Scale. Optimize. Succeed.

GDPR Compliance

Our obligations under the EU and UK GDPR, the rights you hold, and the specific measures we take as both a data controller and a processor for our clients.

Template notice for the site owner. This policy is a well-structured starting point, not legal advice. Have a qualified lawyer in your jurisdiction review it against how your business actually collects and processes data, and replace every placeholder contact detail, before you remove this notice.

Last updated: 1 August 2026  ·  Effective immediately upon posting

Our Commitment

The General Data Protection Regulation (EU 2016/679) and the UK GDPR give individuals meaningful control over their personal data and place clear obligations on the organisations that handle it. We treat those obligations as a baseline rather than a ceiling, and we apply the same standards to clients outside the EU and UK because maintaining two tiers of data handling is both impractical and hard to justify.

Controller or Processor?

  • Website visitors and enquiries — we are controller. Governed by this page and our Privacy Policy.
  • Newsletter subscribers — controller.
  • Managing a client’s ad accounts and analytics — processor, under a Data Processing Agreement.
  • Handling a client’s customer lists for email or SMS — processor, under a DPA.
  • Our own staff and supplier records — controller.

Where we act as processor we only process personal data on documented instructions from the client, and we will tell them promptly if we believe an instruction infringes data protection law.

The Lawful Bases We Rely On

We never process personal data without a lawful basis, and we record which basis applies to each activity in our processing register.

  1. Consent — newsletter subscriptions and non-essential cookies. Freely given, specific, informed and as easy to withdraw as to give.
  2. Contract — delivering the services a client has engaged us for, and taking steps at your request before entering a contract.
  3. Legal obligation — tax, accounting and statutory record-keeping.
  4. Legitimate interests — site security, service improvement and limited B2B communication, always subject to a documented balancing test.

Vital interests and public task are not relied upon in the normal course of business.

Your Rights and How to Exercise Them

  • Access (Art. 15) — a copy of your data and details of how it is processed. 30 days.
  • Rectification (Art. 16) — correction of inaccurate or incomplete data. 30 days.
  • Erasure (Art. 17) — deletion where there is no overriding lawful reason to retain. 30 days.
  • Restriction (Art. 18) — processing paused while a dispute is resolved. Immediate on receipt.
  • Portability (Art. 20) — your data in a structured, machine-readable format. 30 days.
  • Object (Art. 21) — stop processing based on legitimate interests; absolute for direct marketing.
  • Automated decisions (Art. 22) — not applicable, we perform none.

Send requests to dpo@dazzlecommerce.com. We acknowledge within 72 hours and respond within one month, extendable by two further months for complex requests — we will tell you if that applies and why. If your data sits inside a client’s systems that we manage, we will forward your request to that client as controller within five working days.

Technical and Organisational Measures

Article 32 requires security appropriate to the risk. Ours includes TLS 1.3 in transit and AES-256 at rest; least-privilege, role-based access reviewed quarterly with mandatory multi-factor authentication; client credentials held only in an audited password manager; pseudonymisation and data minimisation wherever the task allows; segregated client environments with no cross-client access; annual penetration testing and continuous dependency scanning; documented business continuity and disaster recovery plans tested annually; and mandatory annual data protection training for every member of staff.

Subprocessors

We use a small number of vetted subprocessors, each bound by a written agreement containing GDPR Article 28 terms. A current named list with locations and transfer mechanisms is available to clients on request. Clients receive at least 30 days’ notice before we add or replace a subprocessor, and may object on reasonable data protection grounds; where an objection cannot be resolved, the client may terminate the affected service without penalty.

International Data Transfers

We operate across five countries, so transfers outside the UK and EEA are sometimes necessary. Where they occur we rely on an adequacy decision where one covers the destination; Standard Contractual Clauses plus the UK International Data Transfer Addendum where relevant; a documented Transfer Impact Assessment for each recipient; and supplementary measures including encryption, pseudonymisation and strict access control.

Data Processing Agreements

Every client engagement includes a Data Processing Agreement before any personal data is shared. Ours covers subject matter and duration, nature and purpose, categories of data and data subjects, controller and processor obligations, subprocessor terms, transfer mechanisms, assistance with data subject requests, breach notification, and deletion or return of data at the end of the engagement. We are happy to sign your DPA instead of ours.

Personal Data Breaches

  1. The incident is contained and assessed immediately on detection.
  2. Where we are controller and the breach poses a risk to rights and freedoms, we notify the supervisory authority within 72 hours of becoming aware.
  3. Where we are processor, we notify the affected client without undue delay so they can meet their own 72-hour obligation.
  4. Where the risk is high, affected individuals are informed directly and told what to do.
  5. Every incident is recorded in our breach register regardless of whether it is notifiable, and a root-cause review follows within 14 days.

Records, Assessments and Governance

We maintain an Article 30 record of processing activities and review it twice a year. Data Protection Impact Assessments are carried out before any processing likely to result in high risk. Privacy by design and by default is applied at the point new tools or workflows are proposed rather than retrofitted afterwards. We are not required to appoint a statutory Data Protection Officer, but we have designated a data protection lead accountable for compliance at dpo@dazzlecommerce.com.

Supervisory Authority and Complaints

Raise a concern with us first — most issues are resolved quickly at that stage. You always retain the right to complain to a supervisory authority: in the United Kingdom the Information Commissioner’s Office at ico.org.uk; in the European Union the data protection authority in your member state; elsewhere your local privacy regulator.

Questions about how we handle your data?

Our privacy team answers within one business day. Email privacy@dazzlecommerce.com or use the contact form — no ticket queue, no chatbot.