GDPR / Data Protection Policy

    Last Updated: 25 March 2025 | Next Review Due: 25 March 2026

    1) Purpose & Scope

    This policy outlines SmartTechHub's approach to personal-data management and compliance with the UK GDPR and Data Protection Act 2018. It applies to all employees, contractors, and partners.

    2) Roles and Responsibilities

    • Data Controller: SmartTechHub Limited
    • DPO Contact: dpo@smarttechhub.co.uk
    • Sub-Processors: Authorised suppliers providing cloud, logistics, and IT support functions under binding DPAs.

    3) Lawful Bases of Processing

    We process personal data under: Contract, Legal obligation, Legitimate interest, and Consent (where applicable).

    4) Data Minimisation & Accuracy

    Only relevant data is collected and kept accurate and up-to-date. We review records regularly and securely delete data when no longer required.

    5) Security Measures

    Technical:

    Encryption, MFA, firewalls, EDR, regular patching, secure configurations, network segmentation, off-site backups, and security monitoring.

    Organisational:

    Employee training, vetting, least-privilege access, supplier audits, incident response plan, annual policy reviews.

    Media Handling:

    All data-bearing devices are sanitised or destroyed per HMG Infosec Standard 5 (Higher) and NIST 800-88 Rev.1, with serial-numbered verification and certificates.

    6) International Transfers

    Data stays within the UK/EEA where possible. If transfer is necessary, appropriate safeguards are applied via adequacy decisions or standard clauses.

    7) Individual Rights

    We recognise and support all data-subject rights under UK GDPR. Requests to exercise rights should be sent to dpo@smarttechhub.co.uk.

    8) Incident & Breach Management

    Any breach posing risk to individuals will be reported to the ICO within 72 hours. Affected parties will be informed without undue delay.

    9) Accountability & Governance

    We maintain Records of Processing Activities (RoPA), conduct DPIAs where necessary, and carry out annual audits and staff refresh training. Senior management oversees compliance.

    10) Marketing & Communications

    All marketing is opt-in only. Subscribers can unsubscribe at any time. We never sell or rent marketing data.

    11) Retention

    Personal data retained for minimum periods needed to satisfy contractual and legal requirements (typically six years) then securely erased.

    12) Contact

    Data Protection Officer – SmartTechHub Limited

    Email: dpo@smarttechhub.co.uk

    Address: 7 Bell Yard, London WC2A 2JR

    Data Protection Questions?

    Our Data Protection Officer is available to assist with any GDPR-related inquiries.