Legal

GDPR Policy

Last updated: 20 September 2026 1. Purpose This policy explains Pedro Media's approach to the UK General Data Protection Regulation, the Data Protection Act 2018 and related privacy requirements. It should be read with the Privacy Policy. 2. Data protection principles Personal data will be processed lawfully, fairly and transparently; collected for clear and legitimate purposes; limited to what is necessary; kept accurate where reasonably possible; retained no longer than needed; and protected with appropriate security. Pedro Media remains accountable for these principles. 3. Roles and responsibility Pedro Media is the data controller for enquiries, customer communications and website administration records it determines how to use. For some client work, Pedro Media may act as a processor under the client's written instructions. Privacy enquiries can be sent through the Contact page or to abadeer.ewyda@gmail.com. 4. Lawful processing Before processing personal data, we identify an appropriate lawful basis. Common bases are steps requested before a contract, performance of a contract, compliance with law, legitimate interests balanced against individual rights, and consent where required. Special category data is not intentionally requested through website forms and should not be submitted unless specifically agreed and lawfully required. 5. Privacy by design and minimisation Projects and internal processes should collect only information needed for a stated purpose. Access is limited to people and providers who need it. New uses, integrations or higher-risk processing are reviewed for privacy impact and may require a formal data protection impact assessment. 6. Individual rights We support applicable rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Requests are recorded, identity may be verified, and responses are normally provided within one month unless the law permits an extension. Legal exemptions may apply. 7. Security and access Reasonable safeguards include access controls, authenticated administration, restricted service permissions, secure hosting, software updates and appropriate backups. Access is reviewed and removed when no longer needed. 8. Processors and suppliers Service providers that process personal data must offer appropriate security and privacy commitments. They receive only the information required for their service and may not use it for unrelated purposes. 9. International data transfers Transfers outside the United Kingdom must use a lawful transfer mechanism and an appropriate assessment where required, including adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses. 10. Retention and deletion Personal data is retained according to its purpose, legal duties, contractual needs and potential claims. When no longer required, it is securely deleted or anonymised where reasonably practicable. 11. Personal data breaches Suspected breaches are assessed promptly, contained where possible and documented. Where a breach is likely to risk people's rights and freedoms, Pedro Media will notify the Information Commissioner's Office without undue delay and, where required, within 72 hours of becoming aware. Affected individuals will be informed when the law requires it. 12. Complaints and oversight Questions or complaints should first be sent to Pedro Media using the contact details above. Individuals may also contact the Information Commissioner's Office at ico.org.uk. This policy is reviewed when processing activities or legal requirements materially change.