Lunar-Burst
  • Home
  • About
  • Services
  • Contact

GDPR Compliance

Our commitment to protecting your personal data under the UK General Data Protection Regulation.

Last updated: January 2024

Our Commitment

Lunar-Burst takes data protection seriously. As a financial consultancy, we handle sensitive personal and financial information, and we recognise the trust you place in us when sharing this data. This page outlines how we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller Information

Lunar-Burst acts as the data controller for personal information collected through our services and website. This means we determine how and why your personal data is processed.

Data Controller: Lunar-Burst

Address: 47 Castle Boulevard, Nottingham, NG7 1FE

Data Protection Contact: [email protected]

Your Rights Under UK GDPR

The UK GDPR provides you with specific rights regarding your personal data. We are committed to facilitating the exercise of these rights:

Right to Be Informed

You have the right to know how we collect and use your personal data. We provide this information through our Privacy Policy and at the point of data collection.

Right of Access

You can request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request. We will respond within one month of receiving your request.

Right to Rectification

If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will address your request promptly.

Right to Erasure

Also known as the "right to be forgotten", you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.

Right to Restrict Processing

You can ask us to limit how we use your data while you contest its accuracy or object to our processing. During restriction, we may store your data but not actively use it.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you can request your data in a structured, commonly used, machine-readable format.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. For marketing, we will stop processing immediately upon your objection.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not use automated decision-making in our services.

Exercising Your Rights

To exercise any of your data protection rights, please contact us at [email protected]. When making a request, please provide:

  • Your full name and contact details
  • A clear description of the right you wish to exercise
  • Any information that will help us locate your records

We may need to verify your identity before processing your request. We will respond to valid requests within one month, though this may be extended by up to two months for complex requests, in which case we will inform you.

Lawful Bases for Processing

We process personal data only when we have a valid legal basis. The bases we rely upon include:

Contractual Necessity

When you engage our financial management services, we process your data as necessary to fulfil our contractual obligations. This includes analysing your financial information to provide advice and creating reports and recommendations.

Consent

Where we rely on consent, you have given clear, informed agreement to the processing of your data for specific purposes. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Legitimate Interests

We may process data based on our legitimate business interests, provided these do not override your fundamental rights. Examples include improving our services, ensuring network security, and preventing fraud. We conduct balancing tests to ensure our interests do not unduly impact you.

Legal Obligation

Certain processing is required to comply with UK law, including financial regulations, tax requirements, and anti-money laundering obligations.

Special Category Data

Financial consultancy occasionally involves special category data, such as health information relevant to insurance or retirement planning. We only process such data with your explicit consent or where necessary for reasons of substantial public interest, and we apply additional safeguards to protect this information.

Data Protection Principles

We adhere to the data protection principles set out in UK GDPR:

  • Lawfulness, fairness, and transparency: We process data lawfully and are open about how we use it
  • Purpose limitation: We collect data for specified, explicit, and legitimate purposes only
  • Data minimisation: We collect only what is necessary for the intended purpose
  • Accuracy: We keep personal data accurate and up to date
  • Storage limitation: We retain data only as long as necessary
  • Integrity and confidentiality: We protect data against unauthorised access and loss
  • Accountability: We can demonstrate compliance with these principles

Data Breach Procedures

In the unlikely event of a personal data breach, we have procedures in place to:

  • Detect, investigate, and report breaches promptly
  • Notify the Information Commissioner's Office within 72 hours where required
  • Inform affected individuals without undue delay when the breach is likely to result in high risk to their rights and freedoms
  • Document all breaches and the actions taken in response

International Data Transfers

We primarily store and process your data within the United Kingdom. Where international transfers are necessary, we ensure compliance with UK GDPR requirements by implementing appropriate safeguards such as standard contractual clauses or relying on adequacy decisions.

Complaints

If you are dissatisfied with how we handle your personal data, please contact us first so we can address your concerns. You also have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Website: ico.org.uk

Contact Our Data Protection Team

For any questions about our GDPR compliance or to exercise your rights:

Email: [email protected]
Post: Data Protection, Lunar-Burst, 47 Castle Boulevard, Nottingham, NG7 1FE

Lunar-Burst

Practical financial guidance for individuals and businesses across Nottingham and the East Midlands.

Quick Links

  • About Us
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Location

47 Castle Boulevard
Nottingham, NG7 1FE
United Kingdom

© 2024 Lunar-Burst. All rights reserved.

We use cookies to enhance your browsing experience and analyse site traffic. By clicking "Accept All", you consent to our use of cookies.

Cookie Preferences

Essential Cookies

Required for the website to function. Cannot be disabled.

Analytics Cookies

Help us understand how visitors interact with our website.

Marketing Cookies

Used to deliver relevant advertisements and track campaigns.