dynamo-ridge
  • Home
  • About
  • Programs
  • Contact

GDPR Compliance Statement

Last Updated: May 25, 2026

Our Commitment to Data Protection

dynamo-ridge is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our data protection responsibilities seriously and strive to be transparent about how we collect, use, and protect your personal data.

Data Controller Information

For the purposes of UK GDPR, the data controller is:

dynamo-ridge
47 Lothian Road
Edinburgh, EH1 2DJ
United Kingdom
Email: [email protected]

What Personal Data We Collect

We collect and process the following categories of personal data:

From Parents/Guardians:

  • Full name
  • Email address
  • Postal address
  • Contact preferences

From/About Program Participants (Children):

  • First name and surname
  • Age/date of birth
  • Educational progress data
  • Assessment results
  • Attendance records

Legal Basis for Processing

We process personal data under the following legal bases as defined in UK GDPR Article 6:

1. Contract (Article 6(1)(b))

Processing enrollment information, delivering programs, and fulfilling our service obligations.

2. Consent (Article 6(1)(a))

Marketing communications and optional activities. You can withdraw consent at any time.

3. Legitimate Interests (Article 6(1)(f))

Improving our services, conducting research, and maintaining business operations, provided this does not override your fundamental rights.

4. Legal Obligation (Article 6(1)(c))

Complying with legal requirements such as tax obligations and safeguarding duties.

Special Category Data

If we process special category data (such as health information relevant to program participation), we do so only with explicit consent or where necessary for reasons of substantial public interest.

How We Protect Your Data

We implement appropriate technical and organizational measures including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Staff training on data protection
  • Secure data storage with limited access
  • Regular backups and disaster recovery procedures

Data Retention

We retain personal data only as long as necessary:

  • Program enrollment records: 7 years (educational record retention)
  • Financial records: 7 years (tax compliance)
  • Marketing consent: Until consent is withdrawn or 3 years of inactivity
  • Website analytics: 14 months

After the retention period, data is securely deleted or anonymized.

Your Rights Under UK GDPR

Right to Access (Article 15)

You can request a copy of the personal data we hold about you.

Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete personal data.

Right to Erasure (Article 17)

You can request deletion of your personal data in certain circumstances, such as when it's no longer necessary for the purpose collected.

Right to Restrict Processing (Article 18)

You can request limitation on how we process your data while a concern is being addressed.

Right to Data Portability (Article 20)

You can request your data in a structured, commonly used format for transfer to another service.

Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making (Article 22)

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected] or write to us at the address above. We will respond to your request within one month, though this may be extended by two additional months for complex requests.

Proof of Identity

To protect your privacy, we may ask for proof of identity before fulfilling data subject requests.

No Fee

We do not charge a fee for exercising your rights unless requests are manifestly unfounded or excessive.

Data Sharing and Third Parties

We share personal data only when necessary:

Service Providers (Data Processors)

We work with third-party service providers who process data on our behalf under strict contractual terms:

  • Website hosting providers
  • Email service providers
  • Payment processors

All processors are required to implement appropriate security measures and process data only as instructed.

Legal Disclosures

We may disclose personal data if required by law, court order, or regulatory authority.

International Transfers

We primarily store and process data within the United Kingdom. If data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:

  • UK adequacy decisions
  • Standard contractual clauses
  • Binding corporate rules

Data Breach Procedures

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the ICO within 72 hours where feasible
  • Inform affected individuals without undue delay
  • Document the breach and our response
  • Take measures to mitigate harm

Children's Data

Our programs serve children and young people. We take extra care when processing children's data:

  • We obtain parental consent before collecting children's data
  • We collect only data necessary for program delivery
  • We provide age-appropriate privacy information
  • We implement enhanced security for children's data

Privacy by Design

We incorporate data protection principles into everything we do:

  • Minimizing data collection
  • Limiting access to personal data
  • Ensuring data accuracy
  • Implementing security from the outset
  • Defaulting to privacy-friendly settings

Updates to This Statement

We review and update this GDPR compliance statement regularly to reflect changes in our practices or legal requirements. The "Last Updated" date at the top indicates the most recent revision.

Complaints and Supervisory Authority

If you have concerns about how we handle your personal data, please contact us first so we can address your concern. You also have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Phone: 0303 123 1113
Website: dynamo-ridge.com

Contact Our Data Protection Team

For questions about data protection or to exercise your rights:

Email: [email protected]
Address: 47 Lothian Road, Edinburgh, EH1 2DJ, United Kingdom

dynamo-ridge

Building financial confidence in young people across the UK.

Quick Links

  • About Us
  • Programs
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

© 2026 dynamo-ridge. All rights reserved.