered Office: [Registered Office Address], London, United Kingdom
Email: privacy@swamitime.com
If you have any questions about this GDPR compliance page or how we handle your personal data, please contact us using the details above. We take all data protection enquiries seriously and will respond promptly.
3. Lawful Basis for Processing
Under the UK GDPR, all processing of personal data must have a valid lawful basis. There are six lawful bases for processing, and SWAMITIME SOLUTIONS LTD relies on the following three, depending on the nature and purpose of the processing activity:
| Lawful Basis | Description | Used by SWAMITIME | Example |
|---|---|---|---|
| Consent | The individual has given clear consent for us to process their personal data for a specific purpose. | Yes | Newsletter subscriptions, cookie preferences, marketing communications |
| Contract | The processing is necessary for a contract we have with the individual, or because they have asked us to take specific steps before entering into a contract. | Yes | Client engagement agreements, service delivery, project scoping |
| Legal Obligation | The processing is necessary for us to comply with the law (not including contractual obligations). | Not Primary | Financial record-keeping, regulatory reporting |
| Vital Interests | The processing is necessary to protect someone's life. | N/A | Not applicable to our business operations |
| Public Task | The processing is necessary for us to perform a task in the public interest or for official functions, with a clear basis in law. | N/A | Not applicable to our business operations |
| Legitimate Interests | The processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual's personal data that overrides those legitimate interests. | Yes | Business development, service improvements, website analytics |
We carefully assess each processing activity to identify the appropriate lawful basis and document our justification. Where we rely on legitimate interests, we conduct a Legitimate Interests Assessment (LIA) to balance our interests against the rights and freedoms of the data subject.
4. Your Rights Under GDPR
The UK GDPR provides individuals with eight fundamental data subject rights. We are committed to upholding these rights and ensuring you can exercise them easily and effectively.
-
The Right to be Informed
You have the right to be informed about the collection and use of your personal data. We provide this information through our Privacy Policy, this GDPR Compliance page, and at the point of data collection. We ensure that our privacy notices are concise, transparent, intelligible, and easily accessible.
-
The Right of Access (Subject Access Request)
You have the right to obtain confirmation that your data is being processed and to access your personal data. You can request a copy of the personal data we hold about you, along with supplementary information about how we process it. This is commonly known as a Subject Access Request (SAR). See section 6 below for details on how to submit a SAR.
-
The Right to Rectification
You have the right to have inaccurate personal data rectified, or completed if it is incomplete. If you believe any information we hold about you is incorrect or incomplete, please contact us and we will correct it promptly—within one month of your request.
-
The Right to Erasure (Right to be Forgotten)
You have the right to request the deletion or removal of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected, you withdraw consent, or the data has been unlawfully processed. This right is not absolute and may be subject to legal or regulatory obligations that require us to retain certain data.
-
The Right to Restrict Processing
You have the right to request the restriction or suppression of your personal data in certain circumstances. When processing is restricted, we are permitted to store the data but not use it. You may exercise this right if you contest the accuracy of the data, the processing is unlawful, or you have objected to processing.
-
The Right to Data Portability
You have the right to obtain and reuse your personal data for your own purposes across different services. This allows you to receive personal data you have provided to us in a structured, commonly used, and machine-readable format (such as CSV or JSON), and to transmit that data to another data controller.
-
The Right to Object
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes. If you object to processing for direct marketing, we will stop processing your data for this purpose immediately. For objections on other grounds, we will assess whether our legitimate grounds override your interests.
-
Rights Related to Automated Decision-Making and Profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. SWAMITIME SOLUTIONS LTD does not currently engage in any automated decision-making or profiling activities that produce legal or similarly significant effects.
5. How to Exercise Your Rights
To exercise any of your data protection rights, please contact us using the details below. We aim to make the process as straightforward as possible.
Email: privacy@swamitime.com
Response Timeframe: Within 30 calendar days (extendable by a further two months for complex requests, with notification).
Information to Provide: Full name, contact details, the specific right you wish to exercise, and any supporting details to help us identify and locate your data. We may ask for proof of identity before processing your request.
We will not charge a fee to exercise your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
6. Subject Access Request (SAR)
A Subject Access Request (SAR) allows you to find out what personal data we hold about you, why we hold it, and who we disclose it to. You are entitled to receive a copy of your personal data along with supplementary information.
How to Submit a SAR
To submit a Subject Access Request, please email us at privacy@swamitime.com with the subject line "Subject Access Request". To help us process your request efficiently, please include the following:
- Your full name and any previous names you may have used
- Your contact details (email address and telephone number)
- A description of the specific information you are requesting (this helps us narrow the scope)
- Any relevant dates or timeframes (e.g. "data relating to my engagement as a client from January 2024")
- Proof of identity (we may request a copy of photo ID such as a passport or driving licence)
What to Expect
- Acknowledgment: We will acknowledge receipt of your SAR within 5 working days.
- Response Time: We will respond to your SAR within 30 calendar days. If your request is complex or numerous, we may extend this by up to a further two months, and we will notify you of any extension within the initial 30-day period.
- Format: We will provide the information in a clear, commonly used electronic format unless you request otherwise.
- Refusal: If we refuse to comply with your request, we will explain why and inform you of your right to complain to the Information Commissioner's Office (ICO).
Third-Party Data
Where responding to a SAR would involve disclosing information relating to another individual (a third party), we will carefully consider whether it is reasonable to disclose that information without the third party's consent. We may redact third-party data or withhold it where appropriate.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable laws and regulations. Our data retention policy is based on the following criteria:
- Contractual Obligations: Data relating to client engagements is retained for the duration of the contract plus a period of 6 years following contract termination, in line with statutory limitation periods for contractual claims.
- Financial Records: In accordance with UK tax and accounting regulations, financial records are retained for a minimum of 6 years from the end of the last company financial year they relate to.
- Marketing Data: Personal data used for marketing purposes is retained until consent is withdrawn or the data subject objects. We review marketing consent periodically and refresh consent every 24 months.
- Website Analytics: Anonymised analytics data may be retained indefinitely for trend analysis. Personal identifiers are removed or pseudonymised where possible.
- Recruitment Data: CVs and application materials for unsuccessful candidates are retained for 12 months after the recruitment decision, unless the candidate consents to longer retention for future opportunities.
When personal data is no longer required, we securely delete or anonymise it in accordance with our data disposal procedures.
8. Data Transfers
SWAMITIME SOLUTIONS LTD primarily stores and processes personal data within the United Kingdom. Where possible, we ensure that all personal data remains within the UK or the European Economic Area (EEA).
In certain circumstances, we may need to transfer personal data to third-party service providers or partners located outside the UK or EEA. Where such transfers occur, we ensure that appropriate safeguards are in place in accordance with UK GDPR requirements, which may include:
- Adequacy Decisions: Transferring data to countries that have been deemed by the UK Government to provide an adequate level of data protection.
- Standard Contractual Clauses (SCCs): Using the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses, as applicable, to ensure contractual protections for transferred data.
- Binding Corporate Rules: Where applicable, relying on approved binding corporate rules for intra-group transfers.
We conduct Transfer Impact Assessments (TIAs) for any restricted transfers to assess the level of protection in the destination country and the effectiveness of the safeguards in place.
9. Data Breach Procedures
We have robust procedures in place to detect, investigate, and respond to personal data breaches. A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- ICO Notification: Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
- Data Subject Notification: Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify the affected data subjects without undue delay, describing the nature of the breach and providing recommendations to mitigate potential adverse effects.
- Internal Investigation: All breaches are logged in our internal breach register, and a full investigation is conducted to identify root causes and implement corrective measures to prevent recurrence.
- Staff Training: All employees receive training on identifying and reporting potential data breaches as part of their data protection awareness training.
10. Data Protection Impact Assessments (DPIAs)
We conduct Data Protection Impact Assessments (DPIAs) for any processing activity that is likely to result in a high risk to individuals' rights and freedoms. A DPIA is a systematic process that helps us identify and minimise the data protection risks of a project or processing activity.
We carry out a DPIA in the following circumstances:
- When introducing new technologies or systems that process personal data
- When processing that is likely to result in a high risk to individuals
- When processing special category data or criminal offence data on a large scale
- When systematically monitoring publicly accessible areas on a large scale
- When engaging in profiling or automated decision-making with legal or significant effects
- When combining, comparing, or matching personal data from multiple sources
If a DPIA identifies a high risk that cannot be adequately mitigated, we will consult with the ICO before proceeding with the processing activity.
11. Third-Party Processors
We may engage third-party service providers to process personal data on our behalf. These may include cloud hosting providers, email service providers, analytics platforms, customer relationship management (CRM) systems, and professional advisers.
Before engaging any third-party processor, we conduct thorough due diligence to ensure they:
- Provide sufficient guarantees to implement appropriate technical and organisational measures to meet UK GDPR requirements
- Process personal data only in accordance with our documented instructions
- Have appropriate security measures in place to protect personal data
- Do not engage sub-processors without our prior authorisation
- Assist us in responding to data subject rights requests
- Notify us of any personal data breaches without undue delay
- Delete or return all personal data at the end of the contract
All third-party processor relationships are governed by a written contract that includes the mandatory data processing terms required under Article 28 of the UK GDPR. We maintain a register of all processors and sub-processors, which is reviewed and updated regularly.
12. Changes to This Policy
We may update this GDPR Compliance page from time to time to reflect changes in our data processing practices, regulatory requirements, or for other operational, legal, or regulatory reasons. We encourage you to review this page periodically to stay informed about how we protect your personal data.
When we make material changes, we will:
- Update the "last updated" date at the top of this page
- Notify our active clients and subscribers of significant changes via email where appropriate
- Post a prominent notice on our website for a reasonable period
This page was last updated on 01 June 2026.
13. Supervisory Authority
If you believe that we have not adequately addressed your data protection concerns or have infringed your rights under data protection law, you have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO).
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO. Please contact us first so we can attempt to resolve the matter.
Have Questions About Your Data Rights?
If you have any questions about your data rights or wish to exercise any of your rights under the GDPR, please contact our data protection team.
Contact Us: privacy@swamitime.com