Last Updated: June 1, 2026
Our Commitment to Data Protection
branch-signal is committed to protecting the personal data of our clients and website visitors in full compliance with the UK General Data Protection Regulation and the Data Protection Act 2018.
This document outlines our approach to GDPR compliance and explains how we uphold your data protection rights.
Data Controller Information
For the purposes of data protection legislation, the data controller is:
branch-signal
42 Kensington High Street
London W8 4PE
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so under GDPR Article 6:
- Contract: Processing is necessary for the performance of our vehicle rental contract with you
- Legal Obligation: Processing is necessary to comply with legal requirements, such as tax and accounting obligations
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your rights
- Consent: Where required, we obtain your explicit, freely given, specific, informed, and unambiguous consent
Data Processing Principles
We adhere to the following data protection principles:
- Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and in a transparent manner
- Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes only
- Data Minimization: We collect only the data that is adequate, relevant, and necessary
- Accuracy: We take reasonable steps to ensure data accuracy and keep it up to date
- Storage Limitation: Data is retained only as long as necessary for the purposes specified
- Integrity and Confidentiality: We implement appropriate security measures to protect data
- Accountability: We can demonstrate compliance with these principles
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to be Informed
You have the right to clear, transparent information about how we use your personal data. This is provided through our Privacy Policy and this GDPR statement.
Right of Access
You have the right to request access to your personal data. We will provide you with a copy of the data we hold about you, free of charge, within one month of your request.
Right to Rectification
You have the right to have inaccurate personal data corrected or completed if it is incomplete. We will respond to rectification requests within one month.
Right to Erasure
In certain circumstances, you have the right to request the deletion of your personal data. This applies when:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
Right to Restrict Processing
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling in our operations.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with your request. Please include sufficient information to allow us to identify you and verify your identity.
We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Staff training on data protection and security
- Incident response and breach notification procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, where required by law.
Third-Party Data Processors
When we engage third-party service providers who process personal data on our behalf, we ensure that:
- A written contract is in place with appropriate data protection clauses
- The processor provides sufficient guarantees of security and compliance
- The processor acts only on our documented instructions
- The processor implements appropriate technical and organizational measures
International Data Transfers
We primarily process data within the United Kingdom. If we transfer personal data outside the UK, we ensure that appropriate safeguards are in place, such as:
- Adequacy decisions by the UK government
- Standard contractual clauses approved by the UK authorities
- Other legally recognized transfer mechanisms
Data Protection by Design and Default
We implement data protection considerations into our operations from the outset, including:
- Minimizing data collection to what is strictly necessary
- Implementing privacy-friendly default settings
- Regularly reviewing and updating our data protection practices
- Conducting privacy impact assessments where appropriate
Complaints and Supervisory Authority
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
Email: [email protected]
However, we encourage you to contact us first so that we can address your concerns directly.
Updates to This Statement
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. The "Last Updated" date at the top of this page indicates when the statement was last revised.
Contact Us
If you have any questions about our GDPR compliance or data protection practices, please contact us at [email protected].