Last Updated: September 1, 2026
vale-moose Ltd is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We recognize the importance of protecting personal data and maintaining transparency about our data processing activities.
For the purposes of UK data protection law, the data controller is:
vale-moose Ltd
42 Station Road
Birmingham B15 2AA
United Kingdom
Email: [email protected]
We process personal data under the following lawful bases established by UK GDPR:
When you provide explicit consent for specific processing activities, such as receiving marketing communications or using certain website features. You may withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal.
Processing necessary to fulfill contractual obligations when you engage our safety consulting services. This includes managing service delivery, communication about projects, and providing requested information.
Processing necessary for legitimate business interests, including:
We balance these interests against your rights and only proceed when processing does not override your fundamental rights and freedoms.
Processing required to comply with legal and regulatory obligations applicable to our business operations, including tax law, employment law, and professional standards.
Under UK GDPR, you have comprehensive rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data along with supplementary information about the processing.
You may request correction of inaccurate personal data and completion of incomplete data we hold about you.
You may request deletion of your personal data when:
You may request that we limit how we use your data when:
When processing is based on consent or contract and carried out by automated means, you may request that we provide your data in a structured, commonly used, machine-readable format and transmit it directly to another controller where technically feasible.
You may object to processing based on legitimate interest or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing relates to legal claims.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals. Should this change, we will update this statement and ensure appropriate safeguards are in place.
To exercise any of the rights described above, contact us at [email protected] with sufficient detail to identify yourself and specify your request. We may request additional information to verify your identity before processing requests.
We will respond to valid requests within one month of receipt. This period may be extended by two additional months when requests are complex or numerous. We will inform you of any extension within one month of receiving the request.
You will not be charged a fee for exercising your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
We collect only personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
We take reasonable steps to ensure personal data is accurate and kept up to date. Inaccurate data is corrected or deleted without delay.
We retain personal data only as long as necessary for the purposes it was collected or to comply with legal obligations. Specific retention periods are detailed in our Privacy Policy.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
When we engage third parties to process personal data on our behalf, we ensure:
Personal data is primarily processed within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as:
Our services are not directed to children under 18 years of age. We do not knowingly collect or process personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant updates will be communicated through website notification or direct contact. The "Last Updated" date indicates when this statement was most recently revised.
You have the right to lodge a complaint with the Information Commissioner's Office if you believe we have not complied with applicable data protection law:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
For questions about our GDPR compliance or data protection practices, contact:
vale-moose Ltd
Email: [email protected]