thicket-verse
Home About Services Contact Information on this site is advertising in nature

GDPR Compliance Statement

Last Updated: August 14, 2026

Our Commitment to GDPR Compliance

thicket-verse is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement outlines how we meet our obligations as a data controller when processing personal data.

Data Controller Information

Data Controller: thicket-verse
Address: 47 Finsbury Square, London EC2A 1PX, United Kingdom
Contact Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so:

  • Consent: You have provided clear, informed consent for specific processing activities
  • Contract: Processing is necessary to perform our service agreement with you
  • Legal Obligation: Processing is required to comply with UK law
  • Legitimate Interests: Processing is necessary for our legitimate business interests, balanced against your rights and freedoms

Your Rights Under GDPR

As a data subject, you have the following rights:

Right of Access

You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR).

Right to Rectification

You can request that we correct any inaccurate or incomplete personal data we hold about you.

Right to Erasure

Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances.

Right to Restrict Processing

You can ask us to limit how we use your personal data in specific situations.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format.

Right to Object

You can object to our processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that significantly affects you.

How to Exercise Your Rights

To exercise any of your GDPR rights, please submit a written request to [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you accordingly.

Data Protection Principles

We adhere to the following data protection principles:

  • Lawfulness, fairness, and transparency: We process data legally, fairly, and transparently
  • Purpose limitation: We collect data only for specified, explicit, and legitimate purposes
  • Data minimization: We collect only the data necessary for our purposes
  • Accuracy: We ensure personal data is accurate and kept up to date
  • Storage limitation: We retain data only as long as necessary
  • Integrity and confidentiality: We implement appropriate security measures
  • Accountability: We are responsible for demonstrating compliance

Data Security Measures

We implement technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication procedures
  • Staff training on data protection obligations
  • Secure data backup and recovery procedures

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.

International Data Transfers

Your personal data is processed and stored within the United Kingdom. We do not transfer personal data outside the UK unless appropriate safeguards are in place to ensure GDPR-level protection.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our standard retention periods are:

  • Consultation requests: 12 months from last contact
  • Active client files: Duration of engagement plus 7 years
  • Marketing communications: Until consent is withdrawn

Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children without appropriate parental or guardian consent.

Complaints

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Phone: 0303 123 1113
Website: www.ico.org.uk

Updates to This Statement

We may update this GDPR Compliance Statement to reflect changes in our practices or legal requirements. We will notify you of any significant changes through our website.

Contact Us

For questions about our GDPR compliance or to exercise your data protection rights, please contact us at [email protected]

thicket-verse

Professional benefits and pensions consultation services in London.

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Navigation

  • About
  • Services
  • Contact

© 2026 thicket-verse. All rights reserved.

We use cookies to improve your browsing experience and analyze site traffic. By continuing to use this site, you consent to our use of cookies.

Learn More