GDPR Compliance
Last updated: September 2026
Our Commitment to GDPR
corviqen-core is committed to protecting the personal data of individuals in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page outlines how we comply with data protection requirements and explains your rights.
Data Controller Information
corviqen-core acts as the data controller for personal information collected through our website and services.
corviqen-core
47 Meridian House
Cambridge Street
London, SW1V 4QQ
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by GDPR Article 6:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications)
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request prior to entering a contract (e.g., providing consultation services)
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided your rights do not override those interests (e.g., website analytics)
- Legal Obligation: Where processing is necessary for compliance with legal obligations
Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
Right to Access (Article 15)
You have the right to request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification (Article 16)
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
Right to Erasure (Article 17)
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purpose it was collected.
Right to Restriction (Article 18)
You have the right to request that we restrict processing of your personal data in certain circumstances.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object (Article 21)
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us using the details below. We will respond to your request within one month of receipt. In some cases, we may need to verify your identity before processing your request.
Email: [email protected]
We will not charge a fee for responding to most requests. However, if your request is clearly unfounded, repetitive, or excessive, we may charge a reasonable fee or refuse to act on the request.
Data Security Measures
We implement appropriate technical and organisational measures to protect personal data, including:
- Secure data storage with encryption where appropriate
- Access controls limiting data access to authorised personnel
- Regular security assessments and updates
- Staff training on data protection requirements
- Secure disposal procedures for data no longer required
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law. Our standard retention periods are:
- Enquiry data: 2 years from last contact
- Client consultation records: 6 years from end of engagement
- Website analytics: 26 months
- Marketing consent records: Duration of consent plus 2 years
International Data Transfers
We primarily process data within the United Kingdom and European Economic Area. If we transfer personal data outside these areas, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK Government or European Commission
- Standard contractual clauses approved by relevant authorities
- Binding corporate rules where applicable
Data Breach Procedures
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will:
- Notify the Information Commissioner's Office within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay if the breach is likely to result in high risk to their rights and freedoms
- Document all breaches and maintain records of our response
Complaints
If you are dissatisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire, SK9 5AF
United Kingdom
Website: ico.org.uk
We encourage you to contact us first to resolve any concerns directly.
Updates to This Information
We may update this GDPR compliance information periodically to reflect changes in our practices or legal requirements. Material changes will be communicated through our website.