UK GDPR Compliant

1. Our Commitment to GDPR

PICMS is fully committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We handle personal data with the utmost care and respect for individual privacy rights.

Key Commitment: All customer data is stored exclusively in UK/EU data centres (AWS EU-West-2, London), ensuring your data never leaves the UK/EEA unless explicitly authorised.

2. Lawful Basis for Processing

We process personal data based on the following lawful bases under Article 6 of the UK GDPR:

Contract

Processing necessary to provide our compliance management services as agreed in our Terms of Service.

Legitimate Interests

Processing for improving our services, ensuring security, and communicating with users.

Legal Obligation

Processing required to comply with applicable laws and regulations.

Consent

Where you have given explicit consent for specific processing activities.

3. Your Data Subject Rights

Under UK GDPR, you have the following rights regarding your personal data:

Right Description Response Time
Right of Access Request a copy of all personal data we hold about you 30 days
Right to Rectification Request correction of inaccurate or incomplete data 30 days
Right to Erasure Request deletion of your personal data ("right to be forgotten") 30 days
Right to Data Portability Receive your data in a structured, machine-readable format 30 days
Right to Restriction Request limitation of processing in certain circumstances 30 days
Right to Object Object to processing based on legitimate interests 30 days
Right to Withdraw Consent Withdraw consent at any time where processing is based on consent Immediate

To exercise any of these rights, contact us at privacy@picms.com

4. Data Protection Measures

We implement comprehensive technical and organisational measures to protect your data:

4.1 Technical Measures

4.2 Organisational Measures

5. Data Processing Agreements

As a data processor, we enter into Data Processing Agreements (DPAs) with all customers, ensuring:

Download our standard Data Processing Agreement.

6. International Data Transfers

Your data is primarily stored within the UK (AWS EU-West-2, London). If international transfers are necessary:

7. Data Retention

We retain personal data only as long as necessary:

8. Data Breach Procedures

In the event of a personal data breach, we will:

9. Sub-Processors

We use the following sub-processors to deliver our services:

All sub-processors are bound by data processing agreements and undergo regular security assessments.

10. Supervisory Authority

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Data Protection Contacts

General Enquiries: privacy@picms.com

Data Protection Officer: dpo@picms.com

Data Subject Requests: dsar@picms.com

Address: PICMS Ltd, London, United Kingdom