Data Protection Policy

Reviewed: August 14, 2025

Introduction

Pinksheep Marketing Limited is committed to protecting the rights and freedoms of individuals and ensuring that all personal data is handled in compliance with the United Kingdom General Data Protection Regulation (UK GDPR), the European Union General Data Protection Regulation (EU GDPR), the Data Protection Act 2018, and other applicable privacy laws. This policy outlines our approach to managing personal data in a manner that meets legal requirements while being transparent, clear, and practical for staff and stakeholders.

 

Scope

This policy applies to all employees, contractors, and third parties who process personal data on behalf of Pinksheep. It covers all data processing activities, whether carried out in the UK, the EU, or internationally, and applies to both automated and manual processing.

 

Key Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Special Categories of Data: Sensitive personal data such as race, ethnicity, political opinions, religion, trade union membership, genetic/biometric data, health data, or sexual orientation.
  • Processing: Any operation performed on personal data, including collection, storage, use, sharing, and deletion.
  • Data Controller: The entity that determines the purposes and means of processing personal data.
  • Data Processor: The entity that processes personal data on behalf of the controller.
  • Supervisory Authority: In the UK, the Information Commissioner’s Office (ICO). For EU operations, the relevant national data protection authority.

 

Data Protection Principles

Pinksheep adheres to the following principles as set out in UK/EU GDPR:

  • Lawfulness, fairness, and transparency – data must be processed lawfully and openly.
  • Purpose limitation – data must only be collected for specified, explicit, and legitimate purposes.
  • Data minimisation – data collected must be relevant and limited to what is necessary.
  • Accuracy – personal data must be accurate and kept up to date.
  • Storage limitation – data must not be kept for longer than necessary.
  • Integrity and confidentiality – personal data must be processed securely.
  • Accountability – we are responsible for, and must be able to demonstrate, compliance with these principles.

 

Lawful Basis for Processing

We will only process personal data where there is a lawful basis under the UK/EU GDPR, including: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest, or legitimate interests pursued by the controller.

 

Roles and Responsibilities

  • Data Protection Officer (DPO) – Billy Gubby is responsible for oversight of data protection compliance, reviewing this policy, advising on data protection issues, and acting as the contact point with supervisory authorities.
  • Employees – All staff are responsible for complying with this policy, following data security measures, and reporting any suspected breaches immediately.
    •  

      Rights of Data Subjects

      • Right to be informed – individuals must be provided with clear and transparent information about processing.
      • Right of access – individuals can request access to their personal data.
      • Right to rectification – individuals can request correction of inaccurate data.
      • Right to erasure – individuals can request deletion of their personal data in certain circumstances.
      • Right to restrict processing – individuals can request restriction of processing in certain cases.
      • Right to data portability – individuals can receive their data in a structured, machine-readable format.
      • Right to object – individuals can object to certain processing, including direct marketing.
      • Rights in relation to automated decision-making and profiling.
        •  

          Security of Processing

          Pinksheep implements appropriate technical and organisational measures, including secure access controls via Microsoft 365 and Microsoft SSO for other software, ESET Protect endpoint security, encryption of devices, role-based permissions, and secure backup procedures. Physical records are stored in locked facilities.

           

          International Data Transfers

          Where personal data is transferred outside the UK or EU, we will ensure adequate protection via adequacy decisions, standard contractual clauses, or other lawful mechanisms in compliance with UK and EU GDPR.

           

          Data Breach Reporting

          All personal data breaches must be reported immediately to the DPO. Where required, the ICO and any relevant EU supervisory authority will be notified within 72 hours. Affected individuals will be informed where the breach is likely to result in a high risk to their rights and freedoms.

           

          Data Retention and Disposal

          Personal data will be retained only for as long as necessary to fulfil its purpose and to comply with legal obligations. Data no longer required will be securely deleted or destroyed in line with our retention schedule.

           

          Accountability and Review

          Pinksheep will maintain records of processing activities, conduct regular audits, provide ongoing training, and review this policy annually or following significant changes to our processing activities or applicable law.

          A PDF copy of this policy is available on request.

Download the free whitepaper

Quickly understand the challenges and the steps to take to work towards a more sustainable future.

We will NEVER spam, rent or sell your information.

This site is protected by reCAPTCHA and the
Google Privacy Policy and Terms of Service apply.