Last updated: 4 August 2026
sage-stoat is committed to compliance with the UK General Data Protection Regulation and the Data Protection Act 2018. This page outlines how we fulfil our obligations as a data controller when processing personal information.
For the purposes of data protection legislation, the data controller is:
sage-stoat
47 Colmore Row
Birmingham
B3 2BS
United Kingdom
Email: [email protected]
We process personal data only where we have a lawful basis to do so. The specific basis depends on the purpose of processing:
You have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data. We will respond to access requests within one month.
You can request correction of inaccurate or incomplete personal data. We will update our records promptly upon verification.
You can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purpose collected or if you withdraw consent. This right is subject to legal and regulatory retention requirements.
You can request that we limit how we use your data in specific situations, such as while we verify accuracy or assess a deletion request.
You can object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we can demonstrate compelling legitimate grounds.
You can request that we transfer your data to another service provider in a structured, commonly used format where technically feasible.
Where processing is based on consent, you can withdraw that consent at any time. This does not affect the lawfulness of processing conducted before withdrawal.
To exercise any of these rights, please contact us by email at [email protected] or by post at the address above. We may need to verify your identity before processing your request.
We adhere to the following data protection principles:
We implement technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by law.
We do not routinely transfer personal data outside the United Kingdom. If international transfer becomes necessary, we will ensure appropriate safeguards are in place as required by data protection legislation.
We do not use automated decision making or profiling in our consultancy services. All assessments and recommendations are made by qualified human consultants.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk
We review this GDPR compliance statement regularly and will notify you of material changes through our website or by email where appropriate.