Last Updated: June 19, 2026
Our Commitment to GDPR Compliance
agile-spring.com is committed to complying with the General Data Protection Regulation (GDPR) and protecting the personal data of individuals in the European Economic Area (EEA) and the United Kingdom.
Data Controller
For the purposes of GDPR, agile-spring.com acts as the data controller for the personal information we collect through our website and services.
Contact Details:
Email: [email protected]
Address: 42 Buchanan Street, Glasgow G1 3JN, United Kingdom
Types of Data We Process
We process the following categories of personal data:
- Identity Data: First name, last name
- Contact Data: Email address
- Technical Data: IP address, browser type, device information
- Usage Data: Information about how you use our website and services
- Communication Data: Information you provide when contacting us or submitting inquiries
Lawful Basis for Processing
We only process your personal data when we have a lawful basis to do so under GDPR:
- Consent: You have given clear consent for us to process your personal data for a specific purpose
- Contract: The processing is necessary for a contract we have with you or because you have asked us to take specific steps before entering into a contract
- Legal Obligation: The processing is necessary for us to comply with the law
- Legitimate Interests: The processing is necessary for our legitimate interests or the legitimate interests of a third party, unless your interests and fundamental rights override those interests
Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
Right to be Informed
You have the right to be informed about the collection and use of your personal data. This privacy notice and our Privacy Policy provide this information.
Right of Access
You have the right to access your personal data and receive information about how we process it. You can request a copy of your personal data by contacting us.
Right to Rectification
You have the right to have inaccurate personal data corrected or completed if it is incomplete.
Right to Erasure
Also known as the "right to be forgotten," you can request the deletion of your personal data in certain circumstances, such as:
- The personal data is no longer necessary for the purpose we collected it
- You withdraw your consent
- You object to the processing and there are no overriding legitimate grounds
- The personal data was unlawfully processed
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to the processing of your personal data in certain circumstances, particularly when we process data based on legitimate interests.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not currently use automated decision-making processes.
How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two further months where necessary, taking into account the complexity and number of requests.
We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is clearly unfounded, repetitive, or excessive.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Regular backups and disaster recovery procedures
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and applicable legal requirements.
International Data Transfers
Your personal data is primarily processed within the United Kingdom. If we transfer personal data outside the UK or EEA, we will ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Complaints
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
Children's Privacy
Our services are not directed at children under the age of 16, and we do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.
Updates to This Notice
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.