GDPR Compliance
Last updated: July 2026
Our Commitment to Data Protection
valley-flow is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights under this regulation.
Data Controller Information
For the purposes of GDPR, valley-flow is the data controller responsible for your personal information. You can contact us at:
valley-flow
47 Meadow Lane
Bristol BS8 2PQ
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process your personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal obligation: Processing is necessary for us to comply with the law
- Legitimate interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
Right to Be Informed
You have the right to be informed about the collection and use of your personal data. This information is provided through our privacy policy and this GDPR compliance page.
Right of Access
You have the right to request access to your personal data. You can request a copy of the personal data we hold about you, and we will provide this within one month of your request.
Right to Rectification
You have the right to have inaccurate personal data corrected. If you believe any information we hold about you is incorrect or incomplete, please contact us so we can update our records.
Right to Erasure
You have the right to request the deletion or removal of your personal data when there is no compelling reason for us to continue processing it. This is also known as the "right to be forgotten."
Right to Restrict Processing
You have the right to request the restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to obtain and reuse your personal data for your own purposes across different services. We will provide your data in a structured, commonly used, and machine-readable format.
Right to Object
You have the right to object to processing of your personal data in certain circumstances, particularly when we are relying on legitimate interests as the legal basis for processing.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision making.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request. In some cases, we may need to verify your identity before processing your request.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Secure data storage and transmission
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
When determining the appropriate retention period, we consider:
- The amount, nature, and sensitivity of the personal data
- The potential risk of harm from unauthorized use or disclosure
- The purposes for which we process your data
- Whether we can achieve those purposes through other means
- Applicable legal requirements
International Data Transfers
We process and store your personal data within the United Kingdom and European Economic Area. If we need to transfer your data outside these regions, we will ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights, we will also notify you directly.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Updates to This Information
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.