Last updated: November 2024
PICMS is fully committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We handle personal data with the utmost care and respect for individual privacy rights.
Key Commitment: All customer data is stored exclusively in UK/EU data centres (AWS EU-West-2, London), ensuring your data never leaves the UK/EEA unless explicitly authorised.
We process personal data based on the following lawful bases under Article 6 of the UK GDPR:
Processing necessary to provide our compliance management services as agreed in our Terms of Service.
Processing for improving our services, ensuring security, and communicating with users.
Processing required to comply with applicable laws and regulations.
Where you have given explicit consent for specific processing activities.
Under UK GDPR, you have the following rights regarding your personal data:
| Right | Description | Response Time |
|---|---|---|
| Right of Access | Request a copy of all personal data we hold about you | 30 days |
| Right to Rectification | Request correction of inaccurate or incomplete data | 30 days |
| Right to Erasure | Request deletion of your personal data ("right to be forgotten") | 30 days |
| Right to Data Portability | Receive your data in a structured, machine-readable format | 30 days |
| Right to Restriction | Request limitation of processing in certain circumstances | 30 days |
| Right to Object | Object to processing based on legitimate interests | 30 days |
| Right to Withdraw Consent | Withdraw consent at any time where processing is based on consent | Immediate |
To exercise any of these rights, contact us at privacy@picms.com
We implement comprehensive technical and organisational measures to protect your data:
As a data processor, we enter into Data Processing Agreements (DPAs) with all customers, ensuring:
Download our standard Data Processing Agreement.
Your data is primarily stored within the UK (AWS EU-West-2, London). If international transfers are necessary:
We retain personal data only as long as necessary:
In the event of a personal data breach, we will:
We use the following sub-processors to deliver our services:
All sub-processors are bound by data processing agreements and undergo regular security assessments.
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
General Enquiries: privacy@picms.com
Data Protection Officer: dpo@picms.com
Data Subject Requests: dsar@picms.com
Address: PICMS Ltd, London, United Kingdom