Our approach
H4NSON LIMITED is responsible for processing personal information in accordance with applicable UK data protection law, including the UK GDPR and Data Protection Act 2018 as amended. We aim to use information fairly and transparently, for defined purposes, and to limit it to what is relevant. Accuracy, appropriate retention and security form part of that responsibility. Our privacy policy explains our business uses of personal information.
Making a request
Email david@h4nson.co.uk or write to H4NSON LIMITED, Unit 3, 69 Upper Accommodation Road, Leeds, LS9 8LS. Explain the information or processing your request concerns and how we can contact you. You do not need to use particular legal wording. We may ask for proportionate information to verify your identity or clarify a request where needed to handle it safely.
Access and correction
You can ask whether we hold personal information about you and request a copy, together with information about how it is used. If information is inaccurate or incomplete, you can ask us to correct or complete it. Let us know which record needs attention and provide enough detail for us to assess the change.
Other rights
Depending on the processing and the applicable legal conditions, you may ask for erasure, restriction of use or a portable copy of certain information. You may object to processing based on legitimate interests, and you can object to direct marketing at any time. Where consent is the lawful basis, you may withdraw it. Rights do not always require the deletion of information we must keep for legal reasons or the handling of legal claims.
Responses and decisions
We respond within the period required by applicable law, generally one month, subject to any lawful extension or adjustment. If we cannot carry out a request in full, we explain the relevant reason and your options for raising a concern. We do not use this website to make solely automated decisions producing legal or similarly significant effects about you.
Internal handling and service providers
Access to personal information should be limited to people who need it for their work. Relevant service providers must be considered for their role and the safeguards needed, including appropriate processing terms where they act on our instructions. Personal information should be retained only for the relevant purpose and applicable record-keeping requirements, then removed or otherwise handled appropriately.
Security incidents and concerns
If we become aware of a personal data breach, we assess the incident and take appropriate steps, including notification to the relevant authority or affected individuals where the law requires it. If you believe information sent to us is at risk, contact us promptly. You can also raise a complaint with the Information Commissioner’s Office.