GDPR Compliance
Last Updated: June 2026
Our Commitment to GDPR
iris-logic is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and respect your rights as a data subject.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities
- Contract: When processing is necessary to fulfill our service agreement with you
- Legal Obligation: When we must process data to comply with legal requirements
- Legitimate Interest: When processing is necessary for our legitimate business interests, balanced against your rights
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You can request confirmation of whether we process your personal data and obtain a copy of that data.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data under certain circumstances, including when the data is no longer necessary for its original purpose.
Right to Restriction
You can request that we limit how we use your personal data in specific situations.
Right to Data Portability
You can request to receive your personal data in a structured, commonly used format and transmit it to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that significantly affects you.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, though this may be extended by two additional months for complex requests.
Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you may contact our data protection contact at [email protected].
International Data Transfers
We primarily process data within the United Kingdom and European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Supervisory Authority
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not complied with GDPR requirements.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Updates to This Information
We may update our GDPR compliance information as regulations evolve or our practices change. Material changes will be communicated through our website.