GDPR Compliance Statement
Last Updated: July 13, 2026
Our Commitment to Data Protection
agile-tale.com is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we fulfil our obligations as a data controller.
Data Controller Information
For the purposes of UK data protection law, the data controller is:
agile-tale.com
47 Charter Row
Sheffield S1 3LB
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by UK GDPR:
Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. This applies to course enrolment, delivery of educational services, and related communications.
Legitimate Interests (Article 6(1)(f))
Processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights. Our legitimate interests include:
- Improving educational content and service delivery
- Website analytics and performance optimisation
- Fraud prevention and security
- Internal administrative purposes
Legal Obligation (Article 6(1)(c))
Processing is necessary to comply with legal obligations, including tax reporting, financial record-keeping, and regulatory requirements applicable to educational service providers.
Consent (Article 6(1)(a))
Where we rely on consent, you have the right to withdraw it at any time. This applies to marketing communications and non-essential cookies.
Your Rights Under UK GDPR
Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with supplementary information about the processing.
Right to Rectification (Article 16)
You may request correction of inaccurate personal data and completion of incomplete personal data.
Right to Erasure (Article 17)
In certain circumstances, you may request deletion of your personal data. This right is not absolute and may be limited by legal retention obligations.
Right to Restriction (Article 18)
You may request restriction of processing in specific situations, such as while we verify data accuracy or assess whether our legitimate interests override your objection.
Right to Data Portability (Article 20)
Where processing is based on consent or contract and carried out by automated means, you may receive your personal data in a structured, commonly used format and transmit it to another controller.
Right to Object (Article 21)
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making (Article 22)
We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects.
Exercising Your Rights
To exercise any of your data protection rights, contact us at:
Email: [email protected]
We will respond to valid requests within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
Right to Lodge a Complaint
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and updates
- Staff training on data protection responsibilities
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
International Transfers
We primarily process data within the United Kingdom. If data is transferred internationally, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK government
- Standard contractual clauses approved by the ICO
- Other mechanisms recognised under UK GDPR
Data Protection by Design and Default
We implement data protection principles throughout our systems and processes, including:
- Data minimisation: collecting only necessary information
- Purpose limitation: using data only for specified purposes
- Storage limitation: retaining data no longer than necessary
- Confidentiality and integrity: protecting data against unauthorised access
Updates to This Statement
We review and update this GDPR compliance statement regularly to reflect changes in our practices or legal requirements. The last update date appears at the top of this page.