GDPR Compliance
Last updated: July 2026
Our Commitment to GDPR
fresh-latch is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we fulfil our obligations under these regulations and how we protect your data rights.
Data Controller
fresh-latch acts as the data controller for personal information collected through our website and services. As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with data protection laws.
Data Controller: fresh-latch
42 Restoration Lane
London, SW1A 2BB
United Kingdom
[email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by GDPR:
Contract Performance
Processing necessary for the performance of our photograph restoration services, including collecting your contact details to communicate about your project and delivering completed work.
Legitimate Interests
Processing necessary for our legitimate business interests, such as improving our services, maintaining security, and preventing fraud, where these interests do not override your fundamental rights.
Consent
Where we rely on your consent for processing (such as for marketing communications or displaying restored photographs in our portfolio), you have the right to withdraw that consent at any time.
Legal Obligation
Processing necessary to comply with legal obligations, such as maintaining financial records for tax purposes.
Your Data Protection Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to request copies of your personal data. We will provide this information within one month of your request.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, in a structured, commonly used format.
Right to Object
You have the right to object to our processing of your personal data under certain conditions, particularly where we process data based on legitimate interests.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. If your request is complex or we receive numerous requests, we may extend this period by up to two months, but we will notify you of any extension within the first month.
We may ask you to verify your identity before processing your request to ensure we are providing personal data to the correct individual.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Project communications: Retained for the duration of the project plus six years for legal and warranty purposes
- Photographs and digital files: Retained for thirty days after final delivery unless you request extended storage or immediate deletion
- Financial records: Retained for seven years as required by UK tax regulations
- Website analytics: Anonymised and retained for two years
International Transfers
Your personal data is primarily processed and stored within the United Kingdom. In the event that data is transferred outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office.
Data Security Measures
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of personal data in transit and at rest
- Access controls and authentication measures
- Regular security assessments
- Staff training on data protection
- Secure disposal of physical and digital materials
Data Breach Procedures
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay.
Complaints
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire, SK9 5AF
Website: ico.org.uk
Contact Our Data Protection Lead
For any questions regarding our GDPR compliance or to exercise your data protection rights, please contact:
Data Protection Enquiries
fresh-latch
42 Restoration Lane
London, SW1A 2BB
United Kingdom
[email protected]