We use essential cookies to ensure our website functions properly. By continuing to browse, you accept our use of cookies.

amber-fell
Home Services About Contact This content is promotional in nature

GDPR Compliance Statement

Last updated: 1 September 2026

Our Commitment to GDPR Compliance

amber-fell is committed to full compliance with the General Data Protection Regulation and the UK Data Protection Act 2018. This statement outlines how we meet our obligations as a data controller and the measures we have implemented to protect your personal data.

Data Controller Information

For the purposes of GDPR, the data controller is:

amber-fell
47 Charter House Street
London EC1M 6JN
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so under Article 6 of GDPR:

  • Consent: When you voluntarily provide information through forms or communications
  • Contract: When processing is necessary to fulfill service agreements
  • Legal Obligation: When required to comply with legal and regulatory requirements
  • Legitimate Interests: When necessary for business operations, provided your rights are not overridden

Data Subject Rights

Under GDPR, you have comprehensive rights regarding your personal data:

Right of Access

You can request confirmation of whether we process your personal data and obtain a copy of that data. We will respond within one month of receiving your request.

Right to Rectification

You can request correction of inaccurate personal data and completion of incomplete data.

Right to Erasure

You can request deletion of your personal data when it is no longer necessary for the purposes it was collected, when you withdraw consent, or when there is no legitimate reason for processing.

Right to Restrict Processing

You can request that we limit how we use your data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You can request to receive your personal data in a structured, commonly used, and machine-readable format, or have it transmitted directly to another controller where technically feasible.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

Rights Related to Automated Decision Making

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

How to Exercise Your Rights

To exercise any of your GDPR rights, please submit a request to [email protected] with the following information:

  • Your full name and contact details
  • Description of your request and the specific right you wish to exercise
  • Any relevant details to help us locate your information
  • Proof of identity if requested

We will respond to all requests within one month. In complex cases, we may extend this by two additional months and will inform you of any delay.

Data Protection Measures

We implement appropriate technical and organizational measures to ensure security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and vulnerability testing
  • Access controls and authentication mechanisms
  • Staff training on data protection obligations
  • Incident response procedures
  • Regular backup and recovery procedures

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.

International Data Transfers

When we transfer personal data outside the United Kingdom or European Economic Area, we ensure adequate safeguards are in place through:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions confirming appropriate data protection levels
  • Binding corporate rules where applicable

Data Retention

We retain personal data only as long as necessary for the purposes it was collected or as required by law. Our standard retention periods are:

  • Inquiry and marketing data: 3 years from last contact
  • Contract and service data: 7 years from contract end
  • Financial records: 7 years as required by law
  • Website analytics: 26 months

Third-Party Processors

When we engage third-party processors, we ensure they provide sufficient guarantees regarding technical and organizational security measures. All processors are bound by data processing agreements that comply with GDPR requirements.

Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Any updates will be posted on this page with a revised date.

amber-fell

Advanced banking infrastructure solutions for modern financial institutions.

Services

  • Core Banking
  • Payment Integration
  • Cloud Migration
  • Compliance Audit

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use

Legal

  • GDPR Compliance
  • Cookie Policy

© 2026 amber-fell. All rights reserved.