Loading...

Data Protection Policy

Audentes Fortuna is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

Legal Framework

This policy is based on the following legal frameworks:

  • GDPR (General Data Protection Regulation): EU Regulation 2016/679
  • Data Protection Act 2018: UK implementation of GDPR
  • Privacy and Electronic Communications Regulations: PECR 2003
  • Human Rights Act 1998: Article 8 - Right to Privacy

Data Protection Principles

We process personal data in accordance with the following principles:

  • Lawfulness, Fairness, and Transparency: Processing must be lawful, fair, and transparent
  • Purpose Limitation: Data must be collected for specified, explicit, and legitimate purposes
  • Data Minimization: Data must be adequate, relevant, and limited to what is necessary
  • Accuracy: Data must be accurate and kept up to date
  • Storage Limitation: Data must be kept in a form that permits identification for no longer than necessary
  • Integrity and Confidentiality: Data must be processed in a manner that ensures appropriate security

Types of Personal Data We Process

We may process the following categories of personal data:

  • Identity Data: Name, title, date of birth, gender
  • Contact Data: Address, email, telephone numbers
  • Financial Data: Bank account details, payment information
  • Transaction Data: Details of services provided and payments
  • Technical Data: IP address, browser type, operating system
  • Usage Data: Information about how you use our website and services
  • Marketing Data: Preferences for receiving marketing communications

Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Consent: When you have given clear consent for specific processing
  • Contract: When processing is necessary for the performance of a contract
  • Legal Obligation: When we are required to process data to comply with legal requirements
  • Vital Interests: When processing is necessary to protect someone's life
  • Public Task: When processing is necessary for the performance of a task in the public interest
  • Legitimate Interests: When processing is necessary for our legitimate business interests

Data Subject Rights

Under GDPR, individuals have the following rights:

  • Right of Access: Request copies of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to processing based on legitimate interests
  • Rights Related to Automated Decision Making: Not be subject to automated decision-making

Data Security Measures

We implement appropriate technical and organizational measures to protect personal data:

  • Encryption: Data encrypted in transit and at rest
  • Access Controls: Role-based access to personal data
  • Network Security: Firewalls, intrusion detection, and monitoring
  • Physical Security: Secure facilities and equipment
  • Staff Training: Regular training on data protection
  • Incident Response: Procedures for handling data breaches

Data Breach Procedures

In the event of a personal data breach, we will:

  • Contain the breach and assess the risk
  • Notify the Information Commissioner's Office within 72 hours if required
  • Inform affected individuals without undue delay if high risk
  • Document the breach and our response
  • Review and improve our security measures

Data Retention

We retain personal data only for as long as necessary:

  • Customer Data: Duration of business relationship + 7 years
  • Employee Data: Duration of employment + 7 years
  • Marketing Data: Until consent withdrawn or 3 years inactive
  • Financial Records: 7 years from transaction date
  • Legal Requirements: As required by applicable laws

International Data Transfers

When transferring data outside the EEA, we ensure adequate protection through:

  • Adequacy decisions by the European Commission
  • Standard contractual clauses
  • Binding corporate rules
  • Certification schemes
  • Codes of conduct and certification mechanisms

Data Protection Impact Assessments

We conduct DPIAs for high-risk processing activities, including:

  • Systematic monitoring of individuals
  • Processing of special categories of data
  • Processing of data relating to criminal convictions
  • Large-scale processing of personal data

Training and Awareness

We provide regular training to all staff on:

  • Data protection principles and requirements
  • Individual rights and how to handle requests
  • Data breach procedures
  • Security measures and best practices
  • Consequences of non-compliance

Contact Information

For data protection inquiries or to exercise your rights:

  • Data Protection Officer: dpo@audentesfortuna.co.uk
  • Email: privacy@audentesfortuna.co.uk
  • Phone: +44 20 XXXX XXXX
  • Address: London, United Kingdom
Last Updated: November 8, 2025