GDPR Compliance Statement
Effective Date: August 2026
Our Commitment to Data Protection
kriegindis adheres to the principles and requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are committed to processing personal data lawfully, fairly, and transparently.
Data Controller Information
For the purposes of data protection law, kriegindis acts as the data controller for personal information collected through our website and consulting services.
kriegindis Environmental Consulting
47 Riverside Gardens
Bristol BS1 6ED
United Kingdom
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legitimate Interests: Processing is necessary for our legitimate business interests in providing professional consulting services, provided these interests are not overridden by your rights
- Legal Obligation: Processing is necessary to comply with legal or regulatory requirements
- Consent: Where you have given explicit consent for specific processing activities
Your Data Protection Rights
Right of Access
You have the right to request a copy of the personal information we hold about you. This is known as a subject access request. We will provide this information within one month of receiving your request, unless the request is complex or there are multiple requests, in which case we may extend this by a further two months.
Right to Rectification
You have the right to request correction of personal information that is inaccurate or incomplete. We will respond to rectification requests within one month.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
This right is not absolute and may be limited by legal retention requirements or other legal grounds for continued processing.
Right to Restrict Processing
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your rights.
Rights Related to Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
How to Exercise Your Rights
To exercise any of your data protection rights, please submit a written request to us using the contact information provided on our contact page. We may need to verify your identity before processing your request.
We will respond to all requests within the timeframes required by law, typically within one month. There is no fee for exercising your rights unless your request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable administrative fee.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Pseudonymization and encryption of personal data where appropriate
- Ongoing assessment and evaluation of the effectiveness of security measures
- Regular testing and assessment of technical measures
- Policies governing access to personal data
- Staff training on data protection obligations
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk to individuals, we will also notify affected individuals without undue delay.
International Data Transfers
Our operations are based in the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the relevant authorities or transfers to countries with adequacy decisions.
Complaints
If you believe we have not handled your personal data in accordance with data protection law, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
Updates to This Statement
We review and update this GDPR compliance statement periodically to reflect changes in our data processing activities or legal requirements. The effective date at the top of this document indicates when this statement was last revised.