Legal · Data protection
GDPR & Data Protection
CSSential’s approach to UK GDPR and responsible personal-data handling.
1. Our data protection commitment
CSSential is committed to handling personal data lawfully, fairly and transparently. We aim to collect only the information we reasonably need, use it for clear purposes, keep it accurate, retain it only as long as necessary and protect it with appropriate security measures.
This statement summarises our approach to the UK GDPR and the Data Protection Act 2018. More detail about information collected through our website and business relationships is available in our Privacy Policy.
2. Data protection principles
When processing personal data for our own purposes, we seek to follow the core data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
We document and review relevant processing activities and take proportionate steps to ensure personal data is handled consistently with those principles.
3. Lawful bases and transparency
Before using personal data, we identify an appropriate lawful basis. Depending on the activity this may include contract, legal obligation, legitimate interests or consent. Where special-category data is ever required, an additional lawful condition must also apply.
We aim to provide clear privacy information at or around the time personal data is collected and to explain material new uses before they begin.
4. Controller and processor responsibilities
CSSential may act as a controller for its own customer, supplier, staff, marketing and website administration activities.
When a customer asks us to process personal data strictly on its behalf as part of a digital service, CSSential may act as a processor. In those circumstances we process the relevant data on documented instructions, apply appropriate security measures and use subprocessors only under suitable contractual arrangements where required.
5. Data subject rights
Individuals may have rights of access, rectification, erasure, restriction, objection and portability, together with the right to withdraw consent where consent is relied upon. There are also specific rules around solely automated decisions where they have legal or similarly significant effects.
Requests can be sent to hello@cssential.com. We will assess each request under the law that applies at the time and may ask for reasonable proof of identity.
6. Security and access control
We use proportionate technical and organisational measures designed to protect personal data. Measures may include access controls, secure authentication, role-based permissions, patching, backups, supplier controls, confidentiality obligations and secure deletion practices appropriate to the system and risk.
Access to personal data is limited to people who reasonably need it for their work.
7. Personal data breaches
We maintain processes for identifying, containing and assessing suspected personal data breaches. Where a breach creates a legal duty to notify the Information Commissioner’s Office or affected individuals, we will aim to make the required notification within the applicable legal timescale.
Customers for whom we act as processor should be informed without undue delay where we become aware of a relevant personal data breach affecting their data.
8. Suppliers and international transfers
We assess relevant service providers proportionately to the nature and risk of the processing and use contractual protections where appropriate.
Where personal data is transferred internationally and UK law requires a transfer safeguard, we use a recognised legal mechanism and any additional measures that are reasonably appropriate to the circumstances.
9. Retention and deletion
Personal data is retained only for as long as reasonably necessary for the relevant business, contractual, legal, security or record-keeping purpose. We periodically review whether information is still needed and delete, anonymise or securely dispose of it when appropriate.
10. Governance and review
We review our data protection practices as our services, systems and legal requirements change. Team members and contractors who handle personal data are expected to follow applicable confidentiality, security and data protection requirements.
Questions or concerns about data protection can be sent to hello@cssential.com. You also have the right to complain to the UK Information Commissioner’s Office.
Questions about this policy?
Email hello@cssential.com or use our contact page.