privacy policy
Privacy Policy
Data protection is a particularly high priority for the management of Martin Design Associates Ltd. It is possible to use the pages of https://martindesignassociates.com without providing personal data. However, if a user wishes to access particular services through our website, the processing of personal data may become necessary. Where processing is necessary and there is no other lawful basis for it, we will generally obtain the data subject’s consent.
The processing of personal data, including a person’s name, address, email address or telephone number, will always be carried out in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable data protection legislation.
Through this Privacy Policy, we aim to inform visitors about the nature, scope and purpose of the personal data we collect, use and process. It also explains the rights available to data subjects.
Martin Design Associates Ltd has implemented appropriate technical and organisational measures to protect personal data processed through this website. However, internet-based data transmissions may have security gaps, meaning absolute protection cannot be guaranteed. Data subjects may therefore contact us using an alternative method, such as by telephone.
1. Definitions
This Privacy Policy uses terminology established under applicable data protection legislation. The following definitions are provided to make this policy clear and understandable.
Personal Data
Personal data means any information relating to an identified or identifiable natural person, known as a data subject. An identifiable person is someone who can be identified directly or indirectly, particularly by reference to information such as a name, identification number, location data, online identifier or factors relating to their physical, physiological, genetic, mental, economic, cultural or social identity.
Data Subject
A data subject is an identified or identifiable natural person whose personal data is processed by the controller.
Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means. This includes collecting, recording, organising, structuring, storing, adapting, altering, retrieving, consulting, using, disclosing, disseminating, aligning, combining, restricting, erasing or destroying personal data.
Restriction of Processing
Restriction of processing means marking stored personal data with the aim of limiting how it may be processed in the future.
Profiling
Profiling means the automated processing of personal data to evaluate certain personal aspects relating to a person. This can include analysing or predicting their performance at work, economic situation, health, preferences, interests, reliability, behaviour, location or movements.
Pseudonymisation
Pseudonymisation means processing personal data so that it can no longer be attributed to a particular data subject without additional information. That additional information must be kept separately and protected through appropriate technical and organisational measures.
Controller
The controller is the natural or legal person, public authority, agency or other body that determines the purposes and means of processing personal data, either alone or jointly with others.
Processor
A processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.
Recipient
A recipient is a person, public authority, agency or other body to whom personal data is disclosed, whether or not they are a third party.
Third Party
A third party is a person, public authority, agency or body other than the data subject, controller, processor or persons authorised to process personal data under the direct authority of the controller or processor.
Consent
Consent means a freely given, specific, informed and unambiguous indication of a data subject’s wishes. Consent is given through a statement or clear affirmative action signifying agreement to the processing of their personal data.
2. Name and Address of the Controller
The controller responsible for processing personal data through this website is:
Martin Design Associates Ltd
4 Fox Oak Park
Common Road
Dunnington
York
YO19 5RZ
Website: https://martindesignassociates.com
Telephone: 01904 488486
3. Cookies
The Martin Design Associates website uses cookies. Cookies are small text files stored on a computer, tablet or mobile device through an internet browser.
Many websites and servers use cookies. Some cookies contain a unique identifier that allows a website to distinguish one browser from another. Cookies can help us provide visitors with a more convenient and user-friendly experience.
Cookies may be used to:
Enable essential website functionality
Remember a visitor’s preferences
Understand how visitors use our website
Improve website content and performance
Provide relevant marketing or advertising, where consent has been given
Support embedded content and third-party services
The law permits us to store cookies on a visitor’s device where they are strictly necessary for the operation of the website. We require permission before placing non-essential cookies.
Visitors can manage or withdraw their cookie consent using the cookie controls available on the website. Cookies can also be restricted or deleted through the settings of the visitor’s internet browser. Disabling particular cookies may affect the functionality of the website.
Consent applies to the following domain:
https://martindesignassociates.com
4. Collection of General Data and Information
The Martin Design Associates website may collect general data and information when a visitor or automated system accesses it. This information may be stored in server log files.
Information collected may include:
The type and version of browser used
The operating system used to access the website
The website from which the visitor arrived
Pages visited within the website
The date and time the website was accessed
The visitor’s internet protocol address
The visitor’s internet service provider
Other similar technical data used to protect our systems
We do not ordinarily use this information to identify individual visitors.
This information may be required to:
Deliver website content correctly
Optimise website content and performance
Maintain the security and reliability of our systems
Identify and respond to technical problems
Provide relevant information to law enforcement authorities following a cyberattack or other unlawful activity
Anonymous or aggregated technical information may be analysed statistically to improve data protection and website security.
5. Contacting Us Through the Website
The Martin Design Associates website contains information that enables visitors to contact us electronically. This may include an email address and online contact forms.
When a data subject contacts us by email or through a contact form, the personal data they provide will be stored and processed for the purposes of responding to their enquiry, communicating with them and providing requested information or services.
The information submitted may include:
Name
Company name
Email address
Telephone number
Project information
The contents of the visitor’s message
Any other information voluntarily provided
Personal data submitted through the website will not be shared with third parties unless this is necessary to respond to the enquiry, deliver a requested service, comply with a legal obligation or protect our legitimate interests.
6. Routine Erasure and Restriction of Personal Data
We will only process and store personal data for as long as it is necessary to fulfil the purpose for which it was collected, meet contractual requirements or comply with a legal or regulatory obligation.
When the reason for retaining personal data no longer applies, or a relevant statutory retention period expires, the information will be securely deleted, anonymised or restricted in accordance with applicable legal requirements.
7. Rights of the Data Subject
Under applicable data protection legislation, data subjects may have the following rights.
Right to Be Informed
Data subjects have the right to receive clear information about how their personal data is collected and used.
Right of Access
Data subjects have the right to request confirmation of whether their personal data is being processed and to receive a copy of the information held about them.
This may include information about:
The purposes of processing
The categories of personal data concerned
The recipients or categories of recipients to whom personal data has been or will be disclosed
How long the personal data is expected to be stored
The right to request correction, deletion or restriction of personal data
The right to object to processing
The right to lodge a complaint with a supervisory authority
The source of personal data not collected directly from the data subject
The existence of automated decision-making or profiling, where applicable
Appropriate safeguards used when transferring information internationally
Right to Rectification
Data subjects have the right to request the correction of inaccurate personal data without undue delay. They may also request that incomplete personal data is completed.
Right to Erasure
Data subjects may have the right to request the deletion of their personal data where:
The information is no longer necessary for the purpose for which it was collected
Consent has been withdrawn and there is no other lawful basis for processing
The data subject successfully objects to the processing
The personal data has been processed unlawfully
The personal data must be deleted to comply with a legal obligation
The personal data was collected in connection with particular online services offered to a child
The right to erasure does not apply in every circumstance. We may continue to retain information where processing is necessary to comply with a legal obligation, exercise freedom of expression, perform a task in the public interest or establish, exercise or defend legal claims.
Right to Restrict Processing
Data subjects may have the right to request that the processing of their personal data is restricted where:
The accuracy of the personal data is disputed
Processing is unlawful and the data subject requests restriction instead of deletion
We no longer require the information, but it is needed to establish, exercise or defend a legal claim
The data subject has objected to processing and the outcome of that objection is still being considered
Right to Data Portability
Where processing is based on consent or a contract and is carried out by automated means, data subjects may have the right to receive personal data they provided in a structured, commonly used and machine-readable format.
They may also have the right to transmit this information to another controller or request that it is transferred directly where technically feasible.
Right to Object
Data subjects may have the right to object to the processing of their personal data where processing is based on legitimate interests or the performance of a task in the public interest.
Where personal data is processed for direct marketing purposes, data subjects have the right to object at any time. Following an objection, their personal data will no longer be processed for direct marketing.
Rights Relating to Automated Decision-Making
Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal or similarly significant effects.
Exceptions may apply where the decision:
Is necessary to enter into or perform a contract
Is authorised by law
Is based on the data subject’s explicit consent
Where an exception applies, appropriate measures will be implemented to protect the data subject’s rights and interests.
Right to Withdraw Consent
Where processing is based on consent, data subjects have the right to withdraw that consent at any time.
Withdrawing consent will not affect the lawfulness of processing undertaken before consent was withdrawn.
Right to Complain
Data subjects have the right to complain to the Information Commissioner’s Office if they are concerned about how their personal data has been handled.
Information Commissioner’s Office
Website: https://ico.org.uk
Telephone: 0303 123 1113
We would appreciate the opportunity to address any concerns directly before a complaint is submitted.
8. Legal Basis for Processing
We will only process personal data where we have a lawful basis for doing so.
The lawful bases we may rely upon include:
Consent
Processing may be based on consent where a data subject has provided a freely given, specific, informed and unambiguous indication of agreement.
Contract
Processing may be necessary to perform a contract with a data subject or to take steps at their request before entering into a contract.
Legal Obligation
Processing may be necessary to comply with a legal or regulatory obligation.
Vital Interests
In rare circumstances, processing may be necessary to protect the vital interests of the data subject or another person.
Public Task
Processing may be necessary to perform a task in the public interest or exercise official authority, where applicable.
Legitimate Interests
Processing may be necessary for the legitimate interests of Martin Design Associates Ltd or a third party, provided those interests are not overridden by the data subject’s interests, rights or freedoms.
9. Legitimate Interests
Where processing is based on legitimate interests, those interests may include:
Operating and managing our business
Responding to enquiries
Communicating with clients and professional contacts
Providing and improving our services
Maintaining accurate business records
Protecting our website, systems and business from misuse
Understanding how visitors use our website
Establishing, exercising or defending legal claims
Before relying on legitimate interests, we will consider the necessity and proportionality of the processing and its potential effect on data subjects.
10. How Long Personal Data Is Stored
Personal data will only be retained for as long as reasonably necessary to fulfil the purposes for which it was collected.
The appropriate retention period will depend on:
The nature and sensitivity of the personal data
The reason it was collected
Whether the purpose can be achieved through other means
Relevant legal, contractual, accounting and reporting requirements
The need to establish, exercise or defend legal claims
When personal data is no longer required, it will be securely deleted or anonymised.
11. Providing Personal Data
In some circumstances, providing personal data may be required by law or necessary to enter into or perform a contract.
If a data subject does not provide information that is required, we may be unable to:
Respond fully to an enquiry
Provide a quotation or proposal
Enter into a contract
Deliver requested services
Comply with a legal or regulatory obligation
Where appropriate, we will explain whether providing particular personal data is mandatory and what may happen if it is not provided.
12. Sharing Personal Data
We may share personal data with carefully selected third parties where this is necessary for the purposes described in this policy.
These parties may include:
Website hosting and technical service providers
IT support providers
Email and communications providers
Professional advisers, including accountants, insurers and legal advisers
Contractors and consultants involved in delivering our services
Analytics and website performance providers
Government bodies, regulators, courts and law enforcement authorities where required by law
Third parties processing personal data on our behalf are required to protect it, maintain confidentiality and only use it in accordance with our instructions and applicable data protection legislation.
We do not sell personal data.
13. International Data Transfers
Some third-party service providers may process or store personal data outside the United Kingdom.
Where personal data is transferred internationally, we will take appropriate steps to ensure it receives an adequate level of protection. This may include relying on an adequacy regulation, approved contractual clauses or another legally recognised safeguard.
14. Data Security
We have implemented appropriate technical and organisational security measures designed to prevent personal data from being accidentally lost, accessed without authorisation, altered, disclosed or used unlawfully.
Access to personal data is limited to employees, contractors and third parties who have a legitimate business need to access it. Those parties are required to process the information securely and maintain confidentiality.
We also maintain procedures for dealing with suspected personal data breaches and will notify affected data subjects and relevant regulators where legally required.
15. External Links
Our website may contain links to third-party websites, services or resources.
We do not control these external websites and are not responsible for their privacy practices. Visitors should review the privacy policy of any external website before submitting personal information.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to our website, services, business operations or legal obligations.
The latest version will always be published on this page. Visitors are encouraged to review it occasionally to remain informed about how personal data is handled.
Last updated: [INSERT DATE]

