gleam-spray
  • Home
  • About
  • Services
  • Contact

GDPR Compliance

Last updated: May 2026

Our Commitment to GDPR

gleam-spray is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). This page outlines how we fulfill our obligations under GDPR when processing your personal data.

Data Controller

gleam-spray acts as the data controller for the personal information we collect and process. Our contact details:

gleam-spray
42 Kingsway
London WC2B 6EX
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process your personal data only when we have a lawful basis to do so under GDPR Article 6:

Contract Performance (Article 6(1)(b))

We process data necessary to deliver pension planning and retirement advisory services you've requested.

Legal Obligation (Article 6(1)(c))

We process data to comply with Financial Conduct Authority regulations, anti-money laundering requirements, and other legal obligations applicable to financial services.

Legitimate Interests (Article 6(1)(f))

We process data for fraud prevention, service improvement, and security purposes, provided these interests don't override your fundamental rights.

Consent (Article 6(1)(a))

Where required, we obtain explicit consent for specific processing activities, particularly for marketing communications.

Your Rights Under GDPR

Right of Access (Article 15)

You have the right to obtain confirmation that we're processing your data and receive a copy of your personal data.

Right to Rectification (Article 16)

You can request correction of inaccurate personal data and completion of incomplete data.

Right to Erasure (Article 17)

You may request deletion of your personal data in certain circumstances. Note that financial services regulations require us to retain certain records for specified periods.

Right to Restrict Processing (Article 18)

You can request that we limit how we use your data in specific situations.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.

Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making (Article 22)

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

Exercising Your Rights

To exercise any of your GDPR rights, contact us at [email protected]. We will respond to your request within one month, though complex requests may require up to three months (we'll inform you if an extension is needed).

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

International Data Transfers

Your personal data is primarily processed within the United Kingdom and European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses or adequacy decisions).

Data Protection Officer

For matters specifically related to data protection, you can contact our Data Protection Officer at [email protected].

Right to Lodge a Complaint

If you believe we've not handled your data properly, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk

Data Minimization and Purpose Limitation

We collect only the personal data necessary for the specific purposes outlined in our Privacy Policy. We do not process data for purposes incompatible with those for which it was collected.

Storage Limitation

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal retention requirements (typically six years for financial services records).

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response procedures

Children's Data

Our services are not directed at individuals under 18. We do not knowingly collect personal data from children.

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.

About Us

  • Our Approach
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Contact

[email protected]

© 2026 gleam-spray. All rights reserved.