Privacy Notice


ProtectMiData Ltd

Version: 1.0
Last updated: 19/02/2026

ProtectMiData Ltd (“ProtectMiData”, “we”, “us”, “our”) is committed to protecting personal data and respecting your privacy. This Privacy Notice explains how we collect, use, store, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, in line with guidance issued by the Information Commissioner’s Office (ICO).

Data Controller

ProtectMiData Ltd acts as a Data Controller when we determine how and why personal data is processed and as a Data Processor where we process personal data on behalf of our clients.

Contact details:
Email: info@protectmidata.co.uk


The personal data we collect

We only collect personal data that is necessary for the provision of our services.

Personal data

  • Name

  • Job title

  • Business contact details (email address, telephone number)

  • Organisation details

  • Correspondence and communications

Special category data

Where required for a specific and agreed purpose, we may collect and process limited special category data, including:

  • Health-related information (e.g. ability or dietary requirements)

Special category data is processed only where lawful, necessary, and subject to enhanced safeguards.


How we use personal data

We process personal data to:

  • Provide Data Protection Officer (DPO) services (including bespoke DPO services)

  • Deliver GDPR compliance and advisory support

  • Manage individual rights requests, including Data Subject Access Requests (DSARs)

  • Provide data breach and incident response support

  • Deliver records management and information governance services

  • Provide staff training and awareness

  • Deliver cyber resilience services

  • Provide AI literacy support

  • Support Freedom of Information (FOI) requests

  • Provide third-party risk management and data-sharing support

  • Communicate with clients in relation to services provided

  • Meet our legal and regulatory obligations


Lawful bases for processing

Under UK GDPR, we rely on the following lawful bases:

  • Contract – where processing is necessary to deliver agreed services

  • Legal obligation – where required by law

  • Legitimate interests – where processing is necessary for our business and does not override your rights

  • Consent – where required, particularly for special category data

Where special category data is processed, an additional condition under Article 9 UK GDPR applies.


Data sharing

  • ProtectMiData Ltd does not share personal data with third parties.

  • Access to personal data is restricted to authorised personnel only.

  • Where we act as a Data Processor, personal data is processed strictly in accordance with our client’s documented instructions.


International transfers

  • All personal data is stored and processed within the United Kingdom and the European Economic Area (EEA).

  • Personal data is not transferred outside the UK or EEA.


Data retention

  • Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected.

  • Retention periods are agreed at the point of collection or contract commencement.

  • At the end of the agreed retention period, data is securely deleted or returned, in line with contractual arrangements.


Data Subject Rights

Under UK GDPR, individuals have the right to:

  • Request access to their personal data

  • Request rectification of inaccurate or incomplete data

  • Request erasure of personal data

  • Request restriction of processing

  • Object to processing

  • Request data portability

  • Withdraw consent at any time (where processing is based on consent)

Requests can be made by contacting us using the details in our Contact section

You also have the right to lodge a complaint with the Information Commissioner’s Office.


Cookies

What are cookies?

Cookies are small text files placed on your device when you visit our website.

Cookies we use

We use:

  • Strictly necessary cookies – required for the website to function

  • Functional cookies – to improve usability and performance

We do not use cookies for advertising or behavioural tracking.

Managing cookies

You can manage or disable cookies through your browser settings. Please note that disabling essential cookies may affect website functionality.

Further information is available in our Cookies Policy.


Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Access controls

  • Secure storage and systems

  • Staff training and awareness

  • Incident and breach response procedures


Changes to this Privacy Notice

We may update this Privacy Notice periodically to reflect changes in law, guidance, or our services. The most current version will always be available on our website.