Skip to content

Legal

GDPR Statement

Last Updated: January 2026

The UK General Data Protection Regulation gives you control over your personal data. This statement explains how Meridian Concepts complies with UK GDPR and protects your rights.

Summary

GDPR at a Glance

Your Data, Your Rights

Access, rectify, erase, or restrict your data at any time.

Transparent Processing

We're clear about what we collect and why we collect it.

Secure Storage

Your data is encrypted and protected against unauthorised access.

Limited Retention

We only keep data for as long as legally or operationally necessary.

For full details, see our Privacy Policy.

Compliance

The Six GDPR Principles

How we uphold each of the core GDPR data protection principles.

01

Lawfulness, Fairness & Transparency

Data must be processed legally, fairly, and transparently.

  • β€”Clear Privacy Policy explaining all data use
  • β€”Valid legal basis for every processing activity
  • β€”No hidden or unexpected data use
  • β€”Open and honest about our practices at all times
02

Purpose Limitation

Data collected only for specific, explicitly stated purposes.

  • β€”Define purposes clearly before collection
  • β€”Inform you of all purposes at the point of collection
  • β€”Never use data for incompatible purposes
  • β€”Seek fresh consent if purposes change
03

Data Minimisation

We only collect what is strictly necessary.

  • β€”Request only essential information
  • β€”No collection of "nice to have" data
  • β€”Regular reviews to eliminate unnecessary fields
  • β€”Optional fields are clearly marked as such
04

Accuracy

Data must be accurate and kept up to date.

  • β€”Mechanisms provided for you to update your data
  • β€”Critical information verified at point of use
  • β€”Inaccuracies corrected promptly on request
  • β€”We encourage you to notify us of any changes
05

Storage Limitation

Data is not kept longer than necessary.

  • β€”Clear retention schedules for all data categories
  • β€”Automatic deletion after retention periods expire
  • β€”Secure data destruction procedures
  • β€”Regular data audits to remove stale records
06

Integrity & Confidentiality

Data must be processed securely at all times.

  • β€”SSL/TLS encryption in transit
  • β€”Secure, access-controlled storage systems
  • β€”Regular staff data protection training
  • β€”Strict internal access controls

Data Subject Rights

Your Rights Under UK GDPR

1

Right to Be Informed

You have the right to clear, accessible information about how we use your personal data.

We provide this through our Privacy Policy, this GDPR Statement, and collection notices at point of data capture.

2

Right of Access

You can request a copy of the personal data we hold about you (Subject Access Request).

We respond within 1 month. This service is free of charge.

3

Right to Rectification

You can request correction of inaccurate or incomplete personal data.

We will act on corrections promptly and within 1 month.

4

Right to Erasure

You can request deletion of your personal data β€” the "right to be forgotten".

Subject to legal retention requirements β€” for example, financial records must be retained for 7 years.

5

Right to Restrict Processing

You can limit how we use your data in certain circumstances.

While restricted, data is stored but not actively processed.

6

Right to Data Portability

You can receive your personal data in a portable, machine-readable format.

Available in CSV, JSON, or PDF. Applies to data processed on the basis of consent or contract.

7

Right to Object

You can object to us processing your data, particularly for direct marketing.

Marketing communications will be stopped immediately on request, no questions asked.

8

Automated Decision-Making Rights

You have protection from decisions made solely by automated means.

We do not use automated decision-making processes that have a significant effect on individuals.

How to Exercise Your Rights

Contact Method

enquiries@meridian-concepts.com

Subject: "GDPR Request β€” [Type]"

Response Time

Within 1 month

We acknowledge within 2 business days

Cost

Free of charge

ID verification may be required

Get in Touch

Contact & Complaints

We'll acknowledge your request within 2 business days and provide a full response within 1 month.

Email Us

enquiries@meridian-concepts.com

Subject: "GDPR Enquiry"

Call Us

+44 (0) XXX XXX XXX

Mon–Fri, 9:00 AM – 5:00 PM GMT

Complain to the ICO

ico.org.uk/make-a-complaint

0303 123 1113