data protection policy
ICO Registration number: ZB575505
1. Introduction
Breaking Atoms Limited is committed to safeguarding the privacy and confidentiality of all data entrusted to us. This Data Protection Policy outlines our approach to data handling, storage, and processing to ensure compliance with applicable data protection laws and to underscore our commitment to handling all data with care and sensitivity.
2. Scope
This policy applies to all personal data collected, processed, or stored by Breaking Atoms Limited, whether from clients, employees, suppliers, or any other individuals we interact with. We acknowledge that personal data is valuable and requires proper protection to maintain trust with data subjects.
3. Data Collection and Use
3.1 Lawful Basis: We will only collect and process personal data when there is a lawful basis for doing so, such as with the data subject's consent, to fulfill contractual obligations, for compliance with legal obligations, to protect vital interests, for the performance of a task carried out in the public interest, or for our legitimate interests.
3.2 Purpose Limitation: Personal data will be collected for specific, explicit, and legitimate purposes, and we will not process it in a manner that is incompatible with those purposes.
3.3 Data Minimization: We will only collect and process personal data that is necessary and relevant for the specified purposes.
4. Data Security
4.1 Confidentiality: Breaking Atoms Limited ensures that personal data is treated as confidential and is accessible only to authorized personnel on a need-to-know basis.
4.2 Security Measures: We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. Regular risk assessments and security audits are conducted to identify and address vulnerabilities.
4.3 Employee Training: All employees and contractors are educated on the importance of data protection, their responsibilities, and best practices for handling data.
5. Data Subject Rights
Breaking Atoms Limited recognizes and respects data subjects' rights and will facilitate the exercise of these rights in accordance with data protection laws. These rights include the right to access, rectify, erase, restrict processing, object to processing, data portability, and the right not to be subject to automated decision-making.
6. Data Sharing and Third Parties
6.1 Third-Party Processors: When engaging third-party processors to handle personal data on our behalf, we conduct due diligence to ensure they meet our data protection standards. Contracts with such processors include specific data protection clauses.
6.2 Data Sharing: We will not share personal data with third parties unless it is necessary to fulfill our contractual or legal obligations, or we have obtained explicit consent from the data subject.
7. Data Retention
Breaking Atoms Limited retains personal data only for as long as necessary to fulfill the purposes for which it was collected, unless otherwise required by law. When data is no longer needed, it will be securely deleted or anonymized.
8. Data Breach Management
In the event of a data breach, Breaking Atoms Limited will promptly assess the risk to affected data subjects and report the breach to the relevant supervisory authority and affected individuals, as required by applicable data protection laws.
9. Compliance and Review
This Data Protection Policy is regularly reviewed and updated to ensure ongoing compliance with data protection laws and best practices. Employees are expected to comply with this policy and cooperate with data protection initiatives.
By adhering to this Data Protection Policy, Breaking Atoms Limited emphasizes its commitment to handling all data with utmost care and sensitivity, ensuring the privacy and security of personal information entrusted to us.